We think we know

Pentest-Tools.com

We think we know how computer systems work, but how come they keep surprising us? We also think we know how humans behave, but we keep finding out we don’t. This podcast is for ethical hackers who are thirsty for challenges and who never settle for easy answers. We challenge some of the best offensive security pros in the world to reveal the unique traits, skills, and real-world experiences that got them where they are today. Get ready to be caught off guard as we debunk misconceptions, dissect wins, and explore what ethical hacking culture teaches us. This is the “We think we know” podcast from Pentest-Tools.com.

  1. We think we know hackers thrive on deep environment knowledge

    09/04/2024

    We think we know hackers thrive on deep environment knowledge

    “Not everything works as configured. Not everyone behaves as trained.” The reality of this statement makes it possible for us, the people in offensive security, to have a job. It also highlights how unpredictable our work can be and how never-ending our learning process is. We work in a space where things are so complex that we need to combine big-picture, higher-level thinking with boost-on-the-ground practice. And our guest today is brilliant at doing just that.  Pete Herzog has spent over two decades distilling the fundamental principles of security testing, turning them into a decade-defining manual - the Open Source Security Testing Methodology Manual (OSSTMM). Pete brings offensive and defensive security concepts together to break down important misconceptions.   Listen to this conversation to uncover: Why you can’t do security without understanding the process behind it [08:23]How automation can help but, at the same time, hurt the ones using it [11:00]Why you can’t rely only on automated security tools in your pentests [19:10]The importance of implementing security controls to change the environment [28:22]Pete’s perspective on "Zero Trust" and how they tackled this ion OSSTMM [35:18]Why he thinks there are “too many parrots, not enough pirates” in this space [43:42]The excitement of researching for OSSTMM v4 and exploring new technologies [51:40]  From the expert systems behind AI-driven tools and their blindspots to generalizations that hurt offensive security outcomes, we explore key elements that shape today’s problems - some of which you’re probably wrestling with as well.  Let’s explore them!

    1h 14m
  2. We think we know our mind is our best hacking tool

    13/02/2024

    We think we know our mind is our best hacking tool

    Inti not only sheds light on what happens when expectations meet reality, but he also shares his unique approach to problem-solving with real-life examples you can add to your own process.  With 12+ years of experience in this space, Inti De Ceukelaire is a Belgian ethical hacker and cybercrime investigator. He currently works as the Chief Hacker Officer at Europe’s largest vulnerability disclosure platform Intigriti and is also a founding member of the Hacker Policy Council. Inti also excelled in various bug bounty competitions, where he’s been rewarded by companies like Google, Meta, Yahoo, The US Department of Defense, or Amazon for identifying critical vulnerabilities in their systems. Dive deeper into this conversation to learn: Why the best hackers started their career by running scripts and trial and error [03:47]Why bug bounty hunters need to nurture their creativity when looking for particular vulns [07:37]What the main differences between bug bounty and pentesting are [09:46]How to impersonate developers as a bug bounty tactic [13:42]Why bug bounty often looks like a rabbit hole [25:24]Why it’s important to define your own success and appreciate your failures [30:33]How AI helps ethical hackers eliminate repetitive and boring tasks [34:19]How deep research can lead to unexpected wins in ethical hacking [43:55]Join us as we explore the intricacies of bug bounties, the crucial role of mindset in hacking, and how to turn every failure into a stepping stone to success.

    48 min
  3. We think we know the value of first principles in offensive security

    02/01/2024

    We think we know the value of first principles in offensive security

    Ready to excel in offensive security this year? Delve into the mind of Vivek Ramachandran, a cybersecurity virtuoso who’s seen (and learned) a lot in this field.  He's a force that fuels both his current company and the broader cybersecurity landscape with original thinking, educational and actionable insights. And there's more to Vivek than just technical savvy. He's on a mission to revolutionize how we view ethical hackers and infosec pros, using his captivating comic books to challenge cliches and spark a new wave of enthusiasm in the next generation. Tune in for this insightful episode with Vivek to find out: Why people mistakenly equate offensive security with functional testing [04:36]How (and why) the Hackers: Superheroes of the Digital Age comics came to be [07:13]Why first principles are essential in mastering and elevating security concepts [12:31]How to build your career on curiosity, gut feeling, generosity, and perseverance [19:33]Why we need human ingenuity as the nature of what we automate changes [29:10]What an entrepreneurial adventure will teach you about yourself - and others [43:45]How being part of the infosec community changes your work, thinking, and career [51:00]Vivek’s vast career is a rich source of inspiration if you’re ready to practice extreme ownership, radical candor, and achieve the kind of alignment between your principles and actions that will propel your work and life to the next level.   Resources from this episode: Vivek on LinkedInVivek’s story in cybersecurityComic books - Hackers: Superheroes of the digital ageVivek on the Philip Wylie ShowAdvanced Wi-Fi security with Vivek at DEF CON 23Training courses on Pentester AcademyOSI model layers

    53 min

Ratings & Reviews

5
out of 5
4 Ratings

About

We think we know how computer systems work, but how come they keep surprising us? We also think we know how humans behave, but we keep finding out we don’t. This podcast is for ethical hackers who are thirsty for challenges and who never settle for easy answers. We challenge some of the best offensive security pros in the world to reveal the unique traits, skills, and real-world experiences that got them where they are today. Get ready to be caught off guard as we debunk misconceptions, dissect wins, and explore what ethical hacking culture teaches us. This is the “We think we know” podcast from Pentest-Tools.com.