<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/atom+xml" href="https://feeds.transistor.fm/classic-bhis-webcasts" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>Classic BHIS Webcasts</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/classic-bhis-webcasts</itunes:new-feed-url>
    <description>Before we started BHIS - Talkin' Bout [infosec] News we had podcast versions of our webcasts. This space is the new home for those classic episodes we've yanked out of the newscast feed. </description>
    <copyright>© 2026 Black Hills Information Security</copyright>
    <podcast:guid>f7c12ad4-87b1-5484-8fe6-9e4a4c555d10</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <language>en</language>
    <pubDate>Mon, 02 Feb 2026 14:26:57 -0500</pubDate>
    <lastBuildDate>Mon, 02 Feb 2026 14:27:11 -0500</lastBuildDate>
    <link>https://bhisclassics.transistor.fm</link>
    <image>
      <url>https://img.transistorcdn.com/Q3HxXyL9VXnBpnPiGVz-KwmDDMupUuwTwlbC3J4P4Ak/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85ODAw/MGZmM2IyNjRiZjE4/ZGNlZjVlZTdiY2Rl/OGM0MC5wbmc.jpg</url>
      <title>Classic BHIS Webcasts</title>
      <link>https://bhisclassics.transistor.fm</link>
    </image>
    <itunes:category text="Education">
      <itunes:category text="How To"/>
    </itunes:category>
    <itunes:type>episodic</itunes:type>
    <itunes:author>Black Hills Information Security</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/Q3HxXyL9VXnBpnPiGVz-KwmDDMupUuwTwlbC3J4P4Ak/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85ODAw/MGZmM2IyNjRiZjE4/ZGNlZjVlZTdiY2Rl/OGM0MC5wbmc.jpg"/>
    <itunes:summary>Before we started BHIS - Talkin' Bout [infosec] News we had podcast versions of our webcasts. This space is the new home for those classic episodes we've yanked out of the newscast feed. </itunes:summary>
    <itunes:subtitle>Before we started BHIS - Talkin' Bout [infosec] News we had podcast versions of our webcasts.</itunes:subtitle>
    <itunes:keywords></itunes:keywords>
    <itunes:owner>
      <itunes:name>Black Hills Information Security</itunes:name>
      <itunes:email>marketing@blackhillsinfosec.com</itunes:email>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>Passwords: You Are the Weakest Link</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Passwords: You Are the Weakest Link</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ca5b1a91-c239-4874-8df7-7ac5f75d7472</guid>
      <link>https://share.transistor.fm/s/51eff1dc</link>
      <description>
        <![CDATA[<p>Why are companies still recommending an 8-character password minimum?  Passwords are some of the easiest targets for attackers, yet companies still allow weak passwords in their environment. Multiple service providers recommend 8-character minimum passwords based on outdated data.  Download Slides: https://www.activecountermeasures.com/presentations </p><p>Chapters<br></p><ul><li>(00:00) - Start</li>
<li>(01:04) - Introduction</li>
<li>(03:26) - In The Beginning</li>
<li>(04:23) - What The Experts Say : PCI</li>
<li>(05:55) - What The Experts Say : Microsoft</li>
<li>(09:29) - What The Experts Say : NIST</li>
<li>(16:01) - What The Experts Say : Google</li>
<li>(16:28) - What The Experts Say : Apple</li>
<li>(16:42) - Still More Experts</li>
<li>(17:49) - Why 15 Characters</li>
<li>(18:06) - Brute Force</li>
<li>(18:44) - Password Spray</li>
<li>(22:48) - Password Cracking</li>
<li>(23:25) - A Hashing Algorithm</li>
<li>(24:07) - More About Hashes</li>
<li>(25:49) - So What Is Password Cracking</li>
<li>(27:16) - Windows Hashes</li>
<li>(27:42) - The LM Hashing Algorithm</li>
<li>(29:46) - LM Hash Is "Weak"</li>
<li>(30:55) - LM Vs. NTLM Cracking</li>
<li>(31:14) - Why 15 Character Passwords – Answer</li>
<li>(32:06) - CJ's Response to the Problem</li>
<li>(36:32) - Let's See the Mathm</li>
<li>(37:09) - Math Examples</li>
<li>(40:30) - From the Field</li>
<li>(42:47) - Would You Like To Play A Game?</li>
<li>(45:03) - Take Aways</li>
<li>(46:46) - Are You Really Going To Let This Guy Decide</li>
<li>(48:33) - Audience Questions &amp; Comments</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Why are companies still recommending an 8-character password minimum?  Passwords are some of the easiest targets for attackers, yet companies still allow weak passwords in their environment. Multiple service providers recommend 8-character minimum passwords based on outdated data.  Download Slides: https://www.activecountermeasures.com/presentations </p><p>Chapters<br></p><ul><li>(00:00) - Start</li>
<li>(01:04) - Introduction</li>
<li>(03:26) - In The Beginning</li>
<li>(04:23) - What The Experts Say : PCI</li>
<li>(05:55) - What The Experts Say : Microsoft</li>
<li>(09:29) - What The Experts Say : NIST</li>
<li>(16:01) - What The Experts Say : Google</li>
<li>(16:28) - What The Experts Say : Apple</li>
<li>(16:42) - Still More Experts</li>
<li>(17:49) - Why 15 Characters</li>
<li>(18:06) - Brute Force</li>
<li>(18:44) - Password Spray</li>
<li>(22:48) - Password Cracking</li>
<li>(23:25) - A Hashing Algorithm</li>
<li>(24:07) - More About Hashes</li>
<li>(25:49) - So What Is Password Cracking</li>
<li>(27:16) - Windows Hashes</li>
<li>(27:42) - The LM Hashing Algorithm</li>
<li>(29:46) - LM Hash Is "Weak"</li>
<li>(30:55) - LM Vs. NTLM Cracking</li>
<li>(31:14) - Why 15 Character Passwords – Answer</li>
<li>(32:06) - CJ's Response to the Problem</li>
<li>(36:32) - Let's See the Mathm</li>
<li>(37:09) - Math Examples</li>
<li>(40:30) - From the Field</li>
<li>(42:47) - Would You Like To Play A Game?</li>
<li>(45:03) - Take Aways</li>
<li>(46:46) - Are You Really Going To Let This Guy Decide</li>
<li>(48:33) - Audience Questions &amp; Comments</li>
</ul>]]>
      </content:encoded>
      <pubDate>Mon, 16 Dec 2019 11:07:00 -0500</pubDate>
      <author>Black Hills Information Security</author>
      <enclosure url="https://media.transistor.fm/51eff1dc/9e8ab6de.mp3" length="33502931" type="audio/mpeg"/>
      <itunes:author>Black Hills Information Security</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ZLT2N9fPg-Yl-g6g3J3FPNLpJu2CPWQFeHlT8rGKvtY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yZWNm/MDg4OGNlZGI3Njg4/M2I1MTE1NzY3Mjkz/NjY5ZC5qcGc.jpg"/>
      <itunes:duration>3615</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Why are companies still recommending an 8-character password minimum?  Passwords are some of the easiest targets for attackers, yet companies still allow weak passwords in their environment. Multiple service providers recommend 8-character minimum passwords based on outdated data.  Download Slides: https://www.activecountermeasures.com/presentations </p><p>Chapters<br></p><ul><li>(00:00) - Start</li>
<li>(01:04) - Introduction</li>
<li>(03:26) - In The Beginning</li>
<li>(04:23) - What The Experts Say : PCI</li>
<li>(05:55) - What The Experts Say : Microsoft</li>
<li>(09:29) - What The Experts Say : NIST</li>
<li>(16:01) - What The Experts Say : Google</li>
<li>(16:28) - What The Experts Say : Apple</li>
<li>(16:42) - Still More Experts</li>
<li>(17:49) - Why 15 Characters</li>
<li>(18:06) - Brute Force</li>
<li>(18:44) - Password Spray</li>
<li>(22:48) - Password Cracking</li>
<li>(23:25) - A Hashing Algorithm</li>
<li>(24:07) - More About Hashes</li>
<li>(25:49) - So What Is Password Cracking</li>
<li>(27:16) - Windows Hashes</li>
<li>(27:42) - The LM Hashing Algorithm</li>
<li>(29:46) - LM Hash Is "Weak"</li>
<li>(30:55) - LM Vs. NTLM Cracking</li>
<li>(31:14) - Why 15 Character Passwords – Answer</li>
<li>(32:06) - CJ's Response to the Problem</li>
<li>(36:32) - Let's See the Mathm</li>
<li>(37:09) - Math Examples</li>
<li>(40:30) - From the Field</li>
<li>(42:47) - Would You Like To Play A Game?</li>
<li>(45:03) - Take Aways</li>
<li>(46:46) - Are You Really Going To Let This Guy Decide</li>
<li>(48:33) - Audience Questions &amp; Comments</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:chapters url="https://share.transistor.fm/s/51eff1dc/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Attack Tactics: Part 3! No Active Directory? No Problem!!</title>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>Attack Tactics: Part 3! No Active Directory? No Problem!!</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6a1df351-b882-4f49-ba3d-01d841943f36</guid>
      <link>https://share.transistor.fm/s/db8c2a8d</link>
      <description>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Reach out to Black Hills Infosec if you need pentesting, threat hunting, ACTIVE SOC, incident response, or blue team services -- https://www.blackhillsinfosec.com/ </p><p>00:00 - Preshow Announcements<br>03:27 - Disclaimer<br>07:30 BYOD and Cloud; Network Blocks<br>12:41 - Eyewitness<br>17:11 - Shodan/ images.shodan.io<br>24:30 - Scraping Users with Google and Burp; Password Spraying<br>30:22 - Attacking Google 2FA; Phishing Ruse<br>35:03 - Credsniper<br>42:14 - Getting Documents; Changing Firewall<br>45:02 - Takeaways<br>49:27 - Q&amp;A </p><p>Description: For this next installment of our Attack Tactics webcast series, John Strand looks at an environment that had no Active Directory. This is odd, but it's becoming more and more common for new companies to have everything in the "cloud" and everything BYOD. This is also a great case-study on how to access services like Git, Slack, Gsuites, Salesforce and so on, because even if you are still using AD, you WILL be moving to the cloud. This webcast is for everyone.</p><p>Finally, as testers, we need to evolve our testing to be able to successfully test these cloud services. This means we all need to up our game and be ready for the next round of cloud-based enterprise technologies!</p><p>Slides can be found here: https://www.blackhillsinfosec.com/webcast-attack-tactics-3/</p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis</p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/ </p><p>#bhis #infosec</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Reach out to Black Hills Infosec if you need pentesting, threat hunting, ACTIVE SOC, incident response, or blue team services -- https://www.blackhillsinfosec.com/ </p><p>00:00 - Preshow Announcements<br>03:27 - Disclaimer<br>07:30 BYOD and Cloud; Network Blocks<br>12:41 - Eyewitness<br>17:11 - Shodan/ images.shodan.io<br>24:30 - Scraping Users with Google and Burp; Password Spraying<br>30:22 - Attacking Google 2FA; Phishing Ruse<br>35:03 - Credsniper<br>42:14 - Getting Documents; Changing Firewall<br>45:02 - Takeaways<br>49:27 - Q&amp;A </p><p>Description: For this next installment of our Attack Tactics webcast series, John Strand looks at an environment that had no Active Directory. This is odd, but it's becoming more and more common for new companies to have everything in the "cloud" and everything BYOD. This is also a great case-study on how to access services like Git, Slack, Gsuites, Salesforce and so on, because even if you are still using AD, you WILL be moving to the cloud. This webcast is for everyone.</p><p>Finally, as testers, we need to evolve our testing to be able to successfully test these cloud services. This means we all need to up our game and be ready for the next round of cloud-based enterprise technologies!</p><p>Slides can be found here: https://www.blackhillsinfosec.com/webcast-attack-tactics-3/</p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis</p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/ </p><p>#bhis #infosec</p>]]>
      </content:encoded>
      <pubDate>Mon, 16 Jul 2018 09:21:00 -0400</pubDate>
      <author>Black Hills Information Security</author>
      <enclosure url="https://media.transistor.fm/db8c2a8d/e043c97f.mp3" length="71318653" type="audio/mpeg"/>
      <itunes:author>Black Hills Information Security</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/qzljceLy4DLoxUZXho7p090Rn-OaHtUo4Ad0n9VrOOI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NjZm/ZjgyZWQyNDM0NmNh/MGFjY2EzYWU5ZjA5/MDkxMC5wbmc.jpg"/>
      <itunes:duration>2955</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Reach out to Black Hills Infosec if you need pentesting, threat hunting, ACTIVE SOC, incident response, or blue team services -- https://www.blackhillsinfosec.com/ </p><p>00:00 - Preshow Announcements<br>03:27 - Disclaimer<br>07:30 BYOD and Cloud; Network Blocks<br>12:41 - Eyewitness<br>17:11 - Shodan/ images.shodan.io<br>24:30 - Scraping Users with Google and Burp; Password Spraying<br>30:22 - Attacking Google 2FA; Phishing Ruse<br>35:03 - Credsniper<br>42:14 - Getting Documents; Changing Firewall<br>45:02 - Takeaways<br>49:27 - Q&amp;A </p><p>Description: For this next installment of our Attack Tactics webcast series, John Strand looks at an environment that had no Active Directory. This is odd, but it's becoming more and more common for new companies to have everything in the "cloud" and everything BYOD. This is also a great case-study on how to access services like Git, Slack, Gsuites, Salesforce and so on, because even if you are still using AD, you WILL be moving to the cloud. This webcast is for everyone.</p><p>Finally, as testers, we need to evolve our testing to be able to successfully test these cloud services. This means we all need to up our game and be ready for the next round of cloud-based enterprise technologies!</p><p>Slides can be found here: https://www.blackhillsinfosec.com/webcast-attack-tactics-3/</p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis</p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/ </p><p>#bhis #infosec</p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:chapters url="https://share.transistor.fm/s/db8c2a8d/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>PODCAST: Lee Kagan &amp; Beau Bullock talk C2</title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>PODCAST: Lee Kagan &amp; Beau Bullock talk C2</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">40d96afa-4480-46eb-90c2-6c4ddc06ab0a</guid>
      <link>https://share.transistor.fm/s/f0d26cc2</link>
      <description>
        <![CDATA[<p>Special guest Lee Kagan from RedBlack Security talks about his script, his previous guest posts and the future of C2 with Beau Bullock and Sierra.</p><p>Check out these links:</p><p><a href="https://www.blackhillsinfosec.com/build-c2-infrastructure-digital-ocean-part-1/"><strong>How to Build a C2 Infrastructure with Digital Ocean – Part 1<br></strong></a><br></p><p><a href="https://www.blackhillsinfosec.com/how-to-build-a-command-control-infrastructure-with-digital-ocean-c2k-revamped/"><strong>How to Build a C2 Infrastructure with Digital Ocean – C2K Revamped<br></strong></a><br></p><p><a href="https://github.com/dafthack"><strong>Beau Bullock’s github</strong></a>: MailSniper, PassphraseGen et al</p><p><a href="https://github.com/invokethreatguy"><strong>Lee Kagan’s github</strong></a>: C2Kv2</p><p><a href="http://www.wildwesthackinfest.com/"><strong>Wild West Hackin’ Fest</strong></a> – our annual information security conference in Deadwood, South Dakota!</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Special guest Lee Kagan from RedBlack Security talks about his script, his previous guest posts and the future of C2 with Beau Bullock and Sierra.</p><p>Check out these links:</p><p><a href="https://www.blackhillsinfosec.com/build-c2-infrastructure-digital-ocean-part-1/"><strong>How to Build a C2 Infrastructure with Digital Ocean – Part 1<br></strong></a><br></p><p><a href="https://www.blackhillsinfosec.com/how-to-build-a-command-control-infrastructure-with-digital-ocean-c2k-revamped/"><strong>How to Build a C2 Infrastructure with Digital Ocean – C2K Revamped<br></strong></a><br></p><p><a href="https://github.com/dafthack"><strong>Beau Bullock’s github</strong></a>: MailSniper, PassphraseGen et al</p><p><a href="https://github.com/invokethreatguy"><strong>Lee Kagan’s github</strong></a>: C2Kv2</p><p><a href="http://www.wildwesthackinfest.com/"><strong>Wild West Hackin’ Fest</strong></a> – our annual information security conference in Deadwood, South Dakota!</p>]]>
      </content:encoded>
      <pubDate>Thu, 12 Jul 2018 09:57:00 -0400</pubDate>
      <author>Black Hills Information Security</author>
      <enclosure url="https://media.transistor.fm/f0d26cc2/560b01a8.mp3" length="64221950" type="audio/mpeg"/>
      <itunes:author>Black Hills Information Security</itunes:author>
      <itunes:duration>2674</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Special guest Lee Kagan from RedBlack Security talks about his script, his previous guest posts and the future of C2 with Beau Bullock and Sierra.</p><p>Check out these links:</p><p><a href="https://www.blackhillsinfosec.com/build-c2-infrastructure-digital-ocean-part-1/"><strong>How to Build a C2 Infrastructure with Digital Ocean – Part 1<br></strong></a><br></p><p><a href="https://www.blackhillsinfosec.com/how-to-build-a-command-control-infrastructure-with-digital-ocean-c2k-revamped/"><strong>How to Build a C2 Infrastructure with Digital Ocean – C2K Revamped<br></strong></a><br></p><p><a href="https://github.com/dafthack"><strong>Beau Bullock’s github</strong></a>: MailSniper, PassphraseGen et al</p><p><a href="https://github.com/invokethreatguy"><strong>Lee Kagan’s github</strong></a>: C2Kv2</p><p><a href="http://www.wildwesthackinfest.com/"><strong>Wild West Hackin’ Fest</strong></a> – our annual information security conference in Deadwood, South Dakota!</p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Hacker Tools: Compliments of Microsoft</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>Hacker Tools: Compliments of Microsoft</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">acde1f0b-0383-485a-9484-ea6bfd839f55</guid>
      <link>https://share.transistor.fm/s/8bd9ad7f</link>
      <description>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Join David "Fletch" and Sally as they explore the cornucopia of wonderful, free tools in the SysInternals Suite that conveniently are signed by Microsoft and that they use on a daily basis to hack their customers.</p><p><br>🔗 Register for FREE Infosec Webcasts, Anti-casts &amp; Summits – <br><a href="https://poweredbybhis.com">https://poweredbybhis.com</a> </p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis</p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ </p><p>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Join David "Fletch" and Sally as they explore the cornucopia of wonderful, free tools in the SysInternals Suite that conveniently are signed by Microsoft and that they use on a daily basis to hack their customers.</p><p><br>🔗 Register for FREE Infosec Webcasts, Anti-casts &amp; Summits – <br><a href="https://poweredbybhis.com">https://poweredbybhis.com</a> </p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis</p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ </p><p>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining</p>]]>
      </content:encoded>
      <pubDate>Mon, 02 Jul 2018 12:21:00 -0400</pubDate>
      <author>Black Hills Information Security</author>
      <enclosure url="https://media.transistor.fm/8bd9ad7f/3512a995.mp3" length="74561436" type="audio/mpeg"/>
      <itunes:author>Black Hills Information Security</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/xI_36VJtRk92NUBkpaZ0kGTp5oVdHYnRXovs9WA_K0E/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83ZjVh/MWQxY2YyOGZhZWM0/ODI0YTY2NWY3YmY5/MzgzYS5qcGc.jpg"/>
      <itunes:duration>3088</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Join David "Fletch" and Sally as they explore the cornucopia of wonderful, free tools in the SysInternals Suite that conveniently are signed by Microsoft and that they use on a daily basis to hack their customers.</p><p><br>🔗 Register for FREE Infosec Webcasts, Anti-casts &amp; Summits – <br><a href="https://poweredbybhis.com">https://poweredbybhis.com</a> </p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis</p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ </p><p>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining</p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Testing G Suites with MailSniper</title>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>Testing G Suites with MailSniper</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">cba9d5b8-ce8a-44d3-a3cc-fb8c33cfba89</guid>
      <link>https://share.transistor.fm/s/161a7526</link>
      <description>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Reach out to Black Hills Infosec if you need pentesting, threat hunting, ACTIVE SOC, incident response, or blue team services -- https://www.blackhillsinfosec.com/ </p><p>Chapters<br></p><ul><li>(00:00) - Intro</li>
<li>(01:00) - Overview</li>
<li>(02:48) - Email</li>
<li>(09:15) - Google Capture</li>
<li>(13:36) - Duo TwoFactor</li>
<li>(16:15) - Proxy Cannon</li>
<li>(17:56) - SOCAT</li>
<li>(18:39) - Demo</li>
<li>(22:28) - Password Spraying</li>
<li>(26:47) -  Invoke Username Harvest</li>
<li>(28:56) - Invoke Spray Gmail</li>
<li>(34:16) - PowerShell Oneliner</li>
<li>(35:47) - MailSniper Repository</li>
<li>(36:40) - Tools for Metadata</li>
<li>(38:40) - PowerMeta</li>
<li>(39:20) - SSO</li>
<li>(40:53) - Google API</li>
<li>(41:26) - Does MailSniper work with Office365</li>
<li>(42:32) - Does MailSniper work with G Suites</li>
<li>(44:18) - Will Microsoft shut down GitHub</li>
</ul><br>Join Matt Toussain as he talks about Mailsniper, a tool written by our very own Beau Bullock. Wouldn't you like to START your pen tests knowing every username for all the individuals in your target environment? Gmail, G Suite, Outlook Web Access, Exchange Web Services... Email. A divine gift issued to hackers with no statute of limitations. In this webcast, we explore an exploitation workflow using new features of the MailSniper toolkit testing G Suite. <p>In addition to leveraging G Suites as an Information disclosure engine, we explore the signaling involved with the Google Accounts authentication API. This allows us to observe and bypass protections Google attempts to implement such as Captchas and even 2FA. We close out with a demonstration of mass account enumeration and password guessing attacks!</p><p>Slides available here: https://www.blackhillsinfosec.com/webcast-testing-g-suites-with-mailsniper/ </p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis<br> <br>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections <br> <br>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ <br> <br>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ <br> <br>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/ </p><p>#bhis  #infosec</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Reach out to Black Hills Infosec if you need pentesting, threat hunting, ACTIVE SOC, incident response, or blue team services -- https://www.blackhillsinfosec.com/ </p><p>Chapters<br></p><ul><li>(00:00) - Intro</li>
<li>(01:00) - Overview</li>
<li>(02:48) - Email</li>
<li>(09:15) - Google Capture</li>
<li>(13:36) - Duo TwoFactor</li>
<li>(16:15) - Proxy Cannon</li>
<li>(17:56) - SOCAT</li>
<li>(18:39) - Demo</li>
<li>(22:28) - Password Spraying</li>
<li>(26:47) -  Invoke Username Harvest</li>
<li>(28:56) - Invoke Spray Gmail</li>
<li>(34:16) - PowerShell Oneliner</li>
<li>(35:47) - MailSniper Repository</li>
<li>(36:40) - Tools for Metadata</li>
<li>(38:40) - PowerMeta</li>
<li>(39:20) - SSO</li>
<li>(40:53) - Google API</li>
<li>(41:26) - Does MailSniper work with Office365</li>
<li>(42:32) - Does MailSniper work with G Suites</li>
<li>(44:18) - Will Microsoft shut down GitHub</li>
</ul><br>Join Matt Toussain as he talks about Mailsniper, a tool written by our very own Beau Bullock. Wouldn't you like to START your pen tests knowing every username for all the individuals in your target environment? Gmail, G Suite, Outlook Web Access, Exchange Web Services... Email. A divine gift issued to hackers with no statute of limitations. In this webcast, we explore an exploitation workflow using new features of the MailSniper toolkit testing G Suite. <p>In addition to leveraging G Suites as an Information disclosure engine, we explore the signaling involved with the Google Accounts authentication API. This allows us to observe and bypass protections Google attempts to implement such as Captchas and even 2FA. We close out with a demonstration of mass account enumeration and password guessing attacks!</p><p>Slides available here: https://www.blackhillsinfosec.com/webcast-testing-g-suites-with-mailsniper/ </p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis<br> <br>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections <br> <br>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ <br> <br>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ <br> <br>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/ </p><p>#bhis  #infosec</p>]]>
      </content:encoded>
      <pubDate>Wed, 20 Jun 2018 09:02:00 -0400</pubDate>
      <author>Black Hills Information Security</author>
      <enclosure url="https://media.transistor.fm/161a7526/76f67fe1.mp3" length="68072505" type="audio/mpeg"/>
      <itunes:author>Black Hills Information Security</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/_3BQAnB5Ub1zrG9Fl3pt8FEIAsqWBC8RoOteo_ljYM8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zYWYy/N2ZkYTNkYzc0YmEy/OGY2OTk3NTg3YTg2/ZjFhZS5wbmc.jpg"/>
      <itunes:duration>2816</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Reach out to Black Hills Infosec if you need pentesting, threat hunting, ACTIVE SOC, incident response, or blue team services -- https://www.blackhillsinfosec.com/ </p><p>Chapters<br></p><ul><li>(00:00) - Intro</li>
<li>(01:00) - Overview</li>
<li>(02:48) - Email</li>
<li>(09:15) - Google Capture</li>
<li>(13:36) - Duo TwoFactor</li>
<li>(16:15) - Proxy Cannon</li>
<li>(17:56) - SOCAT</li>
<li>(18:39) - Demo</li>
<li>(22:28) - Password Spraying</li>
<li>(26:47) -  Invoke Username Harvest</li>
<li>(28:56) - Invoke Spray Gmail</li>
<li>(34:16) - PowerShell Oneliner</li>
<li>(35:47) - MailSniper Repository</li>
<li>(36:40) - Tools for Metadata</li>
<li>(38:40) - PowerMeta</li>
<li>(39:20) - SSO</li>
<li>(40:53) - Google API</li>
<li>(41:26) - Does MailSniper work with Office365</li>
<li>(42:32) - Does MailSniper work with G Suites</li>
<li>(44:18) - Will Microsoft shut down GitHub</li>
</ul><br>Join Matt Toussain as he talks about Mailsniper, a tool written by our very own Beau Bullock. Wouldn't you like to START your pen tests knowing every username for all the individuals in your target environment? Gmail, G Suite, Outlook Web Access, Exchange Web Services... Email. A divine gift issued to hackers with no statute of limitations. In this webcast, we explore an exploitation workflow using new features of the MailSniper toolkit testing G Suite. <p>In addition to leveraging G Suites as an Information disclosure engine, we explore the signaling involved with the Google Accounts authentication API. This allows us to observe and bypass protections Google attempts to implement such as Captchas and even 2FA. We close out with a demonstration of mass account enumeration and password guessing attacks!</p><p>Slides available here: https://www.blackhillsinfosec.com/webcast-testing-g-suites-with-mailsniper/ </p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/bhis<br> <br>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections <br> <br>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ <br> <br>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ <br> <br>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/ </p><p>#bhis  #infosec</p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:chapters url="https://share.transistor.fm/s/161a7526/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Attack Tactics Part 2</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Attack Tactics Part 2</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9f51ccbb-98cc-404a-9589-3b159f76c19c</guid>
      <link>https://share.transistor.fm/s/4ad5aebf</link>
      <description>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Learn active defense cyber deception with John Strand from Antisyphon <br>Training: https://www.antisyphontraining.com/active-defense-cyber-deception-w-john-strand/</p><p>00:00 - Preshow Announcements <br>03:00 - Overview<br>04:51 - Defense against recon<br>10:56 - Other recon findings<br>11:11 - First and second attempts; Defense<br>22:30 - John Strand Snowball of Pain<br>25:23 - Password Spray<br>34:45 - OWA Access; Defense<br>36:55 - OWA Access and Pull down the Global Address List; Looking for VPN Instructions; Defense<br>45:24 - Mailsniper Searching/Defense; VPN Access Defense; Honeybadger<br>49:57 - Defense against Domain Recon/SIM; Kerberoasting/GPP and Defense<br>53:54 - Using Creds and Moving Laterally/Defense<br>57:16 - Secondary C2 Defense<br>58:30 - Tips </p><p>Description: This is the second part of John's series about Attack Tactics. In the first part we discussed how we'd attack. Now, we cover the same attack, but this time we are covering the defensive components the organization could have implemented to stop us every step of the way. </p><p>"We cover event logs, new vendors, SIEM, UBEA and yes... I hate to say it... Cyber Kill Chain. Remember, the goal is to make your next pentester cry; to make hackers give up and most importantly to have puppies and kittens everywhere love you." - John</p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/ffzdt3WUDe </p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — <br>Wild West Hackin' Fest: https://wildwesthackinfest.com/</p><p>#bhis #infosec</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Learn active defense cyber deception with John Strand from Antisyphon <br>Training: https://www.antisyphontraining.com/active-defense-cyber-deception-w-john-strand/</p><p>00:00 - Preshow Announcements <br>03:00 - Overview<br>04:51 - Defense against recon<br>10:56 - Other recon findings<br>11:11 - First and second attempts; Defense<br>22:30 - John Strand Snowball of Pain<br>25:23 - Password Spray<br>34:45 - OWA Access; Defense<br>36:55 - OWA Access and Pull down the Global Address List; Looking for VPN Instructions; Defense<br>45:24 - Mailsniper Searching/Defense; VPN Access Defense; Honeybadger<br>49:57 - Defense against Domain Recon/SIM; Kerberoasting/GPP and Defense<br>53:54 - Using Creds and Moving Laterally/Defense<br>57:16 - Secondary C2 Defense<br>58:30 - Tips </p><p>Description: This is the second part of John's series about Attack Tactics. In the first part we discussed how we'd attack. Now, we cover the same attack, but this time we are covering the defensive components the organization could have implemented to stop us every step of the way. </p><p>"We cover event logs, new vendors, SIEM, UBEA and yes... I hate to say it... Cyber Kill Chain. Remember, the goal is to make your next pentester cry; to make hackers give up and most importantly to have puppies and kittens everywhere love you." - John</p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/ffzdt3WUDe </p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — <br>Wild West Hackin' Fest: https://wildwesthackinfest.com/</p><p>#bhis #infosec</p>]]>
      </content:encoded>
      <pubDate>Wed, 13 Jun 2018 09:36:00 -0400</pubDate>
      <author>Black Hills Information Security</author>
      <enclosure url="https://media.transistor.fm/4ad5aebf/47f311ac.mp3" length="88908718" type="audio/mpeg"/>
      <itunes:author>Black Hills Information Security</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ohUYrIY0Pu_rFc3kVt7G7YCvwBTnR6yCsP4XU4gBtos/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82ZWZj/OGI1YWI5OGZhZTJh/NmI5ZjJlMWU4MmYx/ZjNmYy5wbmc.jpg"/>
      <itunes:duration>3683</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! </p><p>Learn active defense cyber deception with John Strand from Antisyphon <br>Training: https://www.antisyphontraining.com/active-defense-cyber-deception-w-john-strand/</p><p>00:00 - Preshow Announcements <br>03:00 - Overview<br>04:51 - Defense against recon<br>10:56 - Other recon findings<br>11:11 - First and second attempts; Defense<br>22:30 - John Strand Snowball of Pain<br>25:23 - Password Spray<br>34:45 - OWA Access; Defense<br>36:55 - OWA Access and Pull down the Global Address List; Looking for VPN Instructions; Defense<br>45:24 - Mailsniper Searching/Defense; VPN Access Defense; Honeybadger<br>49:57 - Defense against Domain Recon/SIM; Kerberoasting/GPP and Defense<br>53:54 - Using Creds and Moving Laterally/Defense<br>57:16 - Secondary C2 Defense<br>58:30 - Tips </p><p>Description: This is the second part of John's series about Attack Tactics. In the first part we discussed how we'd attack. Now, we cover the same attack, but this time we are covering the defensive components the organization could have implemented to stop us every step of the way. </p><p>"We cover event logs, new vendors, SIEM, UBEA and yes... I hate to say it... Cyber Kill Chain. Remember, the goal is to make your next pentester cry; to make hackers give up and most importantly to have puppies and kittens everywhere love you." - John</p><p>Black Hills Infosec Socials <br>Twitter: https://twitter.com/BHinfoSecurity <br>Mastodon: https://infosec.exchange/@blackhillsinfosec <br>LinkedIn: https://www.linkedin.com/company/antisyphon-training <br>Discord: https://discord.gg/ffzdt3WUDe </p><p>Black Hills Infosec Shirts &amp; Hoodies <br>https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections </p><p>Black Hills Infosec Services <br>Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ <br>Penetration Testing: https://www.blackhillsinfosec.com/services/ <br>Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ </p><p>Backdoors &amp; Breaches - Incident Response Card Game <br>Backdoors &amp; Breaches: https://www.backdoorsandbreaches.com/ <br>Play B&amp;B Online: https://play.backdoorsandbreaches.com/ <br> <br>Antisyphon Training <br>Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ <br>Live Training: https://www.antisyphontraining.com/course-catalog/ <br>On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ </p><p>Educational Infosec Content <br>Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ <br>Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest <br>Active Countermeasures YouTube: https://youtube.com/activecountermeasures <br>Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining </p><p>Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — <br>Wild West Hackin' Fest: https://wildwesthackinfest.com/</p><p>#bhis #infosec</p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:chapters url="https://share.transistor.fm/s/4ad5aebf/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Attack Tactics Part 1</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>Attack Tactics Part 1</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8ed18c69-359d-4f1d-bc48-175bb95f39b9</guid>
      <link>https://share.transistor.fm/s/ac3123c4</link>
      <description>
        <![CDATA[<p>John is starting a new series of webcasts called Attack Tactics. This first part  is a step-by-step walk-through of an attack BHIS launched against a customer, with just a few obfuscating tweaks. He covers the tools, how we used them and any other tricks we had to pull out for the attack.</p><p>The second will be co-hosted by our sister company Active Countermeasures and will go through the defensive side. Stay tuned for more details about that!</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>John is starting a new series of webcasts called Attack Tactics. This first part  is a step-by-step walk-through of an attack BHIS launched against a customer, with just a few obfuscating tweaks. He covers the tools, how we used them and any other tricks we had to pull out for the attack.</p><p>The second will be co-hosted by our sister company Active Countermeasures and will go through the defensive side. Stay tuned for more details about that!</p>]]>
      </content:encoded>
      <pubDate>Mon, 04 Jun 2018 08:27:00 -0400</pubDate>
      <author>Black Hills Information Security</author>
      <enclosure url="https://media.transistor.fm/ac3123c4/37457670.mp3" length="79269924" type="audio/mpeg"/>
      <itunes:author>Black Hills Information Security</itunes:author>
      <itunes:duration>3300</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>John is starting a new series of webcasts called Attack Tactics. This first part  is a step-by-step walk-through of an attack BHIS launched against a customer, with just a few obfuscating tweaks. He covers the tools, how we used them and any other tricks we had to pull out for the attack.</p><p>The second will be co-hosted by our sister company Active Countermeasures and will go through the defensive side. Stay tuned for more details about that!</p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/ac3123c4/transcript.vtt" type="text/vtt" rel="captions"/>
    </item>
  </channel>
</rss>
