SECTION 9 Cyber Security
Technology Podcasts
Just two people trying to do IT and Security the right way.
Location:
United States
Description:
Just two people trying to do IT and Security the right way.
Language:
English
Website:
https://section9.us/podcast/
Episodes
The NIST Cyber Security Framework
4/3/2023
Time to start looking into cyber security frameworks. For this episode we’re looking at the the NIST Cyber Security Framework. We’re also explaining what a cyber security framework is and how they can help.
LINKS
1. NIST Cyber Security Framework (CSF)
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:30:31
Time For a Maintenance Review - 259
3/6/2023
Time for another maintenance episode where we review our systems and management process. This time were looking at our Digital Ocean servers, Automox patch management, Fortinet Firewalls, and the password manager Bitwarden.
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:23:44
How do you roast a server to death? - 258
1/16/2023
Almost roasted our VMware server to death. Don’t do what I did. Enjoy!
LINKS
1. VMware Server: Super Micro SYS-E300-9D-8CN8TP
2. Fans: Noctua NF-A4x20 PWM
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:11:10
How do we evaluate the LastPass hack for Section 9? - 257
1/9/2023
LastPass was hacked last year. As LastPass customers we need to evaluate the impact that has on Section 9. Should we continue to use the product? Should we migrate to a different password manager? How do we evaluate a password manager?
Consider this the start of a longer conversation about LastPass and password managers.
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:30:25
SANS and BHIS Videos for Hacking - 256
12/11/2022
Found some really interesting and helpful videos. One walks you through an Active Directory hacking lab. Another talks about default configurations and bad passwords as a way to hack into systems. The last one is about building a home lab.
These are just what I needed.
LINKS
1. SANS Workshop – NTLM Relaying 101: How Internal Pentesters Compromise Domains
2. The Top $ num Reasons You Got Hacked in 2022 with Kent & Jordan | 1 Hour
3. How to Build a Home Lab for Infosec with Ralph May | 1 Hour
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:24:23
The Active Directory Lab - 255
11/21/2022
Found a video that walks you through the process of setting up an Active Directory Lab for hacking. I wouldn’t be able to do this without a starting point.
LINKS
1. Mitre ATT&CK Matrix
2. How to Build an Active Directory Hacking Lab
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:20:55
Using the MITRE ATT&CK Matrix in a lab - 254
11/7/2022
Last episode was about my crazy study plan, or lack of one. Time to put together a proper study plan. One that works.
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:21:35
A Better Study Plan - 253
10/10/2022
Last episode was about my crazy study plan, or lack of one. Time to put together a proper study plan. One that works.
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:17:20
Learning All At Once - 252
10/3/2022
Time to jump into my crazy, unorganized study process. Trying to study or learn the CISSP, pentesting, risk assessments, and keep up with my current certification requirements. I’ve also signed up for two Antisyphon classes.
Beginner Classes
1. SOC Core Skills
2. Getting Started In Security With BHIS and Mitre Att&ck
3. Active Defense & Cyber Deception
Advanced Classes
1. Introduction to Pentesting
2. Red Team: Getting Access
3. Professionally Evil CISSP Mentorship Program
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:26:59
Asset Management Policy - 251
9/5/2022
Time to create a policy for asset inventory. This will help us define what we need in our asset inventory. It will also help us define what we need in our procedures. The process we use to manage the inventory.
LINKS
1. Enterprise Asset Management Policy Template
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:13:28
Discovering Devices With runZero - 250
8/29/2022
We’re scanning our network with runZero to get an inventory of devices. What did it find? What can we learn from this inventory? How well does it work?
LINKS
1. runZero - Active discovery tool for asset inventory
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:17:47
Do we have adequate security controls in place? - 249
8/22/2022
We’re in the process of implementing the CIS controls. This will take time. We’re also very busy. Are there any gaping security holes that we need to fix? Do we have any security controls in place? Can we wait to implement the CIS controls?
LINKS
1. runZero - Active discovery tool for asset inventory
2. Enterprise Asset Management Policy Template
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:21:29
CIS Controls: Hardware Inventory Part 1 - 248
8/15/2022
Time to get an accurate inventory of the devices on our network. Once we have an inventory, we can move on to policies and procedures.
LINKS
1. runZero - Active discovery tool for asset inventory
2. Enterprise Asset Management Policy Template
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:12:30
Going Back to the CIS Controls - 247
8/1/2022
Time for another maintenance episode. This time were going back to the CIS Controls. This time were using version 8. Hoping to implement the first 7.
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:16:24
Azure Testing - 246
7/11/2022
Time to start learning Azure. We’ve had Azure AD and Microsoft 365 for years. Just added Azure to the mix. Lots to learn.
LINKS
Free Azure Account
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:13:48
The OSINT Rabbit Hole: Part 1 - 245
6/20/2022
Time to go down the OSINT rabbit hole. What is it? What are we looking for? What are some of the tools we can use?
LINKS
1. Kali Linux
2. Shodan
2. Spiderfoot
4. theHarvester
5. OSINT Framework
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:26:31
Kali Linux, Nmap, Shodan, Gophish, Zap and Burp Suite - 244
6/13/2022
Time to dig in and start learning the tools.
LINKS
1. Kali Linux
2. Nmap
3. Shodan
4. Gophish
5. Zap
6. Burp Suite
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:19:07
New Job, VMWare Server, Tools - 243
5/30/2022
Got a new job. This makes our lab environment more important than ever. Some labs will be for me. Others will be for work. We need to make sure everything is working. We also need good documentation. No more messing around.
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:19:09
Organizing IT Before New Job - 242
5/9/2022
There could be a new job in my future. Before that happens, we need to organize our IT. We’re looking at patching, Microsoft Defender for Business, and data recovery.
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:10:04
New Projects: SIGMA, Python, Cloud - 241
5/2/2022
Time for some new projects. Still have a few things to do with Wazuh. Once that’s done, I’ll need something new to work on. Python is the big one. Seems everyone is asking for Python skills these days.
LINKS
1. The Azure Sandbox – Purple Edition
FIND US ON
1. Twitter - DamienHull
2. YouTube
Duration:00:22:03