• 7MS #680: Tips for a Better Purple Team Experience
    Jun 20 2025

    Today I share some tips on creating a better purple team experience for your customers, including:

    • Setting up communication channels and cadence
    • Giving a heads-up on highs/criticals during testing (not waiting until report time)
    • Where appropriate, record videos of attacks to give them more context
    Show More Show Less
    27 mins
  • 7MS #679: Tales of Pentest Pwnage – Part 73
    Jun 13 2025

    In today’s tale of pentest pwnage I talk about a cool ADCS ESC3 attack – which I also did live on this week’s Tuesday TOOLSday. I also talk about Exegol’s licensing plans (and how it might break your pentest deployments if you use ProxmoxRox).

    Show More Show Less
    30 mins
  • 7MS #678: How to Succeed in Business Without Really Crying – Part 22
    Jun 6 2025

    Today I share some tips on presenting a wide variety of content to a wide variety of audiences, including:

    • Knowing your audience before you touch PowerPoint
    • Understanding your presentation physical hookups and presentation surfaces
    • A different way to screen-share via Teams that makes resolution/smoothness way better!
    Show More Show Less
    34 mins
  • 7MS #677: That One Time I Was a Victim of a Supply Chain Attack
    May 30 2025

    Hi everybody. Today I take it easy (because my brain is friend from the short week) to tell you about the time I think my HP laptop was compromised at the factory!

    Show More Show Less
    14 mins
  • 7MS #676: Tales of Pentest Pwnage – Part 72
    May 27 2025

    Today’s fun tale of pentest pwnage discuss an attack path that would, in my opinion, probably be impossible to detect…until it’s too late.

    Show More Show Less
    1 hr
  • 7MS #675: Pentesting GOAD – Part 2
    May 16 2025

    Hey friends! Today Joe “The Machine” Skeen and I tackled GOAD (Game of Active Directory) again – this time covering:

    • SQL link abuse between two domains
    • Forging inter-realm TGTs to conquer the coveted sevenkingdoms.local!

    Join us next month when we aim to overtake essos.local, which will make us rulers over all realms!

    Show More Show Less
    32 mins
  • 7MS #674: Tales of Pentest Pwnage – Part 71
    May 9 2025

    Today’s tale of pentest pwnage is another great one! We talk about:

    • The SPNless RBCD attack (covered in more detail in this episode)
    • Importance of looking at all “branches” of outbound permissions that your user has in BloodHound
    • This devilishly effective MSOL-account-stealing PowerShell script (obfuscate it first!)
    • A personal update on my frustration with ringing in my ears
    Show More Show Less
    49 mins
  • 7MS #673: ProxmoxRox
    May 3 2025

    Today we’re excited to release ProxmoxRox – a repo of info and scripts to help you quickly spin up Ubuntu and Windows VMs. Also, some important news items:

    • 7MinSec.club in-person meeting is happening Wednesday, May 14! More details here.
    • We did our second Tuesday TOOLSday this week and showed you some local privesc techniques when you have local admin on an endpoint
    Show More Show Less
    31 mins