The Cyber Threat Perspective cover art

All Episodes

The Cyber Threat Perspective — 234 episodes

#
Title
1

[Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers

2

Every IT Team Has a Joe | Ep 195

3

Service Accounts: The Shortest Path to Domain Admin | Ep 194

4

Your IT Job Doubled. Nobody Told Your Boss. | Ep 193

5

Subtractive Security: Stop Adding Tools and Start Deleting Attack Paths | Ep 192

6

The CrowdStrike Settings That Actually Stop Us | Ep 191

7

Episode 190 | OWASP Top 10 Part 4: Cryptographic Failures

8

Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

9

Guaranteed way to catch threat actors | Ep 188

10

Avoid this cyber leadership trap | Ep 187

11

Episode 186: Real Life Active Directory Attack Paths

12

[Replay] Episode 172: The Biggest Security Blind Spots in Midsized Companies

13

Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents

14

Episode 184 | Active Directory Isn't Dead. It's Just Undefended.

15

Episode 183 | OWASP Top 10 Part 2: Security Misconfigurations That Get You Hacked

16

Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR)

17

[Replay] Episode 159: How to Break Into Cybersecurity — What Actually Works

18

Episode 181: AI Zero Days (Google Threat Intelligence Report)

19

Episode 180: Cybersecurity Echo Chambers — How to Think Critically in a Hype-Driven Industry

20

Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained

21

Episode 178: Internal Security Controls That Actually Frustrate Attackers

22

Episode 177: Claude Mythos — What It Actually Does, What It Doesn't, and What Your Organization Should Do Now

23

Episode 176: Cybersecurity Advice That Sounds Smart But Fails in Practice

24

Episode 175: NetTools - The Free Active Directory Swiss Army Knife for IT Admins & Pen Testers

25

Episode 174: Web Application Penetration Testing Tools & Techniques with Jordan

26

Episode 173: How to Find Insecure Active Directory Permissions with ADeleg

27

Episode 172: The biggest security blind spots in Midsized companies

28

Episode 171: The future of pentesting with AI

29

Episode 170: The Evasive Adversary

30

Episode 169: Malicious Browser Extensions

31

Episode 168: Do you need a web app pen test?

32

Episode 167: TLS and SSL vulnerabilities - do they matter?

33

Episode 166: Why Your Pentest Didn’t Make You Safer

34

Episode 165: What to expect on your API Pentest

35

Episode 164: Offensive Security in the Age of AI: What Has Changed

36

Episode 163: The Vendor Security Trap: Are You Losing Control?

37

Episode 162: Before the Breach How Attackers Profile Your Organization

38

Episode 161: The Evolution of Pentesting Going Into 2026

39

Episode 160: Should You Alert Your SOC Before a Pentest?

40

Episode 159: How to Break Into Cybersecurity in 2026

41

Episode 158: How to get kicked out of AWS by the FBI

42

Episode 157: AppSec Findings in 2025

43

Episode 156: Post-Exploitation Tactics That Still Work in 2025

44

Episode 155: How We Use AI Offensively

45

Episode 154: Pentesting on a Budget for IT Admins

46

Episode 153: How to Prove Your Security Works Before Attackers Do

47

(replay) Common Pentest Findings That Shouldn't Exist in 2025

48

Episode 152: What is Offensive Security?

49

Episode 151: Tool Time - PingCastle for Defenders

50

Episode 150: How to Use Pentest Findings to Justify Your Next Security Spend

51

Episode 149: Building a Security Stack That Works A Practitioner’s Perspective

52

Episode 148: Securing Windows: Common Misconfigurations That Give Attackers The Advantage

53

Episode 147: When to Accept the Risk

54

Episode 146: What Are the Security Implications of AI?

55

Episode 145: What To Do Minute 1 When Incident Response Arrives

56

Episode 144: How Cyber Threat Actors Are Using AI

57

Episode 143: Stop Wasting Money on Pentests - Do This First

58

Episode 142: How Active Directory Certificates Become Active Threats

59

Episode 141: Are You Making These Windows Security Mistakes

60

Episode 140: Financial Services Cybersecurity Challenges & How to Address Them - Part 2

61

Episode 139: Financial Services Cybersecurity Challenges & How to Address Them - Part 1

62

(Replay) How We Evade Detection During Internal Pentests

63

Episode 138: The 7 Questions Every Security Leader Should Ask After a Pentest

64

Episode 137: Common Pentest Findings That Shouldn’t Exist in 2025

65

Episode 136: A day in the life of an External Penetration Tester

66

(Replay) How To Harden Active Directory To Prevent Cyber Attacks - Webinar

67

Episode 135: We Couldn’t Get In...And That’s a Good Thing, Or Is It?

68

Episode 134: Preventing Data Breaches: Strategies to Mitigate Initial Compromise

69

Episode 133: How Cyber Attackers Steal Credentials & Hijack Sessions

70

Episode 132: Reviewing the Mandiant M-Trends 2025 Report

71

(Replay) How To Defend Against Lateral Movement

72

Episode 131: DMARC & PCI 4.0 Compliance - Is your Organization Compliant?

73

Episode 130: Using Deception Technology to Detect Cyber Attacks

74

Episode 129: How to Analyze Threat Reports for Defenders

75

Episode 128: The Most Common External Pen Test Findings—And How to Fix Them

76

Episode 127: SaaS Supply Chain Attacks - How to Stay Secure

77

Episode 126: Typosquatting - How and Why It Works and How to Defend Against It

78

Episode 125: Whose Job Is Harder? Red or Blue

79

(Replay) How To Monitor Your Attack Surface

80

Episode 124: MFA != Secure

81

Episode 123: Insecure Active Directory Protocols

82

Episode 122: AI/ChatGPT Interviews a Web Pen Tester!!

83

Episode 121: How We Evade Detection During Internal Pentests

84

Episode 120: Demystifying Pentests: What Every Organization Needs to Know

85

Episode 119: Lessons Natural Disasters Can Teach Us About Cybersecurity

86

(Replay) Tales From The Trenches

87

(Replay) Email Spoofing: From Basics to Advanced Techniques and Solutions

88

(Replay) Windows and Active Directory Hardening

89

Episode 118: 2025 - A CISO's Perspective with Mike Whitt

90

Episode 117: Why Do Pentests Cost So Much?

91

Episode 116: Painfully Persistent Problems - Weak Passwords

92

Episode 115: How to understand and address risk w/ Robert McElroy

93

Episode 114: Making Penetration Test Results Actionable

94

Episode 113: Phishing with Malicious RDP Files

95

Episode 112: Key Insights From The Microsoft Digital Defense Report 2024

96

(Replay) How To Actually Protect Credentials

97

Episode 111: Red Team Tools (OST) Managing Open-Source Threats

98

(Replay) Vulnerability Management Deep Dive

99

Episode 110: AD Security Workshop Preview

100

Episode 109: Current State of Pentesting - Internal and External

101

Episode 108: New tales from the trenches!

102

Episode 107: How To Defend Against Lateral Movement

103

(Replay) DNS Security

104

Episode 106: An Overview of Cyber Risk

105

Episode 105: How to Monitor Your Attack Surface

106

Episode 104: How To Get Into Cyber For First Responders

107

Episode 103: Email Spoofing

108

Episode 102: The Global CrowdStrike Outage

109

Episode 101: Infostealers - 10,000 Victims a Day

110

(Replay) How We Hack Medical Devices To Save Lives

111

Episode 100: The OpenSSH RegreSSHion Vulnerability

112

Episode 99: Tool Time - OneDriveEnum & AD Miner

113

Episode 98: Current State of M365 Attacks: Initial Access

114

Episode 97: Current State of M365 Attacks: Enumeration

115

Episode 96: How to Harden Active Directory to Prevent Cyber Attacks

116

Episode 95: Navigating the Legal Maze of Cybersecurity with Alexander Boyd

117

Episode 94: Defending Against Ransomware Part 2

118

Episode 93: Defending Against Ransomware Part 1

119

Episode 92: Cybersecurity Training and Certification Advice

120

Episode 91: The 2024 Verizon Data Breach Investigations Report

121

Episode 90: Transforming Your Security - Insights from Coaching a Collegiate Cyber Defense Team

122

Episode 89: How to Actually Protect Credentials

123

Episode 88: Budgeting for Security: Optimizing Penetration Testing Investments

124

Episode 87: Pentesting Challenges and How to Overcome Them

125

Episode 86: The XZ Backdoor

126

Episode 85: Tool Time - DarkGPT

127

Episode 84: How We Hack Medical Devices to Save Lives

128

Episode 83 - Defense in Depth

129

Ep82 - DFIR For IT & Security Leadership

130

Ep81 - Pentesting Misconceptions

131

Ep 80: Low-Cost, High-Impact Security

132

Episode 79: Bug Bounties

133

Episode 78: Tales from the Trenches

134

Episode 77: DNS Security

135

Episode 76: Windows & Active Directory Hardening

136

Episode 75: Assume Breach - Extracting Maximum Value From Offensive Security Testing

137

Episode 74: Soft Skills and Mental Health For Security Professionals

138

Episode 73: Password Spraying Inside & Out

139

Episode 72: Vulnerability Management Deep Dive

140

Episode 71: A CISO's Perspective on Offensive Security Services

141

Episode 70: Future Trends in Penetration Testing Part 2

142

Episode 69: Future Trends in Penetration Testing Part 1

143

Episode 68: The evolution of penetration testing TTPs

144

Episode 67: A Day In The Life: External Penetration Testing

145

(Replay) HACKERS: How we GET IN and how to STOP US

146

Episode 66: The DevSec Divide: Breaking Down Barriers for Better Security

147

11/2023 Cyber Threat Recap: Okta, Octo Temptest, Smishing

148

Episode 65: Unsecured Credentials and Where To Find Them

149

Episode 64: A Day In The Life: Web Application Penetration Testing

150

Episode 63: A Day in The Life: Internal Penetration Testing

151

Episode 62: What Makes a Great Penetration Test Report?

152

Episode 61: How to Mitigate Social Engineering Attacks

153

Episode 60: Cybersecurity Hot Takes

154

Episode 59: Offensive TTPs and Tooling Trends

155

Episode 58: How To Identify and Mitigate Insecure Windows Services

156

Episode 57: Find and FIX AD CS Vulnerabilities Using Locksmith with Jake and Sam

157

Episode 56: Vulnerabilities & Severity - Explain It To Me Like I'm 5

158

Episode 55: What If Your EDR Doesn't Detect or Respond?

159

Episode 54: Misconfigured and Dangerous Logon Scripts

160

Episode 53: How to Defend and Mitigate PowerShell Attacks

161

Episode 52: How to Prepare for an External Penetration Test

162

Episode 51: Security Automation with PowerShell

163

Episode 50: How Attackers Use PowerShell

164

Episode 49: Scoping Offensive Security Engagements

165

Episode 48: Authentication done right!

166

Episode 47: How to Sharpen your Sword as a Pentester

167

Episode 46: Reducing Active Directory Security Risks from a Hackers Perspective

168

Episode 45: Our Most Common External Pen Test Findings

169

Episode 44: Should penetration testers know how to code?

170

Episode 43: Hacking for Good - Insights and Inspiration with John Hammond

171

Episode 42: OSINT - What You Don't Know Can Hurt You

172

Episode 41: Security Assessment vs Pentest Which is More Impactful and Why

173

Episode 40: How Attackers Target Law Firms and How To Detect & Prevent It

174

Episode 39: Pentesting Certifications Tier List Part 2

175

Episode 38: Pentesting Certifications Tier List Part 1

176

Episode 37: Offensive Security Testing Part 5 - Wireless Pentesting

177

Episode 36: Pentest vs Purple Team vs Red Team

178

Episode 35: Getting Into Pentesting Without an IT Background

179

Episode 34: The State of Web Application Penetration Testing

180

Episode 33: Reflections on Privacy Law and Privacy Issues

181

Episode 32: Our Favorite Pentesting Tools: PingCastle

182

Episode 31: Pentesting War Stories

183

Episode 30: LastPass DataBreach Updates

184

Episode 29: Critical Vulnerabilities You WON’T Find Using Nessus

185

Episode 28: BurpSuite 2023 Roadmap - Huge Improvements!

186

Episode 27: Password Myths Misconceptions and Lies

187

Episode 26: Cloud Security Quick Wins For Defenders

188

Episode 25: What To Do Before You Get A Pentest

189

Episode 24: Active Directory Security Quick Wins For Defenders

190

Episode 23: Offensive Security Testing Part 4 - External Pentesting

191

Episode 22: Yet Another LastPass Breach

192

Episode 21 - SecurIT360 Offensive Security Christmas Special

193

Episode 20 - ChatGPT: The Future of Infosec with AI

194

Episode 19: Staying Frosty Sharp over the Holidays

195

Episode 18: An introduction to Burp Suite

196

Episode 17: Abusing WSUS for Lateral Movement

197

Episode 16: OWASP API Hacking and DevSec with Matt Tesauro

198

Episode 15: Pentesting Certifications - which to get and why

199

Episode 14: Offensive Security Testing Part 3 - Web App Pentesting

200

Episode 13: Offensive Security Testing Part 2 - Mobile Pentesting

201

Episode 12: Law Firm Security Challenges Live at LegalSec22

202

Episode 11: Offensive Security Testing Part 1 - Internal Pentesting

203

Episode 10: Web Application Threats in the Modern Landscape

204

Episode 9: Breaking In Or Branching Out: How To Get A Job In Cybersecurity

205

Episode 8: Hackers: How we get in and how to stop us

206

9-16-22 Week in Review: Uber Hacked, Teams Cleartext Tokens, Intermittent Ransomware Encryption

207

Episode 7: How to Make Threat Actors Cry

208

9-9-22 Week in Review: New EvilProxy Phishing Service and Linux Malware

209

Episode 6: 5 Ways to Get More Value out of your External Penetration Test

210

9-2-22 Week in Review: Okta Phishing, BEC Analysis, LNK Attacks

211

Episode 5: Common High Risk Findings on Internal Penetration Tests & How to Mitigate Them

212

8-26-22 Week in Review: LastPass Breach, Office 365 Abuse, DevSecOps

213

Episode 4: 7 Awesome Ways to Show Off Your Skills as a Pentester

214

8-19-22 Week in Review: Password Snooping, Supply Chain, Cl0p Ransomware

215

Episode 3: It's a Trap! Avoid These 4 Common Pentesting Mistakes

216

8-12-22 Week in Review: BumbleBee Malware & High Profile Phishing Attacks

217

Episode 2: How to Find Passwords on Network Shares Before Attackers Do

218

8-5-22 Week in Review: Evasive Phishing, Tricky Malware and Initial Access Brokers

219

Episode 1: Takeaways from the 2022 Verizon Data Breach Investigations Report

220

July 29th Week in Review: Intergalactic Planetary Phishing, ISOs & LNKs, Ransomware & Extortion

221

July 22nd 2022 CTP Week in Review: RIP Macros, Bad Luck BlackCat, Mr. Eagle

222

July 15th 2022 CTP Week in Review: Macros, Coin Miners, Rustomware, Cookie Phishing

223

July 8th 2022 CTP Week in Review: Office Macros - BRC4 - QNAPWorm - Leaky S3 Buckets - Prevention Over Response

224

July 1st 2022 CTP Week in Review: LNK Malware - LockBit 3.0 Bug Bounty - PwnKit Exploitation In The Wild

225

June 24th 2022 CTP Week In Review: DFSCoerce, Ransomware in OneDrive & PowerShell Forever

226

June 17th 2022 CTP Week In Review: BlackCat - LockBit 2.0 - Saitama DNS Tunneling - Exposed Travis CI Logs

227

June 10th 2022 CTP Week in Review: Dogwalk - Qakbot - Follina - ESXi Ransomware

228

June 3rd 2022 – Cyber Threat Perspective – Week in Review

229

Threat Intel Flash Briefing May 31st 2022 - Follina - CVE-2022-30190

230

May 27th 2022 – Cyber Threat Perspective – Week in Review

231

May 20th, 2022 - Cyber Threat Perspective - Week in Review

232

May 13th, 2022 - Cyber Threat Perspective - Week in Review

233

May 6th, 2022 - Cyber Threat Perspective - Week in Review

234

Threat Intel Flash Briefing - Kerberos Relaying to Local SYSTEM