• 7MS #709: Second Impressions of Twingate
    Jan 10 2026

    Hey friends, in episode #649 I gave you my first impressions of Twingate. It's been a minute, so I thought I'd revisit Twingate (specifically this awesome Twingate LXC) and talk about how we're using it to (almost) entirely replace remote access to our datacenter servers and pentest dropboxes. Also, don't forget:

    • Our pentest class is coming up at the end of the month – more info here.
    • We do a Tuesday TOOLSday video every Tuesday over at 7MinSec Club.
    Show More Show Less
    20 mins
  • 7MS #708: Tales of Pentest Fail – Part 6
    Jan 2 2026

    After sharing a recent story about how a phishing campaign went south, I heard feedback from a lot of you. You either commiserated with my story, told me I wussed out, and/or had a difficult story of your own to share. So I thought I'd keep this momentum up and share another story of fail with you – this time about a Web app pentest that went south.

    Show More Show Less
    26 mins
  • 7MS #707: Our New Pentest Course Has Launched!
    Dec 26 2025

    Today we're thrilled to announce the launch of LPLITE:GOAD (Light Pentest Live Interactive Training Experience: Game of Active Directory). The first class is coming up Tuesday, January 27 – Thursday, January 29 (9:00 a.m. – 1:00 p.m. CST each day). More information, pricing information and more can be found at training.7minsec.com. Today I talk about who should sign up for the course, what you should bring, and some of the awesome things you'll be doing should you choose to join me on this hacking adventure!

    Show More Show Less
    14 mins
  • 7MS #706: Tales of Pentest Pwnage – Part 80
    Dec 19 2025

    I'm so excited to share today's tale of pentest pwnage, because it brings back to life a coercion technique I thought wouldn't work against Windows 11! Spoiler alert: check out rpc2efs, as well as the 7MinSec Club episode we did on the topic this week.

    Also, our January Light Pentest LITE:GOAD class is open for registration here!

    Show More Show Less
    29 mins
  • 7MS #705: A Phishing Campaign Fail Tale
    Dec 12 2025

    This might be obvious, but security is not all domain admin dancing and maximum pwnage. Sometimes, despite my best efforts, a security project does a faceplant. Today's episode focuses on a phishing campaign that had plenty of "bites" but got immediately shut down – for reasons I still don't understand.

    Show More Show Less
    22 mins
  • 7MS #704: DIY Pentest Dropbox Tips – Part 12
    Dec 5 2025

    Hola friends! My week has very much been about trying to turnaround pentest dropboxes as quickly as possible. In that adventure, I came across two time-saving discoveries:

    • Using a Proxmox LXC as a persistent remote access method
    • Writing a Proxmox post-deployment script that installs Splashtop on the Windows VM, and resets the admin passwords on both VMs, all from the Proxmox SSH console without touching the console on either VM

    If you feel some of this is better seen than said, on this week's 7MinSec.club Tuesday TOOLSday broadcast we show this in more detail.

    Show More Show Less
    25 mins
  • 7MS #703: Tales of Pentest Pwnage – Part 79
    Nov 28 2025

    Happy Thanksgiving week friends! Today we're celebrating a turkey and pie overload by sharing another fun tale of pentest pwnage! It involves using pygpoabuse to hijack a GPO and turn it into our pentesting puppet! Muahahahahaah!!!! Also:

    • This week over at 7MinSec.club we looked at how to defend against some common SQL attacks
    • We're very close to offering our brand new LPLITE:GOAD 3-day pentest course (likely in mid-January). It will get announced on 7MinSec.club first, so please make sure you're subscribed there (it's free!)
    • Did you miss our talk called Should You Hire AI Run Your Next Pentest? Check it out on YouTube!
    Show More Show Less
    22 mins
  • 7MS #702: Should You Hire AI to Run Your Next Pentest?
    Nov 21 2025

    Hello friends, in today's episode I give an audio summary of a talk I gave this week at the MN GOVIT Symposium called "Should You Hire AI to Run Your Next Pentest?" It's not a pro-AI celebration, nor is it an anti-AI bashing. Rather, the talk focuses on my experiences using both free and paid AI services to guide me through an Active Directory penetration test.

    Show More Show Less
    21 mins