Purple Squad Security
If you know the enemy and know yourself, you need not fear the result of a hundred battles.
May 6, 2018

Episode 30 – Infosec D&D Tabletop with Jerry Bell and Andrew Kalat from Defensive Security

Jerry Bell and Andrew Kalat from the Defensive Security podcast join me for another Infosec D&D Tabletop game! What maddening scenarios have I found that they will need to overcome?

It's that time again!  We're doing another Infosec tabletop in a D&D style, this time with the fine gentlemen from the Defensive Security podcast!  Jerry and Andrew join me for another infosec tabletop with all new scenarios, pitfalls, and approaches. Special thanks to Ryan McGeehan and his Tabletop Scenarios twitter account for providing the ideas behind this episodes "challenges". Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and as always, I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
April 29, 2018

Episode 29 – The Importance of Community in Infosec w/ Cheryl “3ncr1pt3d” Biswas

Cheryl 3ncr1pt3d Biswas joins me to talk about how our Infosec community differs, as well as some cons like the Diana Initiative.

The idea of "community" is an important one, especially if you talk about a group of people who want to help improve their skills by sharing their ideas, experiences, etc, with like minded individuals.  The Infosec community is no exception to this.  In fact I would argue that it is one of the strongest communities I have encountered yet! Joining me this week is Cheryl "3ncr1pt3d" Biswas to talk about the Infosec community, what makes it special, and the importance of it.  In addition we will be talking about one of Cheryl's many contributions to the community in the form of the Diana Initiative. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and as always, I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
April 22, 2018

Episode 28 – John’s Weird Path To #Infosec And Other Ramblings

With no guest this week, John talks about his own personal path to #infosec and other thoughts on his journey.

With no guest this week, John decides to share his own story about how he got into #infosec and some other thoughts he's had about the journey and why it's a never ending adventure to learn new things. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and as always, I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
April 15, 2018

Episode 27 – Infosec and Mental Health with Danny Akacki

Danny Akacki joins me to talk about his own mental health and the site he created, infosanity.org, to help others who may be struggling.

Stress.  Depression. Anxiety.  Fear.  Uncertainty.  Doubt.  All of these symptoms and conditions are well known to anyone who has spent a few years in security.  This can be a heavy topic, but it's one that we should discuss openly and often.  Danny Akacki joins me on this episode to talk about his own mental health, what are some of the things that has helped him, and he also gives us some insight on his contributions back to the community through the creation of infosanity.org, a website dedicated to helping those in the hacking community who may be struggling and aren't sure where to go. Please remember, if you have a serious concern about your mental health, please, PLEASE seek professional help. Some links of interest:


Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and as always, I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
April 8, 2018

Episode 26 – DFIR in the Cloud with Jonathon Poling

Jonathon Poling (@JPoForenso) comes back to talk about #DFIR in the #cloud, whats easier, whats harder, and whats different. A must for anyone on a #blueteam.

From the crowd to the cloud, we shift focus this episode to a topic that may be holding back some infosec professionals from embracing the cloud - namely what to do when you're attacked?  Digital Forensics and Incident Response (DFIR) is a topic we've covered in the past, but that was from a more traditional view.  I'm fortunate enough to have Jonathon Poling (@JPoForenso) join me again to revisit DFIR, but this time from a cloud perspective.  What's easier, what's harder, and what's different?  Have a listen to find out! Some links of interest:


Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and as always, I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
March 25, 2018

Episode 25 – Securing The Crowd with Nicolas Valcarcel

Nicolas Valcarcel joins me to talk about his experience with the crowd, crowdsourcing, as well as Infosec and shares his experiences and thoughts on how best to secure it for use in your organization.

The crowd.  Recently gaining attention again due to some news events that were much ado about nothing, there is still a bit of a mystery with crowdsourcing and how best to secure it.  Organizations like Bug Crowd and HackerOne have shown it can be used for specific security tasks, but what about in general?  Nicolas Valcarcel joins me on this episode to share his thoughts and experience with security the crowd and what organizations should be aware of when considering using the crowd for their own purposes. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
March 18, 2018

Episode 24 – Fireside Chat with Joe Gray

In this casual fireside-style chat I speak with Joe Gray about TTHG, Conferences and Discount Codes!

In the first of a new format, I sit down with Joe Gray with only a handful of questions and just chat.  We cover things from Through The Hacking Glass, upcoming talks that Joe will be doing, to the various conferences that Joe will be attending.  Lots of great information and stories were shared, and if you'd like to provide feedback, please reach out and let me know!  Also, make sure you listen for a special easter egg that Joe has for those who are in the Atlanta area in September for entry to a conference at no cost! Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
March 11, 2018

Episode 23 – Speaking to Developers with James Jardine

I speak with James Jardine from the DevelopSec Podcast on communication strategies to use when speaking with developers.

Continuing with the theme of soft skills that any infosec professional should have, this episode will focus on developers.  I sit down with James Jardine from the DevelopSec podcast to talk about how best to communicate with developers.  Just like executives, developers have a different language and approach that is needed in order to communicate effectively.  Trying to avoid the all-to-common animosity between developers and security, James and I discuss some strategies to help build bridges between the groups and not burn them to the ground. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
March 4, 2018

Episode 22 – Open Source Intelligence Techniques with Michael Bazzell

I speak with the Godfather of OSINT, Michael Bazzell, about his book and various OSINT topics.

Nothing helps out security more than information.  Heck, it's the first part of our professions name!  In Infosec, knowledge is key and sometimes we need to roll up our sleeves to get the information we need from various open source outlets.  I'm fortunate to have as a guest on this episode the man who literally wrote the book on OSINT techniques, Michael Bazzell.  We discuss OSINT techniques as well as his recently updated book.  Have yourself a listen and hear the advice Michael has for starting your own OSINT adventures. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
February 25, 2018

Episode 21 – The Myth of the Purple Teamer with Haydn Johnson

I speak with Haydn Johnson about the myth of the purple teamer, that is, an individual who does both red and blue team activities as part of their day job.

I love purple teams.  Purple teaming is something that I was hoping to share with more people and more organizations!  It's part of the reason I named this podcast after them.  So why don't I think that a purple teamer exists?  It's an interesting stance, but it's one that makes sense.  Joining me this week is Haydn "Doctor Purple" Johnson to discuss all things purple. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…