Purple Squad Security
If you know the enemy and know yourself, you need not fear the result of a hundred battles.
February 18, 2018

Episode 20 – Physical Penetration Testing with Jek Hyde

I speak with the legendary Jek Hyde about physical penetration testing.

Not all penetration testing is done in a virtual setting or even through a phone call.  Sometimes you need to get down and dirty and actually interact with people.  In this very special episode I sit down and speak with the great Jek Hyde about physical penetration testing and everything that it entitles.  It's a fascinating talk for sure, and one you don't want to miss. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
February 11, 2018

Episode 19 – Speaking to Executives with Tracy Maleeff

Tracy Maleeff joins me to talk about strategies for communicating with senior leadership, which is a key skill for all infosec professionals

Have you heard the term, managing up? It's and old expression used when you need to make sure that your boss has his or her expectations met so that you can focus on your own job.  Information security is really no different, and in a lot of ways it's also more important to get right.  We are an industry of social introverts and generally prefer the warm embrace of an IRC screen, Twitter feed or Slack channel for our communications.  It's taken me many years to get comfortable with speaking with other humans, but more than that I have learned there is a certain technique when speaking with executes - a special breed so to speak - about security.  Tracy Maleeff, the InfoSecSherpa, joins me to help guide us all on proper techniques to communicate with senior leadership. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
January 28, 2018

Episode 18 – Threat Hunting with Will Harmon

Will Harmon from Trustwaves Spider Labs comes to talk about Threat Hunting with me.

Take a pinch of blue, a dash of red, plus some good old fashioned investigative intuition and you get Threat Hunting!  Well, not exactly but it's a start!  This week Will Harmon from Trustwave's Spider Labs comes on the show to explain what Threat Hunting is, why it's important and how people can get started into this exciting infosec field! Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
January 21, 2018

Episode 17 – A Look At The Treacherous Twelve From The CSA

I take a look at the Treacherous Twelve from the CSA to see what threats exist for people moving to the cloud.

The Cloud Security Alliance (CSA) has long been known to be the source of cloud security discussions.  From the CCSK to the partnership with ISC(2) to bring us the CCSP, they are definitely a group to pay attention to.  This week I focus on their "Treacherous Twelve", a list of 12 security concerns for any organization moving to the cloud. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
January 14, 2018

Episode 16 – OSINT with Joe Gray from Advanced Persistent Security

Joe Gray from the Advanced Persistent Security podcast and Through The Hacking Glass fame joins me to talk OSINT.

This week Joe Gray, host of the Advanced Persistent Security podcast, that friend you didn't recognize but added to Facebook anyway, and security researcher joins me to talk about OSINT.  This is a packed episode full of security goodness and definitely not one you want to miss! Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
December 24, 2017

Episode 15 – Infosec Tabletop D&D with Brakeing Down Security

I sit down with Bryan and Brian from Brakeing Down Security to do a fun take on a classic - Infosec Tabletop Simulations - with a D&D twist!

The first of a series, I sit down with Bryan and Brian of Brakeing Down Security fame to have a fun take on a classic tabletop scenario with a D&D feel.  Please hold the hate, I haven't played D&D in many years and I know it's not "classic", but it's fun and lighthearted.  We go through a few different scenarios with you all in the hopes you find it enjoyable, entertaining, and educational. If you enjoyed this episode, please let me know!  I'd like to make this a recurring theme every 12-15 episodes with different podcasters if there's enough interest.  Special shout out to @badthingsdaily on Twitter for helping provide the scenarios! Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
December 22, 2017

2017 Holiday Special – Podcast of Podcasters

The Brakeing Down Security podcast of podcasters!

I feel truly touched to be included in this year's tradition of the podcast of podcasters, hosted by Bryan Brake of Brakeing Down Security.  This is the audio that you will hear from the various other podcasts that were on the episode with me.  I was a bit star-struck, but it was a great time all around.  Enjoy! Podcasts and Podcasters represented on the show:


Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
December 10, 2017

Episode 14 – OWASP Top 10 2017 – A6 Through A10

In this episode I complete my review of the OWASP Top 10 - 2017 looking at items A6 (Security Misconfiguration) through A10 (Insufficient Logging & Monitoring).

In the completion of our look at the OWASP Top 10 for 2017, this episode will cover the final 5 items on the list, from A6 (Security Misconfiguration) through A10 (Insufficient Logging & Monitoring). Some links of interest:


Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
December 3, 2017

Episode 013 – OWASP Top 10 2017 – A1 Through A5

Taking a look at the first 5 vulnerabilities in the OWASP Top 10 - 2017 list.

The Open Web Application Security Project (OWASP) group has created a Top 10 web applications vulnerability list since 2003.  Normally the list gets updated every 3 years or so, with the previous release being 2013.  Now with the 2017 list being finalized, I felt it was appropriate for us to go through it and look at it from a red and blue team perspective. This episode will cover the first 5 items on the list, from A1 (Injection) through to A5 (Broken Access Control). Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…
November 26, 2017

Episode 012 – InfoSec Certifications with Kim Crawley

I speak with Kim Crawley about her recent article in Cylance, Security Certifications You Should Consider Getting, and about certifications in InfoSec in general.

Certifications.  We either love them or hate them, but we cannot deny that they are needed.  Either to prove a set of skills, prove the ability to memorize facts and take tests, or to prove that our egos are bigger than our peers, there are lots of opinions on certifications. This week Kim Crawley joins me to talk about a recent article she has written for Cylance, Security Certifications You Should Consider Getting.  We discuss what certifications are good for, our opinions on them, HR managers, and where you can find resources to help you study. Some links of interest:



Want to reach out to the show?  There's a few ways to get in touch!



Thanks for listening, and I will talk with you all again next time.

Find out more at http://purplesquadsec.com

Read more…