7 Minute Security's Substack

7 Minute Security's Substack

Home
Chat
Archive
About
Tuesday TOOLSday: DIY pentest dropbox tips
Make remote access to your dropbox even easier
Dec 4 • 
Brian Johnson
19:52

November 2025

Tuesday TOOLSday: SQL server defense 101
Don't let attackers relay free high-priv SQL creds!
Nov 27 • 
Brian Johnson
11:57
Tuesday TOOLSday: Lithnet AD Password Protection
Keep bad passwords out of your AD for free? Yes please.
Nov 20 • 
Brian Johnson
18:53
Light Pentest LITE:GOAD logo winner announced!
And it was hard to choose just one
Nov 17 • 
Brian Johnson
Tuesday TOOLSday: LAPS quick install
An essential FREE blue team control for your Active Directory
Nov 13 • 
Brian Johnson
22:04
Tuesday TOOLSday: Pretender
A nice alternative to mitm6
Nov 6 • 
Brian Johnson
15:11

October 2025

Tuesday TOOLSday: Kerberoasting Kleanup
Nuke those old SPN and embrace service account best practices
Oct 30 • 
Brian Johnson
14:55
Tuesday TOOLSday: egress filtering
A quick way to check what's allowed from your internal > external network
Oct 21 • 
Brian Johnson
Tuesday TOOLSday: benefits of a security ticketing system
Ticketing + inventorying = good security
Oct 15 • 
Brian Johnson
20:06
Tuesday TOOLSday: mssqlkaren
Stealing SCCM creds with Karen's help!
Oct 7 • 
Brian Johnson
9:32
Tuesday TOOLSday: coercing HTTP auth w/scheduled tasks
Schtasks continue to be sneaky!
Oct 3 • 
Brian Johnson
22:15

September 2025

Tuesday TOOLSday: coercing SMB auth w/scheduled tasks
Didn't lead to domain admin, but I'll still take it!
Sep 26 • 
Brian Johnson
17:45
© 2025 Brian Johnson · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture