<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[7 Minute Security's Substack]]></title><description><![CDATA[Where I share what I'm learning about penetration testing, blue-teaming and being the owner of a cybersecurity SMB!]]></description><link>https://www.7minsec.club</link><image><url>https://substackcdn.com/image/fetch/$s_!Jlmz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5e61286-8e46-43fd-8d4e-d7f83119f472_363x363.png</url><title>7 Minute Security&apos;s Substack</title><link>https://www.7minsec.club</link></image><generator>Substack</generator><lastBuildDate>Sat, 20 Jun 2026 11:00:06 GMT</lastBuildDate><atom:link href="https://www.7minsec.club/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Brian Johnson]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[7minsec@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[7minsec@substack.com]]></itunes:email><itunes:name><![CDATA[Brian Johnson]]></itunes:name></itunes:owner><itunes:author><![CDATA[Brian Johnson]]></itunes:author><googleplay:owner><![CDATA[7minsec@substack.com]]></googleplay:owner><googleplay:email><![CDATA[7minsec@substack.com]]></googleplay:email><googleplay:author><![CDATA[Brian Johnson]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Tuesday TOOLSday: Mythic C2]]></title><description><![CDATA[Oh my gosh this is so fun]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-mythic-c2</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-mythic-c2</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Tue, 16 Jun 2026 18:05:11 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/201685991/0d9998019e3fb2e9947289c0aab124f4.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hi friends, this week I give you a quick tour of <a href="https://docs.mythic-c2.net/home">Mythic C2</a> including (at a high level):</p><ul><li><p>Install overview</p></li><li><p>Building your first payload</p></li><li><p>Obfuscation techniques</p></li><li><p>Getting an initial shell</p></li><li><p>Privesc to SYSTEM shell</p></li><li><p>Mimikatz maximum pwnage!</p></li></ul><p>P.S. I&#8217;m thinking of doing a live, <em>long</em> livestream (multiple hours?) where I pwn <a href="https://orange-cyberdefense.github.io/GOAD/labs/NHA/">Ninja Hacker Academy</a> from start to finish.  I want to even include the install/setup/configuration of Mythic and use it throughout the stream.  What do you think?  Fun, or dumbest thing ever?  Let me know!</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/p/tuesday-toolsday-mythic-c2/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/p/tuesday-toolsday-mythic-c2/comments"><span>Leave a comment</span></a></p><p>Thanks,<br>Brian</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p> </p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: Hermes]]></title><description><![CDATA[I made the switch from OpenClaw!]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-hermes</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-hermes</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Wed, 10 Jun 2026 20:02:21 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/201486749/38aa0fc6965355ed40c7ad963c049950.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hey friends.  I&#8217;ll talk more about this on the <a href="https://7minsec.com/podcast/">podcast</a> this week, but wanted to announce that I&#8217;ve moved from OpenClaw to <a href="https://hermes-agent.nousresearch.com/">Hermes</a>.  This week I was able to set it up on my Mac Mini in about an hour, and completed the install by setting up a Telegram bot.  Then, as I zipped around the Twin Cities running errands, I told Hermes to:</p><ul><li><p>Install UptimeKuma</p></li><li><p>Install Assistant</p></li><li><p>Research scary movies</p></li><li><p>Create a &#8220;daily digest&#8221; email with info I care about</p></li></ul><p>&#8230;and I&#8217;ve only scratched the service.  This is <em>awesome</em>!</p><p>-Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: 7MinSecWikiScripts]]></title><description><![CDATA[A new home for my scripts!]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-7minsecwikiscripts</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-7minsecwikiscripts</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Wed, 03 Jun 2026 22:08:11 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/200524625/1d76e78934ec8ddddba47c17cacad7b4.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hey friends! </p><p>Yes, I know it&#8217;s Wednesday &#8212; sorry, mom. &#128517; But I&#8217;ve got a new Tuesday TOOLSday for you anyway!</p><p>This week I&#8217;m announcing a brand new GitHub repo: <a href="https://github.com/7MinSec/7MinSecWikiScripts">7MinSec WikiScripts</a> &#8212; a soon-to-be-growing collection of scripts (built with a lot of AI help) to make pentesting life easier. You can find it linked from the Scripts section over at <a href="https://7minsec.wiki">7MinSec.wiki</a>.</p><p>The repo is organized into folders for lab setup, Dropbox deployments, maintenance tasks, and pentesting goodies. The first script out of the gate is <code>install-exegol.sh</code> &#8212; a one-shot installer for <a href="https://exegol.readthedocs.io/">Exegol</a>, which is basically my must-have toolkit for every internal network pentest. It bundles CrackMapExec, Impacket, Responder, and a ton more into a clean container environment so you&#8217;re not wrestling with dependency nightmares on a fresh Kali box.</p><p>Check out the video, grab the script, and let me know what you think!</p><p>Have a great week, </p><p>Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: How to turn your phone into a "Brick"]]></title><description><![CDATA[Fewer distractions and less doom-scrolling!]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-how-to-turn-your</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-how-to-turn-your</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Tue, 12 May 2026 19:09:56 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/197255955/efc454e6fe0e5cffa56756e1d5b6cf45.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This week&#8217;s Tuesday TOOLSday is a bit of a departure from the usual pentest/blue team chatter &#8212; but stay with me! Burnout and too much screen time are very real in IT/security, so I wanted to share a $50 gizmo called <strong>Brick</strong> that&#8217;s helped me doom scroll less, focus more, and sleep better over the past week.</p><p>The short version: <a href="https://getbrick.com">Brick</a> is a small NFC device (magnetic back, so I stuck mine on the fridge) that pairs with the Brick app. You pick the apps you want bricked &#8212; socials, games, whatever your time-sucks are &#8212; and tap your phone to the device to enable &#8220;mindfulness mode.&#8221; To get those apps back, you have to physically walk over and tap again. That tiny bit of friction has been <em>surprisingly</em> effective at breaking my continual &#8220;pocket check&#8221; habit.</p><p>A few things I dig about it:</p><ul><li><p>$50 one-time fee, no subscription</p></li><li><p>One brick pairs with multiple devices (good for the family)</p></li><li><p>5 emergency unbricks are allowed within the app (if you&#8217;re stuck somewhere without the physical device)</p></li><li><p>Lets you schedule brick/unbrick on a timer without the physical device (great for a &#8220;Tommy Needs Sleepy&#8221; wind-down)</p></li></ul><p>Grab one at <a href="https://getbrick.com">getbrick.com</a> if you&#8217;re curious. (7MinSec is <em>not</em> a sponsor, not an affiliate, this is not an ad, etc.)</p><p>Got your own focus/mental health hacks for fellow burnt-out IT folks? Leave a comment!</p><p>Thanks, </p><p>-Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: 7MinSec.wiki - April updates]]></title><description><![CDATA[Good to be back in the TT saddle!]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-7minsecwiki-april</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-7minsecwiki-april</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Wed, 06 May 2026 00:07:52 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/196583445/a44b1035bcce9bbe0deb6266cd74bfc3.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hi friends, long time no posts!  Sorry about that.  I took a <a href="https://www.7minsec.club/p/7minsecclub-is-taking-a-break">break for a while</a>, and was hoping to <a href="https://www.7minsec.club/p/well-be-back-in-april">be back in April</a>, but only my mom noticed I didn&#8217;t get back into the swing of things until now.</p><p>In today&#8217;s Tuesday TOOLSday I wanted to (re)introduce you to <a href="https://7MinSec.wiki">7MinSec.wiki</a> and some new/updated pages I <a href="https://7minsec.wiki/blog/2026-04-27-wiki-updates/">pushed in April</a>, including:</p><ul><li><p>A way to reboot your Mac remotely and <em><a href="https://7minsec.wiki/cmd/mac/fdesetup/">skip</a></em><a href="https://7minsec.wiki/cmd/mac/fdesetup/"> FileVault protections</a></p></li><li><p><a href="https://7minsec.wiki/pentesting/internal/runascs/">RunasCs</a> - when for whatever reason <a href="https://7minsec.wiki/cmd/windows/runas/">runas</a> won&#8217;t cut it</p></li><li><p>Why I use <a href="https://7minsec.wiki/software/twingate/">Twingate</a>, like, all the time now</p></li><li><p>&#8230;and more!</p></li></ul><p>Have a great week,</p><p>Brian</p><p></p>]]></content:encoded></item><item><title><![CDATA[We'll be back in April!]]></title><description><![CDATA[Thanks for your patience]]></description><link>https://www.7minsec.club/p/well-be-back-in-april</link><guid isPermaLink="false">https://www.7minsec.club/p/well-be-back-in-april</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Mon, 23 Mar 2026 20:27:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Jlmz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5e61286-8e46-43fd-8d4e-d7f83119f472_363x363.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hi friends, in our last post I announced a break from 7MinSec.club to focus on helping our local community/neighbors.  I detailed the specifics of my break in these three podcast episodes:</p><ul><li><p><a href="https://7minsec.com/blog/2026/02/27/7ms-711-how-to-secure-your-community/">7MS #711: How to Secure Your Community</a></p></li><li><p><a href="https://7minsec.com/blog/2026/03/06/7ms-712-how-to-secure-your-community-part-2/">7MS #712: How to Secure Your Community &#8211; Part 2</a></p></li><li><p><a href="https://7minsec.com/blog/2026/03/13/7ms-713-how-to-secure-your-community-part-3/">7MS #713: How to Secure Your Community &#8211; Part 3</a></p></li></ul><p>I&#8217;m getting back into the regular swing of things now, and plan on posting regular 7MinSec.club content starting in April.  I&#8217;m not sure if I&#8217;ll go back to a strict &#8220;Tuesday TOOLSday&#8221; schedule we used to have.  I&#8217;m entertaining the idea of being a bit more frequent in posting throughout the week, rather than a formal big post on Tuesdays.  Either way, thanks for your patience and I look forward to getting back into the swing of things in April.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/p/well-be-back-in-april/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/p/well-be-back-in-april/comments"><span>Leave a comment</span></a></p><p>Brian</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[7MinSec.club is taking a break]]></title><description><![CDATA[We'll be back...]]></description><link>https://www.7minsec.club/p/7minsecclub-is-taking-a-break</link><guid isPermaLink="false">https://www.7minsec.club/p/7minsecclub-is-taking-a-break</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Tue, 13 Jan 2026 16:10:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Jlmz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5e61286-8e46-43fd-8d4e-d7f83119f472_363x363.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello friends.  I&#8217;m pushing the pause button on this Substack for the time being.  I work in the Twin Cities area and there&#8217;s a lot of work to do to take care of my family, friends, neighbors and community.  I appreciate your support and look forward to resuming our Tuesday TOOLSdays and other content as soon as possible.</p><p>-Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: eramba - a free GRC tool]]></title><description><![CDATA[Powerful and priced right!]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-eramba-a-free-grc</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-eramba-a-free-grc</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Tue, 06 Jan 2026 16:03:07 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/183281604/dc3e898254b977b7b1b2248b8d846391.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Happy new year!  Today I give you a quick getting-started guide for <a href="https://www.eramba.org/">eramba</a> (not a partner/sponsor), a &#8220;community driven GRC solution that doesn&#8217;t break the bank.&#8221;  It&#8217;s pretty easy to get installed via <a href="https://www.eramba.org/learning/courses/12/episodes/274">docker</a>, and I added some personal instructions/tweaks of my own on our <a href="https://bpatty.rocks/software/eramba/">BPATTY</a> project.  Eramba looks super feature-packed, has a huge documentation library (complete with an accompanying <a href="https://www.eramba.org/learning">video series</a>), and even includes a beefy <a href="https://www.eramba.org/grc-templates">templates library</a> full of policies, compliance frameworks and more.</p><p>Enjoy!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p>-Brian</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p></p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: wifi pentesting with USB adapters and Proxmox]]></title><description><![CDATA[Making all the picky components work together for pwnage]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-wifi-pentesting</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-wifi-pentesting</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Tue, 30 Dec 2025 16:02:07 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/182956137/d86f7f9ee7d4dde796d1487d7fd9ea27.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Today I give a quick primer on how to use a USB wifi card (such as the <a href="https://www.amazon.com/Panda-Wireless-PAU09-Adapter-Antennas/dp/B01LY35HGO">Panda PAU09</a>) with Proxmox and the <a href="https://bpatty.rocks/hardware/usb-adapters/">monitor mode script (and other tips)</a> to successfully position yourself for maximum wifi pentest pwnage!  </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p>Comments/questions/concerns?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/p/tuesday-toolsday-wifi-pentesting/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/p/tuesday-toolsday-wifi-pentesting/comments"><span>Leave a comment</span></a></p><p>Anything you want me to know?</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p>Thanks,</p><p>-Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: how to fix the ESC8 vulnerability]]></title><description><![CDATA[ADCS vulns are everywhere!]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-how-to-fix-the-esc8</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-how-to-fix-the-esc8</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Tue, 23 Dec 2025 15:02:46 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/182267259/3fa2d15e05e47f1552e21cff57f6c4c2.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This week I jump over to the blue team side of the world and walk through how to find, attack and fix the ADCS ESC8 vulnerability!  Microsoft has some guidance on various cert fix-ups <a href="https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates">here</a> as well.  During our <a href="https://7minsec.com/services/penetration-testing/">penetration tests</a>, we see a <em>ton</em> of the ESC1 and ESC8 vulnerabilities.  You should also review the <a href="https://specterops.io/blog/2021/06/17/certified-pre-owned/">excellent article/research from SpecterOps</a> on finding/fixing all flavors of ESC vulnerabilities.  Lastly, I&#8217;ve had many clients report that the <a href="https://github.com/jakehildreth/Locksmith">Locksmith</a> tool is excellent for finding, understanding,  and even <em>fixing</em> ESC vulnerabilities in your environment.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/p/tuesday-toolsday-how-to-fix-the-esc8/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/p/tuesday-toolsday-how-to-fix-the-esc8/comments"><span>Leave a comment</span></a></p><p>Thanks,</p><p>-Brian</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[LPLITE:GOAD pentesting course has launched!]]></title><description><![CDATA[Let's hack things together in January]]></description><link>https://www.7minsec.club/p/lplitegoad-pentesting-course-has</link><guid isPermaLink="false">https://www.7minsec.club/p/lplitegoad-pentesting-course-has</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Thu, 18 Dec 2025 13:07:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Eae9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Eae9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Eae9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Eae9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Eae9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Eae9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Eae9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:203054,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.7minsec.club/i/181913452?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Eae9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Eae9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Eae9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Eae9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff85f2cba-f886-4b27-8623-7395134d61ea_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hello friends!  I&#8217;m <em>super </em>excited to share that our brand new Active Directory pentesting course, Light Pentest LITE:GOAD (Live Interactive Training Experience: Game of Active Directory) is now open for enrollment!</p><p><strong>When</strong>: Tuesday, January 27 - Thursday, January 29 (9:00 a.m. - 1:00 p.m. each day)</p><p><strong>Where</strong>: online via a Web browser (nothing to download/install on your end!)</p><p>Where to sign up and get more details:</p><p><a href="https://training.7minsec.com/events/90c5636a-a642-45f1-acc3-9c6c547fd887">https://training.7minsec.com/events/90c5636a-a642-45f1-acc3-9c6c547fd887</a></p><p>If you have any comments/questions/concerns, please let me know!</p><p>Thanks,</p><p>Brian</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/p/lplitegoad-pentesting-course-has/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/p/lplitegoad-pentesting-course-has/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: coercion attacks against Windows 11]]></title><description><![CDATA[I thought that was a dead attack path...but it's not!]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-coercion-attacks</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-coercion-attacks</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Tue, 16 Dec 2025 16:01:51 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/181798525/bcd13862f94981b493a815b63c969bd2.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hey friends!  In today&#8217;s Tuesday TOOLSday I demonstrate an attack that I thought Windows 11 and higher was hardened against.  On many a internal pentest you might find a Windows system with WebClient enabled - thus (potentially) opening the opportunity to coerce authentication out of that system with a relay attack, thus giving you excessive rights on that victim machine.</p><p>My understanding as of a few months ago, though, is that Windows 11 OS and greater were immune to that type of coercion.  Turns out I was wrong - check out <a href="https://github.com/Hypnoze57/rpc2efs">https://github.com/Hypnoze57/rpc2efs</a> and today&#8217;s video to see Windows 11 coercion in action!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/p/tuesday-toolsday-coercion-attacks/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/p/tuesday-toolsday-coercion-attacks/comments"><span>Leave a comment</span></a></p><p>Thanks,</p><p>Brian</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: I'm out of commission]]></title><description><![CDATA[Sorry!]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-im-out-of-commission</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-im-out-of-commission</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Tue, 09 Dec 2025 16:02:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Jlmz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5e61286-8e46-43fd-8d4e-d7f83119f472_363x363.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello friends,</p><p>Sorry (mom), no Tuesday TOOLSday video today (maybe later this week though).  My calendar went a bit sideways with work and personal things.</p><p>On the topic of Tuesday TOOLSday, though, I&#8217;ve started to take some of the videos from these streams and bake them into my BPATTY (Brian&#8217;s Pentesting And Technical Tips for You) site for easier reference:</p><p><a href="https://bpatty.rocks/tags/video/">https://bpatty.rocks/tags/video/</a> </p><p>Have a great week!</p><p>-Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: DIY pentest dropbox tips]]></title><description><![CDATA[Make remote access to your dropbox even easier]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-diy-pentest-dropbox</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-diy-pentest-dropbox</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Thu, 04 Dec 2025 15:16:04 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/180613750/ced38bd38278e33cf2d60058c421fb1c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This week I show some tips to help make pentest dropbox deployments easier and faster, and <em>also</em> share a shift I&#8217;m making in remote access to these boxes.  The skinny:</p><ul><li><p>Using a <a href="https://community-scripts.github.io/ProxmoxVE/scripts?id=twingate-connector">Proxmox Twingate LXC</a> makes persistent remote access easy.  You can leave this slim VM on your Proxmox box at all times, and <em>not</em> have to nuke and rebuild it with every new customer project!</p></li><li><p>With a little scripting and some use of the <em>qm</em> command at the Proxmox SSH command line, you can set the admin password for both VMs and also set the VMs to start upon Proxmox boot (in whatever order you choose).</p></li></ul><p>Have fun!</p><p>-Brian</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/p/tuesday-toolsday-diy-pentest-dropbox/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/p/tuesday-toolsday-diy-pentest-dropbox/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[ Tuesday TOOLSday: SQL server defense 101]]></title><description><![CDATA[Don't let attackers relay free high-priv SQL creds!]]></description><link>https://www.7minsec.club/p/fc8</link><guid isPermaLink="false">https://www.7minsec.club/p/fc8</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Thu, 27 Nov 2025 13:07:40 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/180037241/d0bf6b4ffa3b4a375c95ef1a9872fa9b.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Today we cover an easy way you can defend against a common SQL server attack - specifically by <em>disabling</em> stored procedures that attackers and pentesters use to give themselves free AD credentials.  I&#8217;ve got a write-up on the defensive commands here: <a href="https://bpatty.rocks/blueteam/sql/">https://bpatty.rocks/blueteam/sql/</a>.  </p><p>While you&#8217;re here, why not subscribe?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p>Comment/question/concern for me?</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p>Thanks,</p><p>Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: Lithnet AD Password Protection]]></title><description><![CDATA[Keep bad passwords out of your AD for free? Yes please.]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-lithnet-ad-password</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-lithnet-ad-password</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Thu, 20 Nov 2025 13:07:38 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/179284862/a967c9f5c1e2bf922c10e2c2fe6696ae.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This week I came across <a href="https://lithnet.io/products/password-protection">Lithnet&#8217;s Password Protection for Active Directory</a> (not a sponsor!).  It&#8217;s awesome!  It&#8217;s a <em>free</em> utility you can install on your domain controllers to block all of the Have I Been Pwned password list, as well as any custom password lists and words you want to manually import.  Perhaps my favorite feature is the ability to add a banned word like <em>7minutesecurity</em> and have it automatically block variations such as:</p><ul><li><p><em>7minutesecurity!</em></p></li><li><p><em>7minutesecurity2025!</em></p></li><li><p><em>7m1nut3s3cur1ty2028</em></p><p></p></li></ul><p>Check it out, and while you&#8217;re here, why not subscribe?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p>Comment/question for me?</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p>Oh and before I forget, I&#8217;ve got a cheat sheet write-up on installing password protection <a href="https://bpatty.rocks/software/lithnetpp/">here</a>.</p><p>Thanks,</p><p>-Brian</p>]]></content:encoded></item><item><title><![CDATA[Light Pentest LITE:GOAD logo winner announced!]]></title><description><![CDATA[And it was hard to choose just one]]></description><link>https://www.7minsec.club/p/light-pentest-litegoad-logo-winner</link><guid isPermaLink="false">https://www.7minsec.club/p/light-pentest-litegoad-logo-winner</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Mon, 17 Nov 2025 13:07:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-vwJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello friends,</p><p>Just wanted to share with you that we landed on a winner for our Light Pentest LITE:GOAD logo contest - check it out:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-vwJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-vwJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-vwJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-vwJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-vwJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-vwJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg" width="1456" height="1361" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1361,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1793675,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.7minsec.club/i/178897494?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-vwJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-vwJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-vwJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-vwJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd7b1ce4-a053-4eac-ad5e-71ef1d276e9f_4665x4361.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ohhhh I love it so much!   This will start getting worked into our <a href="https://7minsec.com/services/training/#720ef3d3901ebbd19">LPLITE:GOAD</a> page, and you&#8217;ll <em>definitely </em>see more of it if you attend the first live class, which is coming in January, 2026.  I&#8217;ll announce the class sign-up link here in Substack first, so please subscribe if you haven&#8217;t already:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p>And don&#8217;t forget to join us for tomorrow&#8217;s Tuesday TOOLSday where we&#8217;ll be showcasing <a href="https://github.com/lithnet/ad-password-protection">Lithnet AD password protection</a>.</p><p>Thanks,</p><p>-Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: LAPS quick install]]></title><description><![CDATA[An essential FREE blue team control for your Active Directory]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-laps-quick-install</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-laps-quick-install</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Thu, 13 Nov 2025 13:07:37 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/178605410/ebbe2a8596d2eb6b0d431ceab6c30e53.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This week we did a super quick install/demo of <a href="https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview">LAPS (Local Administrator Password Solution)</a>.  LAPS is built right into Active Directory and gives you a free/easy way to assign all of your endpoints a <em>unique</em> local Administrator account password, thus making it harder for hackers who compromise <em>one</em> endpoint to compromise <em>all</em> endpoints.</p><p>Enjoying this content?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p>Questions/comments/concerns for me?</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p>Thanks,<br></p><p>Brian</p><div class="install-substack-app-embed install-substack-app-embed-web" data-component-name="InstallSubstackAppToDOM"><img class="install-substack-app-embed-img" src="https://substackcdn.com/image/fetch/$s_!Jlmz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5e61286-8e46-43fd-8d4e-d7f83119f472_363x363.png"><div class="install-substack-app-embed-text"><div class="install-substack-app-header">Get more from Brian Johnson in the Substack app</div><div class="install-substack-app-text">Available for iOS and Android</div></div><a href="https://substack.com/app/app-store-redirect?utm_campaign=app-marketing&amp;utm_content=author-post-insert&amp;utm_source=7minsec" target="_blank" class="install-substack-app-embed-link"><button class="install-substack-app-embed-btn button primary">Get the app</button></a></div>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: Pretender]]></title><description><![CDATA[A nice alternative to mitm6]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-pretender</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-pretender</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Thu, 06 Nov 2025 13:07:51 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/177994951/164f79889191bfde21b71397f0a547bf.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This week I gave a quick intro of <a href="https://github.com/RedTeamPentesting/pretender">pretender</a>, a tool that has the powers of mitm6 + the spoofing capabilities of Responder.  Specifically, I demonstrated how to selectively spoof a hostname that systems are querying but for which no DNS record exists.  I&#8217;m <em>definitely</em> going to play with this more and use it on future assessments.  There&#8217;s a great overview of the tool with some examples and videos <a href="https://blog.redteam-pentesting.de/2022/introducing-pretender/">here</a>.  </p><p>Do you use pretender on assessments?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/p/tuesday-toolsday-pretender/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/p/tuesday-toolsday-pretender/comments"><span>Leave a comment</span></a></p><p>Questions/comments/concerns for me?</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p>Thanks,</p><p>-Brian</p>]]></content:encoded></item><item><title><![CDATA[Tuesday TOOLSday: Kerberoasting Kleanup]]></title><description><![CDATA[Nuke those old SPN and embrace service account best practices]]></description><link>https://www.7minsec.club/p/tuesday-toolsday-kerberoasting-kleanup</link><guid isPermaLink="false">https://www.7minsec.club/p/tuesday-toolsday-kerberoasting-kleanup</guid><dc:creator><![CDATA[Brian Johnson]]></dc:creator><pubDate>Thu, 30 Oct 2025 12:07:56 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/177377207/664a8e044eb52ecfc16dd958a69647d2.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hello friends!  This week I talked about how you can clean up old Active Directory SPNs.  The main page with all the links is over at our <a href="https://bpatty.rocks/blueteam/kerberoasting/">BPATTY repository</a>, but here are the links we talked about during the livestream:</p><ul><li><p>wald0&#8217;s <a href="https://x.com/_wald0/status/1562871258190348289?lang=en">tweet</a> about Kerberoasting cleanup</p></li><li><p>Microsoft&#8217;s <a href="https://learn.microsoft.com/en-us/archive/technet-wiki/52081.active-directory-a-practical-way-to-clean-up-dead-spns-in-active-directory">practical way to clean up dead SPNs in Active Directory</a></p></li><li><p><a href="https://github.com/MahdiTehrani/Get-SPNReport/blob/d6cf62aade7d681e10d828db0697226cbafb3d40/Get-SPNReport.ps1">Script</a> to cleanup dead SPNs</p></li><li><p><a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731241(v=ws.11)">setspn</a> - a tool to add/modify/delete SPNs</p><p> </p></li></ul><p>Enjoy, and why you&#8217;re here, why not:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.7minsec.club/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.7minsec.club/subscribe?"><span>Subscribe now</span></a></p><p>Thanks,</p><p>Brian</p><div class="directMessage button" data-attrs="{&quot;userId&quot;:112675607,&quot;userName&quot;:&quot;Brian Johnson&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div>]]></content:encoded></item></channel></rss>