<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/static/rss.xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
     xmlns:podcast="https://podcastindex.org/namespace/1.0"
     version="2.0">
<channel>
<title>Purple Squad Security</title>
<link>http://purplesquadsec.com</link>
<atom:link href="https://pinecast.com/feed/purple-squad-security" rel="self" type="application/rss+xml" />
<generator>Pinecast (https://pinecast.com)</generator>
<language>en-US</language><itunes:author>John Svazic</itunes:author>
<description><![CDATA[Information Security, InfoSec, CyberSec, Cyber, Security, whatever you call it, we talk about it! From mobiles and desktops to data centers and the cloud, Purple Squad Security is here to help and give back to our community of information security professionals.  We cover security topics for the red team, blue team, purple team, whatever team!  We are a community of professionals, and this is one man's attempt to give back.  CISSP, CISM, CEH credits can be obtained here!  Also happy to provide info for OSCP, OSCE, and other Offensive Security certified professionals.]]></description>
<itunes:owner>
<itunes:name>John Svazic</itunes:name>
<itunes:email>jsvazic@gmail.com</itunes:email>
</itunes:owner>
<itunes:explicit>no</itunes:explicit>
<itunes:image href="https://storage.pinecast.net/podcasts/covers/19c82c10-888a-4f20-871b-f4f6c51fb5bd/podcast_cover.png" />
<image>
<title>Purple Squad Security</title>
<link>http://purplesquadsec.com</link>
<url>https://storage.pinecast.net/podcasts/covers/19c82c10-888a-4f20-871b-f4f6c51fb5bd/podcast_cover.png</url>
</image><itunes:type>episodic</itunes:type>
<copyright>Copyright (c) 2017 - 2019 - John Svazic</copyright>
<itunes:subtitle>If you know the enemy and know yourself, you need not fear the result of a hundred battles.</itunes:subtitle>
<itunes:complete>Yes</itunes:complete>
<itunes:category text="Technology" />
<item><title>Special Episode - EliteCast Episode 1</title>
<guid isPermaLink="false">https://pinecast.com/guid/255e79b1-4c24-4db0-9727-72901946eb16</guid>
<pubDate>Tue, 05 Jan 2021 08:35:00 -0000</pubDate>

<itunes:duration>00:23:19</itunes:duration>
<itunes:subtitle>An introduction to John's newest podcast for your listening pleasure</itunes:subtitle>
<link>http://purplesquadsec.com/episode/255e79b14c244db0/special-episode-elitecast-episode-1</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/512cb71f-9552-49a3-9847-0018985bb259/image.png" />
<description><![CDATA[<h1>Episode Notes</h1>
<p>Here's the first episode of my new podcast, EliteCast!  This is intended to be a less technical podcast aimed at business leaders and decision-makers to help explain the importance of information security (or <em>cybersecurity</em> as it's normally called by the target audience).  I'm a bit rusty, but I'll get there.  Apparently, a 9-month hiatus does that to a man.</p>
<p>I hope you enjoy it and you choose to subscribe.  It should be live on the usual podcast sites, but if you want the RSS link, check out:</p>
<p><a href="https://pinecast.com/feed/elitecast" rel="nofollow">https://pinecast.com/feed/elitecast</a></p>
<p>Thanks, and take care!</p>
<hr>
<ul>
<li>EliteSec's Website: <a href="https://elitesec.io" rel="nofollow">https://elitesec.io</a></li>
<li>Want to get in touch? <a href="mailto:info@elitesec.io" rel="nofollow">info@elitesec.io</a></li>
</ul>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/255e79b1-4c24-4db0-9727-72901946eb16.mp3?source=rss&amp;ext=asset.mp3" length="16802655" type="audio/mpeg" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 71 - A Casual Conversation with The Cyber Mentor</title>
<guid isPermaLink="false">https://pinecast.com/guid/c64d1002-c461-4a86-bca3-8d28cae96448</guid>
<pubDate>Sun, 08 Mar 2020 14:13:48 -0000</pubDate>

<itunes:duration>00:42:52</itunes:duration>
<itunes:subtitle>The Cyber Mentor stops by to chat about business, getting into Infosec, and what he's doing to give back to the community.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/c64d1002c4614a86/episode-71-a-casual-conversation-with-the-cyber-mentor</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/96e01662-14eb-4a30-9f1c-fb3b80aebdec/image.png" />
<description><![CDATA[<p>Heath "The Cyber Mentor" Adams stops by to have a nice casual chat about how he got into infosec, what he's currently working on, and how he's giving back to the community in a rather novel way.  Definitely someone I respect as a great up-and-comer in the industry, this was a fantastic discussion for sure.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Website - <a href="https://www.thecybermentor.com/" rel="nofollow">https://www.thecybermentor.com/</a></li>
<li>Company - <a href="https://tcm-sec.com/" rel="nofollow">https://tcm-sec.com/</a></li>
<li>Discord - <a href="https://discord.gg/REfpPJB" rel="nofollow">https://discord.gg/REfpPJB</a></li>
<li>Twitter - <a href="https://twitter.com/thecybermentor" rel="nofollow">https://twitter.com/thecybermentor</a></li>
<li>YouTube - <a href="https://www.youtube.com/c/thecybermentor" rel="nofollow">https://www.youtube.com/c/thecybermentor</a></li>
<li>Twitch - <a href="https://www.twitch.tv/thecybermentor" rel="nofollow">https://www.twitch.tv/thecybermentor</a></li>
<li>Udemy - <a href="https://www.udemy.com/course/practical-ethical-hacking/" rel="nofollow">https://www.udemy.com/course/practical-ethical-hacking/</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/c64d1002-c461-4a86-bca3-8d28cae96448.mp3?source=rss&amp;ext=asset.mp3" length="30944751" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 70 - Mul-Tea-Factor with Kat Sweet</title>
<guid isPermaLink="false">https://pinecast.com/guid/3fd15325-affa-4d66-bb43-5035cfc81588</guid>
<pubDate>Sun, 23 Feb 2020 14:35:07 -0000</pubDate>

<itunes:duration>00:42:59</itunes:duration>
<itunes:subtitle>Kat Sweet comes to chat with me about security as we sip tea!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/3fd15325affa4d66/episode-70-mul-tea-factor-with-kat-sweet</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/92affe22-b8ac-4675-b8ce-c308286240ff/image.png" />
<description><![CDATA[<p>Kat Sweet (@TheSweetKat) sits down to chat about incident response and security operations, all while sipping tea with me.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Kat's Twitter - <a href="https://twitter.com/TheSweekKat" rel="nofollow">@TheSweetKat</a></li>
<li>Kat's Blog - <a href="https://thesweetkat.com/blog" rel="nofollow">thesweetkat.com</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/3fd15325-affa-4d66-bb43-5035cfc81588.mp3?source=rss&amp;ext=asset.mp3" length="31028610" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 69 - 2020 Show Update</title>
<guid isPermaLink="false">https://pinecast.com/guid/2690f0b4-aa41-42a5-8781-4cf8cb5a41c6</guid>
<pubDate>Sun, 09 Feb 2020 15:10:00 -0000</pubDate>

<itunes:duration>00:31:46</itunes:duration>
<itunes:subtitle>John talks about the show for 2020</itunes:subtitle>
<link>http://purplesquadsec.com/episode/2690f0b4aa4142a5/episode-69-2020-show-update</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/44f4c553-d959-4f57-9423-3052015b91aa/image.png" />
<description><![CDATA[<p>John sits down to talk solo about the show and what's in store for 2020.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>EliteSec Website - <a href="https://elitesec.io/" rel="nofollow">https://elitesec.io</a></li>
<li>EliteSec Twitter - <a href="https://twitter.com/elitesec_io" rel="nofollow">@EliteSec_io</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/2690f0b4-aa41-42a5-8781-4cf8cb5a41c6.mp3?source=rss&amp;ext=asset.mp3" length="22952618" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 68 - All About The Diana Initiative with Circuit Swan</title>
<guid isPermaLink="false">https://pinecast.com/guid/7dfe7f17-4e6b-4ac4-a95a-8d4c8ee21180</guid>
<pubDate>Mon, 20 Jan 2020 02:34:27 -0000</pubDate>

<itunes:duration>00:40:08</itunes:duration>
<itunes:subtitle>Circuit Swan joins me to talk about the Diana Initiative and a few extras they are doing for this years conference</itunes:subtitle>
<link>http://purplesquadsec.com/episode/7dfe7f174e6b4ac4/episode-68-all-about-the-diana-initiative-with-circuit-swan</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/1dd1f6ed-92b7-4215-9a97-ba3a8ab9724f/image.png" />
<description><![CDATA[<p>Circuit Swan stops by the show to talk all things Diana Initiative.  If you're going to Hacker Summer Camp 2020, you may want to consider adding the Diana Initiative to your list of cons to attend.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Circuit Swan's Twitter: <a href="https://twitter.com/CircuitSwan" rel="nofollow">@CircuitSwan</a></li>
<li>Diana Initiative Twitter: <a href="https://twitter.com/DianaInitiative" rel="nofollow">@DianaInitiative</a></li>
<li>Website - <a href="https://www.dianainitiative.org/" rel="nofollow">https://www.dianainitiative.org</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/7dfe7f17-4e6b-4ac4-a95a-8d4c8ee21180.mp3?source=rss&amp;ext=asset.mp3" length="28976784" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 67 - A casual conversation with Snow</title>
<guid isPermaLink="false">https://pinecast.com/guid/e2c3d6a2-5e8f-4dcb-8bfc-1de9b3251148</guid>
<pubDate>Sun, 15 Dec 2019 15:31:14 -0000</pubDate>

<itunes:duration>00:48:00</itunes:duration>
<itunes:subtitle>Snow stops by the show to chat about physical penetration testing, Kringlecon, and a few other topics</itunes:subtitle>
<link>http://purplesquadsec.com/episode/e2c3d6a25e8f4dcb/episode-67-a-casual-conversation-with-snow</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/c6e13d52-cad5-4940-8e45-1c0a96138805/image.png" />
<description><![CDATA[<p>Snow stops by during the winter months to share with us the true origin of her hacker handle, stories from some physical penetration testing, a quick note on her Kringlecon talk, and so much more!  A great way to round out the year!</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Snow's Twitter: <a href="https://twitter.com/_sn0ww" rel="nofollow">@_sn0ww</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/e2c3d6a2-5e8f-4dcb-8bfc-1de9b3251148.mp3?source=rss&amp;ext=asset.mp3" length="34646758" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 66 - Fireside Chat with Adrian Cheek</title>
<guid isPermaLink="false">https://pinecast.com/guid/2da9c018-12e6-42f4-917a-8019bf6fa71b</guid>
<pubDate>Sun, 01 Dec 2019 16:35:23 -0000</pubDate>

<itunes:duration>00:42:05</itunes:duration>
<itunes:subtitle>Adrian Cheek stops by to talk about taking down criminal websites, passive DNS, and threat hunting</itunes:subtitle>
<link>http://purplesquadsec.com/episode/2da9c01812e642f4/episode-66-fireside-chat-with-adrian-cheek</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/2393c6c9-2375-40c0-ab81-600ca44eec07/image.png" />
<description><![CDATA[<p>Adrian Cheek stops by the show this week to have a nice fireside chat with me.  We talk about passive DNS, which Adrian first introduced to me a few years ago, and then move on to threat hunting.  Adrian has a very interesting history and it was a joy to speak with him.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Adrian's Twitter: <a href="https://twitter.com/Outkast_TI" rel="nofollow">@Outkast_TI</a></li>
<li>Farsight Passive DNS - <a href="https://www.farsightsecurity.com/solutions/dnsdb/" rel="nofollow">https://www.farsightsecurity.com/solutions/dnsdb/</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/2da9c018-12e6-42f4-917a-8019bf6fa71b.mp3?source=rss&amp;ext=asset.mp3" length="30380683" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 65 - Fireside Chat with The Gibson</title>
<guid isPermaLink="false">https://pinecast.com/guid/106de6dc-d5ed-4c9e-8131-fb8f04fdc50d</guid>
<pubDate>Sun, 17 Nov 2019 15:21:44 -0000</pubDate>

<itunes:duration>00:52:38</itunes:duration>
<itunes:subtitle>I sit down with The Gibson to chat about the Fediverse, SMB Security, and life in general</itunes:subtitle>
<link>http://purplesquadsec.com/episode/106de6dcd5ed4c9e/episode-65-fireside-chat-with-the-gibson</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/3733b3f8-77aa-4880-b6a6-74455008e6fd/image.png" />
<description><![CDATA[<p>I'm trying a slightly different format for the next few episodes, and I'd appreciate any feedback you may have.  </p>
<p>In this episode I sit down with The Gibson, mayor of hackers.town, to talk about a variety of things from the Fediverse, working with the under-serviced SMB market, old school technologies, and the Infosec community as a whole.  We're all over the place, but it's a good thing.  Just a nice casual conversation talking about things that interest us.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Gibson's Mastodon: @TheGibson@hackers.town</li>
<li>Hacker's Town: https://hackers.town</li>
<li>Gibson's Twitter: <a href="https://twitter.com/gibsonmainframe" rel="nofollow">@gibsonmainframe</a></li>
<li>BlackFire Security: <a href="https://blackfiresec.com/" rel="nofollow">https://blackfiresec.com/</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/106de6dc-d5ed-4c9e-8131-fb8f04fdc50d.mp3?source=rss&amp;ext=asset.mp3" length="37976715" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 64 - Fireside Chat with Tanya Janca</title>
<guid isPermaLink="false">https://pinecast.com/guid/629c0c4f-f2a5-4f58-8803-7be80a6d0bba</guid>
<pubDate>Sun, 03 Nov 2019 15:16:00 -0000</pubDate>

<itunes:duration>00:50:50</itunes:duration>
<itunes:subtitle>I sit down with Tanya Janca for a fireside chat about her new company, Security Sidekick</itunes:subtitle>
<link>http://purplesquadsec.com/episode/629c0c4ff2a54f58/episode-64-fireside-chat-with-tanya-janca</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/574567f8-4dc1-4a03-8896-d5e3f1c9cc78/image.png" />
<description><![CDATA[<p>I'm trying a slightly different format for the next few episodes, and I'd appreciate any feedback you may have.  </p>
<p>In this episode I sit down with the amazing Tanya Janca for a fireside chat about her new company, Security Sidekick.  They seem to have some pretty ambitious goals, and I couldn't think of anyone better to help make those a reality.</p>
<p>Some links of interest:</p>
<hr>
<h3>For Tanya:</h3>
<ul>
<li>Tanya's Twitter: <a href="https://twitter.com/shehackspurple" rel="nofollow">https://twitter.com/shehackspurple</a></li>
<li>Tanya's <a href="http://Dev.to" rel="nofollow">Dev.to</a> Profile: <a href="https://dev.to/shehackspurple" rel="nofollow">https://dev.to/shehackspurple</a></li>
<li>Tanya's Blog: <a href="https://medium.com/@shehackspurple" rel="nofollow">https://medium.com/@shehackspurple</a></li>
<li>Tanya's YouTube Profile: <a href="https://www.youtube.com/shehackspurple" rel="nofollow">https://www.youtube.com/shehackspurple</a></li>
<li>Tanya's Twitch Channel: <a href="https://www.twitch.tv/shehackspurple" rel="nofollow">https://www.twitch.tv/shehackspurple</a></li>
<li>Tanya's LinkedIn Profile: <a href="https://www.linkedin.com/in/tanya-janca" rel="nofollow">https://www.linkedin.com/in/tanya-janca</a></li>
</ul>
<h3>For Security Sidekick:</h3>
<ul>
<li>Website: https://securitysidekick.dev</li>
<li>Twitter: <a href="https://twitter.com/SecSidekick" rel="nofollow">https://twitter.com/SecSidekick</a> </li>
<li>YouTube Channel: <a href="https://www.youtube.com/channel/UC3KyuI83jt0l14q8xyffC2A" rel="nofollow">https://www.youtube.com/channel/UC3KyuI83jt0l14q8xyffC2A</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/629c0c4f-f2a5-4f58-8803-7be80a6d0bba.mp3?source=rss&amp;ext=asset.mp3" length="36680841" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 63 - Backdoors &amp; Breaches with John Strand</title>
<guid isPermaLink="false">https://pinecast.com/guid/7a0caa7e-c59c-4028-b791-46c123d64e9e</guid>
<pubDate>Sun, 20 Oct 2019 14:08:05 -0000</pubDate>

<itunes:duration>00:42:55</itunes:duration>
<itunes:subtitle>John Strand (@strandjs) stops by to chat about physical security assessments, Backdoors &amp; Breaches, and the InfoSec community!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/7a0caa7ec59c4028/episode-63-backdoors-breaches-with-john-strand</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/6108cc34-be68-44d8-b5e1-0c221cb70e3c/image.png" />
<description><![CDATA[<p>Oh what I treat I have for you today!  John Strand, former SANS instructor, long time co-host on Enterprise Security Weekly, Founder of Black Hills Information Security, and a whole lot more has taken time out of his busy schedule to stop by and talk about Backdoors &amp; Breaches, the new IR card game from BHIS.  Naturally we talk about more than just the game, but it was all as amazing as I had hoped.  I trust you will enjoy listening to this one about as much as I enjoyed recording it.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Backdoors &amp; Breaches Site - <a href="http://backdoorsandbreaches.com/" rel="nofollow">http://backdoorsandbreaches.com/</a></li>
<li>John's Email - john 'at' <a href="http://blackhillsinfosec.com" rel="nofollow">blackhillsinfosec.com</a></li>
<li>John's Twitter - <a href="https://twitter.com/strandjs" rel="nofollow">@strandjs</a></li>
<li>BHIS Website - <a href="https://www.blackhillsinfosec.com" rel="nofollow">https://www.blackhillsinfosec.com</a></li>
<li>Events where BHIS will be - <a href="https://www.blackhillsinfosec.com/events/" rel="nofollow">https://www.blackhillsinfosec.com/events/</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/7a0caa7e-c59c-4028-b791-46c123d64e9e.mp3?source=rss&amp;ext=asset.mp3" length="30986751" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 62 - #ginfosec with InfoSecSherpa - Empathy as a Service</title>
<guid isPermaLink="false">https://pinecast.com/guid/d6c9095c-1f20-47d7-8439-57a3b6bbcd51</guid>
<pubDate>Sun, 06 Oct 2019 14:52:54 -0000</pubDate>

<itunes:duration>01:01:44</itunes:duration>
<itunes:subtitle>Tracy "InfoSecSherpa" comes back for another #ginfosec episode to talk about Empathy as a Service</itunes:subtitle>
<link>http://purplesquadsec.com/episode/d6c9095c1f2047d7/episode-62-ginfosec-with-infosecsherpa-empathy-as-a-service</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/6ee26164-3b48-4efa-b616-64cd44da7236/artwork.png" />
<description><![CDATA[<p>It's been long enough, and it's time for Tracy "InfoSecSherpa" to return for another #ginfosec episode!  This time around we're going to talk about Empathy as a Service, a talk that she recently did at DerbyCon.  Soft skills will get you everywhere, and Tracy has some great advice to share about a topic she's very passionate about.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Tracy's Talk - <a href="https://www.youtube.com/watch?v=KILlp4KMIPA" rel="nofollow">https://www.youtube.com/watch?v=KILlp4KMIPA</a></li>
<li>Tracy's OSINT-y Goodness Blog - <a href="medium.com/@InfoSecSherpa" rel="nofollow">medium.com/@InfoSecSherpa</a></li>
<li>Tracy's Twitter - <a href="https://twitter.com/InfoSecSherpa" rel="nofollow">https://twitter.com/InfoSecSherpa</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/d6c9095c-1f20-47d7-8439-57a3b6bbcd51.mp3?source=rss&amp;ext=asset.mp3" length="44534872" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 61 – Anniversaries and Updates</title>
<guid isPermaLink="false">https://pinecast.com/guid/b01ea05a-a7b5-4ac6-a72a-76b368cc4e9a</guid>
<pubDate>Sun, 22 Sep 2019 14:43:00 -0000</pubDate>

<itunes:duration>00:37:20</itunes:duration>
<itunes:subtitle>John talks about the 2 year anniversary of the show as well as other behind-the-scenes details.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/b01ea05aa7b54ac6/episode-61-anniversaries-and-updates</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/6c07e71c-27a7-4252-b8d2-313e11b559e2/artwork.png" />
<description><![CDATA[<p>Ah, I love anniversaries.  This is an anniversary episode celebrating 2 years of Purple Squad Security!  Just a few personal rants and discussions for those interested in a bit of a <em>behind the scenes</em> view of things here at the show.  No guests, just me blathering on about stuff.  Enjoy!</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Cyber City<ul>
<li><a href="https://cybercityconf.io" rel="nofollow">Website</a></li>
<li><a href="https://twitter.com/cybercityconf" rel="nofollow">Twitter</a></li>
</ul>
</li>
<li>Podcast Store: <a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/b01ea05a-a7b5-4ac6-a72a-76b368cc4e9a.mp3?source=rss&amp;ext=asset.mp3" length="26960778" type="audio/mp3" />
<itunes:season>1</itunes:season>
</item>
<item><title>Episode 60 – Tabletop D&amp;D with Ken Johnson &amp; Seth Law from Absolute AppSec</title>
<guid isPermaLink="false">https://pinecast.com/guid/e2ee738c-0965-49aa-8b53-7ffda0ce2f96</guid>
<pubDate>Sun, 01 Sep 2019 13:35:46 -0000</pubDate>

<itunes:duration>01:08:14</itunes:duration>
<itunes:subtitle>Ken Johnson and Seth Law from the Absoute AppSec Podcast join me for another Tabletop D&amp;D episode!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/e2ee738c096549aa/episode-60-tabletop-d-d-with-ken-johnson-seth-law-from-absolute-appsec</link>
<itunes:image href="https://storage.pinecast.net/podcasts/95f03ebe-85af-41aa-b6e9-325c53c0c42c/artwork/6e36e701-67f0-4719-87fa-d78498c48a76/artwork.png" />
<description><![CDATA[<p>The hiatus is over!  Welcome back everyone to the latest episode of the Purple Squad Security podcast!  In this episode we have Ken Johnson and Seth Law from the Absolute AppSec Podcast joining me for the latest session of Tabletop D&amp;D.  Enjoy!</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Absolute AppSec<ul>
<li><a href="https://absoluteappsec.com" rel="nofollow">Website</a></li>
<li><a href="https://twitter.com/absoluteappsec" rel="nofollow">Twitter</a></li>
</ul>
</li>
<li>Seth's Twitter Account: <a href="https://twitter.com/sethlaw" rel="nofollow">@sethlaw</a></li>
<li>Ken's Twitter Account: <a href="https://twitter.com/cktricky" rel="nofollow">@cktricky</a></li>
</ul>
<hr>
<p>Want to hear about a new Infosec con?  If you're in and around the Waterloo region area in October, why not check out Cyber City!  This is Waterloo region's premier information security conference.  Tickets are on sale now! </p>
<ul>
<li>Cyber City Conference: <a href="https://www.cybercityconf.io/" rel="nofollow">https://www.cybercityconf.io/</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/e2ee738c-0965-49aa-8b53-7ffda0ce2f96.mp3?source=rss&amp;ext=asset.mp3" length="49214988" type="audio/mp3" />
</item>
<item><title>Episode 58 – Malware Analysis with Kyle Andrus</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=362</guid>
<pubDate>Sun, 23 Jun 2019 15:12:52 -0000</pubDate>

<itunes:duration>00:43:52</itunes:duration>
<itunes:subtitle>Kyle Andrus comes back to talk about what malware analysis is and some starting points for getting into it.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/e00b7b4ac268465f/episode-58-malware-analysis-with-kyle-andrus</link>
<description><![CDATA[<p>Often times in information security, we look upon penetration testing and red teaming with awe and view those professions as the "sexy" side of security.  Truth be told, the defensive side has a lot of exciting opportunities as well!  Kyle Andrus joins me this week to talk about <em>malware analysis</em>, which I think is definitely one of the sexier sides of defense. Some links of interest:</p>
<hr>
<ul>
<li>Practical Malware Analysis Book - <a href="https://nostarch.com/malware" rel="nofollow">https://nostarch.com/malware</a></li>
<li>Cuckoo Sandbox - <a href="https://cuckoosandbox.org/" rel="nofollow">https://cuckoosandbox.org/</a></li>
<li>CyberChef - <a href="https://gchq.github.io/CyberChef/" rel="nofollow">https://gchq.github.io/CyberChef/</a></li>
<li>Leny Zeltser's Blog - <a href="https://zeltser.com/blog/" rel="nofollow">https://zeltser.com/blog/</a></li>
<li>Journey Into Incident Response - <a href="http://journeyintoir.blogspot.com/" rel="nofollow">http://journeyintoir.blogspot.com/</a></li>
<li>Malware Unicorn's Reverse Engineering Workshop - <a href="https://malwareunicorn.org/#/workshops" rel="nofollow">https://malwareunicorn.org/#/workshops</a></li>
<li>MiSec - <a href="https://www.misec.us/" rel="nofollow">https://www.misec.us/</a></li>
<li>Kyle's Twitter Account: <a href="https://twitter.com/chaoticflaws" rel="nofollow">@chaoticflaws</a></li>
</ul>
<hr>
<p>Want to hear about a new Infosec con?  If you're in and around the Waterloo region area in October, why not check out Cyber City!  This is Waterloo region's premier information security conference.  Tickets are on sale now and the CFP is open until July 31st, 2019.  Don't wait, and come participate today!  </p>
<ul>
<li>Cyber City Conference: <a href="https://www.cybercityconf.io/" rel="nofollow">https://www.cybercityconf.io/</a></li>
<li>Cyber City Conference CFP: <a href="https://www.papercall.io/cybercityconf" rel="nofollow">https://www.papercall.io/cybercityconf</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/e00b7b4a-c268-465f-9eb4-012a56cab68f:2a6e1b7c-77cb-428e-b1ae-b49331d17564.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 57 – Tinker After Dark – Tinker Tales by the Fire</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=357</guid>
<pubDate>Sun, 09 Jun 2019 14:45:47 -0000</pubDate>

<itunes:duration>01:20:23</itunes:duration>
<itunes:subtitle>Tinkers back! With the green light to speak as he wants, we get some excellent stories and great retrospectives!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/3c5b25e415b5437b/episode-57-tinker-after-dark-tinker-tales-by-the-fire</link>
<description><![CDATA[<p>There were more than a few of you who were anxiously awaiting his return, and he's back!  Tinker joins me once again to share some stories from his adventures in hackerland.  In addition, I have given Tinker free reign to speak as he chooses, and naturally I participate as well.  Fair warning, this is not safe for work or sensitive ears.  I do ask that you try not to be offended, as his stories and reflections on those events makes for one excellent episode.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Tinker's Fediverse Account: @tinker@infosec.exchange</li>
<li>Tinker's Twitter Account: <a href="https://twitter.com/TinkerSec" rel="nofollow">@TinkerSec</a></li>
<li>Tinker's Blog: <a href="https://www.tinker.sh/" rel="nofollow">https://tinker.sh</a></li>
<li>SecLists: <a href="https://github.com/danielmiessler/SecLists" rel="nofollow">https://github.com/danielmiessler/SecLists</a></li>
<li>Cyber City Conference: <a href="https://www.cybercityconf.io/" rel="nofollow">https://www.cybercityconf.io/</a></li>
<li>Cyber City Conference CFP: <a href="https://www.papercall.io/cybercityconf" rel="nofollow">https://www.papercall.io/cybercityconf</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/3c5b25e4-15b5-437b-8894-cf1d7aae8ec0:510f21a6-15b3-48c1-90a3-ad29b66561dd.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 56 – John Reads: Choose Your Own Red Team Adventure</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=352</guid>
<pubDate>Sun, 26 May 2019 14:10:21 -0000</pubDate>

<itunes:duration>00:32:16</itunes:duration>
<itunes:subtitle>John reads a Choose Your Own Adventure story that was posted on Medium related to Red Teaming!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/243a0741cdcb4e77/episode-56-john-reads-choose-your-own-red-team-adventure</link>
<description><![CDATA[<p>A few weeks ago, Sam King on Twitter mentioned me in a tweet that included a link to a Medium post, but not just any Medium post.  Tim MalcomVetter had posted up an "Choose Your Own Red Team Adventure", which I thought was just amazing!  I used to read a lot of choose your own adventure books as a kid, so I was naturally excited!  For this episode, I will be going through the story the first time, reading aloud as I try my hand at red teaming against a customer.  I hope you enjoy!</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Choose Your Own Red Team Adventure - <a href="https://medium.com/@malcomvetter/choose-your-own-red-team-adventure-f87d6a3b0b76" rel="nofollow">https://medium.com/@malcomvetter/choose-your-own-red-team-adventure-f87d6a3b0b76</a></li>
<li>Tim MalcomVetter's Twitter - <a href="https://twitter.com/malcomvetter" rel="nofollow">@malcomvetter</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/243a0741-cdcb-4e77-8e56-96d952428a66:ba342451-8f4b-44df-a89a-07a03d310251.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 55 – Talking Privacy with Matt Beland</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=341</guid>
<pubDate>Sun, 12 May 2019 14:11:52 -0000</pubDate>

<itunes:duration>00:49:13</itunes:duration>
<itunes:subtitle>Matt Beland stops by to talk about privacy and what that means for a security professional.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/10980e4d1d01420c/episode-55-talking-privacy-with-matt-beland</link>
<description><![CDATA[<p><strong>CORRECTION:</strong> <em>Early in this episode I mentioned that Amazon would ask for your email password when signing up for a new account.  I meant to say Facebook, not Amazon.  The practice has since been discontinued, but I wanted to make it clear that this was a Facebook practice, not Amazon.  Amazon has not, to the best of my knowledge, ever done something like this.  Sorry for the mixup.</em></p>
<hr>
<p>For most security professionals, we view the CIA triad as our grail.  No, not the US government agency that works around the world doing a lot of questionable things, but rather the more tame version of Confidentiality, Integrity, and Availability.  For today's episode, Matt Beland joins me to explain privacy and how it's not all about Confidentiality as I, and I'm sure a few of you, may have thought.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Smooth Sailing Solutions: <a href="http://smoothsailingsolutions.com/" rel="nofollow">smoothsailingsolutions.com</a></li>
<li>Matt's Twitter: <a href="https://twitter.com/beland_matt" rel="nofollow">@Beland_Matt</a></li>
<li>International Association of Privacy Professionals: <a href="https://iapp.org" rel="nofollow">https://iapp.org</a></li>
<li>CIPP / CIPM / CIPT Certifications: <a href="https://iapp.org/certify/programs/" rel="nofollow">https://iapp.org/certify/programs/</a></li>
<li>Ethical Data and Information Management: Concepts, Tools and Methods: <a href="https://www.amazon.com/Ethical-Data-Information-Management-Concepts/dp/0749482044" rel="nofollow">https://www.amazon.com/Ethical-Data-Information-Management-Concepts/dp/0749482044</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/10980e4d-1d01-420c-9aac-d49633b6e7bc:5264c191-653a-49f9-b99c-2be93f3ab088.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 54 – Tribe of Hackers with Marcus J. Carey</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=333</guid>
<pubDate>Sun, 28 Apr 2019 13:00:00 -0000</pubDate>

<itunes:duration>00:29:46</itunes:duration>
<itunes:subtitle>Marcus Carey joins me to talk about his latest book, Tribe of Hackers.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/2940f0a8e3394945/episode-54-tribe-of-hackers-with-marcus-j-carey</link>
<description><![CDATA[<p><em>Tribe of Hackers</em> is a recently released book by Marcus Carey and Jennifer Jin that is a collection of stories from member of our community, or tribe as Marcus describes it.  This was a great and insightful interview, and definitely one you will want to listen to if you haven't read the book yet. Some links of interest:</p>
<hr>
<ul>
<li>Tribe of Hackers: <a href="https://www.amazon.com/Tribe-Hackers-Cybersecurity-Advice-World/dp/1793464189/" rel="nofollow">https://www.amazon.com/Tribe-Hackers-Cybersecurity-Advice-World/dp/1793464189/</a></li>
<li>Tribe of Mentors (inspiration for <em>Tribe of Hackers</em>): <a href="https://www.amazon.com/Tribe-Mentors-Short-Advice-World/dp/1328994961/" rel="nofollow">https://www.amazon.com/Tribe-Mentors-Short-Advice-World/dp/1328994961/</a></li>
<li>The 4 Agreements - <a href="https://www.amazon.com/Four-Agreements-Practical-Personal-Freedom/dp/1878424319/" rel="nofollow">https://www.amazon.com/Four-Agreements-Practical-Personal-Freedom/dp/1878424319/</a></li>
<li>Marcus's Twitter: <a href="https://twitter.com/marcusjcarey" rel="nofollow">@marcusjcarey</a></li>
<li>Jennifer Jin's Twitter: <a href="https://twitter.com/jen_jin" rel="nofollow">@jen_jin</a></li>
<li>Tribe of Hackers Twitter: <a href="https://twitter.com/tribeofhackers" rel="nofollow">@TribeOfHackers</a></li>
<li>Tribe of Hackers Summit - May 2, 2019: <a href="https://www.eventbrite.com/e/tribe-of-hackers-summit-registration-59074697009" rel="nofollow">https://www.eventbrite.com/e/tribe-of-hackers-summit-registration-59074697009</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/2940f0a8-e339-4945-b7ac-a2ecd2d4337e:e7e6da5a-e0ad-4f05-9987-44485086b490.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 53 – #Ginfosec with @InfoSecSherpa – All About Cons!</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=331</guid>
<pubDate>Sun, 14 Apr 2019 14:57:01 -0000</pubDate>

<itunes:duration>01:37:23</itunes:duration>
<itunes:subtitle>The @InfoSecSherpa comes back for another #ginfosec episode where we talk about attending conferences</itunes:subtitle>
<link>http://purplesquadsec.com/episode/df3cd3802bf94d39/episode-53-ginfosec-with-infosecsherpa-all-about-cons-</link>
<description><![CDATA[<p>Once again I am pleased to share a #ginfosec episode with the woman who helps guide others through the mountains of infosec, Tracy InfoSecSherpa Maleeff!  In this extended episode Tracy and I speak about conferences from the attendee point of view; what to expect, what to bring, how to go, and what you should aim to get from the con.  Enjoy! Some links of interest:</p>
<hr>
<ul>
<li>Tracy's Twitter: <a href="https://twitter.com/InfoSecSherpa" rel="nofollow">@InfoSecSherpa</a></li>
<li>Sign up for Tracy's Nuzzle Newsletter: <a href="https://nuzzel.com/InfoSecSherpa" rel="nofollow">https://nuzzel.com/InfoSecSherpa</a></li>
<li>Study on different note taking techniques: <a href="https://www.scientificamerican.com/article/a-learning-secret-don-t-take-notes-with-a-laptop/" rel="nofollow">https://www.scientificamerican.com/article/a-learning-secret-don-t-take-notes-with-a-laptop/</a></li>
<li>Tracy's Unusual Journey into Infosec: <a href="https://www.secjuice.com/infosecsherpa-unusual-journeys/" rel="nofollow">https://www.secjuice.com/infosecsherpa-unusual-journeys/</a></li>
<li>Tracy's Talk at BSides NoVa - Networking with Humans: <a href="https://www.youtube.com/watch?v=bbfyXTZCVC0" rel="nofollow">https://www.youtube.com/watch?v=bbfyXTZCVC0</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/df3cd380-2bf9-4d39-8e8c-ebfeb0d2b0d4:75c20d06-f3e3-4118-b390-d5ed409c5ea9.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 52 – John The Generalist</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=323</guid>
<pubDate>Sun, 31 Mar 2019 13:30:06 -0000</pubDate>

<itunes:duration>00:37:17</itunes:duration>
<itunes:subtitle>John goes solo to talk about him being a generalist in Information Security</itunes:subtitle>
<link>http://purplesquadsec.com/episode/5232ae2821c848e9/episode-52-john-the-generalist</link>
<description><![CDATA[<p>This week John goes solo and decides to talk about a recent threat he spun up about on Twitter, naming himself as a generalist within Information Security and discussing what that means to him. Some links of interest:</p>
<ul>
<li><a href="https://twitter.com/JohnsNotHere/status/1110946271324311552" rel="nofollow">John's Twitter Thread</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/5232ae28-21c8-48e9-b4d7-f93e60156bb8:324732bb-1970-44ef-b0c8-a94129254a9e.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 51 – Fireside Chat with Chris Foulon</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=316</guid>
<pubDate>Sun, 10 Mar 2019 14:19:23 -0000</pubDate>

<itunes:duration>00:39:52</itunes:duration>
<itunes:subtitle>Chris Foulon stops by for a fireside chat about breaking into Information Security.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/0b5bba0b28974884/episode-51-fireside-chat-with-chris-foulon</link>
<description><![CDATA[<p>Chris Foulon stops by for a fireside chat to talk about breaking into Infosec.  For those unfamiliar with the fireside chat series, this is where we come in with a topic but no other real agenda.  It's a casual conversation where I just have a casual conversation with my guest, similar to what would happen in hallway con.  I hope you enjoy! Some links of interest:</p>
<hr>
<ul>
<li>Chris' LinkedIn: <a href="https://www.linkedin.com/in/christophefoulon/" rel="nofollow">https://www.linkedin.com/in/christophefoulon/</a></li>
<li>Chris' Twitter: <a href="https://twitter.com/chris_foulon" rel="nofollow">@chris_foulon</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/0b5bba0b-2897-4884-9f75-5dd84fdce9db:01ed5b89-766c-42f3-8be1-1326b4b3c3a6.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 50 – Tabletop D&amp;D with Tim De Block, Ed Rojas, Daniel Ebbutt, and Kyle Andrus</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=310</guid>
<pubDate>Sun, 17 Feb 2019 14:24:39 -0000</pubDate>

<itunes:duration>01:29:29</itunes:duration>
<itunes:subtitle>Another tabletop D&amp;D episode! Pure mayhem with this one, which is fitting for a bicentennial episode!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/b1b95222cf9c48fd/episode-50-tabletop-d-d-with-tim-de-block-ed-rojas-daniel-ebbutt-and-kyle-andrus</link>
<description><![CDATA[<p>It's that time again!  Yes, another Tabletop D&amp;D episode is upon us!  This time I asked Timothy de Block from the Exploring Information Security podcast to join me, along with a few interesting characters.  Let's just say this particular episode is not for the faint of heart, and we have a few swears thrown in to keep with the atmosphere.  Enjoy! Some links of interest:</p>
<hr>
<ul>
<li>Exploring Information Security Podcast: <a href="https://www.timothydeblock.com/eis/" rel="nofollow">https://www.timothydeblock.com/eis/</a></li>
<li>Tactical Edge: <a href="https://tacticaledge.co/index_en.html" rel="nofollow">https://tacticaledge.co/index_en.html</a></li>
<li>Tactical Edge Twitter: <a href="https://twitter.com/Tactical3dge" rel="nofollow">@Tactical3dge</a></li>
<li>Kyle's Twitter: <a href="https://twitter.com/chaoticflaws" rel="nofollow">@chaoticflaws</a></li>
<li>Ed's Twitter: <a href="https://twitter.com/EdgarR0jas" rel="nofollow">@edgarr0jas</a></li>
<li>Daniel's Twitter: <a href="https://twitter.com/notdanielebbutt" rel="nofollow">@notdanielebbutt</a></li>
<li>Tim's Twitter: <a href="https://twitter.com/TimothyDeBlock" rel="nofollow">@timothydeblock</a></li>
<li>Tabletop Scenarios Twitter: <a href="https://twitter.com/badthingsdaily" rel="nofollow">@badthingsdaily</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/b1b95222-cf9c-48fd-b134-c6c7114f416b:aa5a8d40-75f1-4985-bf1c-25a6789bee8b.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 49 – The Red Team Life with Curtis Brazzell</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=295</guid>
<pubDate>Sun, 03 Feb 2019 14:29:34 -0000</pubDate>

<itunes:duration>00:34:48</itunes:duration>
<itunes:subtitle>Curtis Brazzell from Pondurance joins me to talk about red teaming and managing red teams.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/8faff0cea17847cd/episode-49-the-red-team-life-with-curtis-brazzell</link>
<description><![CDATA[<p>What is a red team?  How does it differ from a penetration tester's day-to-day?  How do red teams stay sharp?  How do they stay motivated?  These are a few of the questions I seek to have answered by Curtis Brazzell, a managing Security Consultant at Pondurance.  It's a great interview and sheds light on the difference between red teaming and penetration testing.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Curtis' Twitter: <a href="https://twitter.com/CurtBraz" rel="nofollow">https://twitter.com/CurtBraz</a></li>
<li>Curtis' LinkedIn Profile: <a href="https://www.linkedin.com/in/curtisbrazzell/" rel="nofollow">https://www.linkedin.com/in/curtisbrazzell/</a></li>
<li>Pondurance Website - <a href="https://www.pondurance.com/" rel="nofollow">https://www.pondurance.com/</a></li>
</ul>
<hr>
<p>We have a new store!  Come check out the various Purple Squad Security goods you can buy to share your following and help the show.  From stickers to mugs, we have a few items up for sale:</p>
<p><a href="https://purplesquadsec.com/store" rel="nofollow">https://purplesquadsec.com/store</a></p>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/8faff0ce-a178-47cd-a4da-d8367455d884:b21cf72b-0cc1-4046-a0e3-7c1108c60882.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 48 – All About Magecart with Yonathan Klijnsma</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=291</guid>
<pubDate>Sun, 20 Jan 2019 16:28:06 -0000</pubDate>

<itunes:duration>00:51:22</itunes:duration>
<itunes:subtitle>Yonathan Klijnsma joins me from RiskIQ to discuss Magecart, what it is, what it does, and how they found it.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/27ca6d864641435f/episode-48-all-about-magecart-with-yonathan-klijnsma</link>
<description><![CDATA[<p>Magecart - a web-based credit card skimming kit used by various groups to grab ahold of online shoppers credit cards.  Interesting?  You bet!  On this episode of the Purple Squad Security podcast I have Yonathan Klijnsma, Head Researcher at RiskIQ, joining me to discuss their research on Magecart.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Inside Magecart Report - <a href="https://cdn.riskiq.com/wp-content/uploads/2018/11/RiskIQ-Flashpoint-Inside-MageCart-Report.pdf" rel="nofollow">https://cdn.riskiq.com/wp-content/uploads/2018/11/RiskIQ-Flashpoint-Inside-MageCart-Report.pdf</a></li>
<li>Ticketmaster breach - <a href="https://www.riskiq.com/blog/labs/magecart-ticketmaster-breach/" rel="nofollow">https://www.riskiq.com/blog/labs/magecart-ticketmaster-breach/</a></li>
<li>British Airways breach - <a href="https://www.riskiq.com/blog/labs/magecart-british-airways-breach/" rel="nofollow">https://www.riskiq.com/blog/labs/magecart-british-airways-breach/</a></li>
<li>Newegg breach - <a href="https://www.riskiq.com/blog/labs/magecart-newegg/" rel="nofollow">https://www.riskiq.com/blog/labs/magecart-newegg/</a></li>
<li>Vision Direct with admin skimming - <a href="https://www.riskiq.com/blog/labs/magecart-vision-direct/" rel="nofollow">https://www.riskiq.com/blog/labs/magecart-vision-direct/</a></li>
<li>Other Magecart Articles - <a href="https://www.riskiq.com/blog/category/magecart/" rel="nofollow">https://www.riskiq.com/blog/category/magecart/</a></li>
<li>RiskIQ Website - <a href="https://www.riskiq.com/" rel="nofollow">https://www.riskiq.com/</a></li>
<li>Krebs on Security Skimming Article - <a href="https://krebsonsecurity.com/all-about-skimmers/" rel="nofollow">https://krebsonsecurity.com/all-about-skimmers/</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/27ca6d86-4641-435f-b803-cf415f5dbcc9:8a496f22-563d-48c7-87bf-c928b4210e2c.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 47 – Happy New Year! Show Updates and Other News</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=286</guid>
<pubDate>Sun, 06 Jan 2019 14:08:55 -0000</pubDate>

<itunes:duration>00:32:51</itunes:duration>
<itunes:subtitle>John talks about his plans for the upcoming year and some show updates.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/6e94ef5919cc48f8/episode-47-happy-new-year-show-updates-and-other-news</link>
<description><![CDATA[<p>Welcome to 2019!  John goes solo in this episode and talks about his personal goals for 2019, plus some updates for the show that should make things a bit more structured and hopefully more interesting for the listeners.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>EliteSec Website: <a href="https://elitesec.io/" rel="nofollow">https://elitesec.io/</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/6e94ef59-19cc-48f8-a7c5-8cc2540b094c:d92be272-ba57-4f1d-a791-e6e21cfe6d30.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 46 – Holiday Special – Storytime with Jayson E. Street</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=282</guid>
<pubDate>Sun, 16 Dec 2018 14:42:42 -0000</pubDate>

<itunes:duration>00:33:11</itunes:duration>
<itunes:subtitle>Jayson E. Street shares a familiar story from one of his #HackerAdventures, but also follows up with a not-well-known epilogue that has me in stitches!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/0d0d57b102f24d6a/episode-46-holiday-special-storytime-with-jayson-e-street</link>
<description><![CDATA[<p>Continuing our storytime theme for the holidays, on this week's show we have a special guest, Jayson E. Street!  For those who follow Jayson online, his hacker adventures bring him to all sorts of interesting places.  Jayson shares a story of one of those places, in which he robs the wrong bank.  Some of you may know this story, but he also provides us with an epilogue to this story that few have heard!  Thanks Jayson!</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Jayson's Website: <a href="http://jaysonestreet.com/" rel="nofollow">http://jaysonestreet.com/</a></li>
<li>Jayson's Twitter: <a href="https://twitter.com/jaysonstreet" rel="nofollow">@jaysonstreet</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/0d0d57b1-02f2-4d6a-86d9-1f61b63349f0:8d81d49e-09a4-4d7c-8787-9a11d5abe4f4.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 45.1 – Holiday Special – Storytime with Tinker – NO MUSIC!!!</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=281</guid>
<pubDate>Thu, 13 Dec 2018 14:19:18 -0000</pubDate>

<itunes:duration>01:06:52</itunes:duration>
<itunes:subtitle>NO MUSIC EDITION!!! Tinker (@Tinkersec) stops by to share a story, and pull a few pop quizzes with John on offensive techniques!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/0beeb74d46664bf0/episode-45-1-holiday-special-storytime-with-tinker-no-music-</link>
<description><![CDATA[<p>Hey everyone, this is a re-release of episode 45 with Tinker, but this one is WITHOUT the background music.  I hope this makes up for the snafu in an otherwise great interview!</p>
<hr>
<p>Happy December everyone!  Whatever holiday you may be celebrating this season, may it be enjoyable.  I've decided for the month of December to treat myself, by having a bunch of people I hold in high regard to join me in sharing of their tales, similar to the fireside chats I've had in the past.  We have no set agenda, we have no set time, but we do plan on sharing some fun stories that hopefully you will enjoy. So consider this a holiday gift my dear listener, and I hope you find it as enjoyable as I do.</p>
<p>This episode we are going to have a man whom I honestly believe should write as many books as possible, and provide audiobook versions as well, the one and only Tinker!</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Tinker's Website: <a href="https://www.tinker.sh/" rel="nofollow">https://www.tinker.sh/</a></li>
<li>Dallas Hackers - <a href="https://dallashackers.com/" rel="nofollow">https://dallashackers.com/</a></li>
<li>Popular Mechanics Article - <a href="https://www.popularmechanics.com/technology/a24676415/dallas-hackers/" rel="nofollow">https://www.popularmechanics.com/technology/a24676415/dallas-hackers/</a></li>
<li>Tinker's Twitter: <a href="https://twitter.com/TinkerSec" rel="nofollow">@tinkersec</a></li>
<li>Tinker's Mastodon - <a href="https://infosec.exchange/@tinker" rel="nofollow">@tinker</a></li>
<li>Infosec Mastodon - <a href="https://infosec.exchange/auth/sign_up" rel="nofollow">https://infosec.exchange/auth/sign_up</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/0beeb74d-4666-4bf0-afdc-6e3acaa46a93:6aac9634-cedc-41c2-90b0-32c5cb88ec86.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 44 – SANS Holiday Hack Challenge with Ed Skoudis</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=269</guid>
<pubDate>Sun, 18 Nov 2018 15:01:48 -0000</pubDate>

<itunes:duration>00:50:58</itunes:duration>
<itunes:subtitle>Ed Skoudis joins me this week to talk all about the 2018 Holiday Hack Challenge.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/8672e5c3353f4d18/episode-44-sans-holiday-hack-challenge-with-ed-skoudis</link>
<description><![CDATA[<p>So, a very popular season is coming up shortly.  I'm not talking about Thanksgiving (for my US listeners) and I'm not talking about Christmas for my Christian listeners.  No, I'm talking about the season that all good little hackers look forward to - the time when the SANS Holiday Hack Challenge is released!</p>
<p>This is probably one of the most ambitious CTFs I have ever known about, and I am lucky enough to get one of the main drivers behind it to join me for today's episode!  Ed Skoudis joins me to talk all about the SANS Holiday Hack Challenge, what it is, what goes into it, and why you should give it a try.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>KringleCon: <a href="https://kringlecon.com/" rel="nofollow">https://kringlecon.com/</a></li>
<li>Holiday Hack Challenge Website: <a href="https://www.holidayhackchallenge.com/2018/" rel="nofollow">https://www.holidayhackchallenge.com/2018/</a></li>
<li>Ed's Twitter: <a href="https://twitter.com/edskoudis" rel="nofollow">@edskoudis</a>    </li>
<li>Infosec Mastodon - <a href="https://infosec.exchange/auth/sign_up" rel="nofollow">https://infosec.exchange/auth/sign_up</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening!  And as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/8672e5c3-353f-4d18-ac7c-5562637be0c0:85b505bd-f5f6-437d-ae98-06fdd033381e.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 43 – Not all vulnerabilities are created equal with Tanya Janca</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=264</guid>
<pubDate>Sun, 04 Nov 2018 13:07:37 -0000</pubDate>

<itunes:duration>00:55:40</itunes:duration>
<itunes:subtitle>Tanya Janca joins me to talk about vulnerabilities, and how not all of them are created equal.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/f99a203471f54e53/episode-43-not-all-vulnerabilities-are-created-equal-with-tanya-janca</link>
<description><![CDATA[<p>Vulnerability disclosure is one of those things that either brings a smile or a scowl to your face, depending on what end of the disclosure you're on.  For some, it's a thing of pride, and hopefully a monetary reward!  For others, it's a punch to the gut, fear inducing, "Oh crap!" moment because someone has shown you a flaw you weren't aware of.</p>
<p>But what if the disclosure isn't actually a valid vulnerability? That's the topic for this episode discussion, and thankfully I have someone who knows about exactly that!  Tanya Janca joins me to discuss when a vulnerability is not a vulnerability!</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>When is a vulnerability not a vulnerability?- <a href="https://medium.com/microsoftazure/when-is-a-vulnerability-not-a-vulnerability-41ff9c880adf" rel="nofollow">https://medium.com/microsoftazure/when-is-a-vulnerability-not-a-vulnerability-41ff9c880adf</a></li>
<li>Microsoft bug bounty: <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty</a></li>
<li>Cyber ladies:<ul>
<li>Twitter: <a href="https://twitter.com/cyber_ladies" rel="nofollow">@Cyber_ladies</a></li>
<li>Meetup: <a href="https://www.meetup.com/find/events/?allMeetups=false&amp;keywords=cyber+ladies&amp;radius=Infinity" rel="nofollow">https://www.meetup.com/find/events/?allMeetups=false&amp;amp;keywords=cyber+ladies&amp;amp;radius=Infinity</a></li>
</ul>
</li>
<li>Devslop show: Live Sundays at 1:00 pm EDT <a href="https://aka.ms/DevSlop-Mixer" rel="nofollow">https://aka.ms/DevSlop-Mixer</a></li>
<li>Recorded episodes: <a href="https://aka.ms/DevSlopShow" rel="nofollow">https://aka.ms/DevSlopShow</a></li>
<li>Blog: <a href="https://medium.com/@shehackspurple" rel="nofollow">https://medium.com/@shehackspurple</a></li>
<li>Open bug bounty: <a href="https://www.openbugbounty.org/" rel="nofollow">https://www.openbugbounty.org</a></li>
<li>Twitter: <a href="https://twitter.com/shehackspurple" rel="nofollow">@shehackspurple</a></li>
<li>Infosec Mastodon - <a href="https://infosec.exchange/auth/sign_up" rel="nofollow">https://infosec.exchange/auth/sign_up</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/f99a2034-71f5-4e53-8544-3945f97836f1:6b78b6c2-0b52-4a98-9070-5bc8eab7843e.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 42 – CyberZoology with Patrick Kelley</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=261</guid>
<pubDate>Sun, 21 Oct 2018 15:03:56 -0000</pubDate>

<itunes:duration>00:56:51</itunes:duration>
<itunes:subtitle>Patrick Kelley comes on to talk about CyberZoology, trains, and Raspberry Pi!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/c9101cbc558c4e1e/episode-42-cyberzoology-with-patrick-kelley</link>
<description><![CDATA[<p>Defending is hard.  The adage of "an attacker only has to be right once" is a bit played out, but it does have a hint of truth in that trying to defend everything is a monumental task.  Defenders are often short on budgets, short on time, and short on patience for silly sayings like these.</p>
<p>This week I'm happy to have Patrick Kelley on to talk about some very interesting work he has done on coming up with defensive techniques for freight trains using a Raspberry Pi!  If you want to hear about unique ways to defend unique environments, you will not want to miss this episode.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Bro: <a href="https://www.bro.org/" rel="nofollow">https://www.bro.org/</a></li>
<li>Suricata: <a href="https://suricata-ids.org/" rel="nofollow">https://suricata-ids.org/</a></li>
<li>Critical Path Security GitHub: <a href="https://github.com/CriticalPathSecurity" rel="nofollow">https://github.com/CriticalPathSecurity</a></li>
<li>Patrick's Twitter: <a href="https://twitter.com/PKELLEY2600" rel="nofollow">@pkelley2600</a></li>
<li>Patrick's LinkedIn: <a href="https://www.linkedin.com/in/pmkelley/" rel="nofollow">https://www.linkedin.com/in/pmkelley/</a></li>
<li>Infosec Mastodon - <a href="https://infosec.exchange/auth/sign_up" rel="nofollow">https://infosec.exchange/auth/sign_up</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/c9101cbc-558c-4e1e-9605-1a1929b09508:b22312dd-e246-43a1-88af-1ab6c53c9206.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 41 – Cyber Security Awareness Month with Tracy Maleeff</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=253</guid>
<pubDate>Sun, 07 Oct 2018 15:31:45 -0000</pubDate>

<itunes:duration>01:04:20</itunes:duration>
<itunes:subtitle>Tracy @InfoSecSherpa Maleeff joins me to talk about Cyber Security Awareness Month</itunes:subtitle>
<link>http://purplesquadsec.com/episode/e6b9f5680b5044bf/episode-41-cyber-security-awareness-month-with-tracy-maleeff</link>
<description><![CDATA[<p>October is Cyber Security Awareness Month, and with that who better to help share some ideas on how to give back to the community than our own InfoSecSherpa!  Tracy Maleeff joins me to talk about Cyber Security Awareness Month, #ginfosec and #inforum.  This will be one of the most relaxed Infosec podcasts you'll hear this year.... Some links of interest:</p>
<hr>
<ul>
<li>GetCyberSafe (Canada) - <a href="https://www.getcybersafe.gc.ca/cnt/rsrcs/csam/thms-en.aspx" rel="nofollow">https://www.getcybersafe.gc.ca/cnt/rsrcs/csam/thms-en.aspx</a></li>
<li>StaySafeOnline (US) - <a href="https://staysafeonline.org/ncsam/themes/" rel="nofollow">https://staysafeonline.org/ncsam/themes/</a></li>
<li>Tracy's Twitter - <a href="https://twitter.com/InfoSecSherpa" rel="nofollow">https://twitter.com/InfoSecSherpa</a></li>
<li>Infosec Mastodon - <a href="https://infosec.exchange/auth/sign_up" rel="nofollow">https://infosec.exchange/auth/sign_up</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/e6b9f568-0b50-44bf-ad28-846ce02999b7:870679f5-68a4-4a28-92aa-c59e7458f4de.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 40 – Tabletop D&amp;D With Rally Security</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=251</guid>
<pubDate>Sun, 23 Sep 2018 15:12:20 -0000</pubDate>

<itunes:duration>01:19:14</itunes:duration>
<itunes:subtitle>I'm joined by a few folks from the Rally Security podcast for another Tabletop D&amp;D Episode!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/cd565bae88144c97/episode-40-tabletop-d-d-with-rally-security</link>
<description><![CDATA[<p>It's that time again!  With milestone episode 40, we have another Tabletop D&amp;D episode for you to enjoy!  This time around we are joined by a few members of the Rally Security podcast to face some scenarios and see how they fare.  Let's just say this was a rather impressive episode for a number of reasons. Some links of interest:</p>
<hr>
<ul>
<li>Rally Security Homepage - <a href="http://rallysecurity.com/" rel="nofollow">http://rallysecurity.com/</a></li>
<li>Rally Security Twitch - <a href="https://www.twitch.tv/rallysecurity" rel="nofollow">https://www.twitch.tv/rallysecurity</a></li>
<li>Rally Security Twitter - <a href="https://twitter.com/RallySecurity" rel="nofollow">https://twitter.com/RallySecurity</a></li>
<li>Ben's Twitter - <a href="https://twitter.com/benheise" rel="nofollow">https://twitter.com/benheise</a></li>
<li>Jake's Twitter - <a href="https://twitter.com/MalwareJake" rel="nofollow">https://twitter.com/MalwareJake</a></li>
<li>AJediDay's Twitter - <a href="https://twitter.com/Ajediday" rel="nofollow">https://twitter.com/Ajediday</a></li>
<li>Tony's Twitter - <a href="https://twitter.com/da_667" rel="nofollow">https://twitter.com/da_667</a></li>
<li>Cubicles and Consequences - <a href="https://www.blackhillsinfosec.com/dungeons-dragons-meet-cubicles-compromises/" rel="nofollow">https://www.blackhillsinfosec.com/dungeons-dragons-meet-cubicles-compromises/</a></li>
<li>Infosec Mastodon - <a href="https://infosec.exchange/auth/sign_up" rel="nofollow">https://infosec.exchange/auth/sign_up</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/cd565bae-8814-4c97-9e06-ec93e9a00473:73835c66-15c9-44cf-97d1-8e3fa1b04eee.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 39 – John’s OSCP Journey</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=249</guid>
<pubDate>Sun, 16 Sep 2018 15:01:45 -0000</pubDate>

<itunes:duration>00:58:02</itunes:duration>
<itunes:subtitle>John goes through his OSCP journey, sharing his preparation, thoughts on the labs and the exam experience.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/3911f683417941a2/episode-39-john-s-oscp-journey</link>
<description><![CDATA[<p>Over the past few months, John has been working on obtaining his OSCP certification.  Recently he attempted and successfully passed the exam!  In this episode he goes over his journey, what he learned as well as a few tips to help those attempting this rather difficult certification.</p>
<p>Some links of interest:</p>
<hr>
<ul>
<li>Penetration Testing - A Hands On Introduction to Hacking - <a href="https://www.amazon.com/Penetration-Testing-Hands-Introduction-Hacking/dp/1593275641" rel="nofollow">https://www.amazon.com/Penetration-Testing-Hands-Introduction-Hacking/dp/1593275641</a></li>
<li>Web Application Hacker's Handbook 2nd Edition - <a href="https://www.amazon.com/Web-Application-Hackers-Handbook-Exploiting/dp/1118026470" rel="nofollow">https://www.amazon.com/Web-Application-Hackers-Handbook-Exploiting/dp/1118026470</a></li>
<li>OSCP Prep:<ul>
<li><a href="https://www.abatchy.com/2017/03/how-to-prepare-for-pwkoscp-noob" rel="nofollow">https://www.abatchy.com/2017/03/how-to-prepare-for-pwkoscp-noob</a></li>
<li><a href="https://github.com/burntmybagel/OSCP-Prep" rel="nofollow">https://github.com/burntmybagel/OSCP-Prep</a> <a href="http://niiconsulting.com/checkmate/2017/06/a-detail-guide-on-oscp-preparation-from-newbie-to-oscp/" rel="nofollow">http://niiconsulting.com/checkmate/2017/06/a-detail-guide-on-oscp-preparation-from-newbie-to-oscp/</a></li>
<li><a href="https://medium.com/@andr3w_hilton/oscp-training-vms-hosted-on-vulnhub-com-22fa061bf6a1" rel="nofollow">https://medium.com/@andr3w_hilton/oscp-training-vms-hosted-on-vulnhub-com-22fa061bf6a1</a></li>
<li><a href="https://tulpa-security.com/2016/09/19/prep-guide-for-offsecs-pwk/" rel="nofollow">https://tulpa-security.com/2016/09/19/prep-guide-for-offsecs-pwk/</a></li>
</ul>
</li>
<li>VulnHub - <a href="https://www.vulnhub.com/" rel="nofollow">https://www.vulnhub.com/</a></li>
<li>HackTheBox - <a href="https://www.hackthebox.eu/" rel="nofollow">https://www.hackthebox.eu/</a></li>
<li>Infosec Mastodon - <a href="https://infosec.exchange/auth/sign_up" rel="nofollow">https://infosec.exchange/auth/sign_up</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Mastodon: <a href="https://infosec.exchange/@JohnsNotHere" rel="nofollow">https://infosec.exchange/@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Patreon - <a href="https://www.patreon.com/purplesquadsec" rel="nofollow">https://www.patreon.com/purplesquadsec</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/3911f683-4179-41a2-934a-3946958b2cbd:83cd4d49-2a92-452e-a6b4-ace185c55837.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 38 – Discussing the Cyber Kill Chain with Amanda Berlin</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=240</guid>
<pubDate>Sun, 26 Aug 2018 16:41:21 -0000</pubDate>

<itunes:duration>00:49:28</itunes:duration>
<itunes:subtitle>Amanda Berlin (@Infosystir) stops by to chat about the Cyber Kill Chain.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/a129ba02d4b7404d/episode-38-discussing-the-cyber-kill-chain-with-amanda-berlin</link>
<description><![CDATA[<p>The cyber kill chain.  For some, it's a nice framework to help build your defenses and help during an incident.  For others, it is an over hyped and rigid list that no real attacker follows anymore.  However you view the cyber kill chain, it is a strong pillar within Infosec, especially when it comes to defending your network.  Amanda Berlin joins me today to talk about the cyber kill chain, what it is and how to disrupt attacks using it! Some links of interest:</p>
<hr>
<ul>
<li>Amanda's Disrupting The Kill Chain Training -  <a href="https://www.youtube.com/playlist?list=PL-giMT7sGCVKIWHVZ-N4A_eJhu6BzH4WM" rel="nofollow">https://www.youtube.com/playlist?list=PL-giMT7sGCVKIWHVZ-N4A_eJhu6BzH4WM</a></li>
<li>Amanda's Cyber Kill Chain Implementation Spreadsheet - <a href="https://docs.google.com/spreadsheets/d/1J0swcA1Phb4mh-Pj8eR9ZEAIm5GEtz0UklP9YhVUbEY/edit#gid=0" rel="nofollow">https://docs.google.com/spreadsheets/d/1J0swcA1Phb4mh-Pj8eR9ZEAIm5GEtz0UklP9YhVUbEY/edit#gid=0</a></li>
<li>Official Cyber Kill Chain Site - <a href="https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html" rel="nofollow">https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html</a></li>
<li>SANS Suspicious Domains Lists - <a href="https://isc.sans.edu/suspicious_domains.html" rel="nofollow">https://isc.sans.edu/suspicious_domains.html</a></li>
<li><a href="http://HaveIBeenPwned.com" rel="nofollow">HaveIBeenPwned.com</a> - <a href="https://haveibeenpwned.com/" rel="nofollow">https://haveibeenpwned.com</a></li>
<li>Brakeing Down Security Podcast - <a href="https://www.brakeingsecurity.com/" rel="nofollow">https://www.brakeingsecurity.com/</a></li>
<li>Amanda's Twitter - <a href="https://twitter.com/InfoSystir" rel="nofollow">https://twitter.com/InfoSystir</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/a129ba02-d4b7-404d-be34-6e7d57b677c1:0d8a94f5-b13b-406f-8472-f186e72aa673.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 37 – Bring Your Own Land with Nathan Kirk</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=235</guid>
<pubDate>Sun, 12 Aug 2018 16:29:39 -0000</pubDate>

<itunes:duration>00:31:21</itunes:duration>
<itunes:subtitle>Nathan Kirk (@sekirkity) stops by the show to discuss the idea of going beyond living off the land and bringing your own!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/78741efa758b43e2/episode-37-bring-your-own-land-with-nathan-kirk</link>
<description><![CDATA[<p><em>Living off the land</em> is a term well understood by both offensive and defensive teams.  For offensive teams, it's meant by using the technologies already present on the system, such as Powershell, Python, and even Perl for those who like a challenge (or are facing an older Unix system).  On the defensive side, enhanced logging and locked down configurations are put in place to detect and prevent the use of these tools by malicious actors to either catch or prevent these actors from doing harm. Nathan Kirk (@sekirkity) joins me this week to talk about the concept behind "Bring Your Own Land". Some links of interest:</p>
<hr>
<ul>
<li>BYOL Article - <a href="https://www.fireeye.com/blog/threat-research/2018/06/bring-your-own-land-novel-red-teaming-technique.html" rel="nofollow">https://www.fireeye.com/blog/threat-research/2018/06/bring-your-own-land-novel-red-teaming-technique.html</a></li>
<li>SpecterOps - <a href="https://specterops.io/" rel="nofollow">https://specterops.io/</a></li>
<li>Ghostpack - <a href="https://www.harmj0y.net/blog/redteaming/ghostpack/" rel="nofollow">https://www.harmj0y.net/blog/redteaming/ghostpack/</a></li>
<li>SharpView - <a href="https://github.com/tevora-threat/SharpView" rel="nofollow">https://github.com/tevora-threat/SharpView</a></li>
<li>Nathan's Twitter - <a href="https://twitter.com/sekirkity" rel="nofollow">https://twitter.com/sekirkity</a></li>
</ul>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/78741efa-758b-43e2-b83e-7158195e8e60:0b73003a-a157-4e8b-a8bb-c3e6dbe45277.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 36 – The Joy of CTFs with Derek Rook</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=226</guid>
<pubDate>Sun, 29 Jul 2018 17:17:14 -0000</pubDate>

<itunes:duration>00:45:17</itunes:duration>
<itunes:subtitle>Derek Root (@_r00k_) joins me to talk about CTFs and how they can be great learning tools for Infosec professionals</itunes:subtitle>
<link>http://purplesquadsec.com/episode/aff38a86ef344679/episode-36-the-joy-of-ctfs-with-derek-rook</link>
<description><![CDATA[<p>Capture The Flag games, or CTFs, are a popular way for infosec pros to brush up on the offensive skills.  From VulnHub to HackTheBox, there are a few different ways to quote "get your hack on"!  Derek Rook (@_r00k_) joins me today to talk about CTFs and how they can assist in your Infosec journey, regardless of your role. Some links of interest:</p>
<hr>
<ul>
<li>Derek's YouTube Channel - <a href="https://www.youtube.com/channel/UCMACXuWd2w6_IEGog744UaA" rel="nofollow">https://www.youtube.com/channel/UCMACXuWd2w6_IEGog744UaA</a></li>
<li>Derek's Twitch Stream - <a href="https://www.twitch.tv/r00k_infosec" rel="nofollow">https://www.twitch.tv/r00k_infosec</a></li>
<li>ippsec's YouTube Channel - <a href="https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA" rel="nofollow">https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA</a></li>
<li>LiveOverflow YouTube Channel - <a href="https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w" rel="nofollow">https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w</a></li>
<li>Mub1x's Twitch Stream - <a href="https://www.twitch.tv/mub1x" rel="nofollow">https://www.twitch.tv/mub1x</a></li>
<li>CCDC (US) - <a href="http://www.nationalccdc.org/" rel="nofollow">http://www.nationalccdc.org/</a></li>
<li>CCDC (Canada) - <a href="https://www.cyberdefencechallenge.ca/" rel="nofollow">https://www.cyberdefencechallenge.ca/</a></li>
<li>SANS Holiday Hack Challenge - <a href="https://holidayhackchallenge.com/past-challenges/" rel="nofollow">https://holidayhackchallenge.com/past-challenges/</a></li>
<li>Open2All CTF team - <a href="https://www.reddit.com/r/OpenToAllCTFteam/" rel="nofollow">https://www.reddit.com/r/OpenToAllCTFteam/</a></li>
<li>CTF Time - <a href="https://ctftime.org/" rel="nofollow">https://ctftime.org/</a></li>
<li>Derek's Twitter - <a href="https://twitter.com/_r00k_" rel="nofollow">https://twitter.com/_r00k_</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/aff38a86-ef34-4679-869c-4405dfb259f6:32e165e5-8359-4b84-acba-11473dbc435d.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 35 – Container Security with Jay Beale</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=223</guid>
<pubDate>Sun, 15 Jul 2018 17:11:08 -0000</pubDate>

<itunes:duration>00:53:55</itunes:duration>
<itunes:subtitle>Jay Beale of InGuardians joins me to talk about container security.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/2aab2185a563451c/episode-35-container-security-with-jay-beale</link>
<description><![CDATA[<p>From jails to virtual machines, process isolation is the "holy grail" of security.  Lately, containers have been the go-to for modern organizations in order to scale and implement things like microservices.  Jay Beale of InGuardians fame joins me to talk all about container security! Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www.beyondtrust.com/resources/webinar/securing-applications-linux-containers/" rel="nofollow">Securing Applications with Linux Containers</a> (Webinar by Jay Beale)</li>
<li><a href="https://www.oreilly.com/ideas/docker-security" rel="nofollow">Docker security - Using containers safely in production</a> (Article by Adrian Mouat)</li>
<li>Clair (Container Scanner) - <a href="https://github.com/coreos/clair" rel="nofollow">https://github.com/coreos/clair</a></li>
<li>InGuardians Website - <a href="https://www.inguardians.com/" rel="nofollow">https://www.inguardians.com/</a></li>
<li>InGuardians Blog - <a href="https://www.inguardians.com/labs/" rel="nofollow">https://www.inguardians.com/labs/</a></li>
<li>InGuardians Twitter - <a href="https://twitter.com/inguardians" rel="nofollow">https://twitter.com/inguardians</a></li>
<li>Jay's Twitter - <a href="https://twitter.com/jaybeale" rel="nofollow">https://twitter.com/jaybeale</a></li>
<li>Jess Frazelle's Twitter - <a href="https://twitter.com/jessfraz" rel="nofollow">https://twitter.com/jessfraz</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Purple Squad Security's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/2aab2185-a563-451c-8a6e-4cb7b277e186:e1e30549-5472-4a55-b553-c3c37b79387d.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 34 – Exploring Powershell with Mick Douglas</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=218</guid>
<pubDate>Sun, 01 Jul 2018 16:48:56 -0000</pubDate>

<itunes:duration>00:53:15</itunes:duration>
<itunes:subtitle>Mick Douglas joins me to talk all things Powershell!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/c978970e83334c52/episode-34-exploring-powershell-with-mick-douglas</link>
<description><![CDATA[<p>Living off the land is pretty standard fare for pen testers.  On Linux systems, the go-to is usually Python, but on Windows it's all about Powershell.  This week I'm fortunate enough to sit down with Mick Douglas to talk all things Powershell! Some links of interest:</p>
<hr>
<ul>
<li>Powercat - <a href="https://github.com/besimorhino/powercat" rel="nofollow">https://github.com/besimorhino/powercat</a><ul>
<li>Mick wants to give a special shout out to Luke Baggett for all the great work he's done on this project!</li>
</ul>
</li>
<li>Kansa - Dave Hall was the original author - <a href="https://github.com/davehull/Kansa" rel="nofollow">https://github.com/davehull/Kansa</a></li>
<li>Mick's Public Projects - <a href="https://github.com/besimorhino?tab=repositories" rel="nofollow">https://github.com/besimorhino?tab=repositories</a></li>
<li>Invoke-IR - <a href="https://github.com/Invoke-IR" rel="nofollow">https://github.com/Invoke-IR</a></li>
<li>Bye-FePhishia - <a href="https://github.com/jcjohnson34/Bye-FePhishia" rel="nofollow">https://github.com/jcjohnson34/Bye-FePhishia</a></li>
<li><a href="http://OverworkedAdmin.com" rel="nofollow">OverworkedAdmin.com</a> - <a href="https://overworkedadmin.com/category/scripting-languages/powershell/" rel="nofollow">https://overworkedadmin.com/category/scripting-languages/powershell/</a></li>
<li>Microsoft TechNet Blog - "Hey Scripting Guy!" - <a href="https://blogs.technet.microsoft.com/heyscriptingguy/" rel="nofollow">https://blogs.technet.microsoft.com/heyscriptingguy/</a></li>
<li><a href="http://InfosecInovations.com" rel="nofollow">InfosecInovations.com</a> - <a href="https://www.infosecinnovations.com/" rel="nofollow">https://www.infosecinnovations.com/</a></li>
<li>Powershell Basics -  <a href="https://www.darkoperator.com/powershellbasics/" rel="nofollow">https://www.darkoperator.com/powershellbasics/</a></li>
<li>Powershell Cheatsheet - <a href="https://github.com/PrateekKumarSingh/CheatSheets/tree/master/Powershell" rel="nofollow">https://github.com/PrateekKumarSingh/CheatSheets/tree/master/Powershell</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/c978970e-8333-4c52-a00c-0dc271bb0855:39f4ec00-3cc4-4ba9-a636-65ee0ecdc302.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 33 – 3 Pillars for Starting a Security Program</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=215</guid>
<pubDate>Sun, 17 Jun 2018 17:28:18 -0000</pubDate>

<itunes:duration>00:43:12</itunes:duration>
<itunes:subtitle>John talks about 3 pillars he uses for starting a new security program.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/3255cdda4ddb46de/episode-33-3-pillars-for-starting-a-security-program</link>
<description><![CDATA[<p>In this episode John goes at it alone and discusses his own experiences with starting up a security program at different organizations by focusing in on what he views are the 3 key pillars for a new security program. Some links of interest:</p>
<hr>
<ul>
<li>CIS Critical Security Controls - <a href="https://www.cisecurity.org/controls/" rel="nofollow">https://www.cisecurity.org/controls/</a></li>
<li>Malware Archeology - Logging Cheat Sheets - <a href="https://www.malwarearchaeology.com/cheat-sheets/" rel="nofollow">https://www.malwarearchaeology.com/cheat-sheets/</a></li>
<li>Linux Security Incident Log Review Checklist - <a href="https://zeltser.com/security-incident-log-review-checklist/" rel="nofollow">https://zeltser.com/security-incident-log-review-checklist/</a></li>
<li>SANS Log Management In-Depth - <a href="https://www.sans.org/brochure/course/log-management-in-depth/6" rel="nofollow">https://www.sans.org/brochure/course/log-management-in-depth/6</a></li>
<li>OWASP Logging Cheat Sheet - <a href="https://www.owasp.org/index.php/Logging_Cheat_Sheet" rel="nofollow">https://www.owasp.org/index.php/Logging_Cheat_Sheet</a></li>
<li>Defensive Security Handbook - <a href="http://shop.oreilly.com/product/0636920051671.do" rel="nofollow">http://shop.oreilly.com/product/0636920051671.do</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/3255cdda-4ddb-46de-886d-d37937dbfaf3:9614b475-cdfc-4dd0-ad08-a2b26fde1f9c.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 32 – Fireside Chat with Deviant Ollam</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=207</guid>
<pubDate>Sun, 03 Jun 2018 17:00:49 -0000</pubDate>

<itunes:duration>00:57:52</itunes:duration>
<itunes:subtitle>I sit down with Deviant Ollam to have a casual conversation about physical penetration testing and hear some great stories from the road.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/d364d59f1a114cc3/episode-32-fireside-chat-with-deviant-ollam</link>
<description><![CDATA[<p>Continuing on with my fireside chat series, where I bring on a guest to just have a casual chat and see where the conversation takes us, my guest this time is Deviant Ollam.  Well known for his work with TOOOL and the locksport community, we take a different path and talk about physical penetration testing as well as hear some great stories from the road.</p>
<p>Some links of interest:</p>
<hr>

<ul>
    <li>Deviant's Twitter: <a href="https://twitter.com/deviantollam" rel="nofollow"><span dir="ltr">@deviantollam</span></a></li>
    <li>The CORE Group: <a href="https://enterthecore.net/" rel="nofollow">https://enterthecore.net/</a></li>
</ul>
<p>And for fun:</p>
<ul>
    <li>Check Box Secure: <a href="http://www.checkboxsecure.com/" rel="nofollow">http://www.checkboxsecure.com/</a></li>
</ul>

<hr>

<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>

<ul>
    <li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
    <li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
    <li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
    <li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>

<hr>

<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/d364d59f-1a11-4cc3-a08d-bad8944babc6:aac009de-12d5-48cc-a752-d7e26daeafbb.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 31 – Killing the Pen Test with Adrian Sanabria</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=201</guid>
<pubDate>Sun, 20 May 2018 16:58:13 -0000</pubDate>

<itunes:duration>00:49:04</itunes:duration>
<itunes:subtitle>Adrian Sanabria joins me to talk about killing what we know as the pen test and replacing it with something better!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/c6e4989adf694654/episode-31-killing-the-pen-test-with-adrian-sanabria</link>
<description><![CDATA[<p>The penetration test, or pen test as it's commonly referred to, is one of the great necessary evils in Infosec today.  My guest for this episode is Adrian Sanabria, who has an interesting thought - let's kill the pen test!  Adrian has been in the industry for quite some time in quite a variety of roles, so he has some great experience and insights to share.  Let's see what his replacement for a pen test entitles! Some links of interest:</p>
<hr>
<ul>
<li>Adrian's Twitter: <a href="https://twitter.com/sawaba" rel="nofollow">@sawaba</a></li>
<li>Savage Security: <a href="https://www.savagesec.com/" rel="nofollow">https://www.savagesec.com/</a></li>
<li>BSides Knoxville: <a href="https://bsidesknoxville.com/" rel="nofollow">https://bsidesknoxville.com/</a></li>
<li>Penetration Testing Execution Standard (PTES): <a href="http://www.pentest-standard.org/index.php/Main_Page" rel="nofollow">http://www.pentest-standard.org/index.php/Main_Page</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/c6e4989a-df69-4654-b51f-57def89a6326:fae84d51-373b-4600-85ea-7b1adde3048f.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 30 – Infosec D&amp;D Tabletop with Jerry Bell and Andrew Kalat from Defensive Security</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=197</guid>
<pubDate>Sun, 06 May 2018 17:03:47 -0000</pubDate>

<itunes:duration>00:55:52</itunes:duration>
<itunes:subtitle>Jerry Bell and Andrew Kalat from the Defensive Security podcast join me for another Infosec D&amp;D Tabletop game! What maddening scenarios have I found that they will need to overcome?</itunes:subtitle>
<link>http://purplesquadsec.com/episode/dec5ee0238634194/episode-30-infosec-d-d-tabletop-with-jerry-bell-and-andrew-kalat-from-defensive-security</link>
<description><![CDATA[<p>It's that time again!  We're doing another Infosec tabletop in a D&amp;D style, this time with the fine gentlemen from the Defensive Security podcast!  Jerry and Andrew join me for another infosec tabletop with all new scenarios, pitfalls, and approaches. Special thanks to Ryan McGeehan and his <a href="https://twitter.com/badthingsdaily" rel="nofollow">Tabletop Scenarios</a> twitter account for providing the ideas behind this episodes "challenges". Some links of interest:</p>
<hr>
<ul>
<li>The Defensive Security Podcast: <a href="https://defensivesecurity.org/" rel="nofollow">https://defensivesecurity.org/</a></li>
<li>Jerry's Twitter: <a href="https://twitter.com/Maliciouslink" rel="nofollow">@maliciouslink</a></li>
<li>Andrew's Twitter: <a href="https://twitter.com/Lerg" rel="nofollow">@lerg</a></li>
<li>Tabletop Scenarios Twitter: <a href="https://twitter.com/badthingsdaily" rel="nofollow">@badthingsdaily</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/dec5ee02-3863-4194-a96a-eb803c2f9c79:4804e8e9-c455-450b-a0c9-ed4b41b89f44.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 29 – The Importance of Community in Infosec w/ Cheryl “3ncr1pt3d” Biswas</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=191</guid>
<pubDate>Sun, 29 Apr 2018 16:52:41 -0000</pubDate>

<itunes:duration>00:46:15</itunes:duration>
<itunes:subtitle>Cheryl 3ncr1pt3d Biswas joins me to talk about how our Infosec community differs, as well as some cons like the Diana Initiative.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/d2e4291a10d346a4/episode-29-the-importance-of-community-in-infosec-w-cheryl-3ncr1pt3d-biswas</link>
<description><![CDATA[<p>The idea of "community" is an important one, especially if you talk about a group of people who want to help improve their skills by sharing their ideas, experiences, etc, with like minded individuals.  The Infosec community is no exception to this.  In fact I would argue that it is one of the strongest communities I have encountered yet! Joining me this week is Cheryl "3ncr1pt3d" Biswas to talk about the Infosec community, what makes it special, and the importance of it.  In addition we will be talking about one of Cheryl's many contributions to the community in the form of the Diana Initiative. Some links of interest:</p>
<hr>
<ul>
<li>Diana Initiative Website: <a href="https://www.dianainitiative.org/" rel="nofollow">https://www.dianainitiative.org/</a></li>
<li>Diana Initiative's Twitter: <a href="https://twitter.com/DianaInitiative" rel="nofollow">@DianaInitiative</a></li>
<li>Cheryl's Twitter: <a href="https://twitter.com/3ncr1pt3d" rel="nofollow">@3ncr1pt3d</a></li>
<li>Cheryl's Website: <a href="whitehatcheryl.wordpress.com" rel="nofollow">whitehatcheryl.wordpress.com</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/d2e4291a-10d3-46a4-bfc9-062ef7c8130d:f4afb392-e92c-428a-977c-6dd65738342c.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 28 – John’s Weird Path To #Infosec And Other Ramblings</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=188</guid>
<pubDate>Sun, 22 Apr 2018 16:40:42 -0000</pubDate>

<itunes:duration>00:42:28</itunes:duration>
<itunes:subtitle>With no guest this week, John talks about his own personal path to #infosec and other thoughts on his journey.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/07512ded98874cf5/episode-28-john-s-weird-path-to-infosec-and-other-ramblings</link>
<description><![CDATA[<p>With no guest this week, John decides to share his own story about how he got into #infosec and some other thoughts he's had about the journey and why it's a never ending adventure to learn new things. Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www.meetup.com/" rel="nofollow">MeetUp.com</a></li>
<li><a href="https://ossec.github.io/" rel="nofollow">OSSEC</a></li>
<li><a href="https://wazuh.com/" rel="nofollow">Wazuh (OSSEC Alternative)</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/07512ded-9887-4cf5-8570-5fae502419bd:59a54810-1f6f-4266-bdd7-2db1e9388a3a.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 27 – Infosec and Mental Health with Danny Akacki</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=187</guid>
<pubDate>Sun, 15 Apr 2018 16:39:47 -0000</pubDate>

<itunes:duration>00:47:50</itunes:duration>
<itunes:subtitle>Danny Akacki joins me to talk about his own mental health and the site he created, infosanity.org, to help others who may be struggling.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/5a008ade4c304635/episode-27-infosec-and-mental-health-with-danny-akacki</link>
<description><![CDATA[<p>Stress.  Depression. Anxiety.  Fear.  Uncertainty.  Doubt.  All of these symptoms and conditions are well known to anyone who has spent a few years in security.  This can be a heavy topic, but it's one that we should discuss openly and often.  Danny Akacki joins me on this episode to talk about his own mental health, what are some of the things that has helped him, and he also gives us some insight on his contributions back to the community through the creation of <a href="https://www.infosanity.org/" rel="nofollow">infosanity.org</a>, a website dedicated to helping those in the hacking community who may be struggling and aren't sure where to go. Please remember, if you have a serious concern about your mental health, please, PLEASE seek professional help. Some links of interest:</p>
<hr>
<ul>
<li><a href="http://www.yourlifecounts.org/need-help/crisis-lines" rel="nofollow">Worldwide Crisis Line Phone Numbers</a></li>
<li><a href="https://www.infosanity.org/" rel="nofollow">Infosanity.org</a></li>
<li><a href="https://twitter.com/DAkacki" rel="nofollow">@DAkacki</a></li>
<li><a href="https://twitter.com/InfoSanityOrg" rel="nofollow">@InfoSanityOrg</a></li>
</ul>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/5a008ade-4c30-4635-a309-5fa2ead2053c:29ae59e7-ddf1-497c-b1b6-e2bd00dbdcd7.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 26 – DFIR in the Cloud with Jonathon Poling</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=183</guid>
<pubDate>Sun, 08 Apr 2018 16:22:55 -0000</pubDate>

<itunes:duration>00:49:15</itunes:duration>
<itunes:subtitle>Jonathon Poling (@JPoForenso) comes back to talk about #DFIR in the #cloud, whats easier, whats harder, and whats different. A must for anyone on a #blueteam.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/4bf710d3c8e34ce9/episode-26-dfir-in-the-cloud-with-jonathon-poling</link>
<description><![CDATA[<p>From the crowd to the cloud, we shift focus this episode to a topic that may be holding back some infosec professionals from embracing the cloud - namely what to do when you're attacked?  Digital Forensics and Incident Response (DFIR) is a topic we've covered in the past, but that was from a more traditional view.  I'm fortunate enough to have Jonathon Poling (@JPoForenso) join me again to revisit DFIR, but this time from a cloud perspective.  What's easier, what's harder, and what's different?  Have a listen to find out! Some links of interest:</p>
<hr>
<ul>
<li><a href="https://github.com/ThreatResponse/margaritashotgun" rel="nofollow">Margarita Shotgun</a></li>
<li><a href="https://docs.microsoft.com/en-us/azure/architecture/aws-professional/services" rel="nofollow">AWS to Azure Mapping</a></li>
<li><a href="https://cloud.google.com/free/docs/map-aws-google-cloud-platform" rel="nofollow">AWS to GCP Mapping</a></li>
<li><a href="https://cloud.google.com/free/docs/map-azure-google-cloud-platform" rel="nofollow">Azure to GCP Mapping</a></li>
<li><a href="https://github.com/duo-labs" rel="nofollow">Duo Labs GitHub</a></li>
<li><a href="https://github.com/airbnb/streamalert" rel="nofollow">StreamAlert</a></li>
<li><a href="https://github.com/Netflix" rel="nofollow">Netflix GitHub</a><ul>
<li><a href="https://github.com/Netflix/repokid" rel="nofollow">RepoKid</a></li>
</ul>
</li>
<li><a href="https://github.com/nccgroup/" rel="nofollow">NCC Group</a><ul>
<li><a href="https://nccgroup.github.io/Scout2/" rel="nofollow">Scout2</a></li>
</ul>
</li>
<li>Ponder The Bits - <a href="https://ponderthebits.com/" rel="nofollow">https://ponderthebits.com/</a></li>
<li><a href="https://twitter.com/JPoForenso" rel="nofollow">@JPoForenso</a></li>
</ul>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and as always, I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/4bf710d3-c8e3-4ce9-b06c-56ee337f3df4:193df311-2885-4bf3-95a3-af0710fcbe7b.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 25 – Securing The Crowd with Nicolas Valcarcel</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=178</guid>
<pubDate>Sun, 25 Mar 2018 16:28:10 -0000</pubDate>

<itunes:duration>00:54:22</itunes:duration>
<itunes:subtitle>Nicolas Valcarcel joins me to talk about his experience with the crowd, crowdsourcing, as well as Infosec and shares his experiences and thoughts on how best to secure it for use in your organization.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/7336957411ee4086/episode-25-securing-the-crowd-with-nicolas-valcarcel</link>
<description><![CDATA[<p>The crowd.  Recently gaining attention again due to some news events that were much ado about nothing, there is still a bit of a mystery with crowdsourcing and how best to secure it.  Organizations like Bug Crowd and HackerOne have shown it can be used for specific security tasks, but what about in general?  Nicolas Valcarcel joins me on this episode to share his thoughts and experience with security the crowd and what organizations should be aware of when considering using the crowd for their own purposes. Some links of interest:</p>
<hr>
<ul>
<li>Crowd Security Whitepaper - <a href="https://github.com/nxvl/crowd-security" rel="nofollow">https://github.com/nxvl/crowd-security</a></li>
<li><a href="https://www.rainforestqa.com/blog/2017-10-12-how-to-make-the-most-of-mechanical-turk/" rel="nofollow">How to Make the Most of Mechanical Turk</a></li>
<li><a href="https://www.rainforestqa.com/blog/2017-08-02-how-we-maintain-a-trustworthy-rainforest-tester-network/" rel="nofollow">How We Maintain a Trustworthy Rainforest Tester Network</a></li>
<li><a href="https://www.rainforestqa.com/blog/2017-06-06-the-pros-and-cons-of-using-crowdsourced-work/" rel="nofollow">The Pros and Cons of Using Crowdsourced Work</a></li>
<li><a href="https://www.rainforestqa.com/blog/2016-04-21-how-we-train-rainforest-testers/" rel="nofollow">How We Train Rainforest Testers</a></li>
<li><a href="https://www.rainforestqa.com/blog/2017-01-06-aws-re-invent-crowdsourced-testing-work-with-amazon-mturk/" rel="nofollow">AWS re:Invent: Managing Crowdsourced Testing Work with Amazon Mechanical Turk</a></li>
<li><a href="https://www.rainforestqa.com/blog/2017-05-02-virtual-machine-security-the-key-steps-we-take-to-keep-rainforest-vms/" rel="nofollow">Virtual Machine Security: The Key Steps We Take to Keep Rainforest VMs Secure</a></li>
<li><a href="https://twitter.com/nxvl" rel="nofollow">@nxvl</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/73369574-11ee-4086-8cc9-46086052254c:70ec2599-7153-47cc-b2b1-0ffc36d399bd.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 24 – Fireside Chat with Joe Gray</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=176</guid>
<pubDate>Sun, 18 Mar 2018 16:04:14 -0000</pubDate>

<itunes:duration>00:54:45</itunes:duration>
<itunes:subtitle>In this casual fireside-style chat I speak with Joe Gray about TTHG, Conferences and Discount Codes!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/d11557e9fc564985/episode-24-fireside-chat-with-joe-gray</link>
<description><![CDATA[<p>In the first of a new format, I sit down with Joe Gray with only a handful of questions and just chat.  We cover things from Through The Hacking Glass, upcoming talks that Joe will be doing, to the various conferences that Joe will be attending.  Lots of great information and stories were shared, and if you'd like to provide feedback, please reach out and let me know!  Also, make sure you listen for a special easter egg that Joe has for those who are in the Atlanta area in September for entry to a conference at no cost! Some links of interest:</p>
<hr>
<ul>
<li>Through The Hacking Glass<ul>
<li>@hackingglass - <a href="https://twitter.com/hackingglass" rel="nofollow">https://twitter.com/hackingglass</a></li>
<li>Facebook - <a href="https://www.facebook.com/hackingglass/" rel="nofollow">https://www.facebook.com/hackingglass/</a></li>
<li>Peerlyst - <a href="https://www.peerlyst.com/posts/announcing-through-the-hacking-glass-a-peerlyst-mentorship-experience-joe-gray" rel="nofollow">https://www.peerlyst.com/posts/announcing-through-the-hacking-glass-a-peerlyst-mentorship-experience-joe-gray</a></li>
</ul>
</li>
<li>RSA Conference USA - <a href="https://www.rsaconference.com/events/us18" rel="nofollow">https://www.rsaconference.com/events/us18</a></li>
<li>Hacker Halted - <a href="https://www.hackerhalted.com/" rel="nofollow">https://www.hackerhalted.com/</a><ul>
<li>Free Admission to conference code: <strong>HH18JGCON</strong></li>
<li>25% off training code: <strong>HH18JJTRN</strong></li>
</ul>
</li>
<li>Hack NYC - <a href="https://q22018.hacknyc.com/en/" rel="nofollow">https://q22018.hacknyc.com/en/</a><ul>
<li>Coupon code: <strong>STORMNYCJJ</strong></li>
</ul>
</li>
<li><a href="https://twitter.com/C_3PJoe" rel="nofollow">@c_3pjoe</a></li>
<li><a href="https://twitter.com/advpersistsec" rel="nofollow">@advpersistsec</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/d11557e9-fc56-4985-8020-e45a4a3f3cd6:48158cea-5b64-416c-84cb-175221ca882b.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 23 – Speaking to Developers with James Jardine</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=174</guid>
<pubDate>Sun, 11 Mar 2018 16:57:26 -0000</pubDate>

<itunes:duration>01:11:13</itunes:duration>
<itunes:subtitle>I speak with James Jardine from the DevelopSec Podcast on communication strategies to use when speaking with developers.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/082b4f73358348e0/episode-23-speaking-to-developers-with-james-jardine</link>
<description><![CDATA[<p>Continuing with the theme of soft skills that any infosec professional should have, this episode will focus on developers.  I sit down with James Jardine from the DevelopSec podcast to talk about how best to communicate with developers.  Just like executives, developers have a different language and approach that is needed in order to communicate effectively.  Trying to avoid the all-to-common animosity between developers and security, James and I discuss some strategies to help build bridges between the groups and not burn them to the ground. Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www.jardinesoftware.com/" rel="nofollow">www.jardinesoftware.com</a></li>
<li><a href="https://www.developsec.com/" rel="nofollow">www.developsec.com</a></li>
<li><a href="http://podcast.developsec.com/" rel="nofollow">podcast.developsec.com</a></li>
<li><a href="http://podcast.wh1t3rabbit.net/" rel="nofollow">podcast.wh1t3rabbit.net</a></li>
<li><a href="https://www.youtube.com/channel/UCdAqgfdGs0-hPa8FhsODwNw" rel="nofollow">DevleopSec YouTube Channel</a></li>
<li><a href="https://twitter.com/DevelopSec" rel="nofollow">@developsec</a></li>
<li><a href="https://twitter.com/JardineSoftware" rel="nofollow">@jardinesoftware</a></li>
<li>Email James:  <a href="mailto:james@jardinesoftware.com" rel="nofollow">james@jardinesoftware.com</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/082b4f73-3583-48e0-b754-20f09bdcd6d6:31093715-e8da-4795-b5ed-02642aa140e8.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 22 – Open Source Intelligence Techniques with Michael Bazzell</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=169</guid>
<pubDate>Sun, 04 Mar 2018 17:19:30 -0000</pubDate>

<itunes:duration>00:33:29</itunes:duration>
<itunes:subtitle>I speak with the Godfather of OSINT, Michael Bazzell, about his book and various OSINT topics.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/7e2b363557744860/episode-22-open-source-intelligence-techniques-with-michael-bazzell</link>
<description><![CDATA[<p>Nothing helps out security more than information.  Heck, it's the first part of our professions name!  In Infosec, knowledge is key and sometimes we need to roll up our sleeves to get the information we need from various open source outlets.  I'm fortunate to have as a guest on this episode the man who literally wrote the book on OSINT techniques, Michael Bazzell.  We discuss OSINT techniques as well as his recently updated book.  Have yourself a listen and hear the advice Michael has for starting your own OSINT adventures. Some links of interest:</p>
<hr>
<ul>
<li><a href="https://inteltechniques.com/" rel="nofollow">https://inteltechniques.com/</a></li>
<li><a href="https://inteltechniques.com/book1.html" rel="nofollow">Open Source Intelligence Techniques, 6th Edition</a></li>
<li><a href="https://inteltechniques.com/buscador/index.html" rel="nofollow">Buscador - OSINT OS</a></li>
<li><a href="https://michaelbazzell.com/forum.html" rel="nofollow">https://michaelbazzell.com/forum.html</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/7e2b3635-5774-4860-9a22-614b68a3251e:f44e1484-f01e-4ea6-bfc4-5e27f3fd6d66.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 21 – The Myth of the Purple Teamer with Haydn Johnson</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=168</guid>
<pubDate>Sun, 25 Feb 2018 14:00:05 -0000</pubDate>

<itunes:duration>00:47:54</itunes:duration>
<itunes:subtitle>I speak with Haydn Johnson about the myth of the purple teamer, that is, an individual who does both red and blue team activities as part of their day job.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/5100ce96b0534318/episode-21-the-myth-of-the-purple-teamer-with-haydn-johnson</link>
<description><![CDATA[<p>I love purple teams.  Purple teaming is something that I was hoping to share with more people and more organizations!  It's part of the reason I named this podcast after them.  So why don't I think that a purple teamer exists?  It's an interesting stance, but it's one that makes sense.  Joining me this week is Haydn "Doctor Purple" Johnson to discuss all things purple. Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www.alienvault.com/blogs/security-essentials/red-teamers-can-learn-secrets-by-purple-teaming" rel="nofollow">Red Teamers Can Learn Secrets by Purple Teaming</a></li>
<li><a href="https://www.darkreading.com/operations/purple-teaming-red-and-blue-living-together-mass-hysteria/d/d-id/1326241" rel="nofollow">Purple Teaming: Red &amp;amp; Blue Living Together, Mass Hysteria</a></li>
<li><a href="https://www.tripwire.com/state-of-security/risk-based-security-for-executives/connecting-security-to-the-business/red-team-v-blue-team-they-are-in-fact-one-the-purple-team/" rel="nofollow">Red Team v. Blue Team? They Are In Fact One – The Purple Team</a></li>
<li><a href="https://www.tripwire.com/state-of-security/risk-based-security-for-executives/connecting-security-to-the-business/top-4-tips-for-purple-team-exercises/" rel="nofollow">Top 4 Tips for Purple Team Exercises</a></li>
<li><a href="http://carnal0wnage.attackresearch.com/2016/01/purple-teaming-lessons-learned-ruxcon.html" rel="nofollow">Purple Teaming - Lessons Learned &amp;amp; Ruxcon Slides</a></li>
<li><a href="https://www.youtube.com/watch?v=KO68mbk9-OU" rel="nofollow">BSidesTO 2015 - Haydn Johnson &amp;amp; Laura Rafferty - Purple View</a></li>
<li><a href="https://www.youtube.com/watch?v=flmxbKfIAE4" rel="nofollow">Hackfest 2016 - Chris Nickerson : Adversarial Simulation: Why your defenders are the Fighter Pilots</a></li>
<li><a href="https://www.slideshare.net/HaydnJohnson" rel="nofollow">Haydn's Slideshares</a></li>
<li><a href="https://twitter.com/haydnjohnson" rel="nofollow">@haydnjohnson</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/5100ce96-b053-4318-806f-2639c16112ac:18397a08-6301-4b1a-97ef-0f9b95d2a3db.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 20 – Physical Penetration Testing with Jek Hyde</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=166</guid>
<pubDate>Sun, 18 Feb 2018 18:39:02 -0000</pubDate>

<itunes:duration>00:53:41</itunes:duration>
<itunes:subtitle>I speak with the legendary Jek Hyde about physical penetration testing.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/44e16126a3d14ee1/episode-20-physical-penetration-testing-with-jek-hyde</link>
<description><![CDATA[<p>Not all penetration testing is done in a virtual setting or even through a phone call.  Sometimes you need to get down and dirty and actually interact with people.  In this very special episode I sit down and speak with the great Jek Hyde about physical penetration testing and everything that it entitles.  It's a fascinating talk for sure, and one you don't want to miss. Some links of interest:</p>
<hr>
<ul>
<li><a href="https://motherboard.vice.com/en_us/article/qv34zb/how-i-socially-engineer-myself-into-high-security-facilities" rel="nofollow">Jek's Motherboard Article</a></li>
<li><a href="https://inteltechniques.com/" rel="nofollow">IntelTechniques.com</a></li>
<li><a href="https://inteltechniques.com/book1.html" rel="nofollow">Open Source Intelligence Techniques (Book)</a></li>
<li><a href="https://www.exploit-db.com/google-hacking-database/" rel="nofollow">Google Hacking Database (Google Dorks)</a></li>
<li><a href="https://redteamtools.com/" rel="nofollow">redteamtools.com</a></li>
<li><a href="https://twitter.com/HydeNS33k" rel="nofollow">@HydeNS33k</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/44e16126-a3d1-4ee1-bdee-a57d15fc29e4:c4a3a4b8-dc47-4cee-a635-b69745bdb9c9.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 19 – Speaking to Executives with Tracy Maleeff</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=164</guid>
<pubDate>Sun, 11 Feb 2018 14:03:44 -0000</pubDate>

<itunes:duration>01:10:13</itunes:duration>
<itunes:subtitle>Tracy Maleeff joins me to talk about strategies for communicating with senior leadership, which is a key skill for all infosec professionals</itunes:subtitle>
<link>http://purplesquadsec.com/episode/050975a4a2e24c51/episode-19-speaking-to-executives-with-tracy-maleeff</link>
<description><![CDATA[<p>Have you heard the term, managing up? It's and old expression used when you need to make sure that your boss has his or her expectations met so that you can focus on your own job.  Information security is really no different, and in a lot of ways it's also more important to get right.  We are an industry of social introverts and generally prefer the warm embrace of an IRC screen, Twitter feed or Slack channel for our communications.  It's taken me many years to get comfortable with speaking with other humans, but more than that I have learned there is a certain technique when speaking with executes - a special breed so to speak - about security.  Tracy Maleeff, the InfoSecSherpa, joins me to help guide us all on proper techniques to communicate with senior leadership. Some links of interest:</p>
<hr>
<ul>
<li><a href="http://nuzzel.com/InfoSecSherpa" rel="nofollow">InfoSecSherpa's Nuzzle Newsletter</a></li>
<li>
<p><a href="https://pbs.twimg.com/media/DAC2hKvXUAUMy2S.jpg" rel="nofollow">Information Needs Chart</a></p>
</li>
<li>
<p><a href="https://www.entrepreneur.com/article/237261" rel="nofollow">How To Effectively Communicate with Different Brain Types</a></p>
</li>
<li>
<p><a href="http://speakupforsuccess.com/be-brief-be-bold-be-gone/" rel="nofollow">Be Brief, Be Bold, Be Gone</a></p>
</li>
<li><a href="https://twitter.com/InfoSecSherpa" rel="nofollow">@InfoSecSherpa</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/050975a4-a2e2-4c51-b3c6-913b8b1e13a4:15ddfb93-a6f6-4adf-bd3c-b02f876f3e20.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 18 – Threat Hunting with Will Harmon</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=158</guid>
<pubDate>Sun, 28 Jan 2018 14:00:20 -0000</pubDate>

<itunes:duration>00:34:07</itunes:duration>
<itunes:subtitle>Will Harmon from Trustwaves Spider Labs comes to talk about Threat Hunting with me.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/c6f438d087e845f8/episode-18-threat-hunting-with-will-harmon</link>
<description><![CDATA[<p>Take a pinch of blue, a dash of red, plus some good old fashioned investigative intuition and you get Threat Hunting!  Well, not exactly but it's a start!  This week Will Harmon from Trustwave's Spider Labs comes on the show to explain what Threat Hunting is, why it's important and how people can get started into this exciting infosec field! Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www2.trustwave.com/2017-Trustwave-Global-Security-Report.html" rel="nofollow">Trustwave Global Security Report - 2017</a></li>
<li>
<p><a href="https://threathunting.org/" rel="nofollow">threathunting.org</a></p>
</li>
<li>
<p><a href="http://www.threathunting.net/" rel="nofollow">threathunting.net</a></p>
</li>
<li>
<p><a href="https://www.sans.org/reading-room/whitepapers/threathunting/" rel="nofollow">SANS Reading Room for Threat Hunting</a></p>
</li>
<li>
<p><a href="https://www.elearnsecurity.com/course/threat_hunting_professional/" rel="nofollow">eLearningSecurity - Threat Hunting Professional</a></p>
</li>
<li><a href="https://www.cybrary.it/course/intro-cyber-threat-intelligence/" rel="nofollow">cybrary.it - Introduction To Cyber Threat Intelligence</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/c6f438d0-87e8-45f8-830f-7cc3860c87fc:7be57a17-c1f3-4fed-946b-6c0b76ed5538.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 17 – A Look At The Treacherous Twelve From The CSA</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=153</guid>
<pubDate>Sun, 21 Jan 2018 14:08:00 -0000</pubDate>

<itunes:duration>00:38:50</itunes:duration>
<itunes:subtitle>I take a look at the Treacherous Twelve from the CSA to see what threats exist for people moving to the cloud.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/e6226c78dd754f4c/episode-17-a-look-at-the-treacherous-twelve-from-the-csa</link>
<description><![CDATA[<p>The Cloud Security Alliance (CSA) has long been known to be the source of cloud security discussions.  From the CCSK to the partnership with ISC(2) to bring us the CCSP, they are definitely a group to pay attention to.  This week I focus on their "Treacherous Twelve", a list of 12 security concerns for any organization moving to the cloud. Some links of interest:</p>
<hr>
<ul>
<li>
<p>CCM - <a href="https://cloudsecurityalliance.org/download/cloud-controls-matrix-v3-0-1/" rel="nofollow">https://cloudsecurityalliance.org/download/cloud-controls-matrix-v3-0-1/</a></p>
</li>
<li>
<p>CSA Top Threats To Cloud Computing Plus: Industry Insights - <a href="https://cloudsecurityalliance.org/download/top-threats-cloud-computing-plus-industry-insights/" rel="nofollow">https://cloudsecurityalliance.org/download/top-threats-cloud-computing-plus-industry-insights/</a></p>
</li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/e6226c78-dd75-4f4c-86aa-e8c77cab5718:8bce8c96-3402-4b36-968d-4b864a0d04a3.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 16 – OSINT with Joe Gray from Advanced Persistent Security</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=151</guid>
<pubDate>Sun, 14 Jan 2018 14:07:44 -0000</pubDate>

<itunes:duration>01:00:47</itunes:duration>
<itunes:subtitle>Joe Gray from the Advanced Persistent Security podcast and Through The Hacking Glass fame joins me to talk OSINT.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/542fa9c423a743e6/episode-16-osint-with-joe-gray-from-advanced-persistent-security</link>
<description><![CDATA[<p>This week Joe Gray, host of the Advanced Persistent Security podcast, that friend you didn't recognize but added to Facebook anyway, and security researcher joins me to talk about OSINT.  This is a packed episode full of security goodness and definitely not one you want to miss! Some links of interest:</p>
<hr>
<ul>
<li>Advanced Persistent Security - <a href="https://advancedpersistentsecurity.net/" rel="nofollow">https://advancedpersistentsecurity.net/</a><ul>
<li><a href="https://twitter.com/C_3PJoe" rel="nofollow">@c_3pjoe</a></li>
</ul>
</li>
<li>Through The Hacking Glass<ul>
<li><a href="https://twitter.com/hackingglass" rel="nofollow">@hackingglass</a></li>
<li><a href="https://twitter.com/rainman_a" rel="nofollow">@rainmain_a</a></li>
<li><a href="https://www.peerlyst.com/users/through-the-hacking-glass" rel="nofollow">Peerlyst</a></li>
</ul>
</li>
<li>OSINT Tools<ul>
<li><a href="https://bitbucket.org/LaNMaSteR53/recon-ng" rel="nofollow">Recon-NG</a></li>
<li><a href="http://osintframework.com/" rel="nofollow">OSINT Framework</a></li>
<li><a href="https://www.paterva.com/web7/buy/maltego-clients/maltego-ce.php" rel="nofollow">Maltego</a></li>
<li><a href="https://www.hunch.ly/" rel="nofollow">Hunch.ly</a></li>
</ul>
</li>
<li>Other Sites<ul>
<li><a href="https://www.indeed.com/" rel="nofollow">Indeed.com</a></li>
<li><a href="https://haveibeenpwned.com/" rel="nofollow">haveibeenpwned.com</a></li>
<li><a href="https://www.innocentlivesfoundation.org/" rel="nofollow">Innocent Lives Foundation</a></li>
</ul>
</li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/542fa9c4-23a7-43e6-8adf-89e62272c77f:2cb7bd36-9810-4dbf-a674-ebf19e1a0c20.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 15 – Infosec Tabletop D&amp;D with Brakeing Down Security</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=147</guid>
<pubDate>Sun, 24 Dec 2017 13:52:03 -0000</pubDate>

<itunes:duration>00:53:54</itunes:duration>
<itunes:subtitle>I sit down with Bryan and Brian from Brakeing Down Security to do a fun take on a classic - Infosec Tabletop Simulations - with a D&amp;D twist!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/d1cc212c63164e6b/episode-15-infosec-tabletop-d-d-with-brakeing-down-security</link>
<description><![CDATA[<p>The first of a series, I sit down with Bryan and Brian of Brakeing Down Security fame to have a fun take on a classic tabletop scenario with a D&amp;D feel.  Please hold the hate, I haven't played D&amp;D in many years and I know it's not "classic", but it's fun and lighthearted.  We go through a few different scenarios with you all in the hopes you find it enjoyable, entertaining, and educational. If you enjoyed this episode, please let me know!  I'd like to make this a recurring theme every 12-15 episodes with different podcasters if there's enough interest.  Special shout out to <a href="https://twitter.com/badthingsdaily" rel="nofollow">@badthingsdaily</a> on Twitter for helping provide the scenarios! Some links of interest:</p>
<hr>
<ul>
<li>Brakeing Down Security - <a href="http://www.brakeingsecurity.com/" rel="nofollow">http://www.brakeingsecurity.com/</a><ul>
<li><a href="https://twitter.com/brakesec" rel="nofollow">@brakesec</a></li>
<li><a href="https://twitter.com/bryanbrake" rel="nofollow">@bryanbrake</a></li>
<li><a href="https://twitter.com/boettcherpwned" rel="nofollow">@boettcherpwned</a></li>
<li><a href="https://twitter.com/InfoSystir" rel="nofollow">@infosystir</a></li>
</ul>
</li>
<li>Tabletop Scenarios - <a href="https://twitter.com/badthingsdaily" rel="nofollow">@badthingsdaily</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/d1cc212c-6316-4e6b-9d96-51372c76fee3:cb4f5634-4171-459a-bbfd-51d97558de7a.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>2017 Holiday Special – Podcast of Podcasters</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=145</guid>
<pubDate>Fri, 22 Dec 2017 17:00:58 -0000</pubDate>

<itunes:duration>01:25:05</itunes:duration>
<itunes:subtitle>The Brakeing Down Security podcast of podcasters!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/92915e9b850f4821/2017-holiday-special-podcast-of-podcasters</link>
<description><![CDATA[<p>I feel truly touched to be included in this year's tradition of the podcast of podcasters, hosted by Bryan Brake of Brakeing Down Security.  This is the audio that you will hear from the various other podcasts that were on the episode with me.  I was a bit star-struck, but it was a great time all around.  Enjoy! Podcasts and Podcasters represented on the show:</p>
<hr>
<ul>
<li><a href="http://www.brakeingsecurity.com/" rel="nofollow">Brakeing Down Security</a><ul>
<li><a href="https://twitter.com/BrakeSec" rel="nofollow">@brakesec</a></li>
<li><a href="https://twitter.com/bryanbrake" rel="nofollow">@bryanbrake</a></li>
<li><a href="https://twitter.com/InfoSystir" rel="nofollow">@InfoSystir</a></li>
</ul>
</li>
<li><a href="https://advancedpersistentsecurity.net/" rel="nofollow">Advanced Persistent Security</a><ul>
<li>@<a href="https://twitter.com/advpersistsec" rel="nofollow">advpersistsec</a></li>
<li><a href="https://twitter.com/C_3PJoe" rel="nofollow">@C_3PJoe</a></li>
</ul>
</li>
<li><a href="https://rallysecurity.com/" rel="nofollow">Rally Security</a><ul>
<li><a href="https://twitter.com/RallySecurity" rel="nofollow">@RallySecurity</a></li>
<li><a href="https://twitter.com/dakacki" rel="nofollow">@Dakacki</a></li>
<li><a href="https://www.twitch.tv/rallysecurity" rel="nofollow">twitch.tv/rallysecurity</a></li>
<li><a href="https://www.youtube.com/rallysecurity" rel="nofollow">youtube.com/rallysecurity</a></li>
</ul>
</li>
<li><a href="https://www.ironsysadmin.com/" rel="nofollow">Iron Sysadmin</a><ul>
<li><a href="https://twitter.com/IronSysadmin" rel="nofollow">@IronSysadmin</a></li>
<li><a href="https://twitter.com/gangrif" rel="nofollow">@gangrif</a></li>
</ul>
</li>
<li><a href="https://www.linkedin.com/in/tzmaleeff/" rel="nofollow">Tracy Maleeff</a><ul>
<li><a href="https://twitter.com/InfoSecSherpa" rel="nofollow">@InfoSecSherpa</a></li>
</ul>
</li>
</ul>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/92915e9b-850f-4821-9764-6e072dd770bf:1b8d8804-1782-4a0b-976c-027ad903ae9b.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 14 – OWASP Top 10 2017 – A6 Through A10</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=139</guid>
<pubDate>Sun, 10 Dec 2017 13:15:14 -0000</pubDate>

<itunes:duration>00:39:44</itunes:duration>
<itunes:subtitle>In this episode I complete my review of the OWASP Top 10 - 2017 looking at items A6 (Security Misconfiguration) through A10 (Insufficient Logging &amp;#038; Monitoring).</itunes:subtitle>
<link>http://purplesquadsec.com/episode/ba805d49dd8d4d6d/episode-14-owasp-top-10-2017-a6-through-a10</link>
<description><![CDATA[<p>In the completion of our look at the OWASP Top 10 for 2017, this episode will cover the final 5 items on the list, from A6 (Security Misconfiguration) through A10 (Insufficient Logging &amp; Monitoring). Some links of interest:</p>
<hr>
<ul>
<li>OWASP Top 10 - <a href="https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf" rel="nofollow">https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf</a></li>
<li>OWASP XSS Filter Evasion Cheat Sheet - <a href="https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_Sheet" rel="nofollow">https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_Sheet</a></li>
<li>OWASP XSS Prevention Cheat Sheet - <a href="https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet" rel="nofollow">https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet</a></li>
<li>OWASP DOM-based XSS Prevention Cheat Sheet - <a href="https://www.owasp.org/index.php/DOM_based_XSS_Prevention_Cheat_Sheet" rel="nofollow">https://www.owasp.org/index.php/DOM_based_XSS_Prevention_Cheat_Sheet</a></li>
<li>Bypass WAF with DOM-based XSS - <a href="https://www.sunnyhoi.com/using-dom-based-xss-bypass-waf/" rel="nofollow">https://www.sunnyhoi.com/using-dom-based-xss-bypass-waf/</a></li>
</ul>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/ba805d49-dd8d-4d6d-b855-56827467bbb2:6912f697-d9c9-49e4-b200-fc205bbaf92f.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 013 – OWASP Top 10 2017 – A1 Through A5</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=133</guid>
<pubDate>Sun, 03 Dec 2017 13:59:04 -0000</pubDate>

<itunes:duration>00:34:17</itunes:duration>
<itunes:subtitle>Taking a look at the first 5 vulnerabilities in the OWASP Top 10 - 2017 list.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/ae1a1761f8594c96/episode-013-owasp-top-10-2017-a1-through-a5</link>
<description><![CDATA[<p>The Open Web Application Security Project (OWASP) group has created a Top 10 web applications vulnerability list since 2003.  Normally the list gets updated every 3 years or so, with the previous release being 2013.  Now with the 2017 list being finalized, I felt it was appropriate for us to go through it and look at it from a red and blue team perspective. This episode will cover the first 5 items on the list, from A1 (Injection) through to A5 (Broken Access Control). Some links of interest:</p>
<hr>
<ul>
<li>OWASP Top 10 - <a href="https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf" rel="nofollow">https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf</a></li>
<li>SQLMap - <a href="http://sqlmap.org/" rel="nofollow">http://sqlmap.org/</a></li>
<li>Burp Suite - <a href="https://portswigger.net/burp" rel="nofollow">https://portswigger.net/burp</a></li>
<li>OWASP Zed Attack Proxy (ZAP) - <a href="https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project" rel="nofollow">https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show's Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/ae1a1761-f859-4c96-a934-51e345c60352:69dd975a-4ad1-4218-950b-cbb1e8f35fc7.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 012 – InfoSec Certifications with Kim Crawley</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=132</guid>
<pubDate>Sun, 26 Nov 2017 13:03:41 -0000</pubDate>

<itunes:duration>00:48:53</itunes:duration>
<itunes:subtitle>I speak with Kim Crawley about her recent article in Cylance, Security Certifications You Should Consider Getting, and about certifications in InfoSec in general.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/7d067e22577f4c6b/episode-012-infosec-certifications-with-kim-crawley</link>
<description><![CDATA[<p>Certifications.  We either love them or hate them, but we cannot deny that they are needed.  Either to prove a set of skills, prove the ability to memorize facts and take tests, or to prove that our egos are bigger than our peers, there are lots of opinions on certifications. This week Kim Crawley joins me to talk about a recent article she has written for Cylance, <em>Security Certifications You Should Consider Getting</em>.  We discuss what certifications are good for, our opinions on them, HR managers, and where you can find resources to help you study. Some links of interest:</p>
<hr>
<ul>
<li>Security Certifications You Should Consider Getting: <a href="https://www.cylance.com/en_us/blog/security-certifications-you-should-consider-getting.html" rel="nofollow">https://www.cylance.com/en_us/blog/security-certifications-you-should-consider-getting.html</a></li>
<li>Kim's Twitter: <a href="https://twitter.com/kim_crawley" rel="nofollow">@kim_crawley</a></li>
<li>Cybrary: <a href="https://www.cybrary.it/" rel="nofollow">https://www.cybrary.it/</a></li>
<li>O'Reilly Safari Books Online: <a href="https://www.safaribooksonline.com/" rel="nofollow">https://www.safaribooksonline.com/</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you all again next time.</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/7d067e22-577f-4c6b-a948-97803a4e24b4:d128c86a-f437-48ff-9137-e14e5d3bd11a.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 011 – Security Scenario Generator with Dr. Z. Cliffe Schreuders</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=130</guid>
<pubDate>Sun, 19 Nov 2017 13:58:52 -0000</pubDate>

<itunes:duration>00:40:38</itunes:duration>
<itunes:subtitle>I speak with Dr. Z. Cliffe Schreuders about a rather amazing project, the Security Scenario Generator (SecGen), which generates random vulnerable VMs!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/4cfbd66731ad4ff8/episode-011-security-scenario-generator-with-dr-z-cliffe-schreuders</link>
<description><![CDATA[<p>As security professionals, we often try to keep our skills sharp.  We normally do this by going to training, reading books, or participating in CTFs.  There are <a href="https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" rel="nofollow">Webgoat</a> and <a href="https://www.owasp.org/index.php/OWASP_Juice_Shop_Project" rel="nofollow">Juice Shop</a> from <a href="https://www.owasp.org/index.php/Main_Page" rel="nofollow">OWASP</a>; sites like <a href="https://www.hackthebox.eu/" rel="nofollow">HackTheBox</a>, <a href="http://overthewire.org/wargames/" rel="nofollow">OverTheWire</a>, and <a href="http://smashthestack.org/wargames.html" rel="nofollow">SmashTheStack</a> which are often mentioned when people are looking for websites to practice on. This week I speak with Dr. Z. Cliffe Schreuders about the Security Scenario Generator, a rather ambitious project that may scratch that vulnerable VM itch you've had for a while. Some links of interest:</p>
<hr>
<ul>
<li>Security Scenario Generator: <a href="https://github.com/cliffe/SecGen" rel="nofollow">https://github.com/cliffe/SecGen</a></li>
<li>Dr. Z. Cliffe Schreuders' Website: <a href="http://z.cliffe.schreuders.org/" rel="nofollow">http://z.cliffe.schreuders.org/</a></li>
<li>Dr. Z. Cliffe Schreuders' YouTube Channel: <a href="https://www.youtube.com/channel/UCAYF5jJkUBcmn1cor50yDOg" rel="nofollow">https://www.youtube.com/channel/UCAYF5jJkUBcmn1cor50yDOg</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/4cfbd667-31ad-4ff8-8352-2bee0e0c0ce1:0c2f836c-2632-40c5-a564-dd7811086aa5.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 010 – Crowdsourced Pen Testing w/ Jason Haddix of Bugcrowd</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=128</guid>
<pubDate>Sun, 12 Nov 2017 13:01:02 -0000</pubDate>

<itunes:duration>00:42:17</itunes:duration>
<itunes:subtitle>I speak with Jason Haddix of Bugcrowd about the crowdsourcing of pen tests and growing the infosec community.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/651bf2b1803f4e5a/episode-010-crowdsourced-pen-testing-w-jason-haddix-of-bugcrowd</link>
<description><![CDATA[<p>Penetration testing.  If you're in the information security field, you have run into your fair share of them.  Now there seems to be a trend with penetration testing moving to a crowdsourcing model.  This week I speak with Jason Haddix of Bugcrowd to explore why that is, what's the draw and how are companies like Bugcrowd helping build the infosec community. Some links of interest:</p>
<hr>
<ul>
<li>Bugcrowd: <a href="https://www.bugcrowd.com/" rel="nofollow">https://www.bugcrowd.com/</a></li>
<li>HackerOne: <a href="https://www.hackerone.com/" rel="nofollow">https://www.hackerone.com/</a></li>
<li>HackTheBox: <a href="https://www.hackthebox.eu/" rel="nofollow">https://www.hackthebox.eu/</a></li>
<li>Bugcrowd Report: <a href="https://www.bugcrowd.com/resource/2017-state-of-bug-bounty/" rel="nofollow">The 2017 State of Bug Bounty</a></li>
<li>Bugcrowd's Twitter: <a href="https://twitter.com/Bugcrowd" rel="nofollow">https://twitter.com/Bugcrowd</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/651bf2b1-803f-4e5a-817c-5d516ce60665:2aa7f9af-1c4e-4666-aa6e-0eb8f362caa7.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 009 – Detecting Intruders on AWS with Scott Piper</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=123</guid>
<pubDate>Sun, 29 Oct 2017 13:19:55 -0000</pubDate>

<itunes:duration>00:42:10</itunes:duration>
<itunes:subtitle>Scott Piper joins me this week to talk about detecting intruders on AWS.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/32aa9b20cb4b4faf/episode-009-detecting-intruders-on-aws-with-scott-piper</link>
<description><![CDATA[<p>The old saying of a defender has to be right 100% of the time while an attacker only has to be right once is growing a bit tired.  Now blue team members should be measured not by keeping the attackers out, but by how quickly they can find out that they're on your network. Scott Piper joins me this week to discuss how we can detect intruders in your AWS cloud infrastructure.  We cover a lot of different tools and techniques that you can use to help detect intruders, and some mitigation strategies to help reduce the risk when an attack is successful. Some links of interest:</p>
<hr>
<ul>
<li>ElastAlert: <a href="https://github.com/Yelp/elastalert" rel="nofollow">https://github.com/Yelp/elastalert</a></li>
<li>StreamAlert: <a href="https://github.com/airbnb/streamalert" rel="nofollow">https://github.com/airbnb/streamalert</a></li>
<li>Prowler: <a href="https://github.com/Alfresco/prowler" rel="nofollow">https://github.com/Alfresco/prowler</a></li>
<li>Security Monkey: <a href="https://github.com/Netflix/security_monkey" rel="nofollow">https://github.com/Netflix/security_monkey</a></li>
<li>AWS Billing Alerts: <a href="https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/free-tier-alarms.html" rel="nofollow">https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/free-tier-alarms.html</a></li>
<li>jq (for JSON parsing on the CLI): <a href="https://stedolan.github.io/jq/" rel="nofollow">https://stedolan.github.io/jq/</a></li>
<li>Summit Route: <a href="https://summitroute.com/" rel="nofollow">https://summitroute.com/</a></li>
<li>Downclimb: <a href="https://summitroute.com/blog/" rel="nofollow">https://summitroute.com/blog/</a></li>
<li>Scott's Twitter: <a href="https://twitter.com/SummitRoute" rel="nofollow">@SummitRoute</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Podcast Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Sign-Up for our Slack community: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/32aa9b20-cb4b-4faf-b449-85f0c97fb61f:e7387b51-3eec-4892-9bcc-62984e9f6cce.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 008 – IAM Securing AWS with J Cole Morrison</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=121</guid>
<pubDate>Sun, 22 Oct 2017 13:02:30 -0000</pubDate>

<itunes:duration>00:32:49</itunes:duration>
<itunes:subtitle>This week I speak with J Cole Morrison about AWS Security and how IAM policies seem to be a lost art that are causing news headlines because of security breaches.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/188d3b31471a4217/episode-008-iam-securing-aws-with-j-cole-morrison</link>
<description><![CDATA[<p>The cloud.  The final frontier.  Well, not exactly but it is a pretty important topic in today's IT environment.  Unfortunately 2017 has been the year of leaks, hacks, and misconfigurations when it comes to the cloud.  Amazon Web Services (AWS) is the cloud provider with the most market share, but its security configuration can leave a bit to be desired. J Cole Morrison joins me this week to discuss IAM policies in AWS, what they are and why they are important.  Cole has written about IAM policies on his blog (link below), which I encourage everyone to read. Some links of interest:</p>
<hr>
<ul>
<li>Cole's IAM Blog Article: <a href="https://start.jcolemorrison.com/aws-iam-policies-in-a-nutshell/" rel="nofollow">AWS IAM Policies in a Nutshell</a></li>
<li>Cole's Website: <a href="https://start.jcolemorrison.com/" rel="nofollow">https://start.jcolemorrison.com/</a></li>
<li>Cole's Twitter: <a href="https://twitter.com/JColeMorrison" rel="nofollow">@JColeMorrison</a></li>
<li>AWS DevOps: <a href="https://awsdevops.io/" rel="nofollow">https://awsdevops.io/</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Slack Sign-Up Link: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/188d3b31-471a-4217-866c-2d78f4eaf208:46f3f366-ec6e-4288-a57e-b680bb99e8ef.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 007 – Securing Linux in Hostile Networks</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=119</guid>
<pubDate>Sun, 15 Oct 2017 13:17:27 -0000</pubDate>

<itunes:duration>00:40:19</itunes:duration>
<itunes:subtitle>I speak with author Kyle Rankin about his latest book, Linux Hardening in Hostile Networks: Server Security from TLS to Tor.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/6d34ce7a013d4eea/episode-007-securing-linux-in-hostile-networks</link>
<description><![CDATA[<p>Linux is often the operating system of choice for server deployments due to its stability and security posturing, right out of the box.  Unfortunately not everything is "production ready" right after an install.  Throughout the internet, there are a lot of Linux hardening and security guides on the internet but most are outdated and provide instructions that are no longer applicable. Kyle Rankin joins me this week to discuss his latest book, <em>Linux Hardening in Hostile Networks: Server Security from TLS to Tor.</em>  This really is a great book and one I would recommend any InfoSec professional pick up to read.  It will make a great reference guide and provides an up-to-date hardening guide for most popular Linux distributions. Some links of interest:</p>
<hr>
<ul>
<li>Kyle's Book:<ul>
<li><a href="https://www.amazon.com/Linux-Hardening-Hostile-Networks-Development/dp/0134173260/ref=sr_1_1" rel="nofollow">Amazon</a></li>
<li><a href="https://www.barnesandnoble.com/w/linux-hardening-in-hostile-networks-kyle-rankin/1124504456?ean=9780134173269#/" rel="nofollow">Barnes &amp;amp; Noble</a></li>
</ul>
</li>
<li>Kyle's Twitter: <a href="https://twitter.com/kylerankin" rel="nofollow">@kylerankin</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Slack Sign-Up Link: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/6d34ce7a-013d-4eea-aa0d-f0c1cab994a9:e53bce15-9a23-4b14-a757-92531a75e99c.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 006 – What up Bropy</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=117</guid>
<pubDate>Sun, 08 Oct 2017 13:34:52 -0000</pubDate>

<itunes:duration>00:35:34</itunes:duration>
<itunes:subtitle>I speak with Matt Domko about Bropy, a tool he built on top of Bro that offers infosec professionals an anomaly detection engine for network analysis.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/85dfa06005894acb/episode-006-what-up-bropy</link>
<description><![CDATA[<p>When people think of an open source IDS, they usually think of Snort.  Bro is another open source IDS that is more than just an IDS.  It is a Network Security Monitor that does so much more.  Matt Domko joins me this week to talk about Bropy, a tool he built that works with Bro to help perform anomaly detection.  This is definitely a tool you will want to have in your bag of tricks. Some links of interest:</p>
<hr>
<ul>
<li>Bro Homepage: <a href="https://www.bro.org/" rel="nofollow">https://www.bro.org/</a></li>
<li>Bropy: <a href="https://github.com/hashtagcyber/bropy" rel="nofollow">https://github.com/hashtagcyber/bropy</a></li>
<li>Matt's Twitter: <a href="https://twitter.com/Hashtagcyber" rel="nofollow">@Hashtagcyber</a></li>
<li>Matt's Bropy Talk at Security Onion Con: <a href="https://www.youtube.com/watch?v=LzFNOuaYc0g" rel="nofollow">https://www.youtube.com/watch?v=LzFNOuaYc0g</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Slack Sign-Up Link: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/85dfa060-0589-4acb-9424-ba9a7752cc0d:592abc0d-5726-4db3-b88a-7e895071e12a.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 005 – #DFIR to Someone Else</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=112</guid>
<pubDate>Sun, 01 Oct 2017 13:43:18 -0000</pubDate>

<itunes:duration>01:03:48</itunes:duration>
<itunes:subtitle>I speak with Jonathon Poling about DFIR and what it entails.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/7410c683025e49aa/episode-005-dfir-to-someone-else</link>
<description><![CDATA[<p>Digital Forensics and Incident Response - DFIR.  The mere mention of the acronym brings forth memories of CSI, plastic bags and agents in suits coming to collect all manner of evidence.  In this episode I speak with Jonathon Poling, a DFIR expert who has graciously agreed to talk DFIR with me!  Another great listen, Jonathon has a lot of great experience in the field and much to share.  Have yourself a listen! Some links of interest:</p>
<hr>
<ul>
<li>Jonathon's Blog: <a href="http://ponderthebits.com/" rel="nofollow">http://ponderthebits.com/</a></li>
<li>Jonathon's Twitter: <a href="https://twitter.com/JPoForenso" rel="nofollow">@JPoForenso</a></li>
<li>Slack Sign-Up Link: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Slack Sign-Up Link: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/7410c683-025e-49aa-8318-43094672dfa3:14ac3fe9-4338-4aa9-bce7-60c442a4ef9a.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 004 – A Day In The Life Of A Red Teamer With Mark Kikta</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=111</guid>
<pubDate>Sun, 24 Sep 2017 13:51:25 -0000</pubDate>

<itunes:duration>00:50:04</itunes:duration>
<itunes:subtitle>I speak with security consultant Mark Kikta about red teams, their activities and all sorts of interesting aspects on how red teams help organizations build a stronger defence.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/6bad8d2ce7364daa/episode-004-a-day-in-the-life-of-a-red-teamer-with-mark-kikta</link>
<description><![CDATA[<p>Red Teams.  For some, it's the "frenemy".  For others, it's the greener grass on the other side of the defence wall.  In this episode I spend some time speaking with security consultant Mark Kikta about Red Teaming.  Mark has been a Red Teamer for a while and has a lot of experience to share.  We talk about a number of different things, share some laughs and try to shed some light on an often misunderstood group. Mark has also graciously offered to hang out in our Slack channel!  Just message <em>@mark</em> to get in touch with him if you have questions or just want to say "hey". Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www.youtube.com/watch?v=GZ-1pwdrN8o" rel="nofollow">CircleCityCon - Seeing Purple Hybrid Security Teams for the Enterprise</a></li>
<li><a href="https://www.amazon.com/Time-Based-Security-Winn-Schwartau/dp/0962870048" rel="nofollow">Time Based Security</a></li>
<li>Slack Sign-Up Link: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Slack Sign-Up Link: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/6bad8d2c-e736-4daa-9899-d8dabf37898e:f31893dc-8f8b-4bb8-90a5-32db04531c88.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 003 – Just the Equifax ma’am</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=109</guid>
<pubDate>Sun, 17 Sep 2017 14:16:59 -0000</pubDate>

<itunes:duration>00:45:39</itunes:duration>
<itunes:subtitle>Equifax suffered one of the biggest breaches in history. I try to break down what happened and what we as Infosec professionals can learn from their mistakes.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/e5766ebc1d9d4c36/episode-003-just-the-equifax-ma-am</link>
<description><![CDATA[<p>Equifax had the largest data breach this year, possibly ever!  How could I possibly pass up this opportunity to discuss what happened?  How did it happen and what lessons could we learn from it?  Equifax did a lot of things wrong for sure, but that doesn't mean that we should throw stones.  Especially given how many of us live in glass houses. Have a listen as I explore the Equifax breach from another perspective, in the hopes of salvaging something of use for others in the infosec community. Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www.equifaxsecurity2017.com/" rel="nofollow">https://www.equifaxsecurity2017.com/</a></li>
<li><a href="http://mashable.com/2017/09/08/equifax-hackers-bitcoin-ransom/#GKuChm2XSkqx" rel="nofollow">Equifax Bitcoin Ransom</a></li>
<li><a href="https://krebsonsecurity.com/2017/09/equifax-breach-response-turns-dumpster-fire/" rel="nofollow">Krebs On Security - Equifax Breach Response Turns Dumpster Fire</a></li>
<li><a href="https://blogs.apache.org/foundation/entry/media-alert-the-apache-software" rel="nofollow">Apache Foundation Responds to Struts Vulnerability Confirmation</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5638" rel="nofollow">CVE-2017-5638 Details</a></li>
<li><a href="https://www.owasp.org/index.php/OWASP_Dependency_Check" rel="nofollow">OWASP Maven Dependency Checker</a></li>
<li><a href="https://wappalyzer.com/" rel="nofollow">Wappalyzer Browser Plug-In</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Slack Sign-Up Link: <a href="https://signup.purplesquadsec.com/" rel="nofollow">https://signup.purplesquadsec.com</a></li>
<li>John's Peerlyst Profile: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/e5766ebc-1d9d-4c36-9c07-e552e9363685:71feb31b-3473-40fc-b1e4-de5882721591.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 002 – Threat Modeling with Archie Agarwal – Part 2</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=107</guid>
<pubDate>Sun, 10 Sep 2017 13:32:09 -0000</pubDate>

<itunes:duration>00:29:49</itunes:duration>
<itunes:subtitle>In the conclusion of my 2 part interview with Archie Agarwal from ThreatModeler, we look at threat modeling outside of early design and architecture.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/60975efc855e406b/episode-002-threat-modeling-with-archie-agarwal-part-2</link>
<description><![CDATA[<p>This is the conclusion of my two part series on threat modeling with Archie Agarwal.  In this episode we go into some benefits on threat modeling, how it can be used beyond the early stages of development and how it can help red teams carry out a more in-depth test against targets! Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www.peerlyst.com/posts/offensive-threat-modeling-for-pen-testers-and-red-teams-threatmodeler" rel="nofollow">Offensive Threat Modeling for Pen Testers and Red Teams</a></li>
<li><a href="https://www.peerlyst.com/posts/how-to-threat-model-a-microservice-architecture-threatmodeler" rel="nofollow">How to Threat Model a Microservice Architecture</a></li>
<li><a href="https://www.peerlyst.com/posts/anyone-can-threat-model-a-commute-to-work-threatmodeler" rel="nofollow">Anyone can Threat Model a Commute to Work</a></li>
<li><a href="mailto:archie@threatmodeler.com" rel="nofollow">Archie's Email</a></li>
<li><a href="http://threatmodeler.com/" rel="nofollow">ThreatModeler Company Website</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Peerlyst: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/60975efc-855e-406b-9070-58192a25b723:3d2b1766-de76-491a-84eb-f0a46110b8e6.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 001 – Threat Modeling with Archie Agarwal – Part 1</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=102</guid>
<pubDate>Sun, 03 Sep 2017 13:09:34 -0000</pubDate>

<itunes:duration>00:49:37</itunes:duration>
<itunes:subtitle>Part 1 of a 2 part discussion about threat modeling with Archie Agarwal, CEO of ThreatModeler.</itunes:subtitle>
<link>http://purplesquadsec.com/episode/55c56693c7114e65/episode-001-threat-modeling-with-archie-agarwal-part-1</link>
<description><![CDATA[<p>Welcome to episode 1!  In this first part of a two part series, I sit down with Archie Agarwal to discuss threat modeling, what it is, why we need it and how it can help with improving your security posture early in your development cycle. Some links of interest:</p>
<hr>
<ul>
<li><a href="https://www.peerlyst.com/posts/offensive-threat-modeling-for-pen-testers-and-red-teams-threatmodeler" rel="nofollow">Offensive Threat Modeling for Pen Testers and Red Teams</a></li>
<li><a href="https://www.peerlyst.com/posts/how-to-threat-model-a-microservice-architecture-threatmodeler" rel="nofollow">How to Threat Model a Microservice Architecture</a></li>
<li><a href="https://www.peerlyst.com/posts/anyone-can-threat-model-a-commute-to-work-threatmodeler" rel="nofollow">Anyone can Threat Model a Commute to Work</a></li>
<li><a href="mailto:archie@threatmodeler.com" rel="nofollow">Archie's Email</a></li>
<li><a href="http://threatmodeler.com/" rel="nofollow">ThreatModeler Company Website</a></li>
</ul>
<hr>
<p>Want to reach out to the show?  There's a few ways to get in touch!</p>
<hr>
<ul>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Peerlyst: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening, and I will talk with you again next time!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/55c56693-c711-4e65-83fb-da9c19475a8f:7eca8cd8-2a22-4669-a2b9-98950a67fbc5.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
<item><title>Episode 000 – Welcome to the Podcast!</title>
<guid isPermaLink="false">https://purplesquadsec.com/?post_type=podcast&amp;p=96</guid>
<pubDate>Tue, 08 Aug 2017 12:40:14 -0000</pubDate>

<itunes:duration>00:09:43</itunes:duration>
<itunes:subtitle>The origin episode! I talk about what the podcast is about, where to find me, welcoming new users and a general overview of the podcast itself. Welcome!</itunes:subtitle>
<link>http://purplesquadsec.com/episode/9611010ff23940a0/episode-000-welcome-to-the-podcast-</link>
<description><![CDATA[<p>Welcome to the first episode of the podcast!  In this episode, I talk about the podcast, what it's about, what I'm hoping to cover, who the podcast is for, and generally just ramble on.  Regardless, welcome to Purple Squad Security!  I hope you enjoy your stay and come back for more.</p>
<hr>
<ul>
<li>Website: <a href="https://purplesquadsec.com/" rel="nofollow">purplesquadsec.com</a></li>
<li>Show Twitter: <a href="https://twitter.com/PurpleSquadSec" rel="nofollow">@PurpleSquadSec</a></li>
<li>John's Twitter: <a href="https://twitter.com/JohnsNotHere" rel="nofollow">@JohnsNotHere</a></li>
<li>John's Peerlyst: <a href="https://www.peerlyst.com/users/john-svazic" rel="nofollow">https://www.peerlyst.com/users/john-svazic</a></li>
</ul>
<hr>
<p>Thanks for listening!</p>
<p>Find out more at <a href="http://purplesquadsec.com" rel="nofollow">http://purplesquadsec.com</a></p>]]></description>
<itunes:explicit>no</itunes:explicit>
<enclosure url="https://dts.podtrac.com/redirect.mp3/pinecast.com/listen/9611010f-f239-40a0-a453-7012d4381091:20f98c60-7e60-449e-9b43-5dad48d17656.mp3?source=rss&amp;ext=asset.mp3" length="1" type="audio/mpeg" />
</item>
</channel>
<!-- generated in 0s 25656us -->
</rss>