Hands-On Hacking with James Gillkey

Summary:

In this episode of Exploring Information Security, host Tim De Block sits down with James Gillkey to discuss hands-on hacking training at ShowMeCon. James is revamping a long-standing pentesting training course to bring modern techniques, updated tools, and a focus on efficiency to security professionals. He shares insights into building effective training labs, leveraging Python virtual environments, and incorporating real-world offensive security methodologies into a structured learning experience.

Topics Discussed

  • The evolution of hands-on hacking training and its history

  • Setting up virtualized pentesting environments with Python and GitHub tools

  • Common mistakes in pentesting and how to avoid them

  • The balance between red team engagements and SOC awareness

  • The importance of password cracking, enumeration, and network recon

  • How cloud security assessments differ from traditional network pentesting

  • The role of AI in pentesting and whether it’s a useful tool or a shortcut

  • ShowMeCon’s Fallout-themed hacking lab and what to expect in the training

Key Takeaways

  • Hands-on experience is crucial. The best way to learn pentesting is by doing it.

  • Virtualized environments simplify tool management and prevent conflicts.

  • AI is an emerging tool in pentesting, but it doesn’t replace fundamental knowledge.

  • Cloud security requires a different mindset due to its unique challenges and toolsets.

  • Communication with SOC teams is essential to avoid unnecessary panic during testing.

  • Efficiency matters. The goal of the training is to give students actionable skills they can use immediately.

Further Resources

Use the promo code “ExploringSec” to get $50 off your registration

Showmecon Links and Resources:

Support the Podcast:

Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

Contact Information:

Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn][YouTube]

Hands on Hacking
James Gilkey


Breaking Bad Code with Kevin Johnson

Summary:

In this episode of Exploring Information Security, host Timothy De Block welcomes Kevin Johnson, founder of Secure Ideas, to discuss web application penetration testing, API security, and hands-on security training. Kevin shares insights on why pentesters need to understand business risk, how API security is often misunderstood, and what participants can expect from his Breaking Bad Code workshop at ShowMeCon. He also reflects on the state of security talks at conferences, the importance of interactive learning, and Secure Ideas’ 15-year journey in the industry.

Topics Discussed:

  • Web Application Security Challenges – Why automated tools alone aren’t enough, and how attackers think differently.

  • API Security & Misconceptions – How APIs change attack surfaces and why developers often overlook key security flaws.

  • Breaking Bad Code Training at ShowMeCon – What attendees will learn and why hands-on hacking beats passive lectures.

  • Security Talks vs. Vendor Pitches – The problem with sales-driven conference talks and why real education matters.

  • The Evolution of Secure Ideas – Celebrating 15 years in business, plus challenge coins and community growth.

  • Fun Side Tangents – Muppets, hacking culture, and why Wacka Hack is the talk you don’t want to miss at ShowMeCon.

Key Takeaways:

  • Effective pentesting goes beyond tools—it’s about understanding the purpose and risk of an application.

  • API security isn’t a separate discipline—it requires a shift in attacker mindset.

  • Hands-on training is the best way to learn—expect to actively hack at the Breaking Bad Code workshop.

  • Security conference talks should educate, not sell—vendor-heavy presentations fail to engage the audience.

  • ShowMeCon is an invaluable event for anyone interested in offensive security and application security.

Guest Info:

  • Kevin Johnson – Founder & CEO of Secure Ideas, security consultant, trainer, and conference speaker.

Links and Resources:

Use the promo code “ExploringSec” to get $50 off your registration

Showmecon Links and Resources:

Support the Podcast:

Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

Contact Information:

Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn][YouTube]

Breaking Bad Code
Kevin Johnson


ShowMeCon and Security Perspectives with Amanda Berlin

Summary:

Use the promo code “ExploringSec” to get $50 off your registration

In this episode of Exploring Information Security, host Timothy De Block welcomes Amanda Berlin, CEO of Mental Health Hackers & Senior Product Manager at Blumira, to discuss her experiences in security product development, incident detection, and the challenges of balancing security with usability. They explore the limitations of pentest reports, the practicality of security automation, and the psychology behind effective security awareness training. Amanda also shares insights on how small businesses can implement security without breaking the bank and what to expect from ShowMeCon.

Topics Discussed:

  • Amanda’s Keynote at ShowMeCon – How she ended up speaking and why Dave’s method of picking speakers is unconventional.

  • Security Automation vs. Usability – Why some industries can implement auto-lockouts, while others (like hospitals) cannot.

  • The Problem with Pentest Reports – Why they often contain unrealistic security expectations that don’t translate to real-world environments.

  • Getting Buy-In for Security Solutions – How to understand what organizations actually need instead of pushing the latest security trend.

  • The Role of Nudge Theory in Awareness Training – Why small, repeated reinforcements can be more effective than long training videos.

  • Security for Small Businesses – Strategies for implementing security on a limited budget and making defenses practical.

  • Side Tangents & Fun Conversations – Crossword puzzles, Wordle streaks, and the absurdity of marketing budgets in cybersecurity.

Key Takeaways:

  • Security needs to be tailored to the environment—automation can improve security, but in some cases, it can create more risks.

  • Pentest reports often miss the mark by listing detected issues without considering operational feasibility.

  • Security awareness is most effective when it’s continuous and engaging, rather than a one-time annual training.

  • Listening to users is critical—security teams must balance technical controls with usability needs.

  • ShowMeCon continues to be a top-tier conference for hands-on security learning and industry networking.

Showmecon Links and Resources:

Support the Podcast:

Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

Contact Information:

Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn][YouTube]

ShowMeCon and Security Perspectives with Amanda Berlin
Amanda Berlin


Real World Windows Forensics and Incident Response with JC at ShowMeCon 2025

Summary:

In this episode of Exploring Information Security, host Timothy De Block sits down with JC, President at Snowfensive, to discuss Windows forensics, incident response, and the upcoming training session at ShowMeCon. JC shares insights on real-world forensic investigations, common challenges organizations face in responding to incidents, and how forensic methodology plays a critical role in cybersecurity operations. This episode is packed with valuable information for security professionals, IT admins, and anyone interested in digital forensics.

Showmecon Links and Resources:

Topics Discussed:

  • ShowMeCon Training Session: What attendees can expect from JC’s Windows forensics course.

  • The Reality of Incident Response: The distinction between forensic analysis and incident response and how they complement each other.

  • Ransomware Trends: The evolution from encryption-based ransomware to data extortion and the impact on organizations.

  • Real-World Forensic Cases: Examples of forensic investigations, including rapid containment strategies and detecting data exfiltration.

  • Critical Thinking in Forensics: How forensic methodology is akin to detective work, and why troubleshooting skills are essential.

  • Challenges in Reporting: Why documenting forensic findings properly is just as important as the investigation itself.

Key Takeaways:

  • Organizations are improving at responding to ransomware but still struggle with preventing data exfiltration.

  • Understanding Windows forensic artifacts is crucial for both security teams and IT administrators.

  • Effective forensic investigations require both technical expertise and strong reporting practices.

  • Training and tabletop exercises are essential for preparing organizations to handle real-world incidents.

Guest Info:

  • JC is a cybersecurity expert specializing in Windows forensics, incident response, and offensive security services. He is the President of Snowfensive and Co-Founder of the Social Engineering Community.

Support the Podcast:

Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

Contact Information:

Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn][YouTube]

Real World Windows Forensics and Incident Response at ShowMeCon 2025
JC


ShowMeCon: A Must-Attend Conference for Cybersecurity Pros

Summary:

In this episode of Exploring Information Security, host Timothy De Block sits down with Dave Chronister and Brooke Deneen to discuss ShowMeCon, the Midwest’s premier security conferences. Dave shares the vision behind ShowMeCon, how it stands apart from other security events, and what attendees can expect from the 2025 edition. Brooke provides insights into the logistics of running the conference and the community-driven experience that makes it special. Whether you're a seasoned security professional or new to the space, this episode highlights why ShowMeCon is a must-attend event.

Use ExploringSec to get $50 off.

Showmecon Links and Resources:

Topics Discussed:

  • The Origin of ShowMeCon: How the conference came to be and its unique place in the cybersecurity event landscape.

  • Balancing Corporate and Hacker Culture: Creating a professional yet welcoming environment that bridges the gap between security research and IT professionals.

  • Venue and Experience: Why the Ameristar Casino in St. Louis is an ideal location and what makes the event an immersive experience.

  • Speaker and Attendee Engagement: The focus on quality content, hands-on learning, and ensuring speakers are passionate and approachable.

  • Expanding to New Cities: Plans to bring the ShowMeCon model to new locations like Nashville and beyond.

  • ShowMeCon 2025 Highlights: The return of pre-conference training, CTFs, lockpicking villages, and an exciting Fallout-themed experience.

  • Building a Security Community: Encouraging new speakers, creating a welcoming space, and fostering professional development.

Key Takeaways:

  • ShowMeCon is designed for practical security education, offering content relevant to both IT and security professionals.

  • The conference prides itself on being a well-run, high-quality event where speakers and attendees engage meaningfully.

  • Training opportunities and community events, such as CTFs and lockpicking villages, enhance the overall experience.

  • ShowMeCon’s future includes expansion to other cities and continued efforts to foster an inclusive and passionate security community.

Guest Info:

  • Dave Chronister is the founder of ShowMeCon and a cybersecurity professional with over 18 years of experience in the industry.

  • Brooke Deneen plays a key role in organizing ShowMeCon and ensuring the event runs smoothly.

Support the Podcast:

Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and cybersecurity events.

Contact Information:

Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn][YouTube]

ShowMeCon: A Must-Attend Conference for Cybersecurity Pros
With Dave Chronister and Brooke Deneen


[RERELEASE] ShowMeCon: What does Jayson E. Street, Dave Chronister, Johnny Xmas, April Wright, and Ben Brown think about security?

In this epic episode of the Exploring Information Security podcast Jayson E. Street (@jaysonstreet), Dave Chronister (@bagomojo), Johnny Xmas (@J0hnnyXm4s), April Wright (@aprilwright), Ben Brown (@ajnachakra), and surprise guests Adrian Crenshaw (@irongeek_adc) and Kevin Johnson (@secureideas)all join me to discuss various security related topics.

ShowMeCon is one of my favorite security conferences. The organizers are awesome and take care of their speakers like no other conference. The venue is fantastic. The content is mind blowing. I can't say enough good things about the even that Dave and Renee Chronister put on every year in St. Louis, Missouri. They know how to put on a conference.

Regular listeners of the podcast will note that I recorded an episode with Dave on ShowMeCon several weeks ago. After that recording he asked if I was interested in doing a recording at the conference. I said yes and thus the birth of this epic episode. This format is experimental. First, it is marked as explicit, because there is swearing. Second, It's over 90 minutes long. I didn't think breaking it up into four or five pieces would serve the recording well. Send me your feedback good or bad on this episode, because I'd like to do more of these. I would really like to hear it for this episode.

In this episode we discuss:

  • Certificates

  • Hiring

  • Interviewing

  • Where to get started

  • Soft skills

  • ShowMeCon and other conferences

  • Community and giving back

  • Imposter syndrome

  • Irongeeks impact on those in attendance

What do the organizers and speakers of ShowMeCon think of security?
ShowMeCon 2017

HallwayCon from the floor of ShowMeCon 2024

Summary:

In this off-the-cuff episode, Timothy De Block brings a mic to the floor of ShowMeCon for the first-ever HallwayCon podcast episode. He walks around with a mic and recorder, engaging in spontaneous conversations with random attendees. Timothy highlights the immense value of attending security conferences, emphasizing that these real, impromptu conversations with professionals are crucial for expanding knowledge and building relationships within the industry. This unique approach captures some just some of the many conversations going on at security conferences.

Key Topics Discussed:

  1. Importance of Networking:

    • Knowing your target employers and daily tasks.

    • Overcoming the fear of talking to strangers.

  2. Effective Techniques:

    • Asking engaging questions.

    • Volunteering and getting involved.

  3. Conference Culture:

    • Evolution of conference attire.

    • Balancing business and casual environments.

  4. Career Challenges:

    • Job market difficulties for younger and older professionals.

    • Role of networking in career advancement.

  5. Humorous Stories:

    • Conference experiences and unique attire.

    • Creative uses of business cards.

  6. Management Insights:

    • Effective management and hiring practices.

    • Importance of structured onboarding.

  7. Impact of AI:

    • AI’s role in security and deepfake technology.

    • Future relevance in cybersecurity.

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

HallwayCon from the floor of ShowMeCon 2024
With ShowMeCon Attendees


What's Happening at ShowMeCon 2024?

Summary:

In this dynamic episode, host Timothy De Block engages in a lively conversation with Joey Smith, Tim McLaren, and Ben Miller live from the floor of Show Me Con 2024. They discuss various topics including the importance of trust in vendor relationships, the evolution of security roles, and the innovative approaches being adopted in the food industry.

Episode Highlights:

Conversations with Industry Experts:

  • Spontaneous discussions about the importance of genuine interactions at conferences.

  • Joey's perspective on the value of treating vendors with respect and professionalism.

Insights from Tim McLaren:

  • Tim shares his experience transitioning from a vendor-specific role to a broader consultancy position.

  • Discussion on the importance of having diverse solutions and the role of trust in customer relationships.

Ben Miller's Take:

  • Ben emphasizes the need for critical thinking and continuous learning in security roles.

  • Reflections on how past experiences shape current practices in cybersecurity.

Vendor Relationships and Trust:

  • The group discusses the significance of building long-term, trust-based relationships with vendors.

  • Examples of how trust influences decision-making and security practices.

Innovations in Security:

  • Conversations on how emerging technologies and innovative solutions are reshaping the cybersecurity landscape.

  • Joey's insights on the latest advancements and their implications for the industry.

Key Quotes:

  • "Trust is between two people. I don't trust the business or a line of questioning; I trust the individuals behind it." - Joey Smith

  • "Critical thinking and adaptability are essential in the ever-evolving field of cybersecurity." - Ben Miller

Recommended Resources:

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

What's Happening at ShowMeCon 2024
With Joey Smith, Tim McLaren, and Ben Miller


Catching up with Mental Health Hackers Founder Amanda Berlin at ShowMeCon

Summary:

In this relaxed and engaging episode recorded from air loungers at Show Me Con, Timothy De Block catches up with Amanda Berlin from Mental Health Hackers during Mental Health Awareness Month. They discuss the importance of mental health in the IT security industry, which is often fraught with stress and high demands.

Episode Highlights:

  1. Personal Stories of Mental Health: Timothy and Amanda share their personal experiences with mental health challenges, emphasizing the common struggles many face in the IT security field.

  2. Impact of Alcohol: The discussion explores the impact of alcohol on mental health, particularly how it affects sleep and stress levels. They touch upon efforts to create event spaces that offer alternatives to alcohol-centric activities.

  3. Mental Health Hackers: Amanda talks about the work of Mental Health Hackers, a group that attends various conferences to provide spaces for people to relax and decompress.

  4. Fundraising and Awareness: Mention of Mental Health Hackers' new t-shirt campaign designed to promote mental wellness, with proceeds supporting their activities at conferences. You can get T-Shirts here: https://www.customink.com/fundraising/mental-health-awareness-for-mhh

Key Quotes:

  • "It’s really about awareness... paying attention to how habits like drinking can impact our mental state and sleep." - Timothy De Block

  • "We need to create environments at events where drinking isn’t the main focus, allowing people to enjoy without the pressure of alcohol." - Amanda Berlin

Additional Resources:

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

Catching Up with Mental Health Hackers at ShowMeCon
With Amanda Berlin


ShowMeCon: How AI will impact Cybersecurity Enhancements and Threats with Jayson E. Street

Summary:

Jayson E. Street

In this engaging episode Jayson E. Street, a renowned cybersecurity expert, joins me to discuss the return of ShowMeCon, the impact of AI in cybersecurity, and innovative strategies for enhancing security and combating threats. Jayson shares his excitement for ShowMeCon, insights on utilizing AI for security enhancements rather than traditional attacks, and offers practical advice for users, executives, and information security professionals.

This podcast sponsored by ShowMeCon.

Episode Highlights:

  • ShowMeCons return

  • Utilizing AI in Cybersecurity

  • Creative Use of AI for Security

  • Practical Security Tips Across the Board

  • The Future of AI in Security

Guest Information:

Jayson E. Street referred to in the past as: A "notorious hacker" by FOX25 Boston, "World Class Hacker" by National Geographic Breakthrough Series and described as a "paunchy hacker" by Rolling Stone Magazine.

He however prefers if people refer to him simply as a Hacker, Helper & Human.

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

ShowMeCon: How AI will impact Cybersecurity Enhancements and Threats
With Jayson E. Street


ShowMeCon: Azure Vulnerabilities with Scott Miller

Scott Miller

Summary:

Scott Miller, a fresh voice in the cybersecurity arena, joins me to discuss the intricacies of hacking Azure services. Scott shares his journey from a recent college graduate to becoming a speaker at cybersecurity conferences, along with valuable insights into Azure AD (Active Directory), vulnerabilities within cloud services, and the art of escalation.

This episode sponsored by ShowMeCon.

Episode Highlights:

  • Scott's Entry into Cybersecurity

  • Focus on Azure AD

  • Exploring Vulnerabilities

  • Methodology and Tools

  • Learning and Resources

  • The Importance of Entry-Level Accessibility

Scott Miller Penetration Tester at Accenture

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

ShowMeCon: Azure Vulnerabilities with Scott Miller
Scott Miller


ShowMeCon: Unraveling the Cybersecurity Fabric of Space and SCADA Networks with Paul Coggin

Paul Coggin

Summary:

In this captivating episode of the "Exploring Information Security" podcast, cybersecurity expert Paul Coggin discusses the intricate world of threat hunting in SCADA networks and the emerging frontier of space cybersecurity. From the inspiration drawn from Transformers movies to the sophisticated attacks like Stuxnet, Coggin delves deep into how monitoring physical indicators could revolutionize our approach to cybersecurity in both terrestrial and extraterrestrial domains.

This podcast is sponsored by ShowMeCon.

Episode Highlights:

  • The significance of ShowMeCon in filling the void left by other conferences.

  • Paul's historical involvement and contribution to the naming of ShowMeCon and DerbyCon.

  • The Internet of Military Things

  • Initiating Threat Hunting in New Domains

  • Case Studies and Practical Applications

  • Looking Ahead: Cybersecurity in Space

Guest Information:

Paul Coggin is a Cyber SME at nou Systems, Inc.

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

ShowMeCon: Unraveling the Cybersecurity Fabric of Space and SCADA Networks with Paul Coggin
Paul Coggin


ShowMeCon: Talking with the Iceland Viking Arnar

Summary:

Arnar is not a speaker this year at ShowMeCon but he will be in attendance. He doesn’t work in the security field but he’s doing some really advanced stuff with cooling in cloud environments. We get into a little bit of everything around what he’s doing as well as talk about AI. Surprise!

This podcast is sponsored by ShowMeCon.

Episode Highlights:

  • What Arnar is looking forward to at ShowMeCon

  • Some of the cool things he’s doing with his company

  • AI

Guest Information:

Arnar

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

ShowMeCon: Talking with the Iceland Viking Arnar
Arnar Gunnarsson


ShowMeCon: Talking Sysmon with Amanda Berlin

Amanda Berlin

Summary:

Amanda Berlin is Lead Incident Detection Engineer at Blumira, where she leads the development of new detections for the Blumira platform, based on threat intelligence and research. In this episode I catch up with her to talk about Sysmon and ShowMeCon. Sysmon is such a great tool for getting more information out of your systems. The best part is it’s free.

This podcast is sponsored by ShowMeCon.

Episode Highlights:

  • What is Sysmon

  • How to use Sysmon

  • ShowMeCon

Guest Information:

Amanda Berlin is Lead Incident Detection Engineer at Blumira

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

ShowMeCon: Talking Sysmon with Amanda Berlin
Amanda Berlin


ShowMeCon: Couch to Compromise with Johnny Xmas

Summary:

Veteran conference speaker Johnny Xmas joins me to discuss ShowMeCon and his talk Couch to Compromise the 2024 edition. His talk is an update from previous years which goes over the latest attacks impacting organizations.

Episode Highlights:

Johnny Xmas with a not a flamethrower

Guest Information:

Johnny Xmas: The Most Interesting Man in Information Security

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

ShowMeCon: Couch to Compromise with Johnny Xmas
With Johnny Xmas


ShowMeCon: Bypassing MFA with Brandon Potter

This is a sponsored podcast by ShowMeCon which is May 13th & 14th. Tickets are still available! They’re also still looking for sponsors. Don't miss out on this opportunity to be part of the cybersecurity event of the year! Whether you're looking to learn, network, or elevate your brand, ShowMeCon is the place to be.

Summary:

Brandon Potter Chief Technology Officer of ProCircular, Inc.

Brandon Potter joins me to discuss the different ways he’s seeing MFA bypassed as part of his companies work. Attackers are using old and new techniques to discover creative ways to bypass MFA. This is a result of more companies getting onboard with MFA. Unfortunately, that means attackers are going to start to find more ways to bypass MFA. A lot of what Brandon is seeing is coming down to misconfiguration with how MFA is implemented and attackers are starting to use browser in the middle to hijack sessions. Finally, we go over how AI is going to impact MFA.

Episode Highlights:

  • ShowMeCon one of the few conferences in the Midwest to attend

  • Bypassing MFA

  • Misconfigurations in MFA

  • Browser-in-the-middle

  • Where is MFA being bypassed?

  • How is AI going to impact bypassing MFA

Guest Information:

Brandon Potter (CISSP, GSEC, GCIH, CCFP, GWAPT) is the Chief Technology Officer of ProCircular, Inc.,

Brandon Potter LinkedIn

ProCircular Website

ProCircular LinkedIn

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

Bypassing MFA with Brandon Part
Brandon Potter, Chief Technology Officer with ProCircular


ShowMeCon: Kevin Johnson and whatever he wants to talk about

This is a sponsored podcast by ShowMeCon which is May 13th & 14th. Tickets are still available! They’re also still looking for sponsors. Don't miss out on this opportunity to be part of the cybersecurity event of the year! Whether you're looking to learn, network, or elevate your brand, ShowMeCon is the place to be.

Summary:

Kevin Johnson CEO of Secure Ideas

Kevin Johnson the Chief Executive Officer of Secure Ideas joined me to discuss ShowMeCon and his keynote presentation on the infosec community rising from the ashes like a phoenix. It’s been a while since I’ve had the opportunity to catch up with Kevin but we got right into it and had a lot of great laughs. It’s a little all over the place with talk about ShowMeCon, reincarnation, and John Wick as a romantic comedy. Also, there is an EXPLICIT tag on this podcast.

Check the episode highlights below for a jingle on the topic.

Episode Highlights:

(Verse 1)
🎶 In the world of cyber, there's a place to be,
ShowMeCon's the event, in the tech sea.
Kevin Johnson's leading, with a tech-savvy crew,
Bringing folks together, showing what they can do. 🎶

(Chorus)
🎵 ShowMeCon, ShowMeCon, where the tech minds meet,
Diving deep in cyber streets, where challenges and passions greet.
From the ashes, we will rise, like a phoenix, bold and wise,
ShowMeCon, the stage is set, for a tech adventure you won't forget. 🎵

(Verse 2)
🎶 Imagine John Wick, with a softer side,
In a rom-com twist, where love and action collide.
He's hacking through the heart, with a smile so wide,
At ShowMeCon, where worlds of tech and romance abide. 🎶

(Bridge)
🎵 Rising from the ashes, with the phoenix's flight,
We'll conquer cyber battles, in the neon light.
Kevin Johnson guides us, through the digital night,
At ShowMeCon, we'll learn, we'll grow, and take our dreams to height. 🎵

(Chorus)
🎵 ShowMeCon, ShowMeCon, where the future's bright,
Join us in the journey, in the quest for cyber might.
From the ashes, we will rise, with our hearts and minds entwined,
ShowMeCon, where dreams take flight, and every moment's a delight. 🎵

Guest Information:

Kevin Johnson is the Chief Executive Officer of Secure Ideas. Kevin has a long history in the IT field including system administration, network architecture and application development. He has been involved in building incident response and forensic teams, architecting security solutions for large enterprises and penetration testing everything from government agencies to Fortune 100 companies. In addition, Kevin is a faculty member at IANS and was an instructor and author for the SANS Institute.

Resources and Mentions:

Secure Ideas

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

ShowMeCon: Kevin Johnson and whatever he wants to talk about
With Kevin Johnson CEO of Secure Ideas


What is ShowMeCon 2024?

Summary:

Dave Chronister the organizer of ShowMeCon joined me to discuss the revival of the conference. ShowMeCon is one of my favorite conferences. I had the pleasure of going to it from 2016-2018. I had plans to return in 2020 but the world event that we shall not speak of happened. I’m happy to see it return in 2024 and I will be there!

We get into a variety of topics around the conference including sponsorship, who attends, the venue, and the theme for 2024. The conference is still looking for sponsors and they’re about to do a second round of call for papers for speakers. If you’re looking to attendee the early bird price ends January 14th, 2024. Looking forward to seeing you there!

Episode Highlights:

  • ShowMeCon is still looking for sponsors

  • Who comes to the conference

  • The origins and venue of ShowMeCon

  • The theme for ShowMeCon 2024

Guest Information:

Dave Chronister organizer of ShowMeCon and CEO of Parameter Security

Resources and Mentions:

  • ShowMeCon

  • For questions reach out to info@showmecon.com

Contact Information:

Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

Check out our services page and reach out if you see any services that fit your needs.

Social Media Links:

[RSS Feed] [iTunes] [LinkedIn]

What is ShowMeCon 2024?
Dave Chronister


ShowMeCon 2018 Live

In this panelist episode of the Exploring Information Security podcast, the first ever podcast panel at ShowMeCon 2018!

Amanda Berlin (@InfoSystir), Wik (@jaimefilson), David Cybuck (@dpcybuck), April Wright (@aprilwright), and Dave Chronister (@bagomojo) join me on the live EIS panel at ShowMeCon, June 7, 2018. This is the first panel I've ever done for the podcast. It went so well, I hope to do more in the future. We cover a variety of topics and have a few laughs.

YouTube version

In this episode we discuss:

  • What's coming back in vogue

  • What to do with master ID

  • What our thoughts are on new password policies from NIST

  • How to handle best practices

ShowMeCon 2018 Live
With Amanda Berlin, Wik (Dave), David Cybuck, April Wright, and Dave Chronister

What does Jayson E. Street, Dave Chronister, Johnny Xmas, April Wright, and Ben Brown think about security?

In this epic episode of the Exploring Information Security podcast Jayson E. Street (@jaysonstreet), Dave Chronister (@bagomojo), Johnny Xmas (@J0hnnyXm4s), April Wright (@aprilwright), Ben Brown (@ajnachakra), and surprise guests Adrian Crenshaw (@irongeek_adc) and Kevin Johnson (@secureideas)all join me to discuss various security related topics.

ShowMeCon is one of my favorite security conferences. The organizers are awesome and take care of their speakers like no other conference. The venue is fantastic. The content is mind blowing. I can't say enough good things about the even that Dave and Renee Chronister put on every year in St. Louis, Missouri. They know how to put on a conference.

Regular listeners of the podcast will note that I recorded an episode with Dave on ShowMeCon several weeks ago. After that recording he asked if I was interested in doing a recording at the conference. I said yes and thus the birth of this epic episode. This format is experimental. First, it is marked as explicit, because there is swearing. Second, It's over 90 minutes long. I didn't think breaking it up into four or five pieces would serve the recording well. Send me your feedback good or bad on this episode, because I'd like to do more of these. I would really like to hear it for this episode.

In this episode we discuss:

  • Certificates
  • Hiring
  • Interviewing
  • Where to get started
  • Soft skills
  • ShowMeCon and other conferences
  • Community and giving back
  • Imposter syndrome
  • Irongeeks impact on those in attendance
What do the organizers and speakers of ShowMeCon think of security?