Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
Sports
Technology
History
About Us
Contact Us
Copyright
© 2024 PodJoint
Podjoint Logo
US
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts126/v4/82/e2/24/82e224dd-3ea8-8097-130f-ffd18992b0f4/mza_9308217718868764874.jpg/600x600bb.jpg
The Security Engineering Show
The Security Engineering Show
5 episodes
1 day ago
These are the stories of the security engineering projects that are worth telling. We skip past the broad strokes to the tactics, obstacles, and the untold stories behind the successes and failures. This is the show for the people who architect strong security systems.
Show more...
Technology
RSS
All content for The Security Engineering Show is the property of The Security Engineering Show and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
These are the stories of the security engineering projects that are worth telling. We skip past the broad strokes to the tactics, obstacles, and the untold stories behind the successes and failures. This is the show for the people who architect strong security systems.
Show more...
Technology
https://d3t3ozftmdmh3i.cloudfront.net/staging/podcast_uploaded_nologo/39868488/39868488-1701315850912-9973c0b414af1.jpg
Something in the Water | Ep. #5 | The Security Engineering Show
The Security Engineering Show
35 minutes 19 seconds
1 year ago
Something in the Water | Ep. #5 | The Security Engineering Show

A pentester navigated from basic internal network access to achieving full Domain Controller (DC) compromise and ultimately SCADA system control, revealing vulnerabilities that could have led to a hazardous chlorine release into a city's water supply. Episode 5 of The Security Engineering Show offers invaluable insights into modern offensive security and real-world breaches.


This is the show for security engineers, by security engineers.


Featuring

Noah Stanford: CEO at 0pass

Finn Foulds-Cook: Senior Penetration Tester at Volkis


00:00 - Intro

1:40 - The Engagement

4:45 - Windows Exploitation and Tooling

6:55 - ADCS, Coerced Auth, and Certs!

11:10 - Domain Controller Takeover

13:20 - Abusing DC Sync and EDR

15:55 - From DA to Azure

18:00 - Disabling your fancy EDR

19:30 - Escalating to Azure Global Admin

21:10 - Everything hacked, now what?

22:03 - Enumerating SCADA

24:31 - From SCADA to DEATH

27:44 - How do we fix all of this?

30:01 - Important security insights

31:47 - Message to Security / IT teams

33:36 - Outro

The Security Engineering Show
These are the stories of the security engineering projects that are worth telling. We skip past the broad strokes to the tactics, obstacles, and the untold stories behind the successes and failures. This is the show for the people who architect strong security systems.