Simply Defensive Podcast Por Simply Cyber Media Group arte de portada

Simply Defensive

Simply Defensive

De: Simply Cyber Media Group
Escúchala gratis

Join us for Simply Defensive, a podcast dedicated to exploring the world of defensive cybersecurity through the lens of real-world experts. In each episode, we'll interview leading professionals from the cybersecurity industry, delving into their experiences, challenges, and innovative solutions. Whether you're a seasoned cybersecurity veteran or just starting to learn about the field, Simply Defensive offers valuable insights and practical advice to help you stay ahead of the curve. Tune in as we discuss the latest threats, emerging technologies, and best practices for protecting your organization from cyberattacks. ========================= Connect with your hosts: Josh Mason: https://www.linkedin.com/in/joshuacmason Wade Wells: https://www.linkedin.com/in/wadingthrulogs ========================= Simply Cyber empowers people who want a rewarding cybersecurity career 💪 ========================= ========================= All the ways to connect with Simply Cyber https://SimplyCyber.io/Socials =========================2025 Simply Cyber Media Group Economía Exito Profesional
Episodios
  • S6E2: John Hammond on Security Research, Storytelling, Deception, and Getting Hired in Cybersecurity
    Mar 17 2026

    John Hammond on Security Research, Storytelling, and Deception for Defenders

    In this Simply Defensive episode, hosts Josh Mason and Wade Wells interview John Hammond, a Huntress security researcher, YouTuber, and educator, about his career path and defensive research. Hammond explains he has never worked as a penetration tester, SOC analyst, or detection engineer, instead “falling into” security research through hands-on Capture the Flag work and building cyber threat emulation course content, earning Offensive Security’s OSCE3 bundle recognition. He discusses why storytelling and communication are critical for translating attacker tradecraft into actionable defenses, emphasizing understanding the attack chain to identify places to break it. He recommends building a public portfolio of write-ups and notes, and says multiple creators covering the same topic can still provide value through different explanations. The conversation also highlights endpoint deception and honeypots, challenges of reversing compiled binaries versus script-based malware, and his advice to document thoroughly in shared organizational knowledge bases.

    00:00 S6E2: John Hammond on Security Research, Storytelling, Deception, and Getting Hired in Cybersecurity
    01:27 Meet John Hammond
    01:57 Security Researcher Life
    04:43 OffSec Certs Explained
    06:55 From CTF to Research
    08:47 Storytelling in Cyber
    12:10 Turning Attacks to Defense
    15:19 Getting Hired as Researcher
    16:48 Portfolio and Honeypots
    19:05 Make the Video Anyway
    21:40 Alternate Data Streams Nerdout
    23:36 CTFs Then and Now
    24:28 Life Shifts Priorities
    25:44 Beyond CTFs Next Trend
    26:52 Deception Meets Detection
    28:48 Honeypots and Program Maturity
    31:13 Malware Reversing Boss Fights
    35:09 Blue Team Advice Document Everything
    37:51 Where to Find John and Training
    38:49 Wrap Up and Farewell

    Más Menos
    39 m
  • From Blue Team Challenges to AI Innovations: A Conversation with Jason Haddix
    Feb 24 2026

    In this episode of Simply Defensive, Josh Mason and Wade Wells sit down with Jason Haddix — CISO veteran, AI security thought leader, and founder of Arcanum Information Security — for a wide-ranging conversation on where AI is actually headed in cybersecurity, and what blue teamers need to know right now.

    Jason shares what he's learned from running AI scaling assessments inside major enterprises, why most organizations are still in the early stages of AI adoption, and how the industry needs to stop thinking about AI security like traditional web app security. He breaks down the stages of AI adoption (from custom bots to agents), explains why input validation is a losing game for LLM security, and makes the case for classifiers, guardrails, and LLM-based routing as the real defense-in-depth play for AI systems.

    Wade and Jason also revisit the Red Blue Purple AI course, talk through how RAG and context engineering are transforming what's possible for blue teamers, and discuss why the credential leakage problem is still one of the biggest vectors defenders aren't taking seriously enough.

    Topics covered:

    • Why CTI struggles to prove value — and where it actually matters most
    • Stealer logs, credential leakage, and when rolling an account isn't enough
    • AI adoption stages: custom bots → RAG → agents
    • Why SOAR skepticism is a preview of AI hesitancy
    • Context engineering vs. prompt engineering
    • Defending AI systems: prompt-level protections, classifiers, guardrails, and LLM routing
    • When does a prompt become IP?
    • Jason's advice for blue teamers: embrace AI as a tool, find your annoying tasks, and start chipping away

    Connect with Jason Haddix:

    • Twitter/X: @jhaddix
    • Arcanum Information Security: arcanam-sec.com
    • GitHub (free tools & resources): ARCanum Information Security on GitHub
    • Newsletter: Executive Offense by Jay Haddix

    Resources mentioned:

    • Red Blue Purple AI Course (ARCanum)
    • Flare (threat intelligence / credential monitoring): flare.io
    • Detections.ai

    Connect with the Hosts:

    • Josh Mason: linkedin.com/in/joshuacmason
    • Wade Wells: linkedin.com/in/wadingthrulogs
    Más Menos
    32 m
  • From Pre-Law to FLARE: How Josh Stroschein Became Google's Malware Analyst
    Dec 1 2025

    In this episode of Simply Defensive, Josh Mason and Wade Wells sit down with Josh Stroschein — aka The Cyber Yeti — a former professor turned reverse engineer now working on one of the largest malware analysis teams in the world.


    Josh shares his unconventional path through .NET development, credit card processing security, and academia before landing at Google. He opens up about teaching reverse engineering while learning it himself, building educational CTFs, and the realities of making it as a full-time reverse engineer in an industry where those roles are rare.


    What you'll hear:

    🔹 From pre-law to pilot training to PhD in cybersecurity

    🔹 How teaching RE forced him to truly master it

    🔹 Life inside Google's FLARE team (via Chronicle → Mandiant)

    🔹 Flareon CTF — the RE challenge that's run for 12 years

    🔹 A wild Black Hat NOC story involving an infected Mac and Atomic Stealer

    🔹 Using AI to build malware samples for training labs

    🔹 Why going low-level is the best advice for blue teamers


    Chapters:

    00:00 Introduction and Welcome

    00:50 Josh's Connection to Dr. Gerald Auger

    02:00 The Non-Traditional Path: Pre-Law, Pilot Training & .NET Dev

    05:00 Getting Into Security at a Credit Card Processor

    07:00 Teaching Reverse Engineering at Dakota State

    10:00 Flareon CTF and Educational CTF Design

    14:00 Is Reverse Engineering Offensive or Defensive?

    17:00 How Rare Are Full-Time RE Roles?

    21:00 The Path to Google: Chronicle, Mandiant & FLARE

    25:00 Learning Through Teaching and YouTube Content

    28:00 Black Hat NOC Story: Catching Atomic Stealer Live

    33:00 Using AI to Create Malware Training Samples

    37:00 Building a Defang Tool (and .NET Nightmares)

    40:00 Advice for Blue Teamers: Go Low-Level


    🎧 Find Josh Stroschein:

    → Website: https://www.thecyberyeti.com

    → YouTube: The Cyber Yeti

    → Podcast: The Cyber Yeti Podcast


    👥 Connect with the Hosts:
    → Josh Mason: https://www.linkedin.com/in/joshuacmason/
    → Wade Wells: https://www.linkedin.com/in/wadingthrulogs/
    → Swimlane: https://www.linkedin.com/company/swimlane


    🎙️ Listen on Your Favorite Platform:
    → Spotify: https://open.spotify.com/show/72QTocT5FSTSPV7o1UcMS4
    → Apple Podcasts: https://podcasts.apple.com/us/podcast/simply-defensive/id1773806182
    → Full Playlist: https://youtube.com/playlist?list=PL4Q-ttyNIRAr6DVrsASx1-Fv-TsooJ3M4


    👍 If you enjoyed this episode, don't forget to like, subscribe, and share with your fellow defenders. Every week, Josh Mason and Wade Wells bring you practical, no-fluff conversations with cybersecurity professionals who are doing the work.


    =========================
    All the ways to connect with Simply Cyber
    https://SimplyCyber.io/Socials
    =========================
    This podcast is presented by Simply Cyber Media Group

    Más Menos
    40 m
Todavía no hay opiniones