SecTools Podcast Series

Follow SecTools Podcast Series
Share on
Copy link to clipboard

SecTools Podcast is a series of audio podcast featuring free or opensource tool authors from Information Security industry, sharing their interesting experience on developing and maintaining amazing tools for the security community. Hosted by Sanoop Thomas (s4n7h0) https://infoseccampus.com https://twitter.com/InfoSecCampus

InfoSec Campus


    • Feb 20, 2025 LATEST EPISODE
    • infrequent NEW EPISODES
    • 33m AVG DURATION
    • 56 EPISODES


    Search for episodes from SecTools Podcast Series with a specific topic:

    Latest episodes from SecTools Podcast Series

    SecTools Podcast E56 with Donato Capitella

    Play Episode Listen Later Feb 20, 2025 38:08


    Donato is a Software Engineer and Principal Security Consultant at WithSecure, with over 12 years of experience in offensive security, security assurance, and software engineering. His background spans a wide range of cybersecurity areas, which gives him a practical and well-rounded perspective when working on securing LLM applications. Donato has conducted extensive research on generative AI security, covering topics such as multi-chain prompt injection, securing ReAct agents, and testing LLM guardrails. He shares his work through a technical YouTube channel (https://www.youtube.com/@donatocapitella) and publishes research articles on the WithSecure Labs blog (https://consulting.withsecure.com/articles/generative-ai-security-findings-from-our-research/).For more SecTools podcast episodes, visit https://infoseccampus.com

    ai react software engineers llm donato principal security consultant
    SecTools Podcast E55 with Andre Tenreiro

    Play Episode Listen Later Sep 15, 2024 24:19


    Andre Tenreiro is a security professional with over a decade of leadership in various sectors, including IT infrastructure, cybersecurity, cloud computing, and IP networks. He has a passion for developing an open-source security tool aimed at identifying phishing domains. In 2020, Andre Tenreiro started the development of an excellent Open Source Intelligence (OSINT) security tool called, openSquat; a "domain squatting and phishing watchdog". It is a tool and service for detecting domain look-alikes by searching for newly registered domains that might be impersonating legitimate domains and brands. Our goal is to help protect organizations and individuals from phishing attacks, brand abuse, and other threats associated with domain squatting. He has also spoken international conferences and engage with media outlets across Asia, Europe, the United States, and Africa.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E54 with Ezz Tahoun

    Play Episode Listen Later Jul 15, 2024 43:15


    Ezz Tahoun, a distinguished cyber-security data scientist, who won AI & innovation awards at Yale, Princeton and Northwestern. He also got innovation awards from Canada's Communications Security Establishment, Microsoft US, Trustwave US, PIA US, NATO, and more. He ran data science innovation programs and projects for OrangeCyber Defense, Forescout Technologies, Royal bank of Canada, Governments, and Huawei Technologies US. He has published 20 papers, countless articles and 15 open source projects in the domain. When he was 19 years old he started his CS PhD in one of the top 5 labs in the world for cyber & AI, in the prestigious University of Waterloo, where he published numerous papers and became a reviewer for top conferences. His designations include: SANS/GIAC-Advisory-Board, aCCISO, CISM, CRISC, GCIH, GFACT, GSEC, CEH, GCP-Professional-Cloud-Architect, PMP, BENG and MMATH. He was an adjunct professor of cyber defense and warfare at Toronto's school of management. Ezz has cofounded Cypienta, an on-prem rule-less event correlation & contextualization solution that plugs into SIEMs, XDRs, and SOARs, to help SOCs find relevant alerts, logs, and events to any investigation in real-time. Cypienta is backed by Techstars, ORNL, TVA, Univ of Tennessee Sys, and supported by 35Mules-Next Era, BAE Systems, and others. Ezz authored MITRE Attack Flow DetectorFor more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E53 with Praveen Kanniah

    Play Episode Listen Later May 29, 2024 29:43


    Praveen is a security enthusiast with 14+ years of experience in application security who loves to break complexity bias. His works include developing frameworks and tools for Container Security, automated Penetration Testing, SAAS Security, Automated Secure Code Analysis, Asset Discovery and Recon and also have worked on Security against Analytics Mitigated threats against Analytics through extensive Research and solution suggestions on browser security and rate limiting.Praveen and his team at PhonePe developed Mantis, an open-source security framework to automate the workflow of asset discovery, reconnaissance, and scanning using a combination of open-source and custom tools.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E52 with Duncan Ogilvie

    Play Episode Listen Later Mar 19, 2024 27:51


    Duncan Ogilvie has started reverse engineering somewhere around 2009. He is the creator of x64dbg, an open-source x64/x32 debugger for windows, and 100+ other projects. Duncan loves to do binary analysis and Windows internals. In this episode, he shares the interesting journey with developing and maintaining x64dbg project. For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E51 with Dimitrios Valsamaras

    Play Episode Listen Later Feb 19, 2024 30:52


    A cybersecurity professional with expertise in mobile, web, and network penetration testing. Dimitrios holds a degree in Computer Science, majoring in Cryptography and Security, and has worked with top companies like Microsoft and Google. He is frequent speaker at prominent security conferences such as BlackHat, Nullcon, Insomni'hack, and Troopers. He is passionate about reverse engineering and was a member of one of Greece's first reverse engineering research groups.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E50 with Angelina Tsuboi

    Play Episode Listen Later Jan 14, 2024 31:05


    Angelina Tsuboi is an aerospace cybersecurity instructor focusing on satellite systems. With over a decade of programming and development experience in addition to being a scientific researcher for NASA, she has been involved in various CubeSat initiatives where she participated in tasks related to command and data handling subsystems and firmware development for the Onboard Computer.Driven by her passion for teaching, Angelina finds joy in simplifying complex subjects such as aerospace, cybersecurity, and programming to empower her students, Angelina focuses on ensuring that her students can readily apply the acquired skills to their professional and personal endeavors.She recently founded Stellaryx Labs, a startup that provides high quality training, consulting, education, and development services at the nexus of software, security, and aerospace.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E49 with Gelei Deng

    Play Episode Listen Later May 31, 2023 34:45


    Gelei is a cybersecurity researcher with wide interests in system security and penetration testing. He is currently pursuing a Ph.D. in computer science from Nanyang Technological University, Singapore, where he explores security challenges in complex human-interactive systems. Gelei is also a blockchain auditor at Quantstamp, Inc., where he contributes to the audits of web3 projects and security protocols. His research interests encompass security testing, software analysis, and large language models. Gelei likes to apply software engineering techniques to solve real-world challenges in security domains. He is now focusing on LLM security and its security-related applications.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E48 with Abhisek Datta

    Play Episode Listen Later Apr 23, 2023 34:19


    Abhisek Datta is an accomplished security professional with over a decade of experience in information security solution engineering, services, vulnerability research, reverse engineering and security tools development.He is an active participant of NULL Security Community, India's largest open security community as a core team member responsible for techndnology development. He is an open source enthusiast and He authored swachalit, the automation Platform that hosts null.co.in and also contributed to several opensource projects. As a security researcher, he is credited with multiple vulnerability discovery across enterprise products with CVEs to his name such as CVE- 2015-0085, CVE-2015-1650, CVE-2015-1682, CVE-2015-2376, CVE-2015-2555, CVE-2014-4117, CVE- 2014-6113.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E47 with Tim Misiak

    Play Episode Listen Later Feb 20, 2023 41:22


    Tim Misiak has been working on debuggers and diagnostics for most of my professional career as a software engineer. For more than a decade, Tim has been working on the Microsoft Debugger Platform team, working on tools such as WinDbg and KD. He started the WinDbgNext project in 2016 that modernized WinDbg UI. Tim also wrote a chunk of the X86/X64 emulator used by Time Travel Debugging. Currently, Tim founded his start up augmend.ioFor more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E46 with Thomas Roccia

    Play Episode Listen Later Jan 31, 2023 28:28


    Thomas Roccia is the Sr. Security Researcher at Microsoft, working on threat intelligence, malware analysis, incident response, and more. He also has the interest in many other topics including mentoring and teaching, open-source, hacking, 3D printing and even blockchain ecosystem.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E45 with Erlend Oftedal

    Play Episode Listen Later Dec 8, 2022 30:26


    Erlend has worked as a developer and security consultant for over 14 years, trying to build and break many different types of systems. He spends some of his free time on security research and open source tools, and is the main author behind retire.js - a free and open source scanner for JavaScript. He is also the chapter leader of the Norwegian OWASP chapter.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E44 With Jeff Foley

    Play Episode Listen Later Nov 21, 2022 43:26


    Jeff Foley has over 20 years of industry experience focused on applied research & development and assessment of security in critical information technology and infrastructure. He is the Project Leader for Amass, an OWASP (Open Web Application Security Project) Foundation flagship project that performs in-depth attack surface mapping and asset discovery. Jeff is also an Adjunct Lecturer teaching Penetration Testing at the SUNY (State University of New York) Polytechnic Institute. Previously, he was the US Manager for Penetration Testing & Red Teaming at National Grid, a multinational electricity and gas utility company. Prior to this, Jeff served as the Director of Penetration Testing & Security Assessment at Northrop Grumman Corporation, an American global aerospace and defense technology company. Jeff is currently working as the Vice President of Attack Surface Protection at ZeroFox. In his spare time, Jeff enjoys experimenting with new blends of coffee and giving back to the information security community.In this episode, Jeff explained his journey of developing and maintaining Amass project - an open-source tool for In-depth DNS enumeration, attack surface mapping and external asset discovery.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E43 With Anand Tiwari

    Play Episode Listen Later Oct 10, 2022 33:19


    Anand Tiwari is an information security professional with a strong technical background working as a Technical Product Manager (PM), focusing on the more technical aspects of a cloud security product. He tries to fill it in by doing in-depth technical research and competitive analysis, given business issues, strategy, and a deep understanding of what the product should do and how the products actually work.He has authored ArcherySec—an open source-tool and has presented at BlackHat, DEF CON USA, and HITB conferences. He has successfully given workshops at many conferences such as DevOpsDays Istanbul, Boston.In this episode, Anand explained his journey of developing and maintaining ArcherySec - an open-source tool for application security orchestration and correlation.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E42 With Nicolas Surribas

    Play Episode Listen Later Sep 11, 2022 22:54


    Nicolas is a French security researcher, a proud dad of two children. He started Wapiti in 2006 when he was learning Python programming language. Nicolas is currently working in the infosec field as a programmer at CybelAngel (since 2015).Wapiti is a web-application vulnerability scanner that allows you to audit the security of your websites or web applications. It performs "black-box" scans (it does not study the source code) of the web application by crawling the webpages of the deployed webapp, looking for scripts and forms where it can inject data. Once it gets the list of URLs, forms and their inputs, Wapiti acts like a fuzzer, injecting payloads to see if a script is vulnerable. In this episode, Nicolas explained his journey of developing and maintaining Wapiti project for over a decade. For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E41 With ONEKEY Team (Marton Illes, Quentin Kaiser, László Vaskó and Florian Lukavsky)

    Play Episode Listen Later Aug 29, 2022 29:43


    unblob is an accurate, fast, and easy-to-use extraction suite. It parses unknown binary blobs for more than 30 different archive, compression, and file-system formats, extracts their content recursively, and carves out unknown chunks that have not been accounted for.unblob is free to use, licensed under MIT license, it has a command line interface and can be used as a Python library. This turns unblob into the perfect companion for extracting, analyzing, and reverse engineering firmware images.unblob was originally developed and currently maintained by ONEKEY and it is used in production in ONEKEY analysis platform.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E40 With Christian Folini

    Play Episode Listen Later Jul 15, 2022 31:23


    Christian Folini is a Swiss security engineer and web application firewall expert working at netnea.com. Christian studied History and Computer Science and graduated with a PhD in Medieval History. He is the author of the ModSecurity Handbook (2ed), He also co-lead the OWASP ModSecurity Core Rule Set (CRS) project that runs on millions of servers globally. Furthermore he serves as the program chair of the Swiss Cyber Storm conference.Christian also teaches ModSecurity and Core Rule Set courses and consult companies who want to integrate ModSecurity and the Core Rule Set into their services or products, also in high security setups. For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E39 With Philippe Humeau

    Play Episode Listen Later Jun 10, 2022 27:48


    Graduated in 1999 from Epita (France) as IT security engineer, Philippe endorsed many roles before creating its latest company CrowdSec. From Pentester to community builder (Magento) or even eCommerce expert (author of 4 books), or CTO, he is tech curious and loves to dive into new trends like IoT, crypto currencies or AI. But whatever the context is, his crush is and will forever be IT security, SecOps and entrepreneurship. LP or investor in several different companies, CrowdSec is not its full time obsession.CrowdSec is an open-source and participative IPS able to analyze visitor behavior & provide an adapted response to all kinds of attacks. It also leverages the crowd power to generate a global CTI database to protect the user network.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E38 With Alexandre Dulaunoy and Raphaël Vinot

    Play Episode Listen Later Mar 21, 2022 28:33


    Alexandre Dulaunoy: Alexandre Dulaunoy leads the Luxembourgian Computer Security Incident Response Team (CSIRT) CIRCL in the research and operational fields. He enjoys working on projects that blend “free information,” innovation, and direct social improvement. When not gardening binary streams, he likes facing the reality of ecosystems while gardening plants or doing photography. He enjoys it when humans use machines in unexpected ways. He also a core contributor to many open source projects such as MISP, ail-framework, cve-search and many others.Raphaël Vinot is a security researcher at the Computer Incident Response Center Luxembourg (CIRCL) since 2012. Raphaël wants to increase the IT consciousness of the human beings populating the internet in order to make it safer for everyone. His day job is a mixture of forensic and malware analysis with a lot of Python on top of it to glue all the pieces together. He loves sharing and thinks everyone should contribute to open source projects.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E37 With Ai Ho (j3ssie)

    Play Episode Listen Later Jan 17, 2022 22:34


    Ai Ho (mostly known as j3ssie) is a self-taught security engineer with a computer science background who loves automation. He got Interested in responsible disclosure/bug bounty nearly three years ago and have been building some of my own tools to do it. He wrote Osmedeus, Jaeles and Metabigor to help his bug bounty efforts and made these projects open source for the community.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E36 With Ruslan Habalov

    Play Episode Listen Later Dec 21, 2021 25:08


    Ruslan Habalov has a computer science background with a focus on code analysis and is interested in scalable solutions to challenging security problems. His security research covered an exploitable remote code execution bug in PHP used against a popular platform in a bug-bounty context as well as side-channel attacks against browsers. As a machine learning enthusiast he's looking for options to unite the best of both worlds.He is currently working as a Senior Security Engineer at Google.Ruslan started the Vulncode-DB project which is a crowd-sourced platform providing vulnerable code for corresponding real world vulnerabilities.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E35 With Jack Baker

    Play Episode Listen Later Nov 19, 2021 30:07


    Jack Baker is a professional security researcher and amateur video game hacker. Jack has spoken at a handful of conferences including DEF CON on subjects relating to reverse engineering and vulnerability research. Jack started his infosec career as a software developer in the fintech space before realizing that breaking things is less stressful than defending them. Since then, Jack has had the opportunity to hack banks, airplanes, and spacecrafts.Jack is the author of Cetus and WAIL, a set of tools used to hack modern web browser games.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E34 With Lukas Rist

    Play Episode Listen Later Oct 14, 2021 38:27


    Lukas Rist authored several open source honeypot projects. After spending a couple of years studying mathmatics and physics, Lukas ventured out to work with Bing and Microsoft Research on making the web a safer place, got payed by DARPA to hunt hackers and taught students in Taiwan open source security.His passion for security and open source got nurtured by The Honeynet Project which lead to a five year stint with Norman Shark, Blue Coat, and Symantec, working on large scale malware analysis and behavioral detection systems.Looking for more purpose, he worked as Senior Software Engineer at Corti, doing real time emergency call classification, striving to build a great engineering team and making sure those tensors keep flowing in order to classify life threatening situations.Currently Lukas is working as Lead Software Engineer with the world largest online wine retail platform Vivino. His team build personalization, recommendation, and prediction systems. In his free time he is working on various open source projects.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E33 With Joxean Koret

    Play Episode Listen Later Aug 17, 2021 30:40


    Joxean Koret has been working for the past 15 years in many different computing areas. He started as a database software developer and DBA for a number of different RDBMS. Eventually he turned towards reverse engineering and applied this DB insights to discover dozens of vulnerabilities in major database products, especially Oracle. He also worked in areas like malware analysis, anti-malware software development and developing IDA Pro at Hex-Rays. He is currently a senior security engineer. Joxean is the author and maintainer for Diaphora and Pigaios projects focused on diffing techniques. For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E32 With Chris Em (a.k.a Cookie Engineer)

    Play Episode Listen Later Jul 28, 2021 28:39


    Chris Em (also known as Cookie Engineer) has almost 2 decades of experience in IT and security industry. He specializes in multiple domains including web intelligence, network security and forensics. During spare time, Chris is working on the Web of Knowledge with his project called the [Tholian Network](https://tholian.network), which aims to automate the Semantic Web whilst using a unique distributed peer-to-peer Network Architecture combined with (co-)evolutionary adaptive AI methodologies and compositional game theory ideas to learn and adapt from user interactions with the Web.Chris has contributed to various open source projects including steganography, network security, drones, adblock proxy and other automation works as well. https://cookie.engineer/#/open-source For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E31 With Marc Ochsenmeier

    Play Episode Listen Later Jun 30, 2021 36:20


    Marc Ochsenmeier is the author of Pestudio on winitor.com. Pestudio is a unique tool that allows you to perform an initial assessment of a malware without even infecting a lab system or studying its code. Marc has initially worked as software developer with a focus on Windows hardening security. He also has a vast expertise in penetration testing and forensics area.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E30 With NJ Ouchn

    Play Episode Listen Later Apr 6, 2021 40:16


    In 2001, NJ founded the Infosec community tools portal ToolsWatch.org. And since 2011, he is co-managing & helping to improve the Black Hat Arsenal the World's largest security event dedicated to open source tools demonstrations. NJ is also the founder of vFeed, Inc a niche startup that provides top-notch correlated vulnerability & threat intelligence feed to 100+ Worldwide customers.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E29 With Martin Donath

    Play Episode Listen Later Mar 28, 2021 37:34


    Martin Donath is the creator of Material for MkDocs, a static site from a set of Markdown files to host the documentation.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E28 With Charlie Belmer

    Play Episode Listen Later Feb 15, 2021 27:50


    Charlie Belmer is a security and privacy engineer at DuckDuckGo. He authored NoSQLi, an open source NoSql Injection CLI tool, for finding vulnerable websites using MongoDB. He writes about security and privacy research on his personal blog nullsweep.comFor more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E27 With Guillaume Valadon

    Play Episode Listen Later Jan 24, 2021 25:00


    Guillaume Valadon is the Security Agent Team Lead at Datadog, and holds a PhD in IPv6 networking. He likes looking at data and crafting packets. In his spare time, he co-maintains Scapy and learns reversing embedded devices. Also, he still remembers what AT+MS=V34 means! Guillaume regularly gives technical presentations, classes and live demonstrations, and writes research papers for conferences and magazines.For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E26 With Vipin Pavithran

    Play Episode Listen Later Dec 22, 2020 29:22


    Vipin Pavithran is a cyber-security professor at Amrita Center for Cybersecurity Systems and Networks, Amrita Vishwa Vidyapeetham. He is the founder and chief mentor of internationally recognized student clubs - amFOSS, Team bi0s, and Team Shakti . He is also known for organizing the premiere InCTF and InCTF Junior - cyber-security contests, which were first of its kind in India when they were introduced. For more SecTools podcast episodes, visit https://infoseccampus.com

    SecTools Podcast E25 With Paulino Calderon

    Play Episode Listen Later Dec 10, 2020 27:56


    Paulino Calderon (@calderpwn) is a published author and international speaker with over 12 years of experience in network and application security. When he isn't traveling to security conferences or consulting for Fortune 500 companies with Websec, a company he co-founded in 2011, he spends peaceful days enjoying the beach in Cozumel, Mexico. He loves open-source software and has contributed to many projects, including Nmap, Metasploit, OWASP Mobile Security Testing Guide (MSTG), OWASP Juice Shop, and OWASP IoT Goat. More SecTools podcast episode here https://infoseccampus.com/

    SecTools Podcast E24 With Anastasios Stasinopoulos

    Play Episode Listen Later Nov 20, 2020 23:56


    Anastasios Stasinopoulos is a Senior Penetration Tester at Obrela Labs - Obrela Security Industries and has a professional experience over 6 years in the field of Information Security working exclusively as a Penetration Tester. Anastasios earned the Bachelor of Science (B.Sc.) degree in "Surveying & Geoinformatics Engineering" from Technological Institution of Athens, the Master of Science (M.Sc.) degree in "Security of Digital Systems" from the Department of Digital Systems of University of Piraeus and also served as Ph.D. candidate at the same department.Anastasios is the author of Commix Project, an automated tool that can be used from web developers, penetration testers or even security researchers in order to test web-based applications with the view to find bugs, errors or vulnerabilities related to command injection attacks.

    SecTools Podcast E23 With Steve Springett

    Play Episode Listen Later Oct 18, 2020 24:31


    Steve Springett is the Senior Security Architect at ServiceNow, Chicago. Steve educates teams on the strategy and specifics of developing secure software. He practices security at every stage of the development lifecycle by leading sessions on threat modeling, secure architecture and design, static/dynamic/component analysis, offensive research, and defensive programming techniques.Steve's passionate about helping organizations identify and reduce risk from the use of third-party and open source components. He is an open source advocate and leads the OWASP Dependency-Track project, OWASP Software Component Verification Standard (SCVS) project, CycloneDX software bill-of-material specification, and participates in several related projects and working groups.- https://dependencytrack.org/- https://cyclonedx.org/- https://owasp.org/scvs

    chicago cybersecurity open source servicenow infosec owasp appsec senior security architect cyclonedx securitytools
    SecTools Podcast E22 With Nishant Sharma

    Play Episode Listen Later Sep 7, 2020 29:35


    Nishant Sharma leads R&D at Pentester Academy and Attack Defense. He has 8+ years of experience in the information security field including 6+ years in WiFi security research and development. He has conducted classroom trainings in Blackhat USA, HITB Amsterdam/Singapore, RootCon, OWASP NZ Day. He has presented research and conducted workshops at Blackhat USA/Asia, DEF CON China, HITB, RootCon, Packet Hacking Village, Wireless Village, IoT village, and Demo labs (DEFCON USA). Prior to joining Pentester Academy, he worked as a firmware developer at Mojo Networks where he contributed in developing new features for the enterprise-grade WiFi APs and maintaining the state of art WiFi Intrusion Prevention System (WIPS). He has a Master's degree in Information Security from IIIT Delhi. He has also published peer-reviewed academic research on HMAC security. His areas of interest include WiFi and IoT security, Linux security. PA Toolkit: https://github.com/pentesteracademy/patoolkit VoIPShark: https://github.com/pentesteracademy/voipshark BLE Mystique: https://github.com/pentesteracademy/blemystique

    SecTools Podcast E21 With Emily Wenger

    Play Episode Listen Later Aug 11, 2020 27:24


    Emily Wenger is a PhD student at the University of Chicago studying machine learning security and privacy. She's particularly interested in understanding and preventing the unintended uses/abuses of facial recognition technology. Emily and team has built Fawkes, a system that helps individuals inoculate their images against unauthorized facial recognition models. Fawkes achieves this by helping users add imperceptible pixel-level changes (we call them "cloaks") to their own photos before releasing them. When used to train facial recognition models, these "cloaked" images produce functional models that consistently cause normal images of the user to be misidentified. * More about Fawkes http://sandlab.cs.uchicago.edu/fawkes/ * Full Research Paper - http://people.cs.uchicago.edu/~ravenben/publications/pdf/fawkes-usenix20.pdf* Fawkes - http://sandlab.cs.uchicago.edu/fawkes/ * Source Code - https://github.com/Shawn-Shan/fawkes

    SecTools Podcast E20 With Isaac Evans

    Play Episode Listen Later Jul 5, 2020 32:50


    Isaac Evans is the leader of r2c (https://r2c.dev/), a small startup working on giving security tools directly to developers. Previously, he conducted research into binary exploitation bypasses for techniques like control-flow integrity and novel hardware defenses on new architectures like RISC-V as a researcher at the US Defense Department under a SFS program and at MIT Lincoln Laboratory. Isaac received his BS/MS degrees in EECS from MIT. Other interests include next-generation programming languages, secure-by-design frameworks, software-defined radio, and the intersection of cryptography and public policy.Isaac spoke about semgrem and its capabilities in this episode. - Source code: https://github.com/returntocorp/semgrep- Test in your browser: https://semgrep.live/

    SecTools Podcast E19 With Kai Jern Lau

    Play Episode Listen Later Apr 21, 2020 27:39


    Kai Jern (xwings), is Lab Director of The ShepherdLab, of JD Security. His research topic mainly on embedded device, hardware security, blockchain security, reverse engineering and various security topics. He presented his findings in different international security conferences like Defcon, HITB, Codegate, QCon, KCon, Brucon, H2HC and etc. He conducted hardware Hacking course in various places around the globe. He is also the owner of hackersbadge.com, actively involved in Unicorn (https://unicorn-engine.org) development and founder of Qiling Framework (https://qiling.io)

    SecTools Podcast E18 With H.D Moore

    Play Episode Listen Later Apr 10, 2020 22:32


    H.D Moore founded the Metasploit Project in early 2003 and later the project was aquired by Rapid7. He spent the last 20 years conducting security assessments, building security products, and pushing the status quo through research, with leadership roles at Digital Defense, BreakingPoint Systems, Rapid7, and Atredis Partners. HD founded Critical Research to address a long-standing need for better network discovery tools. Currently, his research is focused on asset discovery.Metasploit Project - https://www.metasploit.com/

    SecTools Podcast E16 With Brian Carrier

    Play Episode Listen Later Mar 14, 2020 27:12


    Brian leads the digital forensics team at Basis Technology, which builds software for incident response, digital forensics, and custom mission needs. He is the author of the book File System Forensic Analysis and developer of several open source digital forensics analysis tools, including The Sleuth Kit and Autopsy. Brian has a Ph.D. in computer science from Purdue University and worked previously for @stake as a research scientist and the technical lead for their digital forensics lab and incident response team. Brian is the chair person for the Open Source Digital Forensics Conference (OSDFCon) and has been on the committees of many conferences, workshops and technical working groups. Autopsy - https://www.autopsy.com/ The Sleuth Kit - http://sleuthkit.org/ Open Source Digital Forensics Conference https://www.osdfcon.org/

    SecTools Podcast E16 With Miroslav Stampar

    Play Episode Listen Later Jan 19, 2020 34:53


    Miroslav Stampar is an IT Security Advisor - Expert at Croatian Government's CERT, part of the Information Systems Security Bureau (ZSIS). Born in 1982., writing and breaking computer code for as long as I can remember. A PhD candidate with Master's Degree in Computer Science at Faculty of Electrical Engineering and Computing (FER), University of Zagreb, Croatia.Hacker, challenge solver, occasional CTF-er and an author of sqlmap, open source project for automated detection and exploitation of SQL injection vulnerabilities, along with numerous other offensive and defensive information security tools (e.g. Maltrail, DSSS, DSXS, DSVW, tsusen, etc.). Also, Croatian Chapter Lead for The Honeynet Project.SQLmap was initially by Daniele Bellucci in 2006, the project was soon taken over by Bernardo Damele who developed and promoted it. Later in 2009, Miroslav Stampar answered a call for developers and joined the project.

    SecTools Podcast E15 With Joakim Kennedy

    Play Episode Listen Later Oct 28, 2019 43:28


    Joakim Kennedy is a Threat Intelligence Manager for Anomali. His job involves analyzing malware, tracking threat actors and numerous other responsibilities around threat intelligence. He often leads efforts around the Anomali Threat Research Team's reports and blogs. His tool the “Go Reverse Engineering Toolkit” (https://go-re.tk/) was presented at Black Hat Arsenal 2019 and he has been a featured speaker at multiple BSides and other industry events.

    SecTools Podcast E14 With Giovanni Rattaro

    Play Episode Listen Later Oct 27, 2019 41:34


    Giovanni is a senior cyber security expert and manager based in Paris, old Italian Backtrack Linux ambassador/staff and ex DEFT Linux developer, now is the Tsurugi Linux core developer. DFIR instructor in his free time, he has spoken in several security conferences and he is passionate of many other topics like cyber-threat intelligence investigations, OSINT and interpersonal communication.

    SecTools Podcast E13 with Ajin Abraham

    Play Episode Listen Later Jun 16, 2019 49:45


    SecTools Podcast Series Episode 13 with Ajin AbrahamAjin Abraham is a Security Engineer with 8+ years of experience in Application Security including 4 years of Security Research. He is passionate on developing new and unique security tools. Some of his contributions to Hacker's arsenal include OWASP Xenotix XSS Exploit Framework, Mobile Security Framework (MobSF), Xenotix xBOT, NodeJsScan etc to name a few. He has been invited to speak at multiple security conferences including ClubHack, Nullcon, OWASP AppSec Eu, OWASP AppSec AsiaPac, BlackHat Europe, Hackmiami, Confidence, BlackHat US, BlackHat Asia, ToorCon, Ground Zero Summit, Hack In Paris, Hack In the Box, c0c0n and PHDays.

    SecTools Podcast E12 with Mohammed A. Imran

    Play Episode Listen Later Dec 22, 2018 44:40


    Mohammed A. “secfigo” Imran is the Founder and CTO of Eracorp Technologies/Practical DevSecOps and a seasoned security professional with 8 years of experience in helping organisations with their Information Security Programs. He has a diverse background in R&D, consulting and product-based industries with a passion to solve complex security programs. Imran is the founder of Null Singapore, the largest information security community in Singapore where he has organised more than 60 events & workshops to spread security awareness.He was also nominated as a community star for being the go-to person in the community whose contribution and knowledge sharing has helped many professionals in the security industry. He is usually seen speaking and giving trainings in conferences like Blackhat, DevSecCon, AppSec, All Day DevOps, Nullcon and many other international conferences.

    SecTools Podcast E11 with Aseem Jakhar

    Play Episode Listen Later Dec 22, 2018 33:43


    Aseem Jakhar is the Director, research at Payatu Software Labs payatu.com a boutique security testing company. He is a renowned security researcher with extensive experience in system programming, security research and consulting. He is well known in the hacking and security community as the founder of null - The open security community, registered not-for-profit organization http://null.co.in and also the founder of nullcon security conference nullcon.net and hardwear.io security conference http://hardwear.io He currently spends his time researching on IoT security and hacking things. He is an active speaker and trainer at security conferences like AusCERT, Black Hat, Brucon, Defcon, Hack.lu, Hack in Paris, PHDays and many more. He has authored various open source projects including Linux thread injection kit – Jugaad and Indroid which demonstrate a stealthy in-memory malware infection technique, DIVA (Damn Insecure and Vulnerable App) for Android which gamifies Android App vulnerabilities and Expliot - Internet of Things Exploitation framework.

    SecTools Podcast E10 with Yiannis Ioannides

    Play Episode Listen Later Nov 24, 2018 35:41


    Yiannis is a Director at one of the big 4 consulting firm with over 10 years of technical experience providing physical security assessments, penetration tests and red team operations. Yiannis is the developer of the WarBerryPi which has been presented at Blackhat USA 2016, Blackhat Europe 2016 and Blackhat USA 2018 among other conferences. Yiannis lives in Cyprus with his wife and daughter. Music: Royalty Free Music from HookSounds (hooksounds.com)

    SecTools Podcast E09 with Tanya Janca

    Play Episode Listen Later Oct 31, 2018 64:13


    Tanya Janca is a senior cloud security advocate for Microsoft, specializing in application and cloud security; evangelizing software security and advocating for developers and operations folks alike through public speaking, her open source project OWASP DevSlop, and various forms of teaching via workshops, blogs and community events. As an ethical hacker, OWASP Project and Chapter Leader, Cyber Ladies Ottawa founder and leader, software developer and professional computer geek of 20+ years, she is a person who is truly fascinated by the ‘science' of computer science.

    SecTools Podcast E08 with Mike Hodges

    Play Episode Listen Later Oct 11, 2018 16:04


    Mike Hodges is a Senior Security Engineer at Red Ventures leading Red Team Operations and Incident Response. He comes from a background of application development and penetration testing consulting. Currently, his focus is on developing evasive offensive capabilities and fighting off the ever-present imposter syndrome brought on by working in InfoSec.

    SecTools Podcast E07 with Anant Shrivastava

    Play Episode Listen Later Oct 9, 2018 39:20


    Anant Shrivastava has worked on computer and open source software since 2000. He grouped Linux user groups in Bhopal and was also active in other major Linux user groups across India. Anant now working as Regional Director Asia Pacific for NotSoSecure Global Service. He has been Speaker/Trainer at various conferences including BlackHat, RuxCon, Nullcon, C0c0n, Rootconf, Clubhack, G0s, etc. He is active in information security community null and is teaching not only local but also offensive Web test framework (OWTF). In addition, he is a skilled person who actively participates in the Open Web Application Security Project (OWASP) and has contributed to reviewing and documenting various technical documents such as Mobile Security Testing Guide, Mobile ASVS, Web Testing Guide. Since 2011 Anant actively manages the open source project AndroidTamer. Anant leads both Android Tamer and CodeVigilant projects.

    SecTools Podcast E06 with Fotis Chantzis

    Play Episode Listen Later Jul 19, 2018 52:55


    Fotis Chantzis has been a member of the main Nmap development team since 2009, when he wrote Ncrack under the mentorship of Fyodor, the original author of Nmap, during Google Summer of Code 2009 and 2010. He also represented Nmap at the Google Mentor Summit in October 2016. His work includes exploiting the TCP Persist Timer to magnify the effect of a classic network attack (paper published on Phrack #66), the development of Ncrack, a high-speed network authentication tool with a dynamic and optimized timing engine under the Nmap toolset and inventing a new stealthy port scanning attack by abusing the popular XMPP.

    Claim SecTools Podcast Series

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel