Ep. 146 - Demand Transparency with a blue shirt with Jason Frank

Published: May 17, 2021, 12:47 p.m.

b'

In this episode, Chris\\xa0Hadnagy\\xa0and Ryan MacDougall are joined by Jason Frank.\\xa0 Jason\\xa0has an extensive background in helping both government and Fortune 100 organizations, and has served a course instructor for the Black Hat security conference. Jason is now currently the COO at\\xa0SpecterOps, where he is accountable for execution of the company. He oversees the Adversary Simulation\\xa0and Detection\\xa0delivery capabilities, where he helps clients to understand, detect, and respond to adversaries. May 17, 2021

\\xa0

00:00 \\u2013 Intro\\xa0

CLUTCH\\xa0

03:05 \\u2013 Podcast Guest Jason Frank Intro\\xa0

\\xa003:22 \\u2013 Jason at\\xa0BlackHat\\xa0

03:30 -\\xa0SpecterOps\\xa0

04:34 \\u2013 How Jason got to where he is\\xa0

08:50 \\u2013\\xa0Curiousity\\xa0and motivation born\\xa0from failing at a CTF\\xa0

09:50 \\u2013 Adversary Simulation \\u2013 why is Jason using this phrase?\\xa0

12:32 \\u2013 Where are we in the current security culture?\\xa0

16:11 \\u2013 How to get attention of stakeholders, what concepts do you put in play?\\xa0

18:03 \\u2013 Reactive vs. Proactive\\xa0

21:56 \\u2013 How can corporations prepare for and mitigate attacks?\\xa0

23:39 \\u2013 What\\xa0are\\xa0the business repercussions of not letting machines talk to each other, and only the server?\\xa0

25:45\\xa0\\u2013 What are the more recent attacks you\\u2019ve seen coming up that people should be looking for?\\xa0

28:14\\xa0\\u2013 Knowledge bombs \\u2013 terminology that people can look up to recognize \\u201clow hanging fruit\\u201d they may be missing\\xa0\\u2013 Bloodhound\\xa0

30:00\\xa0\\u2013 Cycles where certain things can be exploited such as\\xa0ActiveDirectory\\xa0

30:50\\xa0\\u2013 What other things do companies need to be watching for\\xa0

32:14\\xa0\\xa0\\u2013 PowerShell\\xa0

33:44\\xa0\\u2013 What are some action steps that corporations should start taking right now?\\xa0

34:51\\xa0\\u2013 Colleagues Jason respects most in the industry\\xa0

  • Andrew Morris founder of\\xa0GreyNoise\\xa0
  • Dane Stuckey from Palantir\\xa0
  • Jason Hill from DHS CISA\\xa0
  • Bryan Beyer and Keith McCammon from Red Canary\\xa0

36:50\\xa0\\u2013 Jason\'s Book Recommendations\\xa0

38:31\\xa0\\u2013 Wrap-Up\\xa0

@joemontmania on Twitter\\xa0(Ryan MacDougall)\\xa0

@HumanHacker on Twitter\\xa0(Chris\\xa0Hadnagy)\\xa0

@InnocentOrg\\xa0on Twitter (Innocent Lives Foundation)\\xa0

'