Security Weekly Podcast Network (Audio) The smell of victory, Bongo Fury, Sysmon, Looker, Openclaw, Kimwolf, Josh Marpet - SWN #553
Feb 6, 2026
Josh Marpet, cybersecurity practitioner and commentator, weighs in on AI agent risks and enterprise defenses. Conversation covers built-in Sysmon in Windows, Looker vulnerabilities and unknown inventory dangers, and malicious OpenClaw skills in AI agents. They also debate convenience versus security and the need for default-deny controls.
AI Snips
Chapters
Books
Transcript
Episode notes
Enable Sysmon Enterprise-Wide
- Install and enable Sysmon to monitor process and file activity across endpoints.
- Use centralized policies (e.g., Group Policy) to deploy and enable it enterprise-wide for consistent logging.
Act On End-Of-Support Edge Devices
- Identify and decommission edge devices that are end-of-support to reduce exploitation risk.
- Implement continuous discovery and inventory processes to track EOS devices within 24 months.
Analytics Platforms Are High-Value Targets
- Vulnerabilities in analytics platforms expose internal databases and can enable RCE even when developer permissions are required.
- Hidden or forgotten deployments (old servers, closets) increase real-world risk beyond headline services.



