

Layer 8 Podcast
Layer 8 Conference
Welcome to the Layer 8 Podcast season 5! This season we’ll have conversations with social engineers and OSINT investigators who will tell their stories. We hope you enjoy them.
Episodes
Mentioned books

Feb 19, 2024 • 33min
Episode 99: Ritu Gill on OpSec, Sock Puppets and Lesser Known OSINT Sites
Ritu Gill is back! A return guest who first appeared on episode 20, Ritu (also known as OSINT Techniques) is back to talk about Operational Security, about how to create and curate sock puppets, how to keep the integrity of an investigation and to tell us about Forensic OSINT, a Chrome extension that can easily help with investigations!
This episode is brought to you by Compass Cyber Guard. To find out more about Cyber Guard's social engineering or pentesting services, contact info@layer8podcast.org

Feb 5, 2024 • 36min
Episode 98: Social Engineering My First Bank with Patrick Laverty
Our host, Patrick Laverty, has gotten to talk with experts in OSINT and social engineering and heard their stories. But Patrick has never told one of his own. That's what we get here as he explains how he got access to sensitive areas of a bank during a social engineering job.
This episode is brought to you by Compass Cyber Guard. To find out more about Cyber Guard's social engineering or pentesting services, contact info@layer8podcast.org

Sep 19, 2022 • 47min
Episode 97: Charles Shirer - BSDBandit Talks OSINT!
Charles Shirer, aka @BSDBandit is the part of the internet that exudes positivity and happiness. He frequently posts happy and affirming messages for people to enjoy. He's also a self-taught OSINT expert. In this episode, he'll explain how he learned OSINT, projects he took on and give suggestions and advice for others who might look to follow in his path.

Sep 12, 2022 • 38min
Episode 96: Dr. Abbie Maroño - The Science of Social Engineering
Dr. Abbie Maroño is the Director of Education at Social Engineer, LLC. She earned her PhD in Behaviour Analysis from Lancaster University in the UK. In this episode, we talk about human lie detection and that everything we learned on Lie to Me might be a lie! How can we discern good scientific information from bad, so we can learn the skills of social engineering and Dr. Maroño also talks about her own new podcast where she goes into the detail of the science and research behind many social engineering topics!

Sep 5, 2022 • 44min
Episode 95: Intel Inquirer - Using Dating Apps and Exercise Apps from an OSINT Perspective
Venessa Ninovic is @Intel_Inquirer on Twitter and frequently posts her findings and research at https://intel-inquirer.medium.com/ She has been on the OSINT Curious podcast and presented at the 2022 SANS OSINT Summit. In this episode, she tells us how much OSINT one can find just in dating apps. She explains how some military members failed so badly at OpSec that they were forced to delete their social media applications and she digs into the exercise app Strava. Strava can reveal quite a bit about the person exercising, even as much as where they live!

Aug 29, 2022 • 30min
Episode 94: Alan Neilan - The Phishing Kit Hunter
Alan Neilan is a security analyst who searches for phishing kits in his spare time, using x0rz's Phishing Catcher. Alan often tweets out his work at @aneilan and he also posts his findings under the title "Crap I Found on the Internet" on his blog at aneilan.github.io. In this episode, Alan talks about how he uses certificate transparency certstreams to feed the analysis tool and tells some of his experiences with reporting the kits he's found.

Aug 22, 2022 • 47min
Episode 93: The Gumshoo - Tales of a PI in OSINT
John TerBush, known as TheGumshoo on Twitter joins us to talk about his previous life as a private investigator and how he merged into the information security world. He, like so many others, was doing OSINT before we called it OSINT and he describes some of the locations and techniques. John is also a founding member of OSINT Curious and a course developer/instructor for the SANS SEC 487 and SEC 587 OSINT courses. He is also a threat researcher for Recorded Future. John has some great advice for getting started in the OSINT world and some fun stories of life on the job.

Aug 15, 2022 • 47min
Episode 92: Dalin McClellan - SE'd Into a Highly Secure Building...How?!?
On this episode, we speak with Dalin McClellan, a penetration tester and social engineer for NetSPI. The idea for this episode came from a blog post that Dalin wrote here: Not Your Average Bug Bounty: How an Email, a Shirt and a Sticker Compromised a High Security Datacenter. Dalin explains the preparation necessary for an on site physical penetration test when the location is highly secured with barbed wire fencing, human guards 24x7, retinal scanners and mantraps. Sometimes very simple solutions can be used to bypass highly technical controls. Just ask.

Aug 8, 2022 • 48min
Episode 91: Sylvain Hajri - What Can You Do With An Email Address?
Sylvain Hajri, aka Navlys_ on Twitter created Epieos.com a freemium site that lets you perform passive OSINT with just an email address. Sylvain wears an incredible number of hats as the creator of not just Epieos but also MyOSINTJob, OSINTFr, the SpyingChallenge and is also an organizer of LeHack in France and also the OSINTVillage.
In this episode, Sylvain has great advice on how to use passive OSINT, on how he created his company and whether people should focus on tools and learn python to get better at OSINT, plus even more!

Aug 1, 2022 • 31min
Episode 90: The Next Generation of Phishing Attack Vectors
When we think of phishing attacks, we immediately think of email. In this episode, Chris Cleveland, the Founder and CEO of Pixm Security walks us through a massive phishing attack that his company discovered. In this attack, millions of Facebook credentials were stolen using multiple layers of trusted environments. Have you ever gotten contacted by a friend in Facebook messenger with a link to check out a funny video? After this episode, you might be a little more careful with those.
If you want to read the blog post that we discuss: https://pixmsecurity.com/blog/blog/phishing-tactics-how-a-threat-actor-stole-1m-credentials-in-4-months/


