Operational security
42
MENTIONS
17
EPISODES
15
PODCASTS
Search complete. 42 mentions across 17 episodes found for "Operational security".
Sep 11, 2026
Course 42 - Mobile Malware Analysis Fundamentals | Episode 15: iOS and Android Case Studies and Reporting
S
14:08speaker_2HOST
Why are we intentionally limiting our tools?
S
14:11speaker_3HOST
Well, if you think about the operational security, the OPSEC of live investigation, uploading a fresh, potentially zero-day piece of malware to a public scanner is essentially kipping off the attacker.
S
14:24speaker_2HOST
You're basically giving the bad guy a heads up.
S
14:25speaker_3HOST
Exactly.
S
14:42speaker_3HOST
You essentially spook the suspect before you can even put a tail on them.
S
14:45speaker_2HOST
Okay, that makes sense.
S
14:46speaker_2HOST
The OPSEC risk is huge.
S
14:47speaker_3HOST
It is, but honestly, the data privacy risk is arguably worse, especially when dealing with a consumer device.
Hunting software supply chain malware
P
36:14Paul McCartyGUEST
But it's also the downfall.
P
36:16Paul McCartyGUEST
I am finding so many OPSEC mistakes.
P
36:19Paul McCartyGUEST
I'm finding, Oh, Oh my God.
P
36:22Paul McCartyGUEST
something that's becoming very, very common.
P
36:55Paul McCartyGUEST
And so they just feel, it's not like you and I, like if I were to write a malicious NPM package, put it out there, I'd be worried, right? I don't want to go to jail, right? I got a family.
P
37:05Paul McCartyGUEST
but they just don't think that way.
P
37:07Paul McCartyGUEST
And so what you and I see as an OPSEC mistake to them is just the path of least resistance, right? It's just was, yeah, it was just easier for me to use my own GitHub account.
P
37:16Paul McCartyGUEST
Didn't want to spin up another one.
Army Special Mission Unit Operator | Erick Miyares (throwback ep)
E
153:00Erick MiyaresGUEST
Because I took away their lives, unfortunately, because I, we, what we had to protect.
E
153:07Erick MiyaresGUEST
Organizations always have to protect OPSEC, just some basic OPSEC.
E
153:11Erick MiyaresGUEST
Every military position person has to do OPSEC.
E
153:14Erick MiyaresGUEST
The family is who takes the brunt- Right ... of the OPSEC because they don't understand it.
E
153:18Erick MiyaresGUEST
Right.
E
153:18Erick MiyaresGUEST
They don't do that freaking every yearly OPSEC class.
E
153:22Erick MiyaresGUEST
Their OPSEC class is you telling them not to put anything on social media, and they're like, "But why?" Right? So anyway.
E
153:28Erick MiyaresGUEST
Right.
Infratrust Pulse, AI's Role in Security - BTS #81
V
29:29Vlad BapkinHOST
Like they're ready to run this attack for like maybe months.
P
29:32Paul SidorianHOST
And they can do all that, but the attackers lately seem to lack OPSEC.
P
29:39Paul SidorianHOST
This is probably the third or fourth case I've seen recently of the way we discovered all this information about their toolkits is because they left their own C2 server hanging on the internet with open directory listing turned on.
P
29:53Paul SidorianHOST
I'm not even kidding.
P
29:55Paul SidorianHOST
The vector is exactly the same.
P
29:58Paul SidorianHOST
We've seen stuff land in our own honeypot and trace it back to a directory listing on a C2 server that has all their tradecraft, and it just keeps happening.
P
30:08Paul SidorianHOST
And the OPSEC is totally poor.
V
30:10Vlad BapkinHOST
Paul, I will stop you there a little bit.
THROWBACK THURSDAY: Defending Your Home! w/ Reality Check
M
37:13Michael KlineHOST
Let's see here.
M
37:14Michael KlineHOST
OPSEC.
M
37:17Michael KlineHOST
I've said this before, and you need to keep everything you have and say private.
M
37:22Michael KlineHOST
And this one is a real biggie.
M
37:23Michael KlineHOST
And if you need a refresher on this, I actually did two shows.
M
37:27Michael KlineHOST
I did a show on OPSEC and a show on COMSEC.
M
37:30Michael KlineHOST
And if you need a refresher on how to do good OPSEC, I suggest you go back and listen to those two shows.
M
37:35Michael KlineHOST
But the first rule of prep club is we don't talk about prep club.
Risky Business #851 -- Agents are just ones and zeros, and tigers are just atoms
P
3:54Patrick GrayHOST
But, uh, Grugq, you got any thoughts here? I mean, you know, you're the...
P
3:56Patrick GrayHOST
You're Mr. OPSEC, and I'm-
T
3:58The GrugqHOST
Yeah
P
3:58Patrick GrayHOST
... guessing you have some feelings on their OPSEC or, or lack thereof, right, in this, uh, instance.
T
4:04The GrugqHOST
So, like, to be fair, when you, when you read the story about it, you're getting the how I found them, not the how I failed 20,000 times before I found them.
T
4:14The GrugqHOST
However, that path is so embarrassingly bad.
T
5:21The GrugqHOST
This, uh, that was-
P
5:21Patrick GrayHOST
Yeah
S4E25 – AI agent accountability, learned helplessness, TeamPCP arrests, and Chinese router backdoors
J
45:58Jerry PerulloHOST
And a group, Flare did the write-up here, and it sounds like a lot of the work, and they're actually running a webinar on this right now, so I suspect there will be some great coverage that knocks on between the recording and when we go to press on this.
J
46:11Jerry PerulloHOST
But it sounds like someone really pulled the thread here and unmasked our identity through some OPSEC mistakes that, I mean, God, in the age of AI, you're going to just look the wrong way, and it's going to be OPSEC failure.
J
46:28Jerry PerulloHOST
but these guys like use the same passwords for some things you had like their real name in the wrong place next to an avatar or an alias and then that same alias used elsewhere where they thought they were anonymous and so on and end of the line is um a couple of either teenagers or shortly after teenagers um in australia were picked up and are now going through prosecution for this so Does this mean that everybody will be found given enough time and motivation? It seems like nobody was ever responsible for anything for about 20 years there.
J
47:03Jerry PerulloHOST
And is this just that they had the right victims and now they got the attention of the right investigators? Or do you think people are going to be
S
49:57Sounil YuHOST
Or baby Krebs was part of the tip-off, so to speak, that gave law enforcement what they really needed.
S
50:05Sounil YuHOST
Um, but anyway, there, there are a couple of things here that I think are notable.
S
50:08Sounil YuHOST
One is of course, you know, the OPSEC failures, people will learn from that.
S
50:12Sounil YuHOST
They'll get harder to, or people will continue to follow better OPSEC practices.
EP 90 * Eric Blehm * The Untold Story Behind Fearless, Adam Brown & SEAL Team Six | Targeted Podcast
E
12:17Eric BlehmGUEST
I have my diary.
E
12:19Eric BlehmGUEST
I'm not going to give you OPSEC.
E
12:21Eric BlehmGUEST
I'm not going to give you TTPs, nothing that could jeopardize national security and whatnot.
E
12:26Eric BlehmGUEST
But there's a story there, and I'd be happy to do it.
E
16:25Eric BlehmGUEST
I wanted to do right by the parents.
E
16:27Eric BlehmGUEST
I wanted to do and do right and be honest and because they want the truth.
E
16:32Eric BlehmGUEST
And at the same time, be careful of things like OPSEC.
E
16:36Eric BlehmGUEST
I'm not here to disclose anything or help the enemy in any way.
Bryan Seely, the Hacker Who Rerouted Secret Service Calls to Prove a Point
B
22:17Bryan SeelyGUEST
So it's it's OSINT.
B
22:19Bryan SeelyGUEST
It's OPSEC.
B
22:20Bryan SeelyGUEST
It's teaching your kids not to post.
B
22:22Bryan SeelyGUEST
OK, if you want to be an influencer, fine.
🔴 Aug 28's Top Cyber News NOW! - Ep 1205
G
42:47Gerald AugerHOST
Dude, listen, I didn't find TeamPCP, okay? So I'm not, I'm not simplifying or Um, what's the word? I'm not, um, I'm not devaluing the work that Flare threat intelligence researchers did, but when you see the breakdown of how they found this guy, all I can say is that this is a perfect, perfect example of two things.
G
43:16Gerald AugerHOST
One, why bad OpSec is going to result in you getting arrested if you commit crime.
G
43:22Gerald AugerHOST
And two, the internet never forgets, and you aren't going to remember all the things you did before you decided to become a criminal, which means, going back to step one, your OpSec is gonna get you busted.
G
43:37Gerald AugerHOST
Unbelievable how this dude gets, uh, basically uncovered.
G
43:43Gerald AugerHOST
Knucklehead.
7 more episodes mention Operational security.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.