Skip to main content
Operational security

Operational security

Search complete. 42 mentions across 17 episodes found for "Operational security".

Sep 11, 2026

speaker_2HOST
14:08
Why are we intentionally limiting our tools?
speaker_3HOST
14:11
Well, if you think about the operational security, the OPSEC of live investigation, uploading a fresh, potentially zero-day piece of malware to a public scanner is essentially kipping off the attacker.
speaker_2HOST
14:24
You're basically giving the bad guy a heads up.
speaker_3HOST
14:25
Exactly.
speaker_3HOST
14:42
You essentially spook the suspect before you can even put a tail on them.
speaker_2HOST
14:45
Okay, that makes sense.
speaker_2HOST
14:46
The OPSEC risk is huge.
speaker_3HOST
14:47
It is, but honestly, the data privacy risk is arguably worse, especially when dealing with a consumer device.
Paul McCartyGUEST
36:14
But it's also the downfall.
Paul McCartyGUEST
36:16
I am finding so many OPSEC mistakes.
Paul McCartyGUEST
36:19
I'm finding, Oh, Oh my God.
Paul McCartyGUEST
36:22
something that's becoming very, very common.
Paul McCartyGUEST
36:55
And so they just feel, it's not like you and I, like if I were to write a malicious NPM package, put it out there, I'd be worried, right? I don't want to go to jail, right? I got a family.
Paul McCartyGUEST
37:05
but they just don't think that way.
Paul McCartyGUEST
37:07
And so what you and I see as an OPSEC mistake to them is just the path of least resistance, right? It's just was, yeah, it was just easier for me to use my own GitHub account.
Paul McCartyGUEST
37:16
Didn't want to spin up another one.
Erick MiyaresGUEST
153:00
Because I took away their lives, unfortunately, because I, we, what we had to protect.
Erick MiyaresGUEST
153:07
Organizations always have to protect OPSEC, just some basic OPSEC.
Erick MiyaresGUEST
153:11
Every military position person has to do OPSEC.
Erick MiyaresGUEST
153:14
The family is who takes the brunt- Right ... of the OPSEC because they don't understand it.
Erick MiyaresGUEST
153:18
Right.
Erick MiyaresGUEST
153:18
They don't do that freaking every yearly OPSEC class.
Erick MiyaresGUEST
153:22
Their OPSEC class is you telling them not to put anything on social media, and they're like, "But why?" Right? So anyway.
Erick MiyaresGUEST
153:28
Right.
Vlad BapkinHOST
29:29
Like they're ready to run this attack for like maybe months.
Paul SidorianHOST
29:32
And they can do all that, but the attackers lately seem to lack OPSEC.
Paul SidorianHOST
29:39
This is probably the third or fourth case I've seen recently of the way we discovered all this information about their toolkits is because they left their own C2 server hanging on the internet with open directory listing turned on.
Paul SidorianHOST
29:53
I'm not even kidding.
Paul SidorianHOST
29:55
The vector is exactly the same.
Paul SidorianHOST
29:58
We've seen stuff land in our own honeypot and trace it back to a directory listing on a C2 server that has all their tradecraft, and it just keeps happening.
Paul SidorianHOST
30:08
And the OPSEC is totally poor.
Vlad BapkinHOST
30:10
Paul, I will stop you there a little bit.
Michael KlineHOST
37:13
Let's see here.
Michael KlineHOST
37:14
OPSEC.
Michael KlineHOST
37:17
I've said this before, and you need to keep everything you have and say private.
Michael KlineHOST
37:22
And this one is a real biggie.
Michael KlineHOST
37:23
And if you need a refresher on this, I actually did two shows.
Michael KlineHOST
37:27
I did a show on OPSEC and a show on COMSEC.
Michael KlineHOST
37:30
And if you need a refresher on how to do good OPSEC, I suggest you go back and listen to those two shows.
Michael KlineHOST
37:35
But the first rule of prep club is we don't talk about prep club.
Patrick GrayHOST
3:54
But, uh, Grugq, you got any thoughts here? I mean, you know, you're the...
Patrick GrayHOST
3:56
You're Mr. OPSEC, and I'm-
The GrugqHOST
3:58
Yeah
Patrick GrayHOST
3:58
... guessing you have some feelings on their OPSEC or, or lack thereof, right, in this, uh, instance.
The GrugqHOST
4:04
So, like, to be fair, when you, when you read the story about it, you're getting the how I found them, not the how I failed 20,000 times before I found them.
The GrugqHOST
4:14
However, that path is so embarrassingly bad.
The GrugqHOST
5:21
This, uh, that was-
Patrick GrayHOST
5:21
Yeah
Jerry PerulloHOST
45:58
And a group, Flare did the write-up here, and it sounds like a lot of the work, and they're actually running a webinar on this right now, so I suspect there will be some great coverage that knocks on between the recording and when we go to press on this.
Jerry PerulloHOST
46:11
But it sounds like someone really pulled the thread here and unmasked our identity through some OPSEC mistakes that, I mean, God, in the age of AI, you're going to just look the wrong way, and it's going to be OPSEC failure.
Jerry PerulloHOST
46:28
but these guys like use the same passwords for some things you had like their real name in the wrong place next to an avatar or an alias and then that same alias used elsewhere where they thought they were anonymous and so on and end of the line is um a couple of either teenagers or shortly after teenagers um in australia were picked up and are now going through prosecution for this so Does this mean that everybody will be found given enough time and motivation? It seems like nobody was ever responsible for anything for about 20 years there.
Jerry PerulloHOST
47:03
And is this just that they had the right victims and now they got the attention of the right investigators? Or do you think people are going to be
Sounil YuHOST
49:57
Or baby Krebs was part of the tip-off, so to speak, that gave law enforcement what they really needed.
Sounil YuHOST
50:05
Um, but anyway, there, there are a couple of things here that I think are notable.
Sounil YuHOST
50:08
One is of course, you know, the OPSEC failures, people will learn from that.
Sounil YuHOST
50:12
They'll get harder to, or people will continue to follow better OPSEC practices.
Eric BlehmGUEST
12:17
I have my diary.
Eric BlehmGUEST
12:19
I'm not going to give you OPSEC.
Eric BlehmGUEST
12:21
I'm not going to give you TTPs, nothing that could jeopardize national security and whatnot.
Eric BlehmGUEST
12:26
But there's a story there, and I'd be happy to do it.
Eric BlehmGUEST
16:25
I wanted to do right by the parents.
Eric BlehmGUEST
16:27
I wanted to do and do right and be honest and because they want the truth.
Eric BlehmGUEST
16:32
And at the same time, be careful of things like OPSEC.
Eric BlehmGUEST
16:36
I'm not here to disclose anything or help the enemy in any way.
Bryan SeelyGUEST
22:17
So it's it's OSINT.
Bryan SeelyGUEST
22:19
It's OPSEC.
Bryan SeelyGUEST
22:20
It's teaching your kids not to post.
Bryan SeelyGUEST
22:22
OK, if you want to be an influencer, fine.
Gerald AugerHOST
42:47
Dude, listen, I didn't find TeamPCP, okay? So I'm not, I'm not simplifying or Um, what's the word? I'm not, um, I'm not devaluing the work that Flare threat intelligence researchers did, but when you see the breakdown of how they found this guy, all I can say is that this is a perfect, perfect example of two things.
Gerald AugerHOST
43:16
One, why bad OpSec is going to result in you getting arrested if you commit crime.
Gerald AugerHOST
43:22
And two, the internet never forgets, and you aren't going to remember all the things you did before you decided to become a criminal, which means, going back to step one, your OpSec is gonna get you busted.
Gerald AugerHOST
43:37
Unbelievable how this dude gets, uh, basically uncovered.
Gerald AugerHOST
43:43
Knucklehead.

7 more episodes mention Operational security.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.