BHIS Webcasts

Black Hills Information Security

Details

Podcast audio-only versions of weekly webcasts from Black Hills Information Security

Recent Episodes

JUL 10, 2026
Proxy Execution with Microsoft Edge WebView2 - Matthew Eidelberg
How do sideloading techniques work in today’s runtime environment? Join us for a free one-hour BHIS webcast with Matthew Eidelberg on proxy execution via Microsoft Edge WebView2. Matthew will break down techniques that blur the line between legitimate app behavior and malicious activity, showing how shared runtime components are changing execution and detection boundaries. You’ll learn how traditional sideloading concepts apply in modern environments, how WebView2 is increasingly embedded across the ecosystem, and how attackers can exploit it to bypass common detection methods. 🛝 Webcast Slides https://www.blackhillsinfosec.com/wp-content/uploads/2026/04/Proxy-Execution-with-Microsoft-Edge-Webview2.pdf Chapters (00:00) - Intro - Proxy Execution with Microsoft Edge WebView2 - Matthew Eidelberg (00:49) - Agenda (01:31) - DLL Hijacking (04:48) - DLL Proxy Attacks (06:05) - Execution Flow (07:17) - Windows Apps (12:05) - What is WebView2? (13:21) - Webview Security Issue (16:42) - Domain_action.dll (20:01) - Weaponizing the Flaw (22:38) - Tooling - FaceDancer (24:11) - FaceDancer - Usage (25:32) - FaceDancer - Examples (27:06) - FaceDancer - Common Questions (30:00) - FaceDancer - Caveats (30:44) - Microsoft's Response Timeline (34:04) - Microsoft's Disclosure Process (36:29) - Defensive View (38:37) - Wrap Up (39:49) - Q&A Creators & Guests Ryan Poirier - Producer Ashley Knowles - Guest Matthew Eidelberg - Guest Tom Smith - Guest Chat with your fellow attendees in the BHIS Discord server: https://discord.gg/bhis in the #🔴live-event-chat channel 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com Click here to watch a video of this episode. Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com Click here to view the episode transcript.
69 MIN
MAY 13, 2026
Intro to PAMSkeletonKey for Persistence w/ Ben Bowman
How does PAM abuse fit into a real‑world attack chain? 🛝 Webcast Slides https://www.blackhillsinfosec.com/wp-content/uploads/2026/04/PAM_Tool_Slide_Deck.pdf Join us for a free one‑hour BHIS webinar with Ben Bowman as he introduces PAMSkeletonKey, a tool designed for red teamers and CTF players to explore persistence, lateral movement, and privilege escalation on Linux systems. Ben will teach why the tool was created, how to use it safely in lab environments, and what this technique means for defenders working to detect or prevent authentication abuse. You'll learn a practical understanding of Linux PAM (Pluggable Authentication Modules) authentication and how it can be abused to create a skeleton‑key backdoor for persistence. Get started with PAMSkeletonKey: https://github.com/her3ticAVI/PAMSkeletonKey Chapters (00:00) - Intro – 2026-04-02 Intro to PAMSkeletonKey for Persistence - Ben Bowman (01:33) - What I Don't Know (02:14) - Remember Mimikatz? Me neither. (03:59) - What is PAM? (04:43) - PAM Architecture Deep Dive (06:54) - PAM Module Types (08:25) - How PAM Authentication Works (12:18) - What does this tell us? (13:44) - What Code Changes Do We Make? (17:28) - Pivoting & Attack Scenarios (18:57) - The Topic of Stolen Valor (21:14) - The Improvements (25:50) - Demo Time (41:57) - References (45:39) - Q&A (59:00) - Antisyphon Training's New LMS Walk Through Creators & Guests Ben Bowman - Guest Logan Bender - Guest Ryan Poirier - Producer Brett Jones - Guest John Strand - Host Chat with your fellow attendees in the BHIS Discord server: https://discord.gg/bhis in the #🔴live-chat channel 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com Click here to view the episode transcript.
67 MIN
APR 24, 2026
Learning to Trust AI Agents with Automation w/ Ethan and Derek
What if you could safely harness AI agents to automate real work, without spending a dime? Join us for a free one-hour BHIS webcast with Ethan Robish and Derek Banks to cut through the hype and learn what coding agents really are, why they’re not just for developers, and how to start for free. You’ll learn how tools like Opencode work, how to overcome security and trust barriers, and how to give agents the context, skills, and guardrails they need to safely plan, execute, and iterate. 🛝 Webcast Slides https://www.blackhillsinfosec.com/wp-content/uploads/2026/03/SLIDES_Mar-26-Learning-to-Trust-AI-Agents-with-Automation-w-Ethan-Robish.pdf Chapters (00:00) - Intro - Learning to Trust AI Agents with Automation Ethan and Derek (01:37) - Background (05:26) - What is a coding agent? (11:41) - Pick one and start learning (12:31) - The Cost of AI (15:26) - Opencode - Getting Started (19:26) - Free Models - Never truely free (22:21) - What can I do here? (24:40) - Running models locally (27:33) - Why would I need a coding agent? (28:00) - Code Agent Examples (35:48) - Openwork Demo (38:49) - Ask the agent to help you use it better (Help me help you) (41:07) - But AI always makes things up (43:44) - Prompting an LLM (46:37) - Concepts & Terminology (49:25) - Context usage (51:02) - Model Tokein Limits (55:14) - Guiding an Agent : Best Practices (57:18) - 80% planning 20% execution (58:05) - Guardrails for command execution (01:00:37) - Q&A Creators & Guests Jason Blanchard - Host Deb Wigley - Host Tom Smith - Guest Ethan Robish - Guest William Corbin - Guest Chat with your fellow attendees in the BHIS Discord server: https://discord.gg/bhis in the #🔴live-chat channel 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com Click here to watch a video of this episode. Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com Click here to view the episode transcript.
84 MIN
MAR 19, 2026
Do it, do it NOW! - A Pre-Incident Checklist w/ Patterson
Post-incident “lessons learned” are extremely valuable and very, very expensive! But you don’t have to wait until “right of boom” to make meaningful improvements to your cybersecurity resilience! Join us for a free one-hour webcast with Patterson Cake from Black Hills Information Security: Do it, do it NOW!! A Pre-Incident Checklist. You’ll learn the top 10 low-effort, high-impact lessons every business should review and fix before a cybersecurity incident. 🛝 Webcast Slides https://www.blackhillsinfosec.com/wp-content/uploads/2026/03/SLIDES_IR-Preparedness-Checklist-03032026.pdf Chapters (00:00) - Intro - Do it, do it NOW! - A Pre-Incident Checklist - Patterson (06:27) - Presuppositions (08:28) - In the event of an Emergency... (10:04) - YOUR INCIDENT RESPONSE PLAN IS USELESS (12:47) - YOUR CYBER INSURANCE PROVIDER SHOULD NOT BE YOUR ADVERSARY (15:44) - YOUR LOG DETAIL & RETENTION ARE INADEQUATE (18:51) - YOUR MOST IMPORTANT ASSET IS __________ (20:48) - IMPLEMENT OUT-OF-BAND COMMS BEFORE CRISIS & TEST REGULARLY (23:34) - YOUR STAFF ARE AWESOME BUT NOT SUPERHUMAN (25:45) - EFFECTIVE IR TAKES TRAINING & PRACTICE (28:04) - YOU MUST HAVE IMMUTABLE BACKUPS (31:45) - YOU HAVE 0 HOURS TO FIX INTERNET-FACING VULNERABILITIES (35:11) - THE TWO IR PLAYBOOKS YOU NEED MOST (43:48) - 10 Things (50:49) - Q&A (57:37) - The "Working with BHIS" part Creators & Guests Jason Blanchard - Host Deb Wigley - Host Ryan Poirier - Producer Bryan Strand - Guest Patterson Cake - Guest Chat with your fellow attendees in the BHIS Discord server: https://discord.gg/bhis in the #🔴live-chat channel 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com Click here to watch a video of this episode. Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com Click here to view the episode transcript.
84 MIN
MAR 12, 2026
Breach Assessment - The Curious Case of the Comburglar w/ Troy Wojewoda
What if an attacker lived inside your network for seven months and your tools never noticed? During a real breach assessment, Black Hills Information Security uncovered a stealthy intrusion using a COM-based persistence technique hidden in native Windows scheduled tasks. There were no obvious indicators of compromise. No suspicious process names. No malicious file hashes. Just a quiet foothold designed to stay invisible. 🛝 Webcast Slides https://www.blackhillsinfosec.com/wp-content/uploads/2026/03/SLIDES_CuriousCaseOfTheComburglar_BreachAssessment-2026-03-12.pdf Chapters (00:00) - Intro - Breach Assessment - The Curious Case of the Comburglar - Troy Wojewoda (02:15) - Agenda (03:02) - What Is a Breach Assessment? (10:50) - 5 Pillars of Data Telemetry (16:23) - The Hunt Begins (29:15) - Attack Chain (38:39) - Timeline & Scope (45:21) - Threat Hunting Playbook (51:29) - Key Takeaways (53:52) - Q&A Creators & Guests Troy Wojewoda - Guest Jason Blanchard - Host Deb Wigley - Host Logan Bender - Guest Keith Chew - Guest Chat with your fellow attendees in the BHIS Discord server: https://discord.gg/bhis in the #🔴live-chat channel 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com Click here to watch a video of this episode. Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com Click here to view the episode transcript.
79 MIN