{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"7MS #731: CARTP \u2013 Cloud Red Team Tactics for Attacking and Defending Azure \u2013 THE FINAL CHAPTER!","description":"Hey friends! Fair warning: today\u2019s episode is a bit of an emotional rollercoaster \u2014 we\u2019ve got a big security win, some honest lab feedback, and a very personal share about my dad\u2019s funeral. Buckle up.  CARTP&amp;nbsp;certified, baby!&amp;nbsp;\u2014 I\u2019m officially a&amp;nbsp;Certified Azure Red Team Professional (CARTP), courtesy of the folks at&amp;nbsp;Altered Security. It\u2019s been a long time coming (I originally signed up for the live version and fell off after missing a couple Saturdays), but I came back for the self-paced 30-day version and finally finished the job. The lab experience \u2014 the good:&amp;nbsp;\u2014 ~25 objectives, a solid lab guide, and a really fun variety of attack paths. Highlights include stealing tokens, enumerating Azure tenants, attacking apps and VMs and key vaults, simulated phishing against real tenant email addresses, popping reverse shells, and some clever OneDrive-based follow-on attacks via session hijacking. There\u2019s even some web app pen testing (hello, server-side template injection!) sprinkled in. The lab experience \u2014 the not-so-good:&amp;nbsp;\u2014 The included videos are\u2026 not my favorite format. Think notepad-on-screen copy-paste tutorials with zero context. To fill in the gaps, I leaned heavily on Claude \u2014 pasting blobs of the lab guide and asking things like \u201cwhy did stealing this token give me X but not Y?\u201d \u2014 and it did a great job standing in where a live instructor would normally add color and context. Exam tips (spoiler-free, I promise):&amp;nbsp;\u2014 A few things that helped me:  I had Claude build me a CliffsNotes study guide from all our study-session chats \u2014 token context, command flags, the works. Before hitting start on the 24-hour clock, I fed Claude a list of all the tools I\u2019d been using in the lab and had it build a one-shot PowerShell script to pull them all down from GitHub onto a fresh Windows VM. If your exam lab environment fails to spin up (as mine did in the US region), just try a different region \u2014 UK worked great for me. Enumerate. Enumerate. Enumerate. Know your tools, know which ones cover which areas of an Azure tenancy, and know how to get more verbose\/tabular output when you need it. Take screenshots and notes as you go \u2014 the lab closes after 24 hours and you\u2019ve got 48 hours to submit your report, so if you forgot to grab a screenshot of a flag\u2026 you are SOL, my friend.   The exam itself:&amp;nbsp;\u2014 I started around 5:30 p.m., wrapped up around 11 p.m., and had the final flag captured, a full Word report drafted, and was in bed at a reasonable hour. Submitted the report the next morning after the gym and a mint hot cocoa, and had my pass confirmation back well within their 7-business-day window. Private pen test training is happening:&amp;nbsp;\u2014 I\u2019m currently running a private 3-day session of our Active Directory pen testing class (version 2.0 \u2014 it got a big facelift!). It\u2019s built on the&amp;nbsp;Game of Active Directory&amp;nbsp;platform and we fully pwn three separate domains over the course of three days. If you can send 3\u20137 people, reach out at&amp;nbsp;7MinSec.com\/training&amp;nbsp;to line up a private session. I\u2019m also building an interest list for a public version later this fall (reach out if interested)! Also: check out 7MinSec.club&amp;nbsp;\u2014 I dropped a little show-and-tell video over on&amp;nbsp;7MinSec.club&amp;nbsp;this week giving you a peek at what the training looks like in action. Dad\u2019s funeral:&amp;nbsp;\u2014 I shared some words at my dad\u2019s service this past Saturday and wanted to capture them here while they\u2019re fresh, since this podcast is basically my journal at this point. The service was perfect \u2014 very \u201chim.\u201d He\u2019d actually written funeral instructions (yes, they literally sat in a safety deposit box for years) specifying things like: max 10-minute message from the pastor, specific Bible verses, specific songs, and \u2014 my favorite \u2014 if the service runs over 45 minutes, someone needs to pull the fire alarm. He came up with that final instruction at his brother\u2019s funeral, which ran nearly two hours. He leaned over, squeezed my knee and said, \u201cIf my service goes over 45 minutes, pull the fire alarm.\u201d The song:&amp;nbsp;\u2014 I played and sang at the service. The song was \u201cJesus Savior Pilot Me\u201d \u2014 not a personal favorite of my dad\u2019s exactly, but he called it \u201cthe one about Jesus flying airplanes\u201d after seeing me perform it years ago at the Minnesota State Fair chapel. I practiced it in the car on the way to Caribou every morning until I could get through it without crying. My guitar teacher\u2019s advice: close your eyes, focus on your fingers, and pretend you\u2019re just playing a tune in a room. It worked. Mostly. Thank you: \u2014 Seriously, so many of you have sent kind messages and I just want you to know it means the world. He taught me a lot about being a good dad, a good husband, and how to live with passion, a good attitude about your work, and a heart for serving others.  ","author_name":"7 Minute Security","author_url":"https:\/\/7MinSec.com","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42123380\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42123380"}