This week, Adam and Andy talk about a Red Team/Pentesting tool called EvilGinx. They explain how this tool works and how cyber-criminals can use it to bypass MFA enabled accounts. Most importantly, they provide several ways to mitigate against this using enterprise driven phishing education campaigns, security awareness training, and device-based conditional access.


Youtube Video Link:

https://youtu.be/a2NLk0GnUJ8


Contact:

Website: http://bluesecuritypod.com

Twitter: https://twitter.com/bluesecuritypod

Instagram: https://www.instagram.com/bluesecuritypodcast/

Facebook: https://www.facebook.com/bluesecpod


Andy Jaw

Twitter: https://twitter.com/ajawzero

LinkedIn: https://www.linkedin.com/in/andyjaw/

Email: andy@bluesecuritypod.com


Adam Brewer

Twitter: https://twitter.com/ajbrewer

LinkedIn: https://www.linkedin.com/in/adamjbrewer/

Email: adam@bluesecuritypod.com


Send in a voice message: https://anchor.fm/blue-security-podcast/message