
Hosted by SANS Institute
Wait Just an Infosec is a weekly hour-long cybersecurity-focused broadcast produced by SANS Institute, streamed live on LinkedIn and YouTube, Tuesdays at 10am ET and available to listen to in podcast format on Wednesdays.
25 episodes · publishes weekly · latest 2024-01-24 · ~41 min/episode
Rank
#902
Substance
73.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#902 of 6182
Substance
Top 15%
outscores 85% of the index
Wait Just an InfoSec ranks #902 on The B2B Podcast Index with a substance score of 73.0 out of 100, scored across 1 recent episode. It scores highest on specificity & evidence and guest caliber. The episode provides concrete price ranges for stealer logs, named malware families with behavioral distinctions, a specific attribution case (Lapsus$/Uber 2022 via Group-IB's zip-marker methodology), and a real VirusTotal detection-rate anecdote - all above average for the genre - though the Brian/Phil segment contributes almost no concrete evidence.
Averaged across 1 recently scored episode, with cited evidence.
The Ann segment delivers genuine technical value on stealer mechanics, the Google cookie-refresh API abuse, and the competitive stealer-developer ecosystem, but these insights are diluted by a rambling poll segment, conference plugs, generic closing advice, and a second segment (Brian/Phil) that offers little beyond long-standing network-segmentation platitudes. Net density is moderate at best.
“the stealers have the backdoor installed, so whenever uh, the buyer receives the locks, the steel developer would get the locks as well. Which means they might as well sell it to someone else”
“once you fetch the API to the Google server and they give you the fresh cookies for the machine... it gives you the fresh cookies so it never expires. Uh, it means that the attackers always have the access to the user's uh, Google accounts”
The AI-phishing angle is thoroughly recycled by 2024, and most predictions (SIM swapping, SEO poisoning, MDM gaps) are industry-standard. The genuinely fresh material - stealer developers forming revenue-sharing arrangements, the cookie-refresher becoming a competitive differentiator among stealer families - is interesting but buried and brief.
“Meta Steeler stole like not stole the code but copy pasted the code from redline... I'm pretty uh, sure that you know, Meta Stealer gives up like uh, um, some percentage of their profit to Redline developer for example because they're using their code”
“you can see how competitive the steel market is actually”
Ann (Russian Panda) is a genuine practitioner doing hands-on stealer reverse engineering at eSentire, lending real credibility; however the other contributors (Mary DeGrazia, Phil Hagan, Brian Ventura) are primarily SANS instructors speaking in educator mode rather than operators running security programs at scale, which caps the overall caliber.
“she is a threat researcher with Ecentire and I have been following her work for a number of years now. She does some amazing blog articles. She does a lot of documentation of her reverse engineering”
“I am a SANS instructor and the course author for our network forensic course, uh, forensics 572”
The episode provides concrete price ranges for stealer logs, named malware families with behavioral distinctions, a specific attribution case (Lapsus$/Uber 2022 via Group-IB's zip-marker methodology), and a real VirusTotal detection-rate anecdote - all above average for the genre - though the Brian/Phil segment contributes almost no concrete evidence.
“they usually pay like from $3 to 10 uh, dollars per lock for example for like the uh, fresh cookie that it's working for valid credentials”
“VPN logs for sale, RDP logs for sale. And they're usually ranging up from like from $3,000 up to like $10,000”
The host sets up questions competently and Mary lands one genuinely probing follow-up about log resale exclusivity that draws out useful information, but there is no meaningful pushback on any claim, several questions are essentially definitional softballs, and the Brian/Phil segment is barely a dialogue at all.
“does a threat actor only sell that, you know, those logs to one person?... Or you know, can they sell those logs like 2, 300, you know, 400 people and they're just being passed around everywhere”
“Ann, predictions in terms of uh, Steelers being used even more so and initial access brokers, uh, first and foremost, let's just get this out there. What is a stealer?”
First period on the Index - history builds from here.
1 scored on substance · 25 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/wait-just-an-infosec" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/wait-just-an-infosec/badge.svg" alt="Ranked #80 on The B2B Podcast Index" width="360" height="136" />
</a>Track Wait Just an InfoSec's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.