Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Maril Vernon -- You Get What You Inspect, Not What You Expect

41 min29 augusti 2023

Om avsnittet

Maril Vernon is passionate about Purple teaming and joins Robert and Chris to discuss the intricacies of purple teaming in cybersecurity. She underscores the significance of fostering a collaborative environment between developers and the security team. Drawing from her experiences, Maril shares the challenge of development overlooking her remediation recommendations. She engaged directly with the developers, understanding their perspective and learning to frame her remediations in developer-centric language. This approach made her recommendations actionable and bridged the communication gap between the two teams. Meryl Vernon is a senior application security architect and Purple Team program manager. Meryl is also co-host and co-founder of the Cyber Queens podcast, an all-female-led podcast aimed at increasing female and LGBTQ diversity in cybersecurity.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Meryl Vernon is a senior application security architect and Purple Team program manager.
Learn more about Security Journey

Connect with Maril Vernon:
Purple Team Exercise Framework
Scythe

Mentioned in this episode:
Purple Team Exercise Framework
Scythe
MITRE ATT&CK Framework
AttackIQ
SafeBreach
PlexTrac
Atomic Red Team
mitre-attack/attack-navigator
9781260464009
The Pentester BluePrint: Starting A Career As An Ethical Hacker P 9781119684305
Watkins
The Pentester Blueprint: Starting a Career as an Ethical Hacker

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Maril Vernon: You Get What You Inspect, Not What You Expect
02:31 Yeah, I'm very, very glad to have you here. And as
04:08 Yeah, definitely. Congratulations. What sparked your interest and what led you
06:30 I think my understanding of purple teaming, I may not have
10:44 Writing your remediations in dev. I must understand... I know we're
13:13 You in the code as you're preparing your remediation
14:45 Yeah. Let's talk about collaborative methods of AppSec. So, that's sort
19:19 Can you take us through a story of purple teaming
23:36 Long is this process going
25:36 Continuing on about purple teaming, what are some— you talked a
27:30 From a vendor perspective, so you mentioned a couple of different
30:03 Do the tools, the purple team commercial tools, stack up against
31:32 Do you see purple teaming going in the future
34:32 All right. Well, Meryl, we really appreciate you joining us today
37:14 Excellent. And what's your top recommendation for those interested in security

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.