Payload Podcast 009 - Steven Flores

Payload Podcast 009 - Steven Flores

🎙 John Hammond 👥 2.2M 📅 July 16, 2026 ⏱ 61 min 👁 3K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

WMICOMpayloadEDRoffensive security

Summary

In this episode of the Payload Podcast, host John Hammond interviews Steven Flores, an offensive security engineer at SpecterOps. The conversation begins with a discussion of Windows Management Instrumentation (WMI) and its offensive uses, tracing back to Matt Graeber’s foundational DEF CON talk in 2015. Steven explains that WMI is a wrapper for various technologies like COM and DCOM, and highlights that while many focus on Win32_Process, there are numerous other attack surfaces. The discussion then shifts to modern payload development challenges, particularly evading EDRs. Steven emphasizes a data-driven approach, noting that different EDRs prioritize different behaviors; for example, Elastic detects unbacked memory execution well, while CrowdStrike is less concerned. He discusses the importance of tailoring payloads to specific EDRs and the increased difficulty of operations due to extensive monitoring and correlation. The conversation touches on the use of LLMs in EDRs and the need for careful planning in post-exploitation. Steven also shares insights into his team’s testing methodology and the value of open-source defensive tools like Elastic’s YARA rules. He mentions his upcoming DEF CON talk and demonstrates some of his research, focusing on lesser-known WMI use cases. The episode concludes with a discussion on the balance between offensive and defensive open-source contributions.

204 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners in offensive security, offering practical insights into WMI, EDR evasion, and payload development. Steven’s arguments are grounded in his extensive experience and are presented with nuance, acknowledging the complexity of modern EDRs. He advocates for a data-driven approach, which strengthens the credibility of his claims. The discussion is well-structured, moving from foundational concepts to advanced techniques, and provides actionable knowledge.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; while the content is expert-driven, it is largely anecdotal and lacks formal citations. The quality of sources is limited to the speakers’ expertise and references to public work like Matt Graeber’s talk and Elastic’s open-source rules. The title accurately reflects the content, and the episode maintains focus on the advertised topic. No comments were provided for analysis.

146 words

Title / Content Match

The title accurately reflects the content: a podcast episode with Steven Flores discussing offensive security topics.

Quality & Reliability

8/10

The discussion features a recognized offensive security expert with deep practical experience. Claims are grounded in professional practice, but some statements are anecdotal and not backed by formal citations. The podcast format allows for informal opinions, but the technical depth and expertise lend credibility.

Key Moments

Cited Sources

  • Just Hacking Training — Training platform mentioned in the description.
  • CodeCrafters — Resource for learning to code, mentioned in the description.
  • CyberDefenders — Blue team training and SOC analyst certifications, mentioned in the description.
  • InfoSec Map — Cybersecurity events map, mentioned in the description.
  • OpenVPN — VPN hosting service, mentioned in the description.
  • Newsletter — John Hammond's newsletter, mentioned in the description.

Concurring Sources

Contribution & Novelties

The episode provides unique insights into the practical aspects of offensive security, particularly around WMI and EDR evasion, from a seasoned expert. It highlights the importance of data-driven testing and tailoring payloads to specific EDRs, which is not commonly discussed in public forums. The discussion on the balance between offensive and defensive open-source contributions offers a fresh perspective.

Pour aller plus loin :

96 words

Radar Profile

The radar profile shows high scores in technical depth and information quality, reflecting the expert-level content. The moderate score in information quantity suggests the episode is focused rather than broad, and the high reliability score indicates the credibility of the speaker. Overall, the profile is well-balanced for a specialized technical podcast.

Reliability 8/10