---
title: "Live Q&A, Keynote Video: Basic Pen Testing Techniques [2019-03-19]"
description: Join Black Hills security analysts Beau Bullock and Brian Fehrman for a virtual keynote catered to higher-level IT and executives interested in learning pen testing techniques and hopefully will change their thinking on security to a more layered (“security in depth”) approach.
image: https://info.varonis.com/hubfs/Coffee-Series_Bullock-Fehrman-1.png
---

[![Varonis Logo](https://info.varonis.com/hubfs/2024%20Website%20Redesign/00_Logos/Varonis_Logo_Black.svg "Varonis Logo")](https://www.varonis.com?hsLang=en)

### Varonis Coffee Series

# **Post-Exploitation Basics with Black Hills**

**CPE Web Event** | On-Demand | Video Replay  
([View in your timezone](http://everytimezone.com))

**![Coffee-Series_Bullock-Fehrman](https://info.varonis.com/hs-fs/hubfs/Coffee-Series_Bullock-Fehrman.png?width=5001&name=Coffee-Series_Bullock-Fehrman.png)Keynote Video with Q&A**

Let's ride with Black Hills security analysts Beau Bullock, Brian Fehrman, and Derek Banks, and learn how to spot the tricks of lowdown data rustlers. This virtual keynote is perfect for city slickers --  higher-level IT executives -- interested in experiencing the pen tester way of life. Beau, Brian,and Derek will show how simple hacking techniques are still very effective, but can be defended against if you follow their advice.

If you'd like (ISC)² CPE credits for the virtual keynote, please submit your (ISC)² member number in the form and email [Frank Martinez](mailto:fmartinez@varonis.com?Subject=Virtual%20Keynote%20CPE%20Credit) after viewing.

##### Share

### Watch The Recording!

![black hills twitter](https://info.varonis.com/hs-fs/hubfs/black%20hills%20twitter.jpg?width=300&height=300&name=black%20hills%20twitter.jpg)

### Beau Bullock, Brian Fehrman, and Derek Banks

#### Security Analysts, Black Hills Information Security

**Beau Bullock** has held positions in the financial and health industries and has experience with all aspects of enterprise network security including penetration testing, vulnerability analysis, data loss prevention, wireless security, firewall management, and employee security training. Beau is a [Hack Naked TV host](http://www.blackhillsinfosec.com/?page_id=4621), and frequent speaker at industry events.

**Brian Fehrman** has been interested in security from the time his family obtained their first computer. He found a passion for programming by learning to code, from there he learned to apply this knowledge to interacting with the physical world through signal processing, robotics, computer vision, and artificial intelligence.

**Derek Banks** has almost 20 years of experience in the Information Technology industry as a systems administrator for multiple operating system platforms and monitoring and defending those systems from potential intruders. He has worked in the aerospace, defense, banking, manufacturing, and software development industries. Derek has experience with forensics, incident response, creating custom host and network based monitoring solutions as well as penetration testing, vulnerability analysis, and threat modeling.

In this virtual keynote, Beau, Brian, and Derek will explain and demonstrate a few key pen testing ideas and techniques: 

- Password spraying: going broad but not deep 
- Rounding up hashes with Inveigh: gather them, break the easy ones, and then escalate to higher-privileged accounts 
- Finding passwords in Active Directory fields 
- Unleashing Bloodhound to discover hidden security flaws in your AD environment 
- Tools and methods to stop common post-exploitation attacks 

Our Clients

![Varonis Customers](https://info.varonis.com/hs-fs/hubfs/Varonis%20Landing/logo-white-left.png?t=1498677966558&width=600&height=66&name=logo-white-left.png)

![Varonis Customers](https://info.varonis.com/hs-fs/hubfs/Varonis%20Landing/logo-white-right.png?t=1498677966558&width=600&height=35&name=logo-white-right.png)

> “Password spraying is used in 99% of my pen testing. It's really an awesome technique for not generating as many alerts because you're not going to lock out accounts. It's the opposite approach to brute-forcing, and hinges on just *one* employee using a weak password. And then I'm in.
> 
>  — Beau Bullock (@_dafthack) [January 23, 2019](https://twitter.com/_sigil/status/1088078490526728192?ref_src=twsrc%5Etfw)

© 2026 Varonis Systems, Inc