
Payload Podcast 011 - Reunion
Source: YouTube · John Hammond · published Sep 19, 2026 · 50:57
This episode of the Payload podcast is a casual reunion where hosts John and Johnny catch up after a month-long break, covering Microsoft's new Windows Endpoint Security Platform (WESP) research, AI-assisted reverse engineering, Jev (a probabilistic AI model), and John's upcoming agentic Huntress CTF 0:52-1:31.
Key Takeaways:
• The hosts frame this as a "chill Friday hangout" episode—no guest, just banter—since both have been extremely busy with work, house buying, and content creation 1:31-2:00
• John is scrambling to build the Huntress Capture the Flag event for Cybersecurity Awareness Month, launching October 1st at ctf.huntress.com, with only ~13 days of prep left 3:06-3:29
• Johnny explains WESP: Microsoft's post-CrowdStrike-incident initiative to migrate EDR vendors out of the kernel into user mode, similar to Apple's Endpoint Security Framework, now available in public preview of the Windows Canary build 7:03-8:39
• Without an official SDK, John hooked Codex up to an IDA MCP server and successfully generated a working proof-of-concept client that registers consumers and receives process creation events—demonstrating how AI can substitute for missing developer documentation 11:47-14:09
• Both hosts argue it's time to stop adding "I used AI" disclaimers—AI is just a tool, and quality/reviewing responsibility lies with the researcher, not the model 20:19-22:46
• They discuss Jev, a new "stage zero" model that returns probabilistic/classification outputs (e.g., "93% malicious") instead of chat-style text, which they see as cheaper and better suited to threat hunting triage than agents like Claude or Sonnet 23:25-26:20
• John teases agentic CTF design ideas: since AI has "steamrolled" traditional jeopardy-style CTFs, he's exploring challenges that test participants' ability to build bots that solve tasks at machine speed, plus dynamic difficulty scaling 36:06-37:29
Overall, the episode blends personal updates with sharp technical discussion of where AI and Windows security research intersect, closing with a promise to return in two weeks and possibly a long-form evening "tinker and bro out" session with bourbon and Rocket League 50:20-50:49.
Sources:
- 0:52 Episode intro and framing as a casual catch-up
- 3:06 John's CTF preparation crunch at Huntress
- 7:03 Crash course on WESP and its post-CrowdStrike origins
- 11:47 AI-assisted reverse engineering producing a working WESP PoC without an SDK
- 20:19 Discussion on dropping AI disclaimers and researcher accountability
- 23:25 Jev explained: probabilistic stage-zero classification for security work
- 36:06 Agentic and dynamic CTF design ideas
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
I like that tune. >> You like that? We still got to come up with like a soo cop. A nice little What do you got there? >> Did I did this is just the energy drink of the day. So, you know, >> dude, I've been on the uh on the Have you tried a Bloom before? >> I don't think I have. No. What is a Bloom? >> I don't know. I was at the gas station the other day, the local 7-Eleven, and they had like uh I'm a sucker for anything like I think it was like a blue raspberry or something like that. >> Nice. >> Had like prebiotics in it. It was okay. Like it didn't hit like a like a ghost hits, but it it like a healthier natural more version, but that's not what I get energy drinks for. Well, hey, hello everybody. Welcome back. The old uh Payload podcast. Look, if you aren't too familiar, this is kind of…