Skip to content

Pro Wrestling to Pen Testing

A guest who once wrestled a 750-pound bear joins us to talk about something even harder to pin down: trust. Phillip Wiley walks us through how he moved from system administration into application security and then full-time penetration testing, and why that “boring IT background” ends up being a serious edge when you’re trying to break things responsibly. We get practical about what actually helped him get hired, including self-driven learning, building real projects, and using OSCP-style training to close the gap between theory and hands-on hacking.

Then we go straight into social engineering and phishing. Phillip shares how believable pretexts work best when they sound like normal corporate life, why you should only impersonate roles you truly understand, and how nerves and ethics show up during real engagements. We also talk about the uncomfortable side of the job: even when a test is authorized, some people still struggle with the feeling of deceiving another human being.

Finally, we tackle deepfakes and voice cloning. We discuss why being on podcasts or speaking publicly can increase your risk, attempt a quick live deepfake experiment, and break down the small visual tells that gave it away. From there, we zoom out to AI in penetration testing, what automation can scale today, where human testers still matter most, and why mentoring is the best way to strengthen the next generation and your own legacy. If this conversation helps, subscribe, share it with a friend in security, and leave a review with the biggest risk you think most teams still ignore.

 

 

Full Transcript

Aaron Pritz:
Thanks for tuning in to Simplifying Cyber. I’m Aaron Pritz.

Bronwen Hudson:
And I’m Bronwen Hudson, guest hosting today.

Aaron:
Cody Rivers is off on a secret mission or assignment today, so Bronwen, thanks for filling in. And speaking of filling in, we have Phil Wylie today. I wasn’t even planning that bad dad joke, but we’ll get it out of the way at the top of the episode.

Phil, thanks for joining the show. Tell us a little about yourself and your background. The fun fact that immediately jumps out is that you’ve wrestled a 750-pound bear, so we have to get to that at some point.

Phillip Wylie:
First, thanks for inviting me to be on the show. Also, you improved what I think about you right away because you started with a dad joke. I’m a big fan. My poor wife has to suffer through them all the time.

I’m Phillip Wylie. I’ve been on the offensive-security side since 2012, which is the area I became most passionate about. I’ve been in cybersecurity for more than 20 years, and before that I spent six years as a system administrator.

One big tip for people who want to get into cybersecurity: there are many IT roles that are helpful once you move into security. Starting in system administration or other IT functions can be incredibly valuable. My sysadmin career has helped me in pen testing more than almost anything else I’ve done.

Aaron:
What got you into pen testing? Was it accidental, intentional, or a job change?

Phillip:
It was somewhat of a job change, but it was also something I wanted to do. In 2005, the company I worked for hired a new CISO with a more modern view of how security organizations should operate.

Before that, we were all doing similar work: firewall administration, intrusion detection, vulnerability scanning, and risk assessments. The new CISO began creating distinct cybersecurity functions, and I was assigned to the AppSec team.

That was one of the most pivotal experiences in my security career. I managed third-party pen tests, used DAST tools and web application vulnerability scanners, and became really interested in the work. I learned that penetration testing was an actual career path—something I hadn’t realized before.

When I was laid off in 2012, I applied for a role in Verizon’s cybersecurity consulting division and got hired. That’s where I started in pen testing, and it’s an area I’ve been passionate about ever since.

Aaron:
What did your training look like? You’ve authored a book to help others get into pen testing, but tell us about your own learning path and what you now do to help others transition into the field.

Phillip:
Before I applied for the Verizon role, I took the Foundstone Ultimate Hacking course. Foundstone was a major boutique pen-testing firm that was later acquired by McAfee. They offered training and developed hacking and pen-testing tools that were widely used in the late 1990s and early 2000s.

I also took the Certified Ethical Hacker course. But I got the job largely because the hiring manager saw I did a lot of self-study and self-learning. I taught myself web design, ran a side business, and hosted client websites on a server at home. He saw that I liked to build things and learn.

I later took the OSCP course to learn the hands-on hacking side. I understood the idea of pen testing, but I didn’t yet have those offensive skills. OSCP helped prepare me for that work.

Aaron:
Self-learning and hosting your own environments seem like valuable skills for a pen tester. You’re always pivoting and standing up infrastructure as you work toward the next step in an engagement.

Phillip:
Absolutely. It also helps to understand how technology works. As a system administrator at a mortgage company, I managed IIS web servers. At home, I hosted sites with Apache because it was free and I was using open-source tools.

That helped me learn the directory structure of Apache web servers, how the technology was set up, and how it worked. To be a good pen tester, you need to understand how the technology works and how to defend it before you can break into it. That experience gave me a strong foundation; I just had to learn the hacking piece.

From Powerlifting to Wrestling Bears

Aaron:
Let’s take a step back. Bronwen did some great OSINT before the call, and we learned that you have a background in construction, powerlifting, professional wrestling, and wrestling a bear. How did those experiences influence the way you approach offensive security?

Bronwen:
Especially the bear. We definitely need to double-click on that one.

Phillip:
After graduating high school, I had no idea what I wanted to do for a living. I hadn’t taken school very seriously, and my grades and college entrance exams weren’t strong enough to enroll right away. The university told me I could get letters of recommendation from my teachers and come back, but I didn’t know what I wanted to study or whether college was even the right direction for me.

I had started powerlifting in 1980, and in my senior year of high school, 1984, I competed in my first powerlifting competition. My friends told me, “You’re a big guy—you should be a pro wrestler.” I thought it sounded cool, so I went to wrestling school and did that for a couple of years.

When you start in professional wrestling, you lose a lot. You have to pay your dues. I was getting close to being sent to Kansas City, where there was a circuit that could help people get more experience before coming back to be a more credible wrestler.

Back then, the people who lost regularly were called jobbers. You made the good guys or the stars look good before the main event.

If I could do it over, I would have worked more on public speaking. It would have helped with the on-mic side of wrestling. I probably would have taken acting courses, too.

Aaron:
You’re telling us wrestling isn’t real?

Phillip:
It isn’t 100% scripted. You generally know how the match will end, but wrestlers travel so much that there often isn’t time to rehearse every move. They might tell you a few moves or how they want to finish the match, but you learn to go with the flow.

There are signals. Someone might squeeze your wrist twice to signal that you should reverse a move. Sometimes, if you’re on the mat or in a corner, they’ll quietly tell you what is coming next. A lot of it is designed so the crowd cannot tell what’s happening.

When I wrestled, it was still regulated much more like a real sport. You needed a wrestling license, and the Texas Wrestling and Boxing Commission would check your blood pressure and weigh you in. Later, when wrestling was more openly positioned as sports entertainment, many of those regulations went away.

Bronwen:
So how did the progression from powerlifting to wrestling to a bear happen?

Phillip:
People ask why I did that. I was 21 years old, and young guys do stupid stuff. That’s also one reason women live longer than we do.

I worked as a bouncer at a nightclub. Since I was still breaking into wrestling, I was lucky to wrestle once a week. The club ran special events, especially on Sundays when bringing in a live band wasn’t always cost-effective. One of those events was wrestling a bear.

Because I was a local pro wrestler and worked at the nightclub, they used my wrestling promo photo to promote it. It was open to anyone who wanted to wrestle the bear.

I didn’t beat the bear, but I didn’t get taken down. The bear took everyone else down by grabbing their legs and sweeping them. I was able to avoid getting taken down.

Aaron:
The bear watched too much Karate Kid. “Sweep the leg, Johnny.”

Phillip:
This bear had been trained differently from many wrestling bears. A lot of them stood on their hind legs, which made them more vulnerable. This one had been trained to wrestle while sitting down, so it had a broad base and was nearly impossible to take down.

It was about 750 pounds, which was large even for a wrestling bear.

Aaron:
I played in a band in college for about $75 and a case of beer, so I can only imagine what the bear was getting paid. Probably a pot of honey.

Phillip:
I doubt that kind of event is legal anymore, and rightfully so. But it was more common back then. I’d heard of other people wrestling bears, though some were smaller. This one was 750 pounds.

Social Engineering and Pretexting

Aaron:
Let’s talk about social engineering. What techniques work for you when you’re conducting a pen test? What is your go-to move?

Phillip:
My pro wrestling career never really helped with social engineering, but my IT experience did.

On one engagement, we were running a phishing campaign to get employees to visit a website. I was making pretext calls to encourage people to go there. If someone didn’t get the email, I would direct them to the site.

The pretext was that security patches had been deployed overnight, but not all systems received them. The person needed to log in to the website to deploy the patch. Of course, the website was ours, and we captured credentials when they logged in.

My IT experience made the pretext more convincing. At one point, I even helped troubleshoot someone’s Outlook email issue because I had encountered the same issue myself. That gave me greater credibility.

The persona you use for a pretext needs to be something you understand. If you haven’t worked in that area, you need to study it.

Bronwen:
That’s an interesting ethical dynamic. Security knowledge can become an advantage for ethical hacking purposes, but it is still a double-edged sword.

Phillip:
That is interesting. A good friend of mine who runs the Dallas Hackers Association, known as Wirefall, eventually stopped doing social engineering because he didn’t like deceiving people. He didn’t like being dishonest.

Many people are comfortable with it because it is part of an approved engagement, but others simply don’t feel comfortable deceiving or conning people, even for a legitimate security assessment.

Nerves are also a major factor. Social engineering wasn’t easy for me. It would likely be easier today because I’ve gained more comfort through podcasting, public speaking, and conferences. But a lot of people in cybersecurity are introverted or shy, so it can be challenging.

I’ve seen people overcome that because they were interested in social engineering or physical security. I once heard about two people who specialized in physical security assessments and carried a candy bar with them. Once they got into a building, they would go to the restroom, eat the candy bar, and use it to calm their nerves and boost their blood sugar.

Deepfakes and Voice Cloning

Aaron:
Speaking of masks, let’s talk about deepfakes. They have existed for a while, but audio and video capabilities have advanced significantly in the past couple of years. What are your thoughts? Do you use deepfakes in pen tests, and how concerned should people be?

Phillip:
I haven’t personally used them in pen tests, but it’s alarming how much easier they have become. Around 2020, Alyssa Miller gave a conference talk on deepfakes. Back then, they took a ton of effort and weren’t nearly as convincing as they are now.

Today, AI makes this possible for people with little to no skill. Voice cloning is especially striking. I had a podcast guest who had gone back to her maiden name after a divorce. In Riverside, I could update the written references, but I also tried the voiceover tool to replace her last name. You couldn’t tell the difference.

There are tools that work even better than that. The danger for people like us who podcast or speak publicly is that there are many recordings of our voices available. It’s easy for someone to collect samples and clone them.

That is scary. People already get scammed by relatively simple tactics. Deepfakes make it easier to deceive even more people.

Aaron:
Let’s try something. I’m going to leave the podcast and attempt to come back as Phil using only a screenshot from this call. We haven’t met before today, and I haven’t had time to train anything. This is untested and unrehearsed.

A few years ago, this could have taken weeks. Now it can happen during a Zoom or Riverside meeting.

Bronwen:
Let’s do it.

Phillip:
I don’t know what’s happening, but I’m in.

Bronwen:
I love an unhinged podcast.

Phillip:
I’ve been the subject of a few experiments like this. At Dallas Hackers Association, one of the emcees cloned images of me and created some different demonstrations. At my conference in May, Wirefall was the closing keynote. He had me record statements, then people had to guess whether I actually said them or whether he used voice-cloning technology. It was very close to my real voice.

Bronwen:
You are an obvious target because there are so many recordings of you. But my concern is also the average person who may not realize this is possible. An attacker may find a way to clone a grandmother’s voice or use that technology to manipulate a more vulnerable person. Awareness is the key.

Phillip:
It’s getting very scary. You hear about criminals trying to convince people that a loved one has been kidnapped. Families should have some kind of password or code word they can use to validate whether an emergency is real or a scam.

Aaron:
What’s your password, Phil?

Phillip:
“Big Brown Bear 87.” I’m kidding.

Bronwen:
Well, look at what we have here.

Aaron:
It changed your shirt to something with what looks like Cyrillic text. That’s odd.

Bronwen:
It did a good job with the hair, but there is something not quite right about the eyebrows and face.

Phillip:
That’s pretty wild. The colors in the shirt are off, too. If someone were wearing a plain black or solid-colored shirt with no patterns, it might be harder to spot the problems.

Bronwen:
Aaron, walk us through what you did.

Aaron:
That was an app called Dululu Stream, an AI replication tool. It works from a single image. It can do some wild things.

It looks more animated than traditional deepfakes, but traditional deepfakes used to stitch a face inside another face. If I wanted to impersonate Phil, I would have needed a hat, a bald cap, or other props. This tool is doing a much more complete body swap.

That can be interesting for entertainment, but it is scary when it is used for manipulation and even worse when it is used for crime and the darker parts of the internet.

Bronwen:
Demonstrating this kind of technology and talking about it as often as possible is important. I want people in my circles to understand that it is possible.

Phillip:
That is another reason to keep cameras on during conference calls. Voice cloning or voice-changing is much easier when video is off. Even if video can be faked, people may notice something is wrong with the image. If you knew what shirt I was wearing that day, you might notice the mismatch. Otherwise, it can be much harder to detect.

AI and the Future of Pen Testing

Aaron:
What is changing in AI and pen testing? What is AI doing well, where does it fall short, and what advice do you have for new or career-changing professionals entering the field?

Phillip:
Automated AI pen-testing solutions have come a long way and are promising. I think they should be used alongside manual pen testing because we need ways to scale.

At a large bank where I worked, we had 13 people on the team and were able to get through only about half of our PCI pen testing. If we had tools like this, we might have been able to test more frequently, perhaps even twice a year.

AI can help with scale, but it is not necessarily a replacement for manual pen testers. Human testers find zero days, and these products have not reached that level. Perhaps if we reach a highly capable form of artificial general intelligence, it could get closer. But today, AI can take on the repetitive work and allow people to dig deeper.

It can create time to assess areas that may not otherwise be covered, such as IoT, OT, or AI platforms. Let AI handle the low-hanging fruit so the human testers can do more creative and complex work.

AI can do some complex work, but I do not think it is a replacement yet. It is exciting to see experienced people who have built manual pen-testing tools begin applying AI. I recently had Dave Kennedy on my podcast, and he has created AI-powered endpoint-detection capabilities that can improve accuracy and reduce the alert fatigue SOC teams experience.

I was curious about what would happen when people with years of practical experience and tool-building expertise got their hands on AI. Many of them have been working on it for a while, and we are only beginning to see what they have created.

The optimal solution is a highly skilled professional using AI as a tool. At Suzu Labs, we use AI during pen tests, but we do not rely on it completely. The combination is the best solution.

For people trying to enter the field, and for those already in it, learn how to use AI to support your work. Use it to automate tasks and make your life easier, but validate the output. Do not take AI results at face value because the information can be wrong.

Learning AI can help future-proof your career and may help someone get a foot in the door. Sometimes experienced professionals get comfortable and stop putting the same effort into learning new technology. We saw delayed cloud adoption among pen testers several years ago because there were fewer cloud pen-testing courses and fewer practitioners learning those technologies early.

With AI, people seem to be adopting sooner. For experienced professionals, keep up with new technology and learn how to use AI. For newcomers, AI skills may help you earn a role where an organization does not have a traditional entry-level opening. You may bring skills that current staff do not yet have.

Mentorship and Giving Back

Aaron:
What advice do you have for more senior practitioners who want to mentor the next generation effectively?

Phillip:
Connect with people online and go to conferences. Conferences are a great place to meet people, and BSides events are especially good because many students attend them. They are often free or low-cost, which makes them more accessible.

Mentorship helps train the next generation. When I worked in IT, people could be very gatekeepy. You might have a Unix administrator who did not want to share their secrets because they worried about being replaceable.

But if you avoid mentoring people because you are worried about being replaced, remember: you will need to be replaced eventually. You will retire. You will want to take a vacation. You may get sick. You need people who can do your job, so teach the people around you.

There is no better way to learn what you do than to teach others.

In 2018, I started teaching at Dallas College and shifted my focus. I used to be very competitive, numbers-driven, and goal-oriented. Then I began focusing more on teaching and mentoring.

The world needs mentors, coaches, and teachers. That shift has been life-changing for me. My life has been better because I help others. Seeing people improve their lives is incredibly gratifying.

My wife inspired me. She taught ESL, and I saw people who needed help reach out to her because they trusted her. Seeing the good she was doing motivated me to change.

I probably would have retired by now if I were purely technical. Speaking at conferences, podcasting, meeting people, and mentoring others are what have kept me going.

You do not have to mentor full-time. Help people when you have time. Answer a few questions, give them recommendations, let them do the work, and have them come back when they need more help. I prefer that approach over a rigid, year-long mentorship commitment because it lets me help more people as they come along.

Bronwen:
What kinds of questions do people typically bring to you? Is it mainly, “Where do I start?”

Phillip:
Yes, people ask where to start and how to break into cybersecurity. One important piece of advice is to speak with people who entered the field recently.

People who got into cybersecurity 20 years ago can still offer valuable advice, but the landscape has changed dramatically. It used to be easier to find a job if you had the right skills, certifications, and experience. Now it is more difficult. People are being laid off, taking longer to find jobs, and many organizations are reducing headcount to save money.

Some people thought AI would replace everyone, but that has not worked out the way they expected.

Where to Find Phillip

Aaron:
Where should listeners go to find your podcast, book, speaking, and training?

Phillip:
My LinkedIn profile is a good starting point—just search for Phillip Wylie. My podcast, The Phillip Wylie Show, is on YouTube and major podcast platforms.

My YouTube channel also has a full semester’s worth of lectures from when I taught pen testing at Dallas College.

My book, The Pentester Blueprint, is available on Amazon. I’m also on X, Instagram, and TikTok.

Aaron:
Everywhere you want to be.

Phillip:
Like MasterCard.

Closing Thoughts

Aaron:
What did we learn today? If you want to be harder to deepfake, wear a multicolored shirt with text and patterns on it.

More seriously, Phil wrestled a 750-pound bear, has done a lot of interesting things in his career, and is still energized by giving back. Sharing knowledge and helping others can keep your energy up, and that is important.

Phil, any final thoughts for listeners?

Phillip:
Be kind to others. We are living through difficult times, and small acts of kindness can make a real difference.

Attitude is contagious. If someone cuts you off in traffic and you react negatively, they might carry that negativity home and take it out on their family. But if you hold the door open for someone at a grocery store, you often see them return the favor for the next person.

Spread positivity. Be kind to others.

Bronwen:
That’s a great message to end with.

Aaron:
Phillip, thank you for joining us. We appreciate getting to know you better. Have a great rest of your day and week.

Phillip:
Thanks for inviting me. It’s been a pleasure.

Bronwen:
Thanks, Phillip. We’ll talk to you soon.[ppl-ai-file-upload.s3.amazonaws]