#general

1 messages · Page 897 of 1

rapid merlin
#

Also is it one of those ones where after some time you would have to redo it

rustic plinth
#

this is true, looking at the 101 content there is a decent bit iv not covered yet, so ill go down this track. Also as i see its part of the new SAL1 cert might aswell 😛

mellow narwhal
#

Though I feel it would be a bit better to reword this to say "Other certifications" instead of mentioning the specific names

#

could be controversial

sinful bobcat
#

Man I know that's why I'm seriously thinking of doing it, is there any time limit to try it after I bought it ?

mellow narwhal
#

that's just my take on it though

sinful bobcat
#

It's damn cheap for a certification

chilly veldt
#

@jagged yarrow there's something wrong here, BTL1 does give Job-ready SOC experience, as you do sit and get experience working in a SOC in their training and exam, I have taken the cert and it did give experience

mellow narwhal
#

I mean, CompTIA's certs cost around the same, so it puts SAL1 right up there with the amped up price vs quality worth certifications

rapid merlin
#

I really liked the Soc simulator

jagged yarrow
sinful bobcat
#

Soc simulators are fun

brazen siren
#

I had issues with the SOC simulation. I don't know enough on that side to understand what I'm actually supposed to do. I know how to break shit, but don't know how to guard shit 😄

rapid merlin
manic cedar
#

Is there a way we can download from attackbox to our main system can anybody tell me

sinful moon
#

I think I mentioned above, you can use a local VM to do so. Using Kali as your guest VM would probably be most ideal

chilly veldt
proven quartz
manic cedar
mellow narwhal
brazen siren
sinful moon
# manic cedar Not working

Oh I misread their question anyways, but no not realistically, that’s what I said above when I said a local or even remote VMs you administrate would be better

brazen siren
#

I'd say that it could use a few more levels, starting with ensuring that you are able to tell the difference between malicious actors and non-malicious ones first. Like making it mega apparent.

brazen siren
sinful moon
manic cedar
brazen siren
#

Same if it was a correct call

sinful moon
#

but if you already have a Kali install, then there’s no reason not to be using that

mellow narwhal
#

SAL1 implies the existence of a SAL2 👀

manic cedar
brazen siren
sinful moon
#

There’s nothing “blessed” about the AttackBox other than it’s in the same VPN network. Just OpenVPN in via Kali and you’re set

brazen siren
#

I don't judge

sinful moon
brazen siren
#

Yeah, not virtualized

mellow narwhal
#

yeah thats not advisable like elizabeth said

sinful moon
#

nothing wrong with Kali bare metal mind you, just not as this guy may be doing above

manic cedar
brazen siren
#

However, they're in a separate network, and have no important logins

mellow narwhal
#

just make sure you harden it properly even otherwise

#

if someone gets in, they can pivot

sinful moon
#

It’s in the seclists

mellow narwhal
#

separate network makes it harder, but hey remove all the possibilities right

brazen siren
#

truetrue

manic cedar
mellow narwhal
#

if only you're using this, remove everyone else from sudoers and monitor running services is what I advise

sinful moon
#

then you download the wordlists they give you and use them? what do you even mean lol

manic cedar
#

And attackbox is for an only in q
day

brazen siren
#

Any tips on hardening your Kali?

sinful moon
#

97% of the time you can use a local or remote VMs with no issues instead of the split view

manic cedar
fringe nacelle
#

Just got the cert email from THM

sinful moon
manic cedar
sick lance
#

Blue cert released

wooden totem
#

speedrun

polar wraith
#

did the certificate just go live on the website

sick lance
#

Yeah.

sinful moon
sick lance
vagrant kraken
#

Its live 300 eyro

umbral kiln
cedar swan
neon current
#

Is the new sal1 proctored? Does it expire?

pliant onyx
#

New certs just dropped litolshy

sick lance
#

I would not suggest taking the malware etc

sick lance
vagrant kraken
#

297 Euro its 1 Cert

sick lance
neon current
ancient mirage
#

how are you today guys?

sinful moon
sick lance
gleaming grail
#

300 euro for that?

fringe nacelle
#

$297 USD

vagrant kraken
neon current
sinful moon
#

Anyways respect, this does look like a more legit try for a cert than I expected

fresh ice
#

What are your thoughts on recently launched SAL1 certificate for blue team on tryhackme

gleaming grail
#

Yeah I'll pass

sinful moon
#

I will actually check it out for real

cosmic pendant
near sapphire
#

cert is here YAYYYY!

sick lance
livid burrow
#

omg

fair thunder
#

Can skiddy stop @ing everyone holy shit

livid burrow
#

what is the new certification thing

vagrant kraken
main tiger
fresh ice
#

SAL1 CERTIFICATE

sick lance
sick lance
neon current
livid burrow
candid niche
#

SAL1 😍

fresh ice
#

So the SAL1 certificate isn't free for premium users?

real night
#

Let's goooooooo

vagrant kraken
#

Nothing is Free

livid burrow
#

Wait its paid?

halcyon harness
#

I'm happy that it is a blue team cert

idle mica
#

I can't wait to evaluate that cert. Looks good!

main tiger
fresh ice
#

What if we fail

jolly aspen
#

Price keeps changing. Was there a reduced price for the first x signups?

fringe nacelle
vagrant kraken
neon current
#

Is the sal1 given at a discount for premium users, haha

livid burrow
#

but it seems good

#

more professional

naive violet
vagrant kraken
#

So its open book

real night
#

Considering it was a blue cert, there's a possibility that red cert is getting baked too right?

cosmic pendant
#

🔗 Register for this Class – 
https://www.antisyphontraining.com/course/getting-started-in-security-with-bhis-and-mitre-attck-with-john-strand/

This 16-hour information security training class is designed for people who are new to computer security.

We will cover the core fundamentals with lots of hands-on labs demonstrating the attacks and def...

▶ Play video
fringe relic
vagrant kraken
#

No value

sinful moon
#

It is trying for real to be an actual industry cert and yep those cost money. This is significantly more respectable than I was anticipating so yep, honestly good stuff. I still have to read more about it though

neon current
#

Is this the first official tryhackme certification?

fringe nacelle
#

I'm not a fan of mcq, but good luck to anyone who does it

main tiger
tribal ice
#

yo

tribal ice
#

my diplay name seems to be okay here

idle mica
# vagrant kraken No value

No, not inherently. Being able to operate independently and find information for yourself is a critical skill for any cybersecurity professional

livid burrow
fringe relic
idle mica
#

GIAC certs are open book, but they're still difficult for many individuals

naive violet
cosmic pendant
main tiger
vagrant kraken
idle mica
chilly veldt
#

@jagged yarrow if you'll like, I would love to send you my thoughts when I have gone through the scenarios and can draw differences to BTL1 here later,
I have personally worked with SOC systems for the last 3 years and have a lot of experience in the area

sick lance
#

Sherlock isn't as bad as people make out ml

#

Much like ghost.

idle mica
cosmic pendant
real night
#

There is proabably someone out there is already taking SAL1

neon current
# near hawk Yea, it's unproctored

I like the idea of the certification cause I love tryhackme's rooms, but I already paid for the OSDA, and the BTL1, I can't justify another cert if it's unprotored

wooden totem
#

Is sal1 really that good or is it just marketing

idle mica
#

Well yeah 🤣

jagged yarrow
naive violet
chilly veldt
idle mica
#

I might have missed it, but is there functionality to gift a certification attempt? I know we'd love to do a few giveaways with this

fringe nacelle
#

Let's force Elizabeth to do the Sal1

brisk tree
#

so the exam is 24 hours long or the content?

jagged yarrow
neon current
#

I will say this the Soc tier 1, and tier 2 paths are some of the best in the industry, especially at the cost.

naive violet
jagged yarrow
#

Ah I see.

cosmic pendant
#

"Gold Standard"?

main tiger
#

It will take a while for the cert to get recognized by hiring managers

naive violet
#

There's more to it than that, but the industry takeup will be the proof

fresh ice
#

I have a 1 year premium subscription of tryhackme. And currently pursuing SoC level 1 walkthrough

royal halo
elfin oriole
#

I doubt it will really get recognised

main tiger
# royal halo How long do you recon ?

BTL1 only started getting put on job posts after 1-2 years, so I would say around that ballpark. Suprisingly in the UK its sec+,CEH,BTL1 that are mainly on the job posts

royal halo
elfin oriole
#

More mature certs still aren’t really recognised

sick lance
royal halo
cosmic pendant
#

Certs in many ways have been devauled, the same as college/uni. Because it's become another money grab

naive violet
#

@jagged yarrow Have you considered aligning it with the UK cyber security council specialisms and standards? Gov work in the UK is all moving to those

sick lance
#

Happily to be shown wrong if you can show them.

main tiger
cosmic pendant
naive violet
royal halo
#

but adding to the vast sea of certs is certainly an odd move, esp for tryhackme.

cosmic pendant
#

The ones we post include it

elfin oriole
#

BTL1&2, then SANS and experience is what I’ve seen for SOC roles if they are asking for certs

royal halo
#

Just adding more dilemma to beginners

idle mica
#

Tbf CEH and EC-Council have become a joke nowadays

silent nova
#

The quiz is multiple choice, wow. (Also SOC Sim? Nice.)

steel aspen
cosmic pendant
royal halo
cosmic pendant
#

While EC-Council is a joke, and has demonstrated unethical behavoir themselves. THe marketing and most of the material for the cert is good

steel aspen
amber quarry
#

what's the argument behind this ?

sick lance
cosmic pendant
#

It's the daddy of pentesting certs

idle mica
#

The cert is absolutely useless as well, much like GRTP lmao. The SEC565 class was fantastic, the cert is just a multiple choice time crunch

steel aspen
#

Or maybe unethical stuff I was thinking of

sick lance
cosmic pendant
#

Oh, I can't help with that 🙂

steel aspen
chilly veldt
royal halo
pliant onyx
#

In fact, the teachers encourage students in the university to pursue it

#

And they do it with the students too sometimes

steel aspen
#

How good are CompTIA certs?

fringe nacelle
#

45 seconds a question for the mcq. I wonder how intense or simple the questions will be

naive violet
sick lance
sick lance
amber quarry
twin ridgeBOT
#

Gave +1 Rep to @chilly veldt (current: #8 - 966)

pliant onyx
#

Wow it takes 'ty' too

#

Noice

idle mica
amber quarry
#

that blue team stuff isn't for my anyway 🥴
but it's cool THM is getting in the cert market with relatively affordable stuff

jagged yarrow
# amber quarry what's the argument behind this ?

They don't teach you in an actual SOC environment - we use the SOC Simulator to evaluate actual real-world skills. We sat with analysts at Accenture to replicate exactly what they do. Try out one of the scenarios if you want to see what its like!

sick lance
#

Red team cert next.

idle mica
#

I really enjoyed the old CASP+, but SecurityX was a bit of a regression without the practical lab questions

chilly veldt
#

hmmm, time to ask work if they can pay for this cert

stuck vapor
sick lance
#

MCQ is the one thing. I found strange.

main tiger
chilly veldt
#

could be fun to be the first who has taken it, then I'll just take it tonight to see what it is 😛

fringe nacelle
#

Go for it, the first 100 get a special goody box

hollow saddle
#

where you guyz found the answers of the labs ??

main tiger
#

I was never a fan of BTLO challenges. They were not that realitic.

sick lance
idle mica
#

Oh damn I better take it now for giggles

fringe nacelle
idle mica
#

Gonna yolo it and see what happens 🤣

hollow saddle
#

i also try many labs but always they say incorrect to my answers even a space exit in it

chilly veldt
#

I think I am out qualified for it, so might be easy for me to get

pliant onyx
#

When will it be releasing? Any tentative?

chilly veldt
#

a level 1 cert might be too easy when you have 3 years of experience in SOC and built one 😄

fringe nacelle
#

Gotta flex them muscles

main tiger
#

OSCP still dominant a lot of the time, and CREST especially in the UK

sick lance
#

Granted,.the MCQ only takes 20%.

But still.

idle mica
chilly veldt
#

yeah, plan is that if this is a good one, we might push it to the new employees in the SOC

pliant onyx
#

Just get any/every cert at this point

#

And call yourself a cyber security 'expert'

cosmic pendant
pliant onyx
lament tendon
stuck vapor
#

I hope that they come up with a new ethical OFFENSIVE red team cert

elfin oriole
#

I am curious why is there a multiple choice section when it’s unproctored and open book? Seems somewhat of a moot point?

pliant onyx
#

Elite haxxer (However you write that in scriptkiddie)

lament tendon
#

el1t3 h4xx0r

pliant onyx
steel aspen
pliant onyx
#

Coz it's... offensive... get it...

#

I'll see myself out

lament tendon
ripe vine
#

Is the exam proctored? What’s stopping someone from googling the multiple choice section?

stuck vapor
pliant onyx
#

/j /s

idle mica
# steel aspen Who's next after CompTIA?

It depends on what your goals are. Hands-on experience is always great. Cert-wise, if you can get an employer to pay for a SANS class and GIAC cert, they're generally really good. I've been a big fan of AntiSyphon's training lately

sick lance
wraith granite
#

my first server

#

:D

ripe vine
#

Is it seen as research skills?

steel aspen
stuck vapor
#

Now im doing the holo Network

idle mica
elfin oriole
wraith granite
twin ridgeBOT
#

Gave +1 Rep to @idle mica (current: #380 - 16)

sick lance
cosmic pendant
#

Did you see that video i posted?

jagged yarrow
fringe nacelle
#

Grats on your first cert on THM skidy. Looking forward to seeing more whenever you finish making them

halcyon harness
#

That's cool

jagged yarrow
twin ridgeBOT
#

Gave +1 Rep to @fringe nacelle (current: #399 - 15)

elfin oriole
#

@jagged yarrow Will there be plans to complete the SOC path with a L2 aligned cert?

chilly veldt
#

welp, I should be able to get the go in a few, and then I'll be doing the exam this evening 😎

abstract forge
# sick lance Soc sim scenarios are 40% each

I was just finished studying for today and saw the announcement, really excited, would there be in the rooms and Soc Tier 1 section any practice rooms that would simulate what you would do exactly in those sim scenarios so you would feel comfortable taking the exam right after you are done with everything you can cover from these sections?

idle mica
# steel aspen Mainly security analyst. Sounds interesting and maybe even fun.

Get really familiar with Windows and Active Directory. Build a home lab, maybe use GOAD, instrument it with Wazuh, follow a guide to execute the attacks, and see how they look in the SIEM. Otherwise, I hear the BTLO certs are good. The idea, in my opinion, is to get your foot in the door with an interview and then comfortably show that you know your stuff

chilly veldt
twin ridgeBOT
#

Gave +1 Rep to @idle mica (current: #363 - 17)

ripe vine
twin ridgeBOT
#

Gave +1 Rep to @jagged yarrow (current: #140 - 57)

jagged yarrow
fringe nacelle
#

I actually plan to make my own honeypot for fun @idle mica Got any experience with that?

idle mica
#

And don't be afraid to get there and talk to people. Meeting the right individuals can open up all kinds of doors. It's definitely a networking game as well

jagged yarrow
sick lance
jagged yarrow
pallid lotus
#

So, uh, has anyone actually been hired as a result of SAL1... which released 25 minutes ago? 😄

idle mica
stuck vapor
#

Is there a room for learning proxychains

elfin oriole
#

The SAL1 first 100 is the first to buy or pass? In which case, will there be a memo when the first 100 have been reached @jagged yarrow ?

jagged yarrow
stuck vapor
#

W

pallid lotus
#

Congrats! 😁

abstract forge
solid elk
#

Hey everyone,
I'm looking to learn more about cloud security (AWS, Azure, GCP) and would love to chat with someone who has experience in the field.

If you know any good resources or can connect me with someone, that’d be awesome!

I'm mainly interested in understanding security challenges in cloud architectures.

idle mica
jagged yarrow
elfin oriole
abstract forge
#

nice thank you!

jagged yarrow
steel aspen
stuck vapor
#

Is there a room for learning proxychains?

abstract forge
stuck vapor
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 3501)

steel aspen
idle mica
steel aspen
#

Mainly use Ubuntu though

#

Yeah I definitely understand why active directory is necessary and I guess efficient too. It's just annoying to learn lol.

stuck vapor
#

Active directory is strong but just annoying

steel aspen
#

Company roles and if you wanna call it hierarchy lol.

idle mica
#

Microsoft gives you just enough rope to hang yourself when it comes to configurations and defaults. A poorly configured AD is a walk through the park to abuse your way to DA or EA

steel aspen
#

I even forget what EA is

idle mica
#

Especially with ADCS. Lots of room for abuse there

#

Enterprise Admin

steel aspen
chilly veldt
#

it's just awaiting approval lmao

idle mica
#

I've gotta run to the DMV first in 20 minutes 😭

sturdy pike
#

How much is the cert?

chilly veldt
steel aspen
naive violet
idle mica
steel aspen
#

Ohhh. That makes sense.

idle mica
#

If I CEO had enterprise admin... 😭

#

I'd quit

ancient mirage
#

just got my Jr Penetration tester certificate. bee

sturdy pike
#

The red of 0xC now burns my eyes

steel aspen
#

Yeah nah not smart hahaha

sturdy pike
#

Was it always like this?

steel aspen
#

My critical thinking is critically injuring me rn 🤣

#

Or lack thereof

idle mica
#

Pfft not at all, you learned something new!

steel aspen
#

Yeah too true. AD is still very new. I've done a couple THM rooms on it. Very slowly.

sturdy pike
#

I come here, hear people's successful stories, get motivation, do a couple rooms.

tidal hound
#

Guys I'm not understand that the first 100 candidate finish the class will get the certificate or it will give for anyone who complete the class guys? I'm not really clear about this

steel aspen
#

Think first 100 gets limited edition THM swag

cinder jay
#

need to learn networking from basic . can anyone suggest me

tidal hound
#

oh so I think it's really hard to get T_T

steel aspen
#

But anyone who completes the cert gets it like any other cert

sturdy pike
sturdy pike
lament tendon
tidal hound
cinder jay
#

i dont get it

lament tendon
steel aspen
# tidal hound Nice

It's not a normal Thm cert though. Industry recognised by the sounds of it.

lament tendon
steel aspen
cinder jay
lament tendon
#

But.

#

Whahahaha

#

Epic embed fail. ;D

steel aspen
#

Yeah pretty good

#

Yeah rekt myself 😎

lament tendon
steel aspen
lament tendon
mossy river
#

Please don't advertise here

steel aspen
#

So <link> to stop the embed?

rapid merlin
#

Ok

lament tendon
fringe nacelle
#

Jabba in full force 👀

steel aspen
rapid merlin
#

@hardy juniper Hope you're having a good day!

lament tendon
steel aspen
#

1000s too many

lament tendon
#

You think so?
I personally like that you actually have a choice for those. ^_^

#

They just should not have the ones that are common file extensions like .zip, because those will just be abused.

steel aspen
#

Too many to be able to make scams/virus links lol

lament tendon
#

You don't need TLDs to make phishing domains.

steel aspen
#

Nah but some non tech people wouldn't know ig.

lament tendon
#

Unforunately I cannot make an example outside of the advanced channels, whahahaha.
But it is rather trivial to generate a valid looking domain name while ignoring the TLD altogether.

steel aspen
#

Won't go into it as I know it's not allowed but yeah they should've stuck with the normal TLDs

lament tendon
#

Of course you are correct in that having more TLDs technically enables some more variation in malicious domain names, but I don't think it matters too much when put into correlation with what is already possible through just the domain name itself.

steel aspen
#

Yeah I know you can change domain to make it look the same too but with "custom" TLDs I find you can make it look that much more convincing.

lament tendon
#

Plus, having a non-common TLD that is not .com, .org, .net, etc will already by pretty dang suspicious to a lot of non-tech people, I would believe.

#

Imagine you get a link from your bank and it say your-bank.xyz.

#

(Of course, someone will fall for that, but someone falls for everything.)

steel aspen
#

Yeah most people would see that and turn away I'd like to think but yeah as you say some would. I know people who click links without hovering to see where it's taking them.

sick lance
#

@small remnant please don't advertise here.

steel aspen
#

Might change subject though cos I know at this time this chat gets all sorts of people out and about hahaha and this would be up their alley so to speak.

lament tendon
#

Sorta agree with you on that, but I also don't believe either of us said anything which is new to people in that field. xD
But yee, let's stop.

steel aspen
#

Yeah haven't given trade secrets hahaha but yeah better be safe

tidal hound
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3423)

steel aspen
dark mason
#

Is there a student discount to the cert?

sick lance
dark mason
#

Dang it

#

Maybe next year then

steel aspen
lament tendon
#

How about you?

lament tendon
#

Wait, who overtook, lmao?

sick lance
#

I get my thanks for legit helping out. 😄

steel aspen
idle mica
steel aspen
civic egret
#

Me when I lie

sick lance
#

I mean, there's the proof?

#

¯_(ツ)_/¯

steel aspen
#

Huh lol

lament tendon
twin ridgeBOT
#

Gave +1 Rep to @idle mica (current: #343 - 18)

steel aspen
#

Who's kgbkp

sick lance
#

User X welcomes new users by saying welcome.

The common reply is "Thank you"

Ez Pz rap farming.

grizzled void
steel aspen
#

Nah that's cheating fr

idle mica
lament tendon
lament tendon
cloud quiver
idle mica
#

Oh definitely

sick lance
steel aspen
#

Oh yeah ( don't use htb, didn't like the interface 🤣)

sick lance
#

I don't use HTB either, yet still get brought up in the server kekw

#

Rent free and all that.

steel aspen
lament tendon
slim wave
#

red teaming certification when

cloud quiver
steel aspen
#

The layout was confusing as

sick lance
dark mason
sick lance
#

Rep system is useless.

steel aspen
#

Least THM is neat and everything can be found easily

dark mason
#

I so split, idk if I should choose red teaming or pentesting

steel aspen
#

Organised

sick lance
steel aspen
#

HTB had stuff everywhere and doesn't help there's Labs and Academy lol idek the difference

#

I did try it to see what it was about

queen flare
#

+rep @cloud quiver

twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 3502)

cloud quiver
idle mica
#

Alrighty, lets do this

lament tendon
# steel aspen How similar is it to Thm?

Surprisingly different, in my opinion.
Learning content on THM is better, even tho HTB academy is pretty good as well (at a price, it's helly expensive).
I preferer the HTB machines tho, they have a more realisitic feel to them.
And for single more CTF-like challenges: there are good and bad ones on both platforms, HTB just as a lot more with higher difficulty.

queen flare
sick lance
#

People often say platform X is better than platform Y.

sick lance
lament tendon
idle mica
dark mason
sick lance
steel aspen
#

I find the THM CTFs alright. HTB just throws you in it I guess.

chilly veldt
lament tendon
dark mason
idle mica
#

damnit lol

cloud quiver
sick lance
#

I've done less THM these days, only rooms I do are the ones we get to test.

lament tendon
#

Labs just gives you access to challenges (and some writeups).
Academy has few proper challenges and mostly learning content.

chilly veldt
sick lance
steel aspen
lament tendon
#

And CTF is just a platform for companies and orgs to host their CTFs on HTB infrastructure.

sick lance
#

I didn't bring it up for no reason...

#

If you're going to read a conversation, read all of it, not half.

cloud quiver
sick lance
rugged kayak
sick lance
#

Even if it was a greater problem than it is, I'd address it with admin, not general chat. 🙂

oblique furnace
steel aspen
lament tendon
# oblique furnace uhhhh

I brought that up as a bug a few days back because I can't read either, read the actual task. ;D

oblique furnace
#

im grinding my streak rn

rapid merlin
#

The new cert looks so good

#

Anyone here interested in BCI Technology?

cloud quiver
rugged kayak
#

but they have regular ctfs and prolabs under labs

small atlas
#

@cloud quiver @sick lance I love the fact that new users, old users, anyone are welcomed. Postive vibes. More off it please

lament tendon
#

Or, well, just go visit the platform, whahaha.

upper minnow
lament tendon
#

HTB sometimes hosts some pretty cool stuff on there themselves!

sick lance
cyan spruce
#

Helloo

lament tendon
jaunty charm
steel aspen
dark mason
cyan spruce
#

Thank yall

chilly veldt
#

this just keeps staring me in the face @idle mica 😦

sick lance
dark mason
#

Wait

#

How many tries do we have on the exam

chilly veldt
sick lance
steel aspen
dark mason
#

It's also cheap

idle mica
oblique furnace
#

oh wait im with stupid

#

alright then

chilly veldt
oblique furnace
#

i finished tho

#

time to grind some on portswigger

#

and yall get the daily screenshot

rapid merlin
idle mica
#

double damn :(

chilly veldt
#

big time

rapid merlin
#

What’s the exam like?

#

Do we have to be on cam

#

I had that once

umbral bay
#

Everyone busy doing the SAL1 exam? 🥳 🙌

chilly veldt
idle mica
#

I'm about to start it and just record my time lol

sick lance
idle mica
#

It's too enticing

sick lance
#

Which I find off as they ask for ID.

rapid merlin
chilly veldt
sick lance
rapid merlin
#

Oh wow

umbral bay
idle mica
#

aight, say less, Tuesday just got a hell of a lot more fun

sick lance
#

20% MCQ
40% for both soc sims.

chilly veldt
steel aspen
sick lance
rapid merlin
chilly veldt
#

SOC level 1

sick lance
near sapphire
chilly veldt
rapid merlin
sick lance
#

^

steel aspen
sick lance
#

I suspect if it's a sim, it may vary on how alerts pop up etc

chilly veldt
#

I should grab some snacks and stuff before I start it

umbral bay
steel aspen
#

Makes sense I guess being a real world cert

idle mica
rapid merlin
# sick lance ^

I’ve done some of those already. Today I was studying geofencing

idle mica
#

I'm really enjoying the question bank so far, though

#

Lots of good stuff for that tier 1 position to know

chilly veldt
oblique furnace
#

Day 25

elfin oriole
#

Wondering if I should pivot to SAL1 then pick back up CCD after

oblique furnace
#

i still have no clear way to pay for the next month, hopefully i'll figure it out

#

i got a tech job (unlock an ic locked 13 pro) and the guy hasnt paid up yet

steel aspen
#

There's a lot of free rooms BTW

idle mica
sick lance
#

It's open book anyway.

idle mica
#

Yeah, like with ISC2. Later questions can inform answers for previous ones and all of that

mellow narwhal
#

I love that its at a highly affordable price, as compared to stuff like CEH, where the price vs quality doesn't check out

#

I can't take SAL1 rn, but maybe in later years. I'm looking forward to trying out the soc sims on the website though

queen flare
umbral bay
twin ridgeBOT
#

Gave +1 Rep to @idle mica (current: #332 - 19)

chilly veldt
#

297 US

mellow narwhal
#

Like, 300 dollars approximately

queen flare
#

isn't that close to pentest+ and those certs

finite tulip
mellow narwhal
grizzled void
mellow narwhal
#

Idk if it varies based on country

#

Pentest+ cost here differs from SAL1 by ~$35

queen flare
mellow narwhal
#

BTL1 is way more expensive as compared to this

#

like, more than 2x the cost

steel aspen
umbral bay
hollow nebula
#

has anyone gotten their pentest+

#

can't get above a 76% on the Dions - and dion wants a 90% to pass

rapid merlin
hollow nebula
#

it's really post-exploitation that's holding me back. certain mimikatz commands, certain exploits . i'm just going through the THM rooms and trying to get the commands in my fingers

rapid merlin
hollow nebula
#

oh that looks fun

rapid merlin
#

It’s got red and blue commands and it tells you which team it’s for and what it’s used for

#

It’s nice

hollow nebula
#

i'll have to take a looky loo

rapid merlin
#

im currently a beginner wanting to get into red teaming. im learning all of linux fundamentals first right now but does anyone know of any networking books i can read while im getting a basic understanding of linux?

lament tendon
mellow narwhal
rapid merlin
lament tendon
#

THM and HackTheBox also offer practical tasks alongside the content, which you won't get from a book without setting up your own environment.

sturdy pike
#

Let's see how the new cert is knuckle cracking sounds

mellow narwhal
#

better than books, and you learn everything you need for red teaming

rapid merlin
hollow nebula
#

yes

#

networking held me back for so long because i ignored it and went into pentesting

mellow narwhal
hollow nebula
#

even got sec+ and a job - and felt like a loser because i didn't know how pakcets travelled

rapid merlin
#

I want a networking book too

lament tendon
#

You can learn networking without that, but to actually do literally anything related to working with network, you will need knowledge about Linux and sometimes Windows.

hollow nebula
#

cisco has the free ccna course with packet tracer if you are a visual learner like myself

#

they even make you set up the homeoffice network with drag and drop cables

rapid merlin
#

now lastly do i really need the A+ or can i skip it over?

lament tendon
# rapid merlin I want a networking book too

Again, I would only recommend buying a book if it is either on a big sale (humble bundles are pretty good sometimes), or if you collect books.
In my opinion, they are often not worth the price when compared to other types of text or video based resources.

hollow nebula
#

you can find older versions of books in pdf form pretty easily online

lament tendon
lament tendon
# rapid merlin I love physical books

In that case: completely fair. Based opinion. xD
Got a whole bunch of red/blue teaming field manuals and even the physical NMap book on my shelf too. ;D

idle mica
# umbral bay Noting that one down, thank you. 🙂

Another quick bit of feedback, should the countdown timer be running while reading the SOC Wiki and before hitting "start scenario"? Seems a bit odd, since one is potentially burning time while also waiting for the VMs to start

rapid merlin
rapid merlin
idle mica
#

I really enjoyed the MCQs, too! Good stuff in there

lament tendon
#

I have been doing this for more then two years at this point, and I am okay-ish, still learning new stuff every day.

mellow narwhal
#

Note that I haven't done A+ myself, I'm just speaking from the practice tests I've taken (which are from CompTIA)

rapid merlin
chilly veldt
rapid merlin
lament tendon
idle mica
# chilly veldt unfair 😦

It'll make it that much more fun! Buy him McDonalds or something, bring it to him, and slip him a "pls pls pls" note 🤣

lament tendon
#

You can use some tool like Obsidian or Trilium to manage the whoe thing and sync it onto Github or another cloud service so you can access them from any device, everywhere.

chilly veldt
idle mica
#

me when the VMs start

rapid merlin
chilly veldt
idle mica
#

I used to work for a place that wound up getting rid of the security guards because they made poor business decisions. Guess who was tasked with building security! That's right! The friggin NOC KEKW

rapid merlin
#

Do all communications have to run through cloudflare or can I change that

rapid merlin
#

😂

#

Ah just ignore me

chilly veldt
#

communications in what way?

rapid merlin
#

I’m just gonna look at the new cert

#

Look at the topics eg

devout palm
#

Got a fresh haircut

rapid merlin
#

Nice

#

I rarely ever get my hair cut

#

Sometimes I cut it myself

steep mountain
rapid merlin
cosmic pendant
rapid merlin
rapid merlin
#

Ngl for a long time I could not see this tick here so I thought it was greyed out because I had not done it yet. Very difficult to see

steep mountain
#

I must be blind, where is the security analyst path

#

nvm

#

got my hopes up just for it to be a cert

mellow narwhal
#

what?

elder peak
rapid merlin
elder peak
fast zinc
#

$350 is too much for SAL1 😭.

blissful snow
#

350 thats not a lot

elder peak
#

Cheaper than most cert exams

blissful snow
#

other are like $800+

upper minnow
#

certs are such pyramid schemes

kindred yew
blissful snow
#

brb my dogs unhooked all my speaker wire 😞

blissful snow
kindred yew
#

You need a firewall rule for dogs

#

to filter incoming and outgoing dogs

blissful snow
elder peak
#

Block dogs

blissful snow
#

then my dad opens the dog and lets them in

idle mica
#

I hate how effectively this cert exam simulates a real SOC queue. It's giving me 'nam flashbacks 🤣

blissful snow
#

must put dad in cage

grizzled void
#

I'm interested in knowing what the exclusive swag is. I doubt I'll be first 100 but I still wanna know what I'm about to miss out on

wet marlin
#

happy new year guys

#

im late ik

#

new year new me

blissful snow
#

happy new years

#

im giving you have a different tradition?

junior wigeon
#

I'm new to tryhackme

sick lance
chilly veldt
lament tendon
#

Welcome.

chilly veldt
#

no answer from manager

jaunty charm
junior wigeon
#

I'm doing the Jr penetration tester path. I wanna know what challenges and ctfs I can do while doing that path (?)

#

need begginer-friendly challenges

#

As I'm new to CTFs

sick lance
twin ridgeBOT
#

Gave +1 Rep to @jaunty charm (current: #1766 - 2)

wet marlin
#

yoo

#

new year new (me)ntal illnes

#

and agin as i say college is still a pima

#

pain in my ass

jaunty charm
sand remnant
#

Good morning. How do I obtain my token to verify my account with Discord?

jaunty charm
oblique needle
#

yo new cert just launched

wet marlin
#

suck it

#

heheheh

#

bye4

sharp citrusBOT
rapid merlin
#

wait how do i get roles in here?

eternal sundial
#

Why I cannot share screen captures in THM channels 🙂

grizzled wing
#

click on link above

rapid merlin
#

i knew that

wanton ingot
#

SAL1, interesting.

eternal sundial
#

Did maybe anybody do something similar aranging data from ICMP tunneling Pcap

steep mountain
#

What’s up with light mode?

eternal sundial
#

this is not a room, but THM CTF creating add-on, but I got this challange were its hard to find the flag

dark mason
#

Does tryhackme ship to romania as well?

sturdy pike
#

o i i a i o i i i a i

weary veldt
steep mountain
#

Linux a personality.

near sapphire
dark mason
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @near sapphire (current: #188 - 42)

dark mason
#

It's about 150$ per try

#

And that's way cheaper than anything else I have seen

weary veldt
#

Its 30k in rupees

sturdy pike
#

Fuck it

#

I'm going level 9

#

I won't message before that

#

See ya everyone

latent elm
#

Hello ,

weary veldt
mossy river
#

Please avoid posting answers here, if you need help with a room #room-help would be your best bet 😄

half girder
#

oh thm finally came up with a cert, something to do for the next weeks then 😉

slim arch
#

you can just learn

#

maybe when it's industry recognized, I get it.

rapid merlin
carmine tinsel
#

Last night I had a dream I was doing a thm ctf

frigid cradle
#

Yo guys
Currently doing the persistingAD room
I have forged a new cert with ForgeCertTool and then i proceed to using Rubeus to request a golden TGT from the DC, however after numerous checks and retries i get this krberror16:kdc_err_padata_type_nosupp
Who can tell me if they have encountered this error in the past

frigid cradle
#

Ok

fossil merlin
idle mica
#

Last section... lets see how we do

weary veldt
crystal lynx
#

Hey can anyone guide me about how to understand the burpsuit responder pattern?

strange current
#

Are we winning?

crystal lynx
weary veldt
#

You can search burf suit

#

There will be 3 rooms

tight sparrow
#

hi

pliant onyx
#

2>/dev/null

idle mica
#

It's suspiciously quiet on this scenario...

pliant onyx
#

What if I ctrl C now hmm

toxic glen
#

Man the grass looks so much greener on TryHackMe field, new levels and a certification.

tight sparrow
idle mica
#

What do you mean not really? It's an objective thing 🤣

tight sparrow
#

btw i love this website

tight sparrow
toxic glen
#

TryHackMe website is goated.

idle mica
#

Ahh okay, I was so confused for a sec lmfao

toxic glen
#

It made me want to be a security guy

tight sparrow
#

i am just suprised by one thing tbh that is some of the premium rooms right

wicked cairn
#

Soo with SAL released, do I even do SOC lvl 1 path or just do the SAL thing?

tight sparrow
#

some people just copy paste reupload them on medium or github

#

like posting answers is fine but they straight up post the thing lmao

#

isnt that stealing content

tight sparrow
toxic glen
# tight sparrow isnt that stealing content

It's people just posting blogs because they've heard that posting blog posts about security helps you get a job. Most people who do that are just doing to stick in on there CV, so the content is rather basic.

naive violet
mellow narwhal
toxic glen
tight sparrow
#

plus i just got premium and its been good, the streak thing the site has its just like duolingo and i love streaks i have like a 134 day streak on duolingo

toxic glen
#

Great 🙂

mellow narwhal
#

THM doesn't have control over sites like Medium or Github

#

idk about the legality of it

half girder
#

you can simply write dmca reports to take the "stolen" content off

idle mica
#

^

#

Hack The Box does it all the time for active content

tight sparrow
#

i mean posting answers is fine

toxic glen
#

That's good

tight sparrow
#

that helps people

#

but straight up taking the whole thing is a bit much

idle mica
#

Posting answers doesn't help anyone

#

Helping people come to the answer themselves, sure

tight sparrow
#

no they usually show the process of how they got the answer

#

most of them

mellow narwhal
#

BreachForums is in active use lol, its about time someone made a dmca report

idle mica
#

It's BreachForums, dawg

tight sparrow
#

the website still shows as seized

mellow narwhal
#

no, its active

#

people post season boxes answers on it

toxic glen
#

When I was grinding I looked up answers but made a point to study what I didn't understand.

half girder
toxic glen
#

Nice 😄

wicked cairn
twin ridgeBOT
#

Gave +1 Rep to @naive violet (current: #3 - 2256)

tight sparrow
#

also i never used linux in my life so the learning curve is steep

muted stump
#

my favorite is when I look at a write write-up because I struggle with a specific task. Just to see that the person doing the write-up skipped it. Nice to see other people on the struggle bus lol .

thin vigil
#

Hey gang, Im designing potentially my first modular home network that I can open up ports on. Someone else incredibly well versed in networking is helping me out but I just want to run by is the logic through you guys before I run it through him if that's all right and allowed

tight sparrow
#

how can i get the color roles

sharp citrusBOT
tight sparrow
#

oh thanks

wild turret
#

hello

tight sparrow
#

I got the role! fancy

wild turret
#

yo no slow mode here

carmine tinsel
#

what do u mean vigilante 🤔

toxic glen
#

I think it's a quote from Mr Robot

carmine tinsel
#

ohhh

#

girl I’m dumb

#

💀

toxic glen
#

Naaah, I mean I could be wrong but that's how I understand it.

idle mica
#

Shoot, in this industry, there are plenty of people who would unironically use that as their status while imagining themselves in the third person 🤣

sinful moon
#

Nevermind I'm dumb too

#

they would have said daylight and moonlight if that was the case

#

just hush, I've spent the last two hours troubleshooting a vendor proprtiary docker compose/linux setup for hospitality TVs lol

round orbit
#

I got the fucking job!!

sinful moon
#

Congrats!

round orbit
#

I cannot believe it

sinful moon
#

Don't know what job but that's always great to hear

round orbit
#

I really am gonna be a SOC Analyst

idle mica
#

My man, congrats!!!

sinful moon
#

Very awesome

idle mica
#

Don't get burnt out now lol

round orbit
#

From IT support tech let’s go

eager marsh
round orbit
sinful moon
#

now let me tell you as SOC manager why your True Positive is actually False Positive lol

sinful moon
#

lol not quite the same thing when I manage a managed SOC

round orbit
#

It’s a SOC for clients, not an internal SOC, I don’t know if that means anything or is better/worse

umbral bay
round orbit
#

It’s around an £8k increase

carmine tinsel
#

Soc analysts when I lose my soc in the washer

sinful moon
idle mica
#

Hell yeah man, that's a good jump

umbral bay
round orbit
#

I mean it is further away tbh, but yeah hopefully worth it

idle mica
#

Definitely. More money is more money

glossy shuttle
#

how do i contact tryhack me support? i have an enquiry

chilly veldt
#

So w33t how did it go?

idle mica
#

Still working on the last few alerts, so we'll see!

mossy river
#

Is there anything you think I could help with at all? @glossy shuttle

glossy shuttle
#

thank you

pliant onyx
chilly veldt
glossy shuttle
#

idk i just have an email issue

sick lance
#

I had a friend that took a new job, but ended up slightly worse off due to the cost of travel.

idle mica
#

Definitely, you've gotta factor in all that stuff, like health insurance (depending on where you live), etc. That was my concern with a role I'm currently interviewing for. Compensation is a bit on the lower end, but there are quarterly bonuses, and they cover 100% of all insurance premiums. It really balances out

idle mica
mossy river
#

How are you doing w33t? 😄

idle mica
#

Doing well! Staring at the queue, waiting for the next alert 🤣 How have you been?

mossy river
#

Ahah, the second you look away it will appear I'm sure 😆

#

Busy as usual!

opaque flax
#

Good morning jabba

idle mica
#

Right? That's how it always goes. A watched alert never fires or something lol. Glad to hear you're keeping busy! Unless it's too much, then I'm sorry lol

mossy river
opaque flax
#

It’s 11M

#

Am

idle mica
#

Central gang, lets go

unkempt talon
#

here its 17:21

mossy river
rapid merlin
mossy river
opaque flax
mossy river
sick lance
#

Dinner time, then hot tub 😎

rapid merlin
mossy river
rapid merlin
#

I do love a spag bowl

rapid merlin
mossy river
opaque flax
#

But I am fasting

#

Need to lose some weight to

mossy river
opaque flax
idle mica
#

There it is. I look down at my phone and BAM 🤣

opaque flax
#

Should eat

sick lance
mossy river
sick lance
#

That and the pool.

rapid merlin
#

I like swimming

calm hound
#

Hello everyone

sick lance
#

I prefer wild swimming to pools.

rapid merlin
#

I’ve never swam in a lake either

sick lance
#

Missing out.

rapid merlin
#

I would be worried about standing on something sharp

sick lance
#

I prefer lochs to sea, but depending on the loch, you can't swim with seals/dolphins/sharks or orca.

rapid merlin
#

I try hard to keep my feet soft. So rocks are scary 😅

shut hawk
#

If you're lucky you might see Nessie

rapid merlin
#

Reminds me of that movie

sick lance
#

Or unlucky if you're a fish.

rapid merlin
#

The water horse

sick lance
#

Ah, a kelpie.

rapid merlin
#

I liked that one

sick lance
#

What are you looking for, and why, exactly?

spiral iris
#

is there a version of this for Windows OS?

sinful moon
#

Not realistically, it's all over the place especially with standards changing over the decades

rapid merlin
sinful moon
#

Heck even the paths will be diffrent depending on how far back you go

#

anyways if you liked that picture then yep man hier will be enjoyable to you all too

worn turret
#

Sal 1 cert to expensive

#

Ngl

sinful moon
#

it's price compeditive with similar certs to be fair

eternal timber
#

Cert’s out

rapid merlin
#

Is there a way to monitor network 4G/5G

#

Without plugging a phone into another device

eternal timber
#

I had the strangest dream in which I suffered brain damage and kept spacing out with weeks passing in between

upper knoll
rapid merlin
#

?

mossy river
#

Depends on your phone

rapid merlin
#

As in my own network lmao

mossy river
#

You can connect it to mitmproxy

rapid merlin
mossy river
#

Mitmproxy is for all

#

I've used it on my iPhone

rapid merlin
#

I know we have net analyzer but it’s meh

ancient meadow
#

What's up y'all

vocal oxide
#

Hello everyone, I have a problem with the attack box, it does not have internet to download more tools.

rapid merlin
rapid merlin
mossy river
naive violet
#

Not unless you're a subscriber

pliant onyx
#

Mhm delyeeted after Jabba's response

sinful moon
#

Oh does subscriber actually give attackbox internet access these days? News to me

#

inb4 it's always been a thing lol

pliant onyx
#

It's always been- you sly fox

calm cradle
#

hi guyss

ancient meadow
idle mica
#

Finally finished SAL1 aaand I passed!

sinful moon
#

lol I am serious though, I had no idea, but yeah I had very little reason to stick with Attackbox for long

pliant onyx
vocal oxide
#

Windows is the machine to do a data dump

mossy river
ancient meadow
calm cradle
#

how re u today

ancient meadow
#

How was it?

naive violet
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1497)

pliant onyx
#

Most of the time

sinful moon
eternal timber
pliant onyx
eternal roost
idle mica
#

Dangit, one misclassification 😭 And the company has been taken over

pliant onyx
#

Nice

sinful moon
#

yee

pliant onyx
#

Elizabeth uses Arch btw

sinful moon
#

for over 18 years c:

idle mica
twin ridgeBOT
#

Gave +1 Rep to @eternal roost (current: #78 - 105)

pliant onyx
#

I thought I would have to wait for ages

sinful moon
#

back in my day we had dat sys v init, HAL, ALSA, and kernel 2.6.26

pliant onyx
#

Nvm it was the right password schyupid me