#cyber-and-careers

1 messages · Page 73 of 1

primal shale
#

It makes it kinda easy

lofty apex
#

Yes and I heared that exam is all about memorization

upper vector
#

Oh alright thanks didn't know about this new v7:)

fathom panther
#

Hey everyone! Loving the community here and have been having a great time working my way through rooms on THM! I just have a quick question! Since covid hit i've had to make a career change into tech, sat my A+ a couple weeks back and passed! Since then i've landed a help desk job. However, i really love the security side and over the next few years i want to focus on working my up to a security role. What path should i be taking to work towards that? I'm thinking of doing the net+ and security+ over the next year and a half and from there I hope to land a junior soc analyst role. Does this sound like the right way to go about it? Would love to know other peoples thoughts! Thanks so much in advance 🙂

pseudo creek
#

yes that sounds like a great way to get into security. Also like the above discussion, a CCNA would be a huge boost instead of Net+, just keep growing your skills, watch out for job listings for junior soc analysts, see what they are asking for and work towards that

languid hearth
#

the labs weren't exactly hard on the CCNA R&S tho

fathom panther
#

Perfect thanks a million! Is super exciting am super pumped to be on this path!

exotic epoch
stoic lotus
#

do you guys know any bitcoin miners that actually work? (solo computer)

quick forum
#

Why are you asking? Mining bitcoin is not worth it @stoic lotus

stoic lotus
quick forum
#

The power costs are too high compared to the return

stoic lotus
quick forum
#

I know the maths

#

There's a reason it's only mined on ASICs in countries with exceedingly cheap power.

#

You can do the maths too based on your hash rate.

#

And why are you asking?

stoic lotus
#

this is a free world ill ask whatever i please 😂 🕵️‍♂️

quick forum
#

I mean the discord rules apply.

stoic lotus
#

the only real rules are provided by nature

#

555

undone shore
#

(Bear in mind you're talking to one of the guys with the power to yeet ya out of here. Whether it's legal or not, a little respect and not being an ass go a long way 😛)

polar rock
undone shore
#

The answer to the question though, is probably not.

#

For that reason

#

No one really spends the time gaining knowledge about them because the cost is not worth the return

polar rock
#

^ ditto

stoic lotus
#

so is it worth it to mine any other crypto currencies? or do you believe crypto mining is obselete

undone shore
#

Not really, for either suggestion

stoic lotus
#

yall mustve forgotten about quantum computing 🕵️‍♂️

undone shore
#

It's not obsolete -- it's just not worth it for most people

#

A) Do you have a quantum computer?

polar rock
#

yeah its pretty obsolete now ish. theres still exceptions

undone shore
#

B) It's still very much up in the air what quantum computers will be good for

quick forum
#

I mean it's not so much, we know they won't be good for many classical problems

polar rock
#

bitcoin has moved on to much better things than just mining

undone shore
#

It's likely that they would be pretty good for things like bitcoin mining, but that's not guaranteed

elder grove
#

Tells him it's not worth it. Asks if it's worth it.

#

It's only worth it if you run about 85 extension cords from the the garages in your neighborhood, splitting the cost up evenly so as to not make a big stink. Make sure to get the green ones from around Christmas time so that they blend in with your surroundings.

Also, that's complete sarcasm. Don't steal your neighbors' power. Mining isn't profitable unless you get power dirt cheap.

stoic lotus
#

lmao

hasty geyser
#

I love the need to say that's sarcasm... ya know, just in case

undone shore
#

Poe's Law ftw!

delicate walrus
#

Hi, I just graduated from UC Riverside with a masters degree in Computer Science with a research focus on Operating Systems Security. My job offer got revoked due to the COVID situation. I'm looking for InfoSec positions so if anyone has any leads, please do let me know. Thanks.

#

I'm looking for entry level InfoSec positions in the US.

unreal arrow
#

There’s a job post in the #jobs-board maybe check that out

delicate walrus
#

sure thing. i'll check that out. thankyou 🙂

icy moat
#

Hey there, I just recently took the Cisco Sec + ..twice. and failed with a 710, second one was less, I know there is a new one out, should I study the old material or the new material? If I need to study the new material where is the best place to get it? Thanks

quick forum
#

Cisco sec+?

#

Do you mean CompTIA sec+?

keen forge
#

if you already took the old test, just study the old one. the old test is still available until june 21 i think

south nest
#

I think he means Cisco Cyberops maybe

lament bronze
#

Any bug bounty hunters here?

wise needle
#

#bug-bounty ? Also, it's better to directly ask question so people can see the question directly.

wraith thorn
#

Good day folks I'm struggling for almost a week finding the best path to take for self though to dive into Ethical Hacking path. I have some knowledge on Network, Linux and Windows, Network Security and ZERO knowledge on coding. hope you can help me. Thank you

trail granite
#

we are in the same boat i see

#

i just started with learning the basics on THM coding/programming will come later

dusk void
#

@icy moat wait until new course release or try comptia security+ .

lament bronze
#

@wraith thorn @trail granite I am also a newbie when it comes to ethical hacking. I just started doing tryhackme.

#

I completed my CEH 2 months back

trail granite
#

Yeah im learning for it atm

#

Got some experience in programming python and networking/setting up servers

#

So it wont be that hard i suppose

gleaming basin
#

Whats everyones opinion on Blue Team Certifications?

#

And is it relevant in US?

polar rock
#

blue team certs are amazing and hell yeah they’re relevant in the US

gleaming basin
#

Considering purchasing the Intro courses before I decide on the Level 1.

#

Its worth a little over $100 for all the intro courses :)

polar rock
#

Wait are you talking about general blue team certs or the security.blue team certs?

#

I wouldn’t waste your money on security.blue team

gleaming basin
#

Umm. Good question

#

Not sure. Link comparison?

#

I guess I was talking about securityblue.team

#

BTL1

languid hearth
gleaming basin
#

6 course for 80 euros

polar rock
#

They’re a very new cert so they’re not recognized

polar rock
# gleaming basin 6 course for 80 euros

Don’t get it a.) those small courses are basically just a quick grab for money and cover tools that you can get the same info for free b.) I’ve heard some not amazing things about the instructor and have been advised against it

gleaming basin
#

Fair enough. I trust everyone's opinion in this community.

#

Recommendations on some other blue team pathways, junior level?

#

CySA+? However, the recommendation is 4 years of experience + NET+ and Sec+

forest knoll
polar rock
#

@gleaming basin eLearn, THM is working on a path rn

static tide
gleaming basin
#

Cant wait to see the path. Super excited. Thanks for letting me know @polar rock

forest knoll
#

Have any of u guys done the CompTia learning through their site? Is it any good? Seems pricey

gleaming basin
#

Ive been using Professor Messer on youtube.

#

He covers exam objectives

forest knoll
#

I've been using an app with like 500 questions, just wanna make sure before I take the drop to buying a exam vouchers

stiff kiln
#

I've been using an app with like 500 questions, just wanna make sure before I take the drop to buying a exam vouchers
@forest knoll for compTIA exams ?

forest knoll
stiff kiln
#

Yeah, though in yet to actually do an exam
@forest knoll whats the app called ? If u don’t mind sharing, also check out examcompass.com they have practice tests as well

forest knoll
#

Been using those

royal heath
#

hello guys. I am new to kali. I was just going to follow one of the first tutorials and right off the bat the layout of kali that i have is totally different to the one on instructors screen. He also got different tools like golismero. Any tips for a starter?

polar rock
#

there are different versions and DEs for Kali

royal heath
#

I went and downloaded the one he has suggested from security offensive website and it is not the same. I tried getting from kali direct and again it is not the same version

#

I mean not looking the same and missing features

polar rock
#

If you downloaded it from there direct kali link then yes it is going to be different as they went through a major change from 2019.3 to 2020.4 kali

royal heath
#

that's probably what it is. The video I am watching is on 2019.3 version. The offensive security website is also only offering the new 2020.4 version of kali.

#

That makes sense

icy moat
gleaming basin
#

Well. I did not get that SOC job I interviewed for. At least I gained some interview experience.

#

Onto the next...

ancient prairie
#

it happens, you'll get the next one!

remote mauve
#

however i highly recommend reading some exam prep beforehand

gleaming basin
#

@ancient prairie thanks :)

polar rock
gleaming basin
#

Unfortunately, that was the only SOC job in my area. Currently there are none. But its ok, will continue to learn and grow :)

polar rock
#

If you’re set on staying in your area that will make it harder

#

the easiest way to get a job is being willing and able to move

keen forge
#

@gleaming basin same with my sys admin job :/. Onto the next aha

gleaming basin
#

😩

timber heart
#

could anyone pls share some threads/pipeline which will guide to what to study to get prepare for OSCP from noob level ?

lofty apex
timber heart
#

Pretty amazing stuff....Thanks ARZ

flat barn
#

The road is long 😄

lofty apex
#

Yeah xD

ancient prairie
#

have any eCPPT-holders also completed Throwback and would say it's good practice that lines up with course/exam objectives?

polar rock
#

Only people I can think of are @elder grove and @pseudo nacelle

elder grove
#

Some of the pivoting is relative. Enumeration always is as well.

cosmic ingot
#

Most people outside Cybersecurity profession don’t fully realize and appreciate the complexity of security professionals’ job. I have been publishing and updating this MindMap for many years, not only as an effective educational tool but also enable professionals use this … Continue reading →

pseudo creek
#

pretty accurate it seems although you can find some blending... like Security Architecture (my area) has some cross over with business enablement

distant pier
#

Good one, but remember that mindmap is focussed on the operational units in how a CISO manages those responsibilities and capabilities. It can be different in another organization, and especially in another industry that might be more traditionally focussed.

languid hearth
#

to anyone whos gotten a SANS cert - what do the shipping times looking like?

cosmic ingot
#

yup, I don't think there's one single map that you can use as a definitive reference, but I thought some of you might find this helpful nevertheless 🙂

meager hazel
#

I actually got it around the same time I got my OSCP cert and that took like 6 months lol

languid hearth
#

damn

#

i wish there was an option for faster shipping kekw

pseudo creek
#

spooks are you doing the 100 days of code Python class from Udemy?

languid hearth
#

nope

#

i like bash. bash is my favorite, why would i use anything other than bash /s

pseudo creek
#

ha

chilly barn
cobalt linden
#

I wanna HACK SOMETHING and get some swag

pseudo creek
olive forge
#

Iam planing to do Master in Cyber security . Any drawbacks?
Any suggestions

pseudo creek
#

where are you located?

#

In the US, getting certs will do you better if you are trying to break into Cyber Security. a MS in Cyber Security is better suited if you are already in the field and looking to get into management/higher level position

#

primary drawback would be that a MS would not prepare you for most entry level Cyber jobs and you'd still need to get some certs to be considered entry level, better time spent not doing a MS until later

olive forge
#

IamM from india by doing certifications can i get job abroad?

pseudo creek
#

depends what country, if you were talking about doing a MS in your country of choice as a means of being local, that could help but I will say many countries have a bias in security towards citizens of that country, US has a strong bias especially

olive forge
#

Thank you

willow gate
#

Like I'm planning to do my masters from Europe (italy most likely) and get some certs during that. Will try to get a nice job before my masters end.
That's the plan for now

frigid niche
#

I love the job market in the US right now. All I see are Intern, Senior, Principal, Architect, Manager, Director positions in my area. I have seen some "Entry Level" positions, and I looked at them where they require 5 years of security experience... I'm like WTF? I'm looking to move to security, I have gone through the Sec+ material, and I have the basics for Splunk and pen testing. Any suggestions from the peanut gallery? I am an experienced system admin working mostly with Linux/Unix/VMware, but I can work with Windows too.
https://www.rvcj.com/twitter-is-sharing-impractical-job-requirements-set-by-recruiters-while-hiring-new-employees/

pseudo creek
#

do you see any soc analyst type job listings? I'd also look for system security as a keyword

south nest
#

Is Pentest+ worth is now?

distant pier
#

Now that it is on the DoD recognized list? Probably is.

bitter arrow
#

gov jobs go brrrr

polar rock
shrewd sparrow
#

Hello All!
wondering if you guys have seen the ITCareerSwitch thing about the Cyber Security Trainee. I've had a little look round about it, it looks and smells like BS and usually thats because it is!

Just wondered if anyone here has any more information on it, or has given it a go? you never know eh?

polar rock
#

If the first result on google is “is ITCareerSwitch a scam?” I wouldn’t even look any further

#

There basic thing is just making you overpay for course material from other vendors then taking the A+ which is fairly arbitrary if you even have any clue about IT. And then something a bit more specific like CySa+ or CCNA.

#

their entire business model is just repacking exams

#

lmao they even lie “Official CompTIA A+ Exams (Worth £322)” the A+ is £164 without the student discounts as well

shrewd sparrow
#

fair play. I figured as much, but I thought I would put it out there.

#

thanks for the time though!

stoic linden
#

What do people thing of the EC council CEH cert vs the offensive security pen test cert? Would one be more highly regarded than the other as a first cert to do??

undone shore
#

CEH is widely regarded to be a meme

#

Go OSCP, if it's a choice between them

#

But bear in mind that it's not just a case of walking out to the shops to buy either of them

stoic linden
#

I completely understand there is a lot of work in both but I have the choice and would much rather put the time and effort into the one that is going to hold more weight

static tide
#

oscp teaches you more and holds more weight

junior shuttle
#

can anyone send me a good cyber security analyst roadmap ?

coarse cape
#

sry wrong channel.

pseudo creek
#

that is a good 'roadmap' of sorts

warm hinge
#

Can you really make a career out of bug bounty programs??

languid hearth
#

you can make a career out of anything, if you've got a knack for it.

warm hinge
#

Niiiic3

odd field
#

Hello does anybody know the standard length of a Curriculum Vitae (CV) for the United Kingdom. is 3 pages fine?

quick forum
#

Generally don't exceed 2 sides

undone shore
#

^^^

#

Keep it to two sides of A4

quick forum
#

Remember 2 things

undone shore
#

Your name

#

And email

#

(Yes, I've seen a CV that didn't contain either of those things)

quick forum
#
  1. They're likely to be machine parsed to start with, so keep it straightforward
  2. The poor HR person is likely to have a big pack of them. Make life easy for them. They'll like that.
cosmic ingot
#

we had a class about this in the program I'm currently enrolled in. the instructor said one page. the nice thing was that everything he said, he backed with logic and experience

#

are things so different in the uk? I thought you shouldn't exceed one page without a good reason, but ideally still try to keep it to 1

odd field
#

so 2 sides meaning 1 page? or 4 actual pages on 2 pieces of paper?

#

thanks for the advice

cosmic ingot
#

I think James means 2 sides of 1 page

odd field
#

dam its going to be hard to keep it on 1 page

static tide
#

do resumes even exist on paper in 2020

odd field
#

no i have it as docx or pdf

cosmic ingot
#

uh, yes, but the same applies to a pdf

#

so that doesn't make a difference

odd field
#

fml now i have to figure out how to squeeze in all the vital info.

static tide
#

how many years of experience do you have?

#

i've got 2 jobs on mine, as well as all the other stuff and it fits nicely on one side

odd field
#

6 years of experience 4 different jobs

static tide
#

ah okay so you probs can't fit that on one side

odd field
#

narrow margins ftw, hardly no spacing also now I guess

cosmic ingot
#

I have a class right now but I'll go through my stuff later and send/link you anything relevant I can find if you want @odd field 🙂

odd field
#

also for acronyms do we include the full words or just the acronym?

#

much appreciated @cosmic ingot

#

i feel like recruiters and HR will not understand the I.T acronyms

static tide
#

depends on the acronyms i guess

#

for certs i'd say not, so things like OSCP and CEH would be fine

odd field
#

why cant people read just 1 extra page 😦

#

I would get it if its like 4 to 10 + pages long

static tide
#

i suppose if you put the most interesting stuff at the very top, the more likely they are to read more

odd field
#

ive done that for sure, key achievements and key skills followed by professional experiences

quick forum
#

You want to make it easy for HR

odd field
#

Aaa man I get that, the positions im applying for do not have over 100 candidates

pseudo creek
#

primary reason is people get hundreds of applications... beyond that, there is an idea in business in general that you should be able to sell yourself in 1 page and if you can't be concise on a resume, you can't be concise in your work. I learned throughout the years that people won't even read an email beyond the first paragraph

odd field
#

so dam recruiter/HR must read that extra page lol

quick forum
#

No, they don't have to

#

They will just pass you over

odd field
#

aaa 😦

#

alright I shaw try my hardest to get this thing onto 1 paper page 2 sides then.

undone shore
# odd field so dam recruiter/HR must read that extra page lol

Look put it this way. You're applying to them, not the other way around. As far as they're concerned, you are one of many. There is nothing special about you -- not unless you can get them to read your CV. Then there might be something special, but before that you're a name on a page

#

If your CV isn't what they're looking for, they'll dump it without a second glance

odd field
#

true true

#

bye bye header and footer spaces

#

making progress 2.5 pages

warm hinge
#

anyone here doing ptp?

undone shore
#

Maybe try removing the less important stuff, rather than messing with the spacing?...

odd field
#

Im trying 2 remove the fluff

pseudo creek
#

it should really just be a summary, not a detailed work history

odd field
#

thats what it is, but when you have mucho experience and key points its hard to summarize it all.

#

but that you for all the advice people

#

much appreciated.

long ferry
odd field
#

got it 2 pages 🙂

rugged sable
#

Hi!

Have a TS/SCI clearance, BS compsci, CySA+ and pentest+ but I have no experience. Most of my experience is as a language analyst and anything cyber related I learned through labs on my own/ htb/ thm.

Getting out the military in 2 years is there anything else I can bolster my resume?

#

any suggestions?

#

❤️

pseudo creek
#

Other advice I'd give to people is keep your social media upstanding because if you think people can't find you, you'd probably be wrong

brazen glen
#

@rugged sable - I got out about 8 years ago and can tell you there are a LOT of programs out there for transitioning vets to assist with finding work. BEFORE you get out, use your Tuition assistance for any classes you want to take.

#

If you want to keep your TS/SCI clearance, join Clearance Jobs as there are a lot of companies that will hire you just because of your clearance and can provide training if needed.

#

After 2 years of leaving Active Duty your clearance expires regardless of when you went through reinvestigation

brazen glen
south nest
#

I have an interview tomorrow what should I review?

rugged sable
#

whats the interview for?

south nest
#

Security Analyst im looking at their job page and gonna review that but anything else?

pseudo creek
#

depending on interview, they may ask some behavioral questions, those are always to good to review as well as what do you bring to the team that others may not

visual nova
#

how is the cyber security jobs in the UK

#

thinking moving their out of the states to do Cyber as I gain experience here in about 7-8 years in my 30s

pseudo creek
#

only thing I've seen from recruiters/people that live there is they do not pay as well and it seems for certain jobs (pentesting) you have to have certain certs

rugged sable
visual nova
#

that's what I was thinking but I wanna learn more about the culture etc gain some different experience

#

I am going to stay in the states first get my experience and certs under my belt

pseudo creek
# rugged sable are you saying do not pay as well and taking into account the lower cost of livi...

well that is a complicated question... and I don't know if it evens out later career but based on conversations I've seen, it seems like entry level security people make $30-$40k/yr in UK, while in the US (it can vary) it is $60k-$80k. And US companies are tricky these days, some offering 'unlimited PTO' but its not truly unlimited. Like as a senior level security person, I get 6 weeks of vacation but I suspect the pay difference between me and a senior level security person in UK isn't double

visual nova
#

oh ok gotchy

#

gotchu , but I health care and other things of that nature is a lot cheaper than here in the US

#

but entry level here I would say is about 75K to 85K

pseudo creek
#

yeah 60k is a really low end

visual nova
#

I go to a University were they require you to get 1 year of work experience as a Cyber security Analyst etc basically within your degree filled and your paid , plus I have net + and sec + so the lowest I am taking entry is 75

#

im asking 80k

#

im asking 85k

pseudo creek
#

hopefully you get it, and it is definitely possible

visual nova
#

meet in the middle at 80k but London in not cheap

#

but I am hearing from various poeple on Linked in too come over after I get 6-7 years of experience

pseudo creek
#

and also be aware that the US, if you are a US citizen, will collect taxes on your income still

visual nova
#

easy for me to get a job and the pay should accommodate my experience hopefully be a engineer or red team by than

pseudo creek
#

unless you decide to give up your US citizenship

visual nova
#

OK didn't know that

#

I was going to move back to the states eventually but Live in England for a few years . a good 5 - 6 years

#

But I will decide when I past that road I guess

pseudo creek
#

another potential option is try to find a company based in the UK or with offices at least

#

could get a TDY for a period of time

visual nova
#

temporary citizenship

#

I will look into that as well

pseudo creek
#

its not completely common but sometimes a company will have a need for people in a foreign country and offer you a temporary position

#

so could spend a year or 2 in a foreign country, but it isn't guaranteed although could make job searching/networking a little easier if you have coworkers in the UK

visual nova
#

right ok

#

I will keep that in mind in the futuer

#

future

dusky oracle
#

Am I able to apply for jobs in the US if I am from Canada? Does it need to say that I need a visa?

polar rock
#

@dusky oracle google would give you a better answer than a bunch of random hackers on a discord

dusky oracle
#

👍

forest knoll
#

Stupid question, where do I write up the OSCP exercises? Shall I just document them and tac them to the bottom of the lab report?

fast heart
#

I think so

forest knoll
#

Did u do them?

fast heart
#

nope

forest knoll
#

Lad...

fast heart
#

😄

forest knoll
#

I went through and screenshotted them, was bloomin 81 of them. Looked online and some dude says there's like 108

#

One of them is empire 🤢

fast heart
#

the whoisflynn's lab report template has the excercise answers as an appendix at the end

forest knoll
#

Ohhh so it does, might use that instead of Notion then

undone shore
#

@forest knoll I'm with Szy -- 100% don't recommend.

forest knoll
#

Seems like WAY too many exercises and most seem pointless

undone shore
#

They are a huge timesink. The latter ones are very open ended, and AFAIK, if you don't answer even one of them fully, no points

forest knoll
#

I was wondering if I get 1 "wrong"

undone shore
#

It was getting to the stage where I was writing full page answers for each question, and there were at least three per section

#

Not worth it for five points.

forest knoll
#

Yeah it looked like a lot

undone shore
#

If you're that close to failing then you probably shouldn't be passing anyway (and I say that as someone who failed)

fast heart
#

well, if you really have nothing else to do with your time then go for it

forest knoll
#

I'll probably do a few test reports on lab machines for practice (labs start next week)

#

True true

fast heart
#

but otherwise just study for the exam itself 😄

forest knoll
#

Exam it is!

#

Thank you for saving me from the huge time sink

serene briar
#

Guys new to channel as well as THM.

#

First of all thanks for the amazing content on website.

#

I wanted some help deciding what to be done in terms of security as a career. Currently I am working as a Technical specialist and helps with system integrations and other tasks related to consultancy for my clients in my current job. Want to move to a full time Cyber sec analyst or similar roles

#

What would be the best certs to learn about to achieve this.

forest knoll
#

If I'm wrong feel free to correct me.

meager hazel
#

OSCP is a bit too niche for an analyst role. Might want to start off with one of the "mile wide, inch deep" certs like Security+

#

Also gives you a view into other positions that you may want to consider

serene briar
meager hazel
#

Ah, that's fair. Sec+ could do either of those especially in the objectives you might not have gone deep in yet (cryptography, risk/compliance, etc.)

serene briar
#

Based on what I am reading on their website its more targeted towards guys who are new to the field. Though I am thinking of getting that cert and start from there.

#

Will getting a video resources from Comptia be a good idea or is there any good alternative available for study purporses

warm hinge
#

combination book and videos from for example professor messer

serene briar
#

Will definitely register this for my brother who is about to passout his major and thinking about getting into cybersec

serene briar
warm hinge
meager hazel
#

tru Standard formula for CompTIA+ studying is a good book, practice exams and Prof Messer (he doesn't have videos in the CySA+/PenTest+ tier or above though)

true sandal
#

Doin Sec+ right now with Messer and Darril Gibson's book and it's goin alright.

#

Have a company-sponsored 8day workshop ahead of me in January as well though, so I hope I'll be able to pass after these 3 things.

serene briar
true sandal
#

Absolutely.

serene briar
covert warren
#

Hello there @everyone

undone shore
#

Please don't try to ping everyone 🙂

#

A) It insinuates that you think we're dumb enough to let people ping the entire server

#

B) We have close to 40,000 people in here -- guarantee most of them don't want pinged

covert warren
#

@undone shore okok sorry

#

Anyone here pass the oscp???

warm hinge
#

some have

forest knoll
#

Quite a few tbf

#

I can think of 6 off the top of my head

covert warren
#

If anyone have pass the oscp please tell me!!!

undone shore
#

👀

warm hinge
#

if you have a question just ask @covert warren

covert warren
#

I want to know the roadway map to reach oscp certification... I just put a step in cyber security.. Anyone can help me..

unreal arrow
#

If you check the pins in #resources there are a lot of tips and machines to prepare for OSCP

warm hinge
#

i wanna be a computer engineer

#

and go to

#

MIT

rancid adder
#

that's a very nice goal to have 🙂

covert warren
#

@unreal arrow thanku so much🌹

languid hearth
#

any particular reason MIT?

polar rock
#

Because MIT

somber bramble
gilded prism
#

Penetration testing isn't that bad Goal ig

warm hinge
somber bramble
#

can I dmmmmmmm

warm hinge
#

ig

#

sure

gilded prism
#

Hey Can i still do today's Christmas ctf task tomarrow or will it disappear everyday ?

#

NotLikeThis uh?

#

I meant advert of cyber roomthm

stiff kiln
south nest
#

I got a video interview friday for Security Analyst position! cant believe it lol

#

did well on the phone one today

merry hound
#

Legoo

unkempt nova
#

@south nest Nice to hear that! What is your education background?

full summit
#

so I was wondering if binary exploitation is worth it nowadays in cybersecurity, or if there is a specialization related to it. I am asking because most of my experience is in low level programming, compilers and operating systems (right now I work as an intern on a Linux Kernel Dev position) and I seem to enjoy this category of CTF's the most and they come to me the easiest. I want to work in Cybersecurity, are there any profitable branches that focus on this side of security? Someone mentioned Malware Analyst, but that is more on the blue team side

quick forum
#

If you want OSCP, you need binexp

forest knoll
#

Pretty sure WhatsApp had a buffer overflow last year.

distant pier
#

The specialization is in malware analysis, exploit development/research. @full summit

full summit
#

Nice, will look into those. Thanks :D. So it's not entirely useless learning how to break this stuff. It just seems to be so rare compared to web stuff and what a bug bounty hunter does

#

everything seems to be about web nowadays

distant pier
#

Application Security would be where it is prevalent.

unkempt nova
#

Passed OSCP

forest knoll
#

Way!!! Congrats!!

#

How'd you find the exam?

unkempt nova
#

You just need to keep yourself cool

#

And need to know your method

forest knoll
#

I'm looking at booking it around mid Jan maybe

#

First time?

undone shore
#

Congrats! Gave you the role 🙂

unkempt nova
#

87.5 Marks

forest knoll
#

Smashed it

unkempt nova
#

Thank you @undone shore

forest knoll
#

Oooooo Muiri go Muiri!

undone shore
#

Actually, what's the IP. Gimme a sec. 25.107

#

Did you get 107? (Not mentioning the name)

unkempt nova
#

It was not in my exam

#

😦

undone shore
#

Damnit -- still haven't found anyone who's managed it

#

Beginning to think that damn box is impossible

#

Thanks anyway -- and again, congrats!

unkempt nova
#

You attempted the exam ... right?

undone shore
#

Mhm. Couple of months back

#

Got hit with four horrific ones

forest knoll
#

Can u write scripts and take them in with u?

#

Yeah Muiri has had 0 luck

#

(u can tell I wrote them cause they're terribly written)

undone shore
#

I see no reason why not

#

They're just more tools 🤷‍♂️

unkempt nova
#

What should i try next?

languid hearth
undone shore
languid hearth
#

not likely

#

they make small changes to some boxes

forest knoll
languid hearth
#

no cap id automate web recon

undone shore
#

Worth a shot!

noble barn
#

anyone work in the industry and may have some insight as to what a technical interview for cyber analyst might entail?

languid hearth
#

Networking knowledge, familiarity with Wireshark, TCPDump, TShark, Malware, Viruses, common attack types, Splunk, SIEM, SOAR, general Triage process, and stuff like that.

hazy egret
wise moon
#

any new challenges will be open lately?

static tide
#

has anyone taken a sabbatical ‘year’ in the uk? i wanna go travelling for a bit (when covid dies down). was thinking of working whilst abroad but would deffo prefer having the time off

#

i know it’s best to just ask my employer but wanna know the likelihood of it

warm hinge
#

One of my friends did that. But while away started contracting.

#

Gets £750 a day and just works remotely somewhere in the world

nimble wadi
#

that sounds like living nowt like being your own boss 😄

static tide
#

wowie yes please

cosmic ingot
warm hinge
#

He does DevOps stuff mainly

#

He was one of the guys from canonical that built openstack/enhanced k8 and docker

leaden yew
unkempt nova
#

@leaden yew Thanks 🙂

next vigil
#

Guys is professor masser training vids paid or free? i see both there for sec+ but cant figure out the difference between them

static tide
#

free

#

think you need to pay to download them or something ?

#

and the ebook/book is paid too

#

but just search on youtube

next vigil
#

was about to pay for the video lecs when i saw that free vids option and it got me all confused

next vigil
noble barn
peak jolt
#

Hey all, I currently have Sec+, Linux+, CySA+, CASP+, CEH, and GCIH. I have to get PenTest+ for work, but after that my plan is to work on OSCP. Any advice on prep materials for the OSCP? Any general advice from anyone who took the exam? Something you wish you knew before you took the exam? All help and advice is appreciated. Thanks!!

languid hearth
#

You should be fine to jump right in

peak jolt
#

I'm also working on improving my scripting on the side. Feel like that should help

#

@languid hearth Looks like I got some of my certs added to my roles in the past. Don't remember how I did that... Do you know the process?

languid hearth
#

you just have to ask!

meager hazel
#

Between aiming for PenTest+ and having done some THM already, you should be good to start. If some things in PWK aren't clicking just supplement it with more labs like THM

south nest
#

does anyone here give mock technical interviews 🙂

#

for an entry level security pos

languid hearth
#

not necessarily intro but there are intro topics referenced

south nest
#

Cool beans i just feel like my interviewing skills need to be worked on ill ask some buddies to ask me questions or something

merry hound
#

What would be the certifications that one should get from start and moving on to next level?

pseudo creek
#

for what purpose?

peak jolt
languid hearth
#

you'll have to ask a current mod, I'm former 😅

quasi stream
#

We don't have roles for CASP+ and GCIH atm but I've applied the others @peak jolt (:

peak lion
#

I have some certs ... are there any benefits to adding the roles or just aesthetic?

quick forum
#

Some of them give you access to a secret chat

peak jolt
quick forum
#

That advice is honestly the best you can give tbh

#

It will vary area by area

peak jolt
#

I am not an expert, but I am in a cyber security role and Sec+ is required. All certs build off those topics so it will set you up to not get tripped up on industry acronyms and phrases most people would assume you know

peak lion
#

Sec+ 👍

quasi stream
#

I've asked if we can get these added, but the person to ask is away for a day or so. If they get created, I'll add them to you and let you know 👍

peak jolt
quasi stream
#

Haha thanks 😄

leaden yew
#

I am struggling to find a Junior position in Cyber Security, would working in something else (pure programming, IT services) help to get accepted? I am worried that the companies not involved with cybersec might not want to fund my certs, conferences or CTFs.

peak jolt
# leaden yew I am struggling to find a Junior position in Cyber Security, would working in so...

I worked for a company in their IT department and they gave everyone the option every quarter to spend up to $xxx on certifications and you could get reimbursed. All depends on the company. Letting their employees get certs for free allowed the company to get people to learn skills and become better at their job. All depends. Having experience in IT would come in handy with a junior position if you also get a cert. Also, if there are any projects you can volunteer to work on related to security (like setting up a process for encrypting employee workstations) it would look good on your resume especially if it wasn’t required for your job but you went out of your way to show you can handle security related tasks.

#

If you can get right into a junior cyber security position then by all means do that, but a general IT job is better than nothing so you build experience in the industry.

leaden yew
#

Let's say I want to get a position in a SOC team or Digital Forensics, how can I increase my chances with a job which has nothing to do with security?

quick forum
#

Do some desk support for a bit?

golden ore
uncut falcon
#

Hey, so i have a job interview tomorrow at 3pm for a 2nd line technical analyst position, some of the interview questions are going to be discussing my networking knowledge, i did Cisco's routing and switching course to get onto my degree but that was 3 years ago, so my knowledge has slipped a little, does anyone have any links to some bite size digestible information for my to brush my knowledge up with, they're also going to ask me about cloud and infrastructure, which honestly i don't really have any cloud experience they're willing to pay for people to do certifications which i will do but i would atleast like to present some basic knowledge of cloud infrastructure to get an edge in the interview, does anyone have any recommended reading or videos that i could use for that? Thanks in advance.

terse canyon
#

I am working on a formal report for my technical reporting class and was wondering what type of report you would consider an after action pentest report so that i know which format i should follow while writing it

polar rock
#

those are two very different styles so you can get a good understanding of how people adapt them

#

red siege are very well known for their reports but as you can see they are very different than the offsec idea of a report

terse canyon
#

Thank you very much!!! This type of writing is very different than what i am use to

distant pier
#

You might be able to score extra points, by including a second document that represents the Confidentiality Agreement (CA) or Non-Disclosure Agreement (NDA). @terse canyon

terse canyon
#

especially if this is the career i really want then i better get good at reporting my findings lol

polar rock
#

it can actually be easy once you have a template to work off of

terse canyon
#

would be a lil easier if i had actual data to work off of instead of coming up with this stuff off the top of my head

#

is it considered plagarism to use one of these reports findings?

polar rock
#

you could take thm rooms and make pentest reports

terse canyon
#

now that is a good idea

#

2 birds 1 stone

flat sedge
#

@terse canyon The value in a pentest report is walking the audience through recreating your work, and the remediation suggestions to prevent another attacker from following the same path you did. You could get root on an entire environment, but if your report doesn't show how it was done and suggest remediations, it has no value

terse canyon
next vigil
#

how is security+ study guide from packt? i just found out that i had it from one of the bundles i purchased a while ago on humblebundle

peak jolt
#

what version of Sec+ is it? Might be out of date

pseudo creek
#

and most packt+ books are questionable

peak jolt
#

I have no experience with packt+, but very important for CompTIA to always check the version. Sec+ has changed a lot over the last few versions especially

pseudo creek
#

that one actually has decent reviews on amazon and yeah looks like it was for the previous Security+ exam

peak jolt
#

was it for version 401? Current versions are 501 and 601 with 501 being retired in July 2021

pseudo creek
#

ahh said 501, I just googled and saw 601 was latest

peak jolt
#

501 is ok if you plan to take the exam before it's retired in July

pseudo creek
#

so there you go efex, sounds like it probably isn't a bad book based on Amazon reviews, but just watch what version you register for

junior fjord
#

Hi everyone! Total n00b here. Looking to make transition into CyberSecurity and trying to develop personal road map. Passed my Network Plus and taking Security Plus in two weeks. Debating what I need to do next. Most likely signing up for https://tryhackme.com/signup but seeking general thoughts since I am no experience in IT. I come from a Sales and Marketing background. Liberal Arts major. Appreciate any suggestions, ideas, or thoughts. Thanks!

pseudo creek
stable delta
#

Hello I'm newbie here too! I'm on the same page as texassamurai but come from a different field of work. I just have a question re entry level jobs before taking the cybersecurity route and that is what qualifications/certificates should I go for before applying for jobs in IT field. Thank you ❤️

flat sedge
#

get a degree of competency in an IT domain before jumping into security - it'll make your life easier than trying to learn everything all at once

pseudo creek
flat sedge
#

you'll eventually learn a bit about all the domains, but it's confusing to approach networking from the admin side, the network side and the programming side at the same time - common paths are A+ -> net+ -> sec+, or Cisco certs

stable delta
flat sedge
#

honestly, i only care about the business side of things just enough to know whats in scope for my current project... if that's what you are into, a project manager path may fit better in your wheelhouse

stable delta
#

I don't think I want to be a project manager

pseudo creek
#

or look at the compliance part of security

stable delta
#

I'm kinda done with people-ing now

flat sedge
#

if you are done with people-ing, don't do compliance

#

it's 95% people-ing

pseudo creek
#

business analyst is peopling too

stable delta
#

I know

#

But it's less than what I do now

#

I deal with the general public and there's only so much stupidity I can take lol

flat sedge
#

i like what i do, because it's mostly 'go into the cave and work, do NOT talk to people'

stable delta
#

Not saying I'm a genius either

flat sedge
#

do not do compliance if you have a low tolerance for dumb

stable delta
pseudo creek
#

for compliance, you can do internal compliance so its not the general public, that is the role I'd associate most with business analyst

flat sedge
#

because you WILL be asked 'can i use whatsapp to communicate confidential documents?' on a semi-regular basis

pseudo creek
#

nah, that isn't compliance

stable delta
#

I get asked worst than that

flat sedge
#

i did internal compliance for PCI, SOC2, HITRUST for a bit - it was all people-ing and telling the sysadmins they can't use a ssh key to log in directly as root

pseudo creek
#

compliance is ensuring that you are meeting a certain requirements and documenting

stable delta
#

Yep

#

That's too boring

#

I looked into it

pseudo creek
#

that is pretty much security form of business analyst

stable delta
#

Ok

#

would it be useful if I say what kinda things I want to do in a job to give you an idea?!

flat sedge
#

it is compliance when it comes up during an external audit for program certification 🙂

stable delta
#

They're very broad though

pseudo creek
#

sure try

stable delta
#

Erm

#

I suddenly feel awkward now lol

#

ok

pseudo creek
#

honestly, why do you want to get into IT?

stable delta
#

so I like analysing data and solving problems and fixing them but I don't want to go into first line tech support role, I don't think I have the patience to deal with people who don't use common sense even though i can be dumb at the best of times. I just know i'll be really curt towards people.

pseudo creek
#

you could look into SOC analyst

#

blue/team SOC analyst, where they analyse traffic/logs, etc

stable delta
pseudo creek
#

there is generally a lot of people-ing in security, sometimes with SOC analyst, not so much but security and IT are generally full of people-ing

stable delta
#

It's either IT or sciences and with sciences you need a degree in sciences which I can't afford and don't really want to do another degree

pseudo creek
#

programming maybe less so

flat sedge
#

Working security is almost always a large amount of people management. A SOC role still will require a lot of emailing and communication with other departments

stable delta
#

That's fine

#

what I mean is I don't want to deal with general public anymore

flat sedge
#

and in the worst case, a LOT of argument about who is responsible to fix stuff

static tide
#

i work in a soc and it sounds like something you might like in entry level security, based on what you said above

pseudo creek
#

and generally people will see you as the enemy in security, so its not only people-ing but people being hostile about it

somber trout
#

yeah sorry

flat sedge
#

Zojja is absolutely right about the hostility. Building bridges instead of burning them is 90% of the job

stable delta
static tide
#

net+ and sec+ are great beginner ones

stable delta
flat sedge
#

Entry level soc is usually A+ , Net+ sec+ path

stable delta
#

Ok

#

Do I need to do all of them or any of them is fine?

static tide
#

how competent are you

flat sedge
#

I'd also recommend start playing around in a home lab with CentOS and Splunk to get started figuring out logs

stable delta
#

I got the necessary skills, analysing data, communication,

static tide
#

it skills?

stable delta
#

My IT skills are ok

flat sedge
#

How familiar are you with SELinux?

stable delta
#

I mean

stable delta
static tide
#

if i asked you what happens at a high level when you visit google.com, could you tell me?

stable delta
#

Nope

static tide
#

okay, start with net+ imo

flat sedge
#

SELinux is a great way to get started figuring out logs, because it's hard as hell to understand until you get what its doing

#

it'll also build that log analysis skillset needed in a SOC role

pseudo creek
#

Splunk has a free intro course online too

stable delta
#

Ok thanks everyone ❤️

#

I'll have to do my research properly and look into all of this

pseudo creek
#

good luck 🙂 and also using TryHackMe is great for honing skills

flat sedge
#

when you get a home lab set up, it's fun to see if you can detect yourself attacking your cyberrange

stable delta
#

So do you suggest I install this home lab and have a go to see how much my level of understanding is?

#

will that help me?

flat sedge
#

if you don't have much of a budget, you don't need a lot of resources to get started

stable delta
#

I have a budget

#

I can't afford to spend now

polar rock
#

A home lab can be as simple as a second hand server that’s running multiple vms

stable delta
#

We've been told we'll be made redundant soon 😦

pseudo creek
#

honestly, I'd just use TryHackMe, look at Net+, look at splunk training for their fundamentals course

flat sedge
#

install a virtual machine on your main PC (i like vbox for windows and ovirt for linux) and build a few low ram and disk machines to get started

polar rock
#

or an intel compute stick

stable delta
#

ok guys

#

I know you're all helping

#

but this is too much info now

#

I'm sorry

polar rock
#

or use gns3 it’s a great and not resource intensive way to virtualize a lot

#

you asked about my favorite topic what can I say 🤷‍♂️

flat sedge
#

that's fair quirky - stick with where you are comfortable then, and slowly build out

stable delta
#

Can I go back to the very basics please?

#

So

#

Right now

#

I just have a laptop

#

with an additional screen

pseudo creek
#

yes, look at Net+, look at TryHackMe, hone your Linux skills, hone your networking skills

flat sedge
#

to summarize: a+ net+ sec+ and splunk training course 🙂

stable delta
#

Can I install something on my laptop to test myself?

#

play around or whatever

pseudo creek
#

most people think A+ is too basic (I am not familiar)

flat sedge
#

A+ is for people without much IT background

static tide
#

use professor messer on youtube to study for net+, and see how you find it

flat sedge
#

if someone has a BS or BA in CIS or CS or related, i'd say skip it

#

going for entry level, there's an 'understand the basics of hardware' requirement though

stable delta
#

I have no knowledge of IT let's stick to that because this has gone beyond my brain now

pseudo creek
#

ok then look at A+ it seems

stable delta
#

or maybe because it's the end of the day and my brain is fried from dealing with people lol

#

ok

#

i'll look into A+ and Net+

pseudo creek
#

you are just going to build skills as you go

flat sedge
#

security as a domain is the superset of all IT domains - it's really easy to get out of depth very quickly

stable delta
#

I can see that

flat sedge
#

the key thing to remember, is that you want to feel dumb every day, as often as possible

static tide
#

give this a watch, it’s the whole syllabus for a+

flat sedge
#

because that means you are pushign yourself to learn every day

stable delta
flat sedge
#

if you never feel uncomfortable or dumb, you're doing IT wrong

stable delta
#

lol

#

make myself feel dumb everyday

#

never thought I'd get that advice

flat sedge
#

break a thing you own, and then figure out how to fix it

stable delta
#

I do have a very old laptop

flat sedge
#

for linux, it's stuff like accidentally installing over your bootloader and figuring out how to recover the partitions

stable delta
#

would that work?

flat sedge
#

that would be a great device to install ubuntu or fedora or centos on

static tide
#

don’t worry about that yet imo, you need to know the basics of it before you start breaking things

stable delta
#

@static tide this link has a million videos to go through!

static tide
#

it’s everything you need to know for the exam :)

flat sedge
#

learning linux as a daily driver OS, i wouldn't worry about deliberately breakign it. you'll do that anyway

stable delta
#

@flat sedge is having knowledge about linux important?

flat sedge
#

for security? I think so

static tide
#

i’m not forcing you

flat sedge
#

for THM? you'll develop a lot of basic linux knowledge going through rooms

stable delta
stable delta
#

I suddenly feel reduced to a teeny tiny miniscule irrelevant dot in a room full of IT giants......

ancient prairie
static tide
#

well he has a second playlist too

stable delta
#

Right

#

I've signed up to tryhackme website and will work my way through all of the information on there, will watch the videos on the weekend and get my head round what I really need to do

#

Thanks everyone for all the information/advice ❤️

#

I'll stay on the server if it's ok for any future questions

clear trout
#

idk anyone in here, but I wanted to share that I got promoted at work as Information Security Analyst - master. (my work has levels). I graduated college about 4 years ago and I can't believe I've made it this far!

undone shore
#

Well done!

torpid mulch
#

I'm sure this question has been asked a thousand times, but i keep reading conflicting info and am trying to put together a battle plan...
I'm currently employed on what you could say is a low-level digital forensics role, with some training in OSINT. However i´m looking into a carreer change and would love to get into an pentest role, I'm in the process of getting a bachelor in applied informatics ´on the side´... That being said, I've started with the tryhackme path a week ago. Now, my big dilemma: what certs/courses are worth taking? Both in terms of xontent as in terms of ´looking good on a resume´
I've read that eJPT is a good start and OSCP is highly regarded, but does anyone have any advice?

polar rock
#

considering you already have some experience I would go eJPT then OSCP you could toss in some networking as well if you dont already have some under your belt like ccna or net+ before eJPT

whole cloud
#

As soon as this hellacious holiday season is over, I start a temporary position withing my organization as an Authorization and Accreditation specialist. First position away from a cash register... finally.

torpid mulch
# polar rock considering you already have some experience I would go eJPT then OSCP you could...

Ive had pretty decent networking in my degree, just didnt go the extra mile to get cisco certified (did the CCNA 1-4 courses tho, sadly before they renewed and implemented wireless)
I'll look into the eJPT one. From what I've read OSCP is a whole other level tho... do you guys feel like the certs can replace a bachelor degree? I've still got 3 more years to go since i´m combining it with a full-time job, was wondering if they hire people based on certs alone

whole cloud
#

Two degrees and now a CySA+ cert, this would have marked my fifth full year since graduating that I've been doing high school level work to survive.

whole cloud
#

Thanks. Now I just gotta impress them enough to make it stick.

polar rock
#

eh they can and definitly have hired people with a degree but it is nicer to have one

whole cloud
#

Degrees get stale fast. A compsci degree less so, but trust me.. your degree gets irrelevant fast. Certs are useful because they're always relatively current.

torpid mulch
golden ore
#

but too many companies still like to see that degree

torpid mulch
#

First world problems and all

whole cloud
#

If you have the job history to back you up, you should be fine. In my case, I had two computer related degrees and years of cash register. No one wanted to even look at me.

torpid mulch
whole cloud
#

That's the plan.

torpid mulch
#

Guess I'll just have to be patient and get my sh*t together before considering that carreer change 😁

polar rock
torpid mulch
#

Damn, just did some research on eJPT. Do you really have to take a $2k pass to get the course?

quick forum
#

No

#

eJPT's training material is free (PTS)

#

The exam attempt is $200

#

If you check the pins, it's covered there

torpid mulch
#

Oh, that's misleading on their site
That is a much more acceptable price

golden ore
#

for $2k is probably a bootcamp

quick forum
torpid mulch
#

Ok, thanks!

quick forum
#

2k is the full INE pass

torpid mulch
#

Sorry for the newb questions btw, it's kinda overwhelming

polar rock
solemn shard
#

Super sad that the INE pass now exists and you can't download the slides to view on an ereader

torpid mulch
#

Yeah it was my bad
Didnt completely understand what was included in the free pass, was looking for ´penetration testing student´ and kinda assumed it'd a paid thing

#

No offense ment, thanks again for the info!

solemn shard
#

Luckily I got the eCPPT course before the switch happened so I got those slides

torpid mulch
#

The elearningsecurity site said to enroll in the cyber security pass, as prep for the cert which is the paid one
Hence the confusion

golden ore
quick forum
#

Just the material

unkempt nova
#

How about become a Crest Registered Certified Penetration Tester?

noble barn
#

How difficult is the CEH exam (i know, i know, i know. my work is requiring it). I keep seeing pretty conflicting info on its difficulty. For reference I have been a security analyst for 2 years working with a blue team doing vuln mgmt and also helping out our red team with internal pentests. I am level 9 on THM and just started using HTB as well. Should it be overly difficult for me?

pseudo creek
graceful hazel
#

Is OCSP sufficient to land a job?(without uni)

noble barn
pseudo creek
graceful hazel
#

Yeah I was just wondering how far winning it from advent of cyber could take you

pseudo creek
#

it would be a big boost

graceful hazel
#

yeah ofc

noble barn
#

@graceful hazel Definitely still have to pass that exam after you (hypothetically) win the course though, unfortunately it's notoriously a reasonably difficult exam

languid hearth
pseudo creek
#

yup and you only get a month of lab time so I'd definitely practice before taking OSCP

languid hearth
#

100% THM, HTB, and OffSec Proving Grounds are all great prep

#

I'd use THM for knowledge growth, HTB for final sprint exam prep and OffSec official boxes on Proving Grounds for mock exam

pearl wing
#

some great advice here, I'm someone trying to switch to IT from a a non-IT field (supply chain) and planning to go the route of A+ -> N+ and then Sec+, I am hoping that is enough to land me an entry level job in the field

flat sedge
#

A+ and Net+ are usually enough for entry level sysadmin, provided you have a jr college course or two on linux or windows admin

#

If you can explain what a domain controller is why its used, that would also be a great interview prep question for SA

pearl wing
#

is this advice US specific only? I'm in Canada and wondering if the path is similar to begin an IT career

flat sedge
#

I don't have any experience with what would be different in canadian IT - I'd imagine entry level tasks are largely the same everywhere.

pearl wing
#

thanks

meager hazel
#

Only difference I can think of is CompTIA certs like those aren't part of a required list for a public sector job in Canada, not like with DoD in the US. They would still help show your initiative though

flat sedge
meager hazel
#

You misread (and I should have typed it better, corrected).They aren't in public sector job list in Canada. They are in DoD US

pseudo creek
#

and CEH seems huge in India and it is on the DoD cert list for the US but outside of that...

fringe spade
#

should I stress before eJPT with the rank I have on tryhackme?

meager hazel
#

Have you gone through the PTS material?

fringe spade
#

I'm going through it, I set the exam in 3 weeks

#

is it enough?

meager hazel
#

If you go through all of it you should be fine

fringe spade
meager hazel
#

The exam is open book and you got some time to do it, so there's a good buffer of time to do just-in-time research

fringe spade
static tide
#

que

languid hearth
#

t h o n k

static tide
#

why is that shift allowance like 500% of the basic salary

tulip plover
static tide
#

that is a hefty allowance

alpine trench
#

Why are there over 200k people in this community according to stats but my understanding of supply of cyber security workers is scarce? Maybe 200k isn't a lot.

pseudo creek
#

the supply of mid level/senior cyber security workers is scarce

radiant apex
radiant apex
warm hinge
# radiant apex Yup

just purchased it a few days ago 😆 , was hesitant but in the end it was a no brainer

gilded prism
unkempt nova
#

Anyone have link to professional reporting template for real client?

lofty apex
#

There is a sample pentest report by Cybermentor

polar rock
# alpine trench Why are there over 200k people in this community according to stats but my under...

270k accounts on Tryhackme compared to the world at large that’s pretty small. You then have to account for how many of those people will continue their education and knowledge more than say 0x4. Probably a good 10% - 20%. Then out of those people who will actually get a job and continue to be part of the very small infosec community that actively contributes to research and defense which is pretty small.

junior fjord
polar rock
#

@languid hearth

pseudo creek
pseudo creek
#

GSEC is good if you are totally new to CyberSecurity, GCIH, GWAPT, GPEN and GCFA are all great certs (I'm not familiar with GCIA so I can't speak to but looks solid)

flat sedge
#

As far as immediate usefulness - I think Jr colleges and community colleges are a great place to learn how to be immediately useful to an organization. More long term, the value of a BS and terminal degrees cannot be understated. You want that bigger payday? Get that next degree. There are a large number of reasons for it, but in general, higher degrees = better ability to put thoughts down on paper for other people to understand. Most of the community college and jr college graduates do not have very good writing abilities; writing a coherent report and building documentation is the easiest way to provide HUGE value to an org

polar rock
#

I mean you just use a template broski a majority of the people I know making over 6 figures now don’t have a degree. It makes it easier to get a job, I don’t think it honestly has any affect to your job however

flat sedge
#

average lifespan for most tech and IT is 2 years at the same job - that's a lot of paper that gets shuffled around

#

already in a job and don't plan on moving? great, don't pay for that degree unless the job tells you to, or its a requirement to move into the next job you want

polar rock
#

after a certain point in your career your degree doesnt matter and who you have worked for in the past can vouch more for you

#

I think its relative

#

youre basically pushing people away from community college and jr college to get a cheaper education that does the exact same thing

flat sedge
#

i'm speaking from my perspective and experience - after a certain amount of time in the workforce, i agree with you 100%. A lot of recruiters won't look at the resume or CV without particular keywords. I'm not saying that jr college and CC isn't valuable; I'm saying that getting that next degree or progress towards that degree may be a requirement to move up or to change companies for that next promotion. For example, to go from a system engineer to a system architect may require another degree. If a company denies a promotion once, time to consider the situation at that job. denies it twice? I think it's time to move

languid hearth
#

a degree is honestly more valuable later in your career

#

especially if you want to move into management

trail granite
#

feelsbadman got 4 years left

pseudo creek
#

it really depends, like my company hardly hires anyone without a degree... even our IT help desk has people with BS in CS

trail granite
#

damn

pseudo creek
#

and if somehow you do get hired... you are kind of capped without a degree

#

except if you have military experience but even then

flat sedge
#

A lot of it is dependent on the organization. If an org isn't willing to invest in making you a better employee, be very leery buying into whatever 'loyalty to the company' party line is common

pseudo creek
#

yeah my company basically puts tons of people through school, masters degrees, some bachelors degrees if you don't have and certifications

#

but competition is pretty stiff, and we get way more applicants than jobs available and they have a robust college intern program to get people in

trail granite
#

damn thats sick

#

Thats what i want to do 2 study for 4 years than follow a 2 year program at a big company near me

grave sandal
#

Greetings everyone, I am posting here to get advise for job hunting in the cyber industry. I am currently set to graduate this month with a masters in cybersecurity engineering and am studying towards getting the security+ certification. I have not held a job in the cyber industry yet and have been applying anywhere and everywhere trying to get a potential job lined up for after graduation. I am wondering if anyone can offer advise on job hunting in the industry or any potential positions they know about that are out there I can apply to.

Thank you all and have a wonderful day!

flat sedge
#

Start applying now for internships - I'm assuming you don't have any other IT on your resume? A lot of (the better) companies use internships as a recruitment tool, so it's a low-risk way for them to try out potential employees. Your degree should get you a step above entry level in a SOC, it really helps to know one or two tools reasonably well, so having a home lab is a huge plus when interviewing

grave sandal
flat sedge
#

you are starting your applications really late

tranquil oasis
#

can anyone give advice about the pivoting in ejpt i heard its nothing like the course

grave sandal
#

I have been applying to places since September

flat sedge
#

for June hires as a new grad, you start looking in december/january - for december/jan start, you needed to start looking 2+ months ago

#

if you aren't getting interviews, i'd recommend working with a recruiter or your campus' student careers office to help re-write your resume

alpine trench
fringe spade
alpine trench
fringe spade
# alpine trench what is 0x4?

"0x" means that it's in hexadecimal, so when the number 10 comes up, it is changed to A, so someone with level 10 will have "0xA"

fringe spade
fringe spade
alpine trench
#

My goal is to complete everything. Think I can do it in 6 months? 3 hours a day.

fringe spade
olive orbit
#

Well... Not really. New rooms are being added all the time

#

But thats a good thing! Theres always more to learn

junior fjord
junior fjord
pseudo creek
pseudo creek
primal shale
#

Has anyone worked in IAM and could answer a few questions in dm?

polar rock
#

You’re going to get a quicker and better response if you just directly ask the question

grave sandal
languid hearth
#

maybe not the best way to move up, definitely a good way to start your IT career

pseudo creek
flat sedge
#

I also think it's really beneficial to work in another IT domain before jumping into security full-time.

warm hinge
#

Has anyone bought WAPTX or WAPTXv2?

#

I have heard if you buy the first one you get the second for free

distant pier
warm hinge
#

I don't, I have heard it somewhere arround the office, maybe they bought the WAPTX before WAPTXv2 was released?

#

Is it worth buying over WAPT?

distant pier
polar rock
#

Considering everything has shifted to INE this is probably different now

warm hinge
#

True... but you can download the contents of this courses and then buy the exam

#

Its really easy to find the content

#

@distant pier did you take WAPTX?

distant pier
#

Perhaps now the update applies to the exam voucher.

#

I did not take WAPTX.

polar rock
warm hinge
#

Ok sorry

polar rock
#

not only is it illegal you wont get updated course material, access to videos, or labs

warm hinge
#

Daam

distant pier
warm hinge
#

Ok

#

But, did anyone take the WAPTX exam ? Is it worth the money? Is it hard?

polar rock
#

I dont feel comfortable answering your question as youve already said you will illegaly obtain the course materials

languid hearth
#

mileage will vary for each individual depending on how much you know. If you've taken AWAE, probably not. If this is your first web app cert, probably so.

#

els has very little respect in the industry, 19 current jobs in the u.s. on LinkedIn asking for waptx, vs 100 asking for oswe

warm hinge
flint pilot
#

“Its really easy to find the content”

#

Lol

languid hearth
#

take my advice, drop it right now. you're a mods notice away from getting yeet'd.

warm hinge
#

If you work in a cybersecurity company they'll pay for your certs lol

#

And learning material

warm hinge
#

From what I have heard its a pretty nice course, content wise ofc

flint pilot
#

True true I just read the recent stuff

warm hinge
#

You can probably find stuff about any certification on the internet, its the internet lol

#

Everyone knows that

flint pilot
#

What supuki chan said about the course and all. Thats good advice

warm hinge
#

But people straight up assume you are promoting piracy lol

polar rock
#

no mate

languid hearth
#

its the point that your discussing it here. That's a no-no. This is a partnered Discord. you we're told not to, yet you continue.

polar rock
#

dont act like you didnt do that lmao

#

you straight up said contents of the course

#

dont be modest now that mods are here mate

quick forum
#

They're dealt with

merry hound
#

Okay maybe I asked a generic question last time. So specifically I am focusing to get a entry level Cyber Security job (Penetration testing is what I am interested and want to do) Is preparing for OSCP good to go? As I am in Final Year and will graduate in 6 months 22 days and my resume gets rejected (Prolly have to work on this). Or are 'skillsets ' enough to land a Entry level Cyber Security job as one wouldn't give specific domain role at the start.
Thank you!

pseudo creek
#

Certifications are one of the best ways to get an entry level cyber security job. And to be fair, lots of entry level cyber security jobs aren't entry level jobs. OSCP would a great start but you'd still probably be looking at things like SOC analyst and potentially IT help desk or IT sys admin

flat sedge
#

Pentest is almost never an entry level job - done wrong, it can cause horrendous outages and have a huge business cost. I'd suggest getting into the org in another IT role and building that trust to get that buy-in that you can be trusted not to break stuff

golden ore
#

look through the job boards for the job you are looking for, they will list different "requirements" or things they would like, it would give you a good idea since every company is different

polar rock
merry hound
# pseudo creek Certifications are one of the best ways to get an entry level cyber security job...

I see but the money is also the issue as I don't want to ask the same from my parents and want to invest with myself. So I was thinking I would do these Certs when I have an job but job best suits certs which I feel is like a paradox.
So I am also trying to get engaged in companies coming in my university(Specifically Associate software developer which is also good) so I can get started alongside learning cyber security then switch to my interested role.

flat sedge
#

IMO software dev is a great place to start for pentest - I would only recommend network admin over dev as a place to start for pentest

languid hearth
# merry hound Okay maybe I asked a generic question last time. So specifically I am focusing t...

you'll unfortunately face a lot of rejection because "security isn't an entry level field". Which is partially true because you need to understand networking, IT skills, etc. I was most certainly an exception to that, but I digress.
You can find an entry level Security job out of college. Hell, I did it and I only have my 2 year. Be prepared to face a lot of rejection, but when you find someone who understands what it means to have gone through a certification like the OSCP, the job will likely be yours

flat sedge
#

if you are about to get a BS in compsci, i'd suggest going the dev -> route. pay attention to the SAST results your security team wants to see, and that can be a good 'in' for the security org

pseudo creek
languid hearth
#

also a piece of advice, don't be afraid to admit you don't know something or have experience with something. No one here knows everything.

golden ore
#

If you want to do cyber out of the gate, I would look at analysts jobs as most are entry level

#

you can always move up from there

merry hound
#

Thank you for the insights everyone ! Honestly I was living under a rock that I didn't discover thm earlier. But hey, never the late. I will make sure to follow all the advice and rock it and get back here and message 'I made it'.

pseudo creek
#

and I'd definitely continue applying to places, now is prime time for someone graduating in 6 months

#

refine your resume and just continue searching

warm hinge
#

Does anyone know any company hiring junior pentesters? Location is eu/remote
Almost a year at the SOC and I really wanna change also uni student cs

vale forge
#

Hello everyone,

On cyber careers
On your first year on your security careers what did you focused on?

merry hound
# vale forge Hello everyone, On cyber careers On your first year on your security careers w...

Focus on clearing the fundamentals of Cyber Security and get aquanted with the terminologies and jargons.
Slowly move towards specific domains in this like programming, cryptography, Networking etc.
Move with doing CTF's - - > THM, HTB etc and essentially knowing which specific domain you want to pursue in Cyber Security and work towards getting certified and hired. I did like this and am do following this but someone experienced should be able to give you a better pathway. Cheers!

pseudo creek
#

Yeah I'm not sure how to answer exactly. I was doing network admin stuff, realized that I wanted to do network security stuff so started learning that. Basically I'll say I saw what the job was, what it required and worked towards filling those skills. Which is generally a good idea, if you find a job you are aiming for, try to find a job listing for that job and work towards those skills.

unkempt nova
#

Someone was looking for pentester to find vulnerability on his website. But he given the project to a coder.... hmm

ocean bloom
#

Is it worth getting a CEH?

unreal arrow
#

Not really unless you want a DoD position even tho they seem to be liking Penetst+ more I think it’s only good if you’re in India

flat sedge
#

I've seen a lot of US analyst listing asking for a CEH - while its not a technical cert, it's one of those that management and recruiters seem to like to see

pseudo creek
#

Companies that contract with the US government will also list CEH as an accepted cert but there are better certs out there

quick forum
#

Sec+ is now on the same list

pseudo creek
#

Yeah but somehow CEH still prevails on certain job listings

quick forum
#

Sec+ was only added to the list in the last like... 2 months or something

pseudo creek
#

Yeah so may take a while for job listings to catch up

frigid niche
#

@merry hound Seriously, go for the dev positions. Show that you can code securely, get a grasp of the environment that you are working in and make contacts with the security team. Do smart things like vuln scan the software you work and that would be a great steeping stone into pen testing.

visual herald
#

Sec+ has been on the DoD requirements list for years, I'm not sure about the rest of the US government.

quick forum
#

Ah I meant pentest plus

frail mortar
#

Howdy all, I'm trying to develop a behavioral test for some applicants on the blue side, multiple choice and easy to weed out the wannabes (like me). Would anyone have some insight as to questions I could/should use?

Ideally they'd be fairly straight forward such as Snort has produced these 3 alerts <picture of three alerts>, which would you respond to first?

slim osprey
#

With work experience of 3+ years in cyber security field, is it worth doing Masters in cyber security?

visual herald
frail mortar
visual herald
#

I would say multiple choice is still probably a bad idea. Some idiots may pass by pure random chance, meanwhile the perfect candidate might skip YOU because he thinks your test is demeaning. Just personal feeling, but sending out essay questions, or doing inital 5 minute phone screens, or anything else really would probably work out better in the long run.

flat sedge
#

It usually becomes REALLY apparent if someones resume does not match their knowledge, usually <5 min in a technical interview

distant pier
#

Because the word proficient is ambiguous. It is better to include a year-range related to 'proven work skill in network defense'.

#

People with no prior work skill will abuse ambiguous terms to their advantage. 😉

pseudo creek
pseudo creek
#

@slim osprey Please read the #rules no DMing without asking first, I rather you ask your quesiton here than DM me

slim osprey
#

I wanted to move towards research and developement.

pseudo creek
# slim osprey Ok, Why do you think MS is towards managerial role, won't MBA qualify for that.

Career wise, MS in Cyber is thought of a management move, generally MBAs are pretty rare in tech but you'll find a few, MS Cyber, Comp Sci or others. For research and development, you can do some of that without a MS depending on what you want to do. If your goal is research on things like cryptography algorithms for instance, you would more focus on a PhD in potentially Comp Sci, maybe mathematics, again depends on the area

cosmic ingot
#

Zojja, do you know of any countries in which that's not exactly the case? I've moved away from the idea of doing a MSc, but every now and then I see some practical roles (like pentesting) that interest me which have MSc as a nice-to-have, and sometimes even as a requirement.

#

I live in Greece, forgot to mention. I know you should take stuff in job postings with a pinch of salt sometimes, but a MSc seems kinda important

pseudo creek
#

I would think this is mostly US/Canada. And if it is not a management role, but a lead role, it may have sense to potentially list MSc. I can't speak for other countries though. I'm not sure why they would want a MSc for a pentesting position

cosmic ingot
#

it doesn't have to make sense 🤷‍♀️

#

thanks 🙂

slim osprey
#

Thanks 😀

silver hornet
#

Hey all

#

After trifecta, what would you say, next go and do cysa? Cause its more hands on and so on?

pseudo creek
#

trifecta?

zealous forge
#

OSCP

languid hearth
pseudo creek
#

ahh

forest knoll
#

Whats OSWP like?

languid hearth
#

easy

pseudo creek
languid hearth
#

its a nice weekend course

forest knoll
languid hearth
#

i don't mind sharing my notes if you're interested

silver hornet
#

Interesting

forest knoll
#

Lemme finish OSCP first then I may hit u up 🙂

silver hornet
#

You know i have a problem. I dont have 1 path i am in interesting

languid hearth
#

its enough to get you through the exam, but you'll be missing out on the theory

pseudo creek
silver hornet
#

So its harder. Done aws ccp and liked cloud, started sec+ and loved it.... need more experience, hands in

pseudo creek
#

if you expect to do cloud, I'd go past CCP, I'd consider that more of a manager's cert because it is very basics

silver hornet
pseudo creek
#

OSCP would be good all around honestly

#

I'm going to do it next year even though there is 0% chance I'd ever be a pentester

stiff kiln
#

Hey, Is it important to renew ur comtia certs every three years ? Like do have to take if off of ur resume or like as long as u passed the exam and got the cert u can have it on ur resume even if it expires? If so whats the point of renewing ? do people ask if they’re expired or anything on the interviews ?

#

Or any other cert in general

pseudo creek
forest knoll
#

OSEE looks hard, Advanced Windows exploitation, nah nah nah Im good

languid hearth
#

imo, not really worth it to renew unless your job wants em current

zealous forge
#

Yes i did wonder about renewing. Bet loads dont ask

pseudo creek
#

and I'm pretty bad, I have never renewed/kept up to date a cert, not even CISSP

zealous forge
#

Got ccna coming up to renew... but I cant be bothered - want more cyberz certs

languid hearth
#

ccna cy ops!

pseudo creek
#

yeah I wouldn't worry about it unless your goal is network engineer

stiff kiln
#

Ah thank you all

silver hornet
#

Like comptia , £150 and i think 6 hours study and you can renew your highest cert so all others will renew

pseudo creek
#

just be aware that some certs do rely on others, like I was looking at the CISSP architecture one (which is newer) and I'd need an active CISSP... which I was like damnit guess not

silver hornet
#

I just got mine, so still 3 years to go. Will notnstop at what i have

stiff kiln
#

just be aware that some certs do rely on others, like I was looking at the CISSP architecture one (which is newer) and I'd need an active CISSP... which I was like damnit guess not
@pseudo creek good to know thank u

pseudo creek
zealous forge
#

Not really anymore, even CCNP can be done without CCNA

#

GIAC GCIH for me soon

pseudo creek
#

I know my husband went for the IIOT one and it required a CCNA

zealous forge
#

Oh ok

pseudo creek
#

but weird CCNP doesn't require CCNA anymore

zealous forge
#

How many hours study are people doing a day

#

I am 4-5 hours a day, today like 8 hours and my eyes hurt. That might all change when cyberpunk comes out

pseudo creek
#

most of mine is on the weekends but I try to squeeze an hour/day

silver hornet
#

When on lockdown ( then i started to study ) i did wake up 5am till 10am because after that play with kid and so on. No time.

#

Now trying to listen while driving, do apps when have free time betweencjobs or waiting for windows or linux to load and so on. Or pos system to upload

tropic atlas
primal shale
#

Free?

#

I thought the course is free but you pay for the exam

warm hinge
#

What’s free? @primal shale

primal shale
#

Juniper certification training

tropic atlas
#

sorry, covers 75% of the price of the cert

pseudo creek
#

I believe Microsoft has discounts on their certs right now too

light wave
light wave
ocean bison
#

Hello, guys

#

I want to ask about cyber sec career

#

I interest is security architect engineering and pentester.

#

And should i go wich cyber security position is more flex to me?

#

Example SOC is not flex to me.

#

SOC analyst*

languid hearth
#

pentester is the most flex

#

red team is most flex

grave needle
#

1337 h4x0r is most flex.

light wave
languid hearth
#

firm pentester

#

self employed is very bleh

hexed plover
#

Hii

#

anyone here?

tulip plover
#

just ask away as long as it doesnt break discord or THM discord rules

hexed plover
#

kay

glass karma
#

For incident response, what is the best way to show you have sufficient forensics knowledge/skills? A cert? Practice? Where can we practice?

polar rock
#

Mostly certifications and experience

#

There’s not a lot of places to practice outside of labs from certs but you can do things like DFIRMadness challenges and maybe some various CTF challenges or rooms on Tryhackme

bronze berry
#

yeah, bland corporations prefer paper
the best places to work just go by what you can prove

#

those are usually pretty tight knit too, youll be friends rather than colleagues

glass karma
#

Ty!

ocean bloom
#

So we should not take ceh?

pseudo creek
# ocean bison And should i go wich cyber security position is more flex to me?

I would go with the position you think you'll like more. A security architect is an advanced position, although it will make more money than a pentester. A pentester can become a security architect. And it is difficult to go from no experience to pentester and impossible to go from no experience to security architect.

pseudo creek
ocean bloom
#

No they are no asking, but ceh seems to be the quite well known certificate and not hard for beginner, so i am considering it

pseudo creek
#

its well known for being... not good

#

In the US it is well known due to DoD requirements for government contractors and employees

sleek sedge
#

Are their actually any free certifications on cyber security?

pseudo creek
#

None that I can think of

golden ore
#

you may be able to find free training, but no free certs, plus many certs have annual renewal fees now

tropic atlas
#

reee

#

cries in poor

polar rock
#

aws has free training with a 100$ cert, microsoft / azure has free training with like 15$ certs, splunk has free training and cert of completion with 50$ cert, els has eJPT for free with a 200$ exam fee, Juniper has training free, cant remember the price, same with cisco they had some free training earlier this year as well

polar rock
#

pretty much everything sold in courses can be found with enough time looking through free resources

rugged sable
#

tbf

#

microosoft give away certs at events

#

like vouchers

#

and the events are free

polar rock
#

there is no excuse to leave yourself behind because you cant afford certs, you just have to try a bit harder than someone who can

pseudo creek
#

Cry will charge you money

#

I also heard that SANS ocassionally gives away classes at some of their events, I'd definitely sign up for their Christmas CTF if you haven't already

polar rock
#

their webcasts are pretty good and give you CPEs

pseudo creek
#

some are, some are sales events

polar rock
#

oh also autopsy had a free training earlier this year don’t know if that’s still happening

pseudo creek
#

oh I forgot about that

polar rock
#

also cons are one of the easiest ways to get free stuff including shirts, pins, stickers, and even certs and trainings

#

defcon was crazy

pseudo creek
#

yeah

#

they gave away ton of prizes

#

and also if you follow some of the Udemy instructors like Tib3rius/Heath Adams, sometimes they give away their course away free

quaint pulsar
#

anyone recommend the pentest+ or CEH?

quick forum
#

Pentest+ >>> CEH

unkempt nova
#

Pentest+