#Which specific topic would you like us to cover or host an OffSec live session on?
23 messages · Page 1 of 1 (latest)
- How to develop instincts for rabbit holes
- How to organize your learning progress
- Box walkthroughs where the person doing the box doesn't know the solution beforehand
I would love to see some sort of CPEs involved with OffSec Foundations badges even if it's just 5-10.
Penetration testing again industrial equipment. I have an interest in learning about critical infrastructure and how attacks get into SCADA/PLCs.
I think its an important, none flashy part of penetration testing that will have a long time impact.
Maybe notetaking/learning strategies in every exam learning material, taking effective notes isn't super intuitive for some. A channel for people to connect for mentorship and maybe study groups.
Thank you for your suggestions. Please feel free to react with an emoji if you agree to other person's suggestion. We will give priority to suggestions with the highest number of reactions.
Practical usecase of ai in the current scenario.
or at least closed by default
- AD methodology after getting your initial pivot
AWS pentesting (streaming sessions )
Any cloud really ☁️
Well, AWS is the leader but yeah, any cloud pentesting streaming would be nice
There's no leader...All fail...All hide it..Or do they?
AWS is definitely the market leader followed closely by Azure
I like Azure for MSSQL and AD. The rest ? AWS seems better in my opinion . I’ve used both . AWS more extensively .
I would love to learn more about why OffSec has taken its current stance on disallowing the use of free, publicly available LLMs like Microsoft’s Bing Chat in labs and exams now that it is becoming part of modern security testing processes.
I would love to see a livestream of tips and tricks for Bug Bounty.
Anything related to hardware hacking
OPSEC during pentesting
John Hammond has a few of these as well as some in depth malware analysis
John Hammond almost always knows the solutions to boxes before making the walkthrough. I'm looking for more of a "live enumeration/exploitation process" kind of thing
Right, I bet twitch has some, maybe.
udemy had some of those 'blind' walkthroughs from hackerone were the person is just trying and doing instead of showing, never understood why offsec does not teach that, with all its emphasize on trying harder...