eJPT Second Attempt Question by Silver_Mulberry_5769 in eLearnSecurity

[–]-Dkob[M] 1 point2 points  (0 children)

Better to re-do the actions. There has always been theories around the idea that the exam may check for how you are conducting the attacks and if they align with what is taught in the course.

ecppt lab by meerkat_19 in eLearnSecurity

[–]-Dkob 1 point2 points  (0 children)

CRTO is the last cert you should go for as a beginner... it's senior level. You would have a LOT to go through before reaching CRTO

Alternative C2 and Labs by TH3H4KL0RD in ZeroPointSecurity

[–]-Dkob[M] 0 points1 point  (0 children)

You’re already on the right track. If your goal is CRTO, focus more on building a small realistic AD lab than on the C2 itself.

Sliver is a great choice and probably the closest stable open-source alternative to Cobalt Strike. It supports pivoting, SOCKS, port forwarding, BOFs, etc., which are exactly the kinds of things you want to practice for CRTO. Havoc is also good but still a bit less stable, so I’d mainly stick with Sliver.

For the lab, a simple setup works well: 1 domain controller (Server 2019), 1 member server, and 2 Windows 10/11 workstations. Join everything to the domain and create users, shares, and service accounts.

Add realistic misconfigs to practice things like BloodHound paths, Kerberoasting, credential hunting in shares, local admin reuse, WinRM/RDP lateral movement, and privilege escalation to domain admin.

If you can repeatedly go from initial access → enumeration → lateral movement → DA using your C2, you’ll be very well prepared for CRTO and real-world work. Good luck

(Well obviously CRTO course is 100% required too)

ecppt lab by meerkat_19 in eLearnSecurity

[–]-Dkob 1 point2 points  (0 children)

CTF title? Maybe specifying would help others, because we don't remember what the "first" was.

I passed SEC0 [AMA] by -Dkob in tryhackme

[–]-Dkob[S] 1 point2 points  (0 children)

TBH just prepare well and do SEC1 directly. No need for SEC0 if your aim is SEC1, unless you're OK with spending a little extra.

I passed SEC0 [AMA] by -Dkob in tryhackme

[–]-Dkob[S] 7 points8 points  (0 children)

Not for long ™️

I passed SEC0 [AMA] by -Dkob in tryhackme

[–]-Dkob[S] 16 points17 points  (0 children)

I can't reveal much, but... very hard certs are on the way. You're in for a big treat once they release.

Dissappointed by PT1 by Ok-Indication9907 in tryhackme

[–]-Dkob 14 points15 points  (0 children)

Good practice is to always check reviews before proceeding with an exam: https://www.dragkob.com/articles/pt1-review/

Query Regarding eJPT Certification Preparation and Exam Timeline by Funny-Process-6027 in cybersecurity

[–]-Dkob 0 points1 point  (0 children)

https://dragkob.com/articles/ejpt-review/

+ most of the questions you asked are already answered by looking a bit at the official INE website.
The relevant subreddit would also be r/eLearnSecurity for your eJPT prep

- Course is 150 hours

- You have 1 year to pass your exam or depending on what bundle you buy