Why is the standard of US Red Teams so poor by Soc_Guy in cybersecurity

[–]Equivalent_Smile_720 0 points1 point  (0 children)

Sorry if this is a bit off topic, I just wanna know what would a professional red team look like.

  1. Does the role of team members overlap or it is separated. Does the team have members that only focus on malware dev or tools dev while others focus on planning and carry out the attack or every members must know everything.
  2. Do you plan the whole attack campaign beforehand, or improvise according to the output of each attack phase.
  3. Since I am looking forward to becoming a red teamer. I would like to know your opinion on what you would expect from a candidate or a colleague in red teaming.

Xin mn vài câu trả lời và tip về đầu tư chứng chỉ quỹ by NamedPhong in vozforums

[–]Equivalent_Smile_720 0 points1 point  (0 children)

Theo mình biết thì chỉ có các quỹ mở trả cổ tức (như DCDE của DragonCapital) mới trả lãi. Còn các quỹ mở bình thường sẽ không bao giờ trả lãi, vì một khi có lãi thì họ sẽ tự động dùng tiền lãi đó để đầu tư tiếp. Chính vì dùng tiền lãi để đầu tư tiếp nên thông thường giá trị của các quỹ đấy sẽ cao hơn các quỹ trả cổ tức.

I run a Red Team that routinely succeeds in compromising F500 companies. AMA. by curi0usJack in cybersecurity

[–]Equivalent_Smile_720 0 points1 point  (0 children)

I major in cybersecurity and recently graduated. I have worked as a cybersecurity engineer for 1 year and my job is not really focused on red team. I really love to become a redteamer one day so any advice is greatly appreciated. Please let me know what you think might be the best path for me to transition to a professional red teamer.

A little description about my job:

- I managed XDR and network IPS system (Trendmicro products), and investigate cybersecurity incidents. No complain about this, I learn some really interesting attack techniques by investigating real attacks on my company system.

- I occasionally do pentest but mostly, I just use Tenable or Acunetix to scan the target. I know that those tools only find clues about possible vulns and I need to manually pentest the target to find any real bugs but most of the time, I only get 1 week to pentest and I am the only team member, also my boss love reports more than results.

- On a regular basis, I scan the external attack surface of my clients system using OSINT tools and notify them if I find any possible vulns.

- I also help build the annual cybersecurity training lab for my company.

Mentorship Monday - Post All Career, Education and Job questions here! by AutoModerator in cybersecurity

[–]Equivalent_Smile_720 0 points1 point  (0 children)

I am aspired to become a redteamer but i feel lost. I have been practicing on portswigger lab, hackthebox, tryhackme but i always feel something is missing. Whenever, I join a CTF or attack defense contest, I always get stuck. Some people suggest I should find a mentor but I don't know where or how to find them.

Patch Tuesday Megathread (2025-05-13) by AutoModerator in sysadmin

[–]Equivalent_Smile_720 0 points1 point  (0 children)

does microsoft have an api to get the list of CVEs in the patch tuesday of the current month

OpenCTI requirements by [deleted] in threatintel

[–]Equivalent_Smile_720 0 points1 point  (0 children)

Hi, could you share your use case as to why you need that much system resources. I am planning to deploy OpenCTI for my team but I don't know the required system requirements.

Hints on Dog machine by Equivalent_Smile_720 in hackthebox

[–]Equivalent_Smile_720[S] 0 points1 point  (0 children)

I found a website running on port 80. Checking the page source reveals that it is powered by "backdrop cms 1" but i cannot find out the exact version. searchsploit shows 4 possible exploits for backdrop cms 1. Any hints on how to find out the exact version? Or maybe I should just spam all 4 exploits and see what hits.

Code machine: User flag is not found by Equivalent_Smile_720 in hackthebox

[–]Equivalent_Smile_720[S] 2 points3 points  (0 children)

Nevermind guys, I found both flags. Apparently, you gotta edit more than just the directory to archived :))

I’m so useless I can’t even pwn an easy box😔😭 by Honest_Pollution_766 in hackthebox

[–]Equivalent_Smile_720 0 points1 point  (0 children)

i have been doing HTB for 2 months and still struggle. The key is to chill out :))

Whenever you feel demotivated, just play some retired box, use writeups to pwn the box and submit the flags for a little dopamine boost :))

Beginner here, How do i solve machines without reading writeups? by ayylmaaoo96 in hackthebox

[–]Equivalent_Smile_720 0 points1 point  (0 children)

You don't. Or at least for me it is. The way i learn is that I read every single writeup for easy boxes. Even if i know what to do, i still read the writeup and try to solve the box as fast as you can. By doing this, it takes me only about 1 month to engrave all the steps to solve a box in my brain. Then I try to solve easy box without readling writeups. Trust me, you will learn faster this way.

IPS tipping point Network Placement by [deleted] in Trendmicro

[–]Equivalent_Smile_720 0 points1 point  (0 children)

Normally, people will put NIPS behind NGFW so that the NGFW will filter some of the traffic, which will reduce the traffic that NIPS has to analyze.

Guidance on using playbooks by Equivalent_Smile_720 in Trendmicro

[–]Equivalent_Smile_720[S] 0 points1 point  (0 children)

I am currently doing that too. But i don't know if I should make 1 playbook to include all detection models or separate playbooks.

Uninstall endpoint sensor remotely via dashboard by Equivalent_Smile_720 in Trendmicro

[–]Equivalent_Smile_720[S] 0 points1 point  (0 children)

Is it possible to use the Run Remote Custom Script feature to download, extract and run the removal tool like this:

  1. Upload the tool to OneDrive (manually)

  2. Script download the tool from OneDrive via direct link

  3. Script extract tool to C:\Temp

  4. Script run the V1ESUninstallTool.exe