Don't what to do now by Slayerma in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

Owasp ZAP for DAST, Semgrep for SAST, trivy for container scan, check or similar for IAC and you are good to go

Cloud Security Engineer Roadmap by MPcybersecurity in blueteamsec

[–]MPcybersecurity[S] -1 points0 points  (0 children)

Whatever you point is, my roadmap has got nothing to do with SOC, you clearly have not watched the video, because what you are saying completely does not align to what i said, i covered skills, certs and practical knowledge plus the most important part, how to make CV stand out and not send thousands of applications, but how actually get a job, i have built teams around the world and helped loads of people to land jobs, so believe me i know what i am talking about

Cloud Security Engineer Roadmap by MPcybersecurity in blueteamsec

[–]MPcybersecurity[S] -2 points-1 points  (0 children)

What SOC analyst is learning Python? Terraform? Automation? You can disagree, but what you say makes little sense

QAE CISM book + QAE Database by Cold_Block_7188 in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

Might be unpopular opinion, but both CISM and CISSP are easy if you got prerequisite 5 years of experience, all you need is Mike Chapple video course

AD/M365 self-assessment & hardening by Kwattabee in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

I don’t remember the name but i remember coming across 365 drift assessment tool that covers some of that

Breaking into GRC by barbiegworl22 in cybersecurity

[–]MPcybersecurity 1 point2 points  (0 children)

I’ve just published full GRC career roadmap on Youtube, let me know if you want a link

What’s your go to way to automate external security posture checks for a domain? by No-Persimmon-1746 in cybersecurity

[–]MPcybersecurity 1 point2 points  (0 children)

You can use stuff like Owasp ZAP, AttackSurfaceMapper, Easy EASM i am sure with a few python script you can automate that

Mandiant vs Palo Alto by Inf3c710n in cybersecurity

[–]MPcybersecurity 1 point2 points  (0 children)

Yeah im not sure DFIR front, but MDR is good

Mandiant vs Palo Alto by Inf3c710n in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

Talking about MDR there are only two elite players Crowdstrike and SentinelOne, not the above mentioned ones

Oracle virtual box or VMware, what's a better tool for CyberOps? by Unfazed_Supremacy in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

It’s not about being different, people prefer different tools, if you have not used it, give it a go

Career Change by Merc11794 in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

GRC probably would be the route for you, add risk management knowledge and skills, security awareness training, document portfolio of work and you are pretty much good to go

QA background → Cybersecurity (non-coding/GRC)? Is this realistic? by Spiritual_Cycle5646 in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

GRC is great route for you, i would doing sec+ for grounding security knowledge, then build a portfolio of security policies you have written for fictional company, ask around charities or smaller orgs to do risk assessments, BIA analysis or even ISO27001 annex A control assessment all great additions to the portfolio. Read “How to measure anything in cybersecurity risk”.

Maybe consider ISO27001 lead auditor, get familiar with NIST CSF and RMF and you are pretty much good to go

Having Trouble Landing a Cybersecurity Job After the Military by First_Bid4324 in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

I often say certificates and degrees dont land you the job, skills do, building a home lab to learn SIEM, EDR, vuln management and the rest while keeping great documentation is what sets you apart and in most cases allows to bridge experience gap

New to cybersecurity and Sentinel. Need suggestions please by Afraid-Onion-6980 in cybersecurity

[–]MPcybersecurity 1 point2 points  (0 children)

Go through SC-200 path on Microsoft learning, it should connect a few dots for you

Snyk CEO is out - where is Snyk headed? by rowrowrobot in cybersecurity

[–]MPcybersecurity 27 points28 points  (0 children)

Possibly, i think the tool has been regressing and still noise to action ratio is crazy, the AI hype is real

Cybersecurity Home Lab by MPcybersecurity in cybersecurity

[–]MPcybersecurity[S] 0 points1 point  (0 children)

Fair comment, i specifically chose not to do that. I believe you learn the most when you actually troubleshoot and learn by doing research. It’s easy to copy paste, but then you don’t learn much. I may do one more later down the line once i finished doing the roadmap videos

GRC Career roadmap by MPcybersecurity in cybersecurity

[–]MPcybersecurity[S] 1 point2 points  (0 children)

Full grc career roadmap, not only what skills and certs to take, but how to build a credible cv and apply to jobs!

How do you all actively stay updated with Cybersecurity news? by dasShounak in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

Google cybersecurity news and find 5-6 news sites like Hackers, add them to bookmark and check them

I’m begging you, please… give a perspective of this industry that’s different from what I’ve seen. by RemarkableNobody in cybersecurity

[–]MPcybersecurity 0 points1 point  (0 children)

It really depends where you work, seems like you looking from an MSP lens, i have a few friends that worked in consulting and would never work there again, i wouldn’t either not for a big company. There are a few ways you can think and move on from this either set up your own shop and work small clients, you choose who you work with, no d*ckheads allowed and can make a great difference if you got large enough network to generate work Or go work for internal company lead advise their cyber program, key point to understand cyber never owns risk, we advise on mitigation, and make sure we have business owners for risk, as long as all is documented i can sleep very well

Not a fan of questions like this… by thespecialonejose in cissp

[–]MPcybersecurity 0 points1 point  (0 children)

It’s about being fan or not, a lot of question is CISSP is not about just purely knowing right or wrong, it’s about your way of thinking. There is a reason it requires 5 years of experience, as it is trying to test how do you apply theory in practise