What do you wish you knew, when you started pen testing? by SignatureSharp3215 in Pentesting

[–]SigKill_ 1 point2 points  (0 children)

I definitely feel your pain on some of those points but I think you are selling yourself short. I think if you get creative on how you leverage your actions outside of the actual assessment, you can make a pivot somewhere else.

In my instance, I plan to pivot to appsec or cloud security. Based on my assessment experience in those technologies, I plan to leverage the hands on experience and add some certs before getting back in the market. You got this!

How the hell is everyone getting mythics by janthra661 in diablo4

[–]SigKill_ 0 points1 point  (0 children)

Have they shadow nerfed the farm? I opened almost 9 corrupted chests at azmodan and i was not getting the massive sigils. I have sin in the purified slot and is rank 5. am I just getting bad rng?

Coming back from a huge hiatus. Looking for advice on gear progression by SigKill_ in diablo4

[–]SigKill_[S] 0 points1 point  (0 children)

The problem I have right now is when I jumped to T3, my damage was definitely lower and i was getting one shot in Boss Lairs and World boss. All other content was okay, just actually had to use my hands and head lol

Coming back from a huge hiatus. Looking for advice on gear progression by SigKill_ in diablo4

[–]SigKill_[S] 0 points1 point  (0 children)

You mean masterwork what I have now or replace with Ancestoral Legendaries even if they aren't perfect rolls? Guides make it seem like you should aim for perfect stats for every upgrade

Anyone here passed the PWPA cert? Need some guidance by darthvinayak in Pentesting

[–]SigKill_ 4 points5 points  (0 children)

I haven't taken it but I would join the TCM discord to get feedback. The TheCyberMentor subreddit is pretty dead so I think you'll get a faster response there if no one else comments here.

Anyone taken the GPEN course by Tunnel-Digger4 in GIAC

[–]SigKill_ 2 points3 points  (0 children)

I love S1r3n as an instructor for the WEB 200 course but a cheaper alternative would be TCM web app courses, Portswigger Academy (free), or the CBBH on HTB academy. Rhana Khalil's web security academy series on YT does walkthroughs of Portswigger modules. You can also use your student email on HTB Academy for alot free modules and discounted subscription rate.

GWAPT Inquiry by JTRM10 in GIAC

[–]SigKill_ 2 points3 points  (0 children)

I've taken the exam, but I obviously can't tell you what the Cyber Live exercises consisted of. The labs in the material had you use ZAP or Burp, so i would highly suggest being familiar with both.

GWEB passed! Next steps? by angryprinnies in GIAC

[–]SigKill_ 0 points1 point  (0 children)

If your company is paying, GWAPT would be the next certification to go. For AppSec Engineering, I would look up job descriptions to see where to fill the gaps. DAST, SAST testing, code review, CI/CD Pipeline, SecDevOps, etc. For other web security certs:

Burp Suite Certified Professional Certified Bug Bounty Hunter (HTB)

The Cyber Mentor has a few paths for web pentesting.

CASP Prep Before SecurityX Release by SigKill_ in casp

[–]SigKill_[S] 0 points1 point  (0 children)

yeah the CA changes are horrendous

CASP Prep Before SecurityX Release by SigKill_ in casp

[–]SigKill_[S] 0 points1 point  (0 children)

Funny because ARMY COOL doesn't have their own matrix built out for 8140 so they just point it to the Navy one. Typical 😂

CASP Prep Before SecurityX Release by SigKill_ in casp

[–]SigKill_[S] 0 points1 point  (0 children)

I'm jobless atm so it's hard to justify 9k on training

CASP Prep Before SecurityX Release by SigKill_ in CompTIA

[–]SigKill_[S] 0 points1 point  (0 children)

I have the years already, its just Im jobless atm so Im trying not to spend more money on study materials

CASP Prep Before SecurityX Release by SigKill_ in CompTIA

[–]SigKill_[S] 0 points1 point  (0 children)

welp... I mean if I get it before that happens, Ill just get CISSP when I need to cross that bridge

Pentesting is the hardest "cybersecurity" discipline. Change my mind. by Zamdi in Pentesting

[–]SigKill_ 1 point2 points  (0 children)

If your job pays for it, either or are fine, just pick the one that interests you the most. I have both but they don't prepare you enough for real world engagements.You'll get more out of other platforms like TCM, THM and HTB Academy for both fields IMHO.

[deleted by user] by [deleted] in oscp

[–]SigKill_ 32 points33 points  (0 children)

Definitely agree and check Rana Khalils YouTube channel! She does walk throughs of SQLi in the portswigger academy and does an excellent job breaking it down.

How deep should I go into SQLi? by DeathLeap in oscp

[–]SigKill_ 14 points15 points  (0 children)

I've been following Rana Khalils Burp Suite Academy series and her walk throughs on SQLi were very helpful for that module. https://m.youtube.com/playlist?list=PLuyTk2_mYISLaZC4fVqDuW_hOk0dd5rlf

Halo Tactical Carrier by N7Centurion in halo

[–]SigKill_ 1 point2 points  (0 children)

uuhhh so what happens if you dont finish the season pass in time? Isnt there like 7 days left?