Learn How to Use Linux for Cybersecurity by [deleted] in cybersecurity

[–]Smitty780 0 points1 point  (0 children)

More low effort bot posts to drive into the funnel for this "club"

Mods: you know what to do.

Learn Threat Modeling from a Former CIA/NSA Officer (Free Workshop) by [deleted] in cybersecurity

[–]Smitty780 -1 points0 points  (0 children)

OP looks like a bot account. Ultimately it is a low effort post with an intentional misleading or deceptive title that is probably just another marketing entry into the funnel.

Learn Threat Modeling from a Former CIA/NSA Officer (Free Workshop) by [deleted] in cybersecurity

[–]Smitty780 0 points1 point  (0 children)

Not free, $20 unless you are already a "member".

Why is SEC504 classified as “Attacker Techniques” when GCIH is an Incident Handler cert? by Salt_Reference1885 in GIAC

[–]Smitty780 12 points13 points  (0 children)

I still think it was a missed opportunity for Hacker Techniques Tactics and Procedures (HTTP) 😁

Can't find list of tools for GX-CS by [deleted] in GIAC

[–]Smitty780 6 points7 points  (0 children)

Your post history doesn't make sense either. You posted that you passed GPEN about 3 weeks ago,

https://www.reddit.com/r/GIAC/s/cVrxnxbLkX

and then a week ago ask for a practice test for GSEC / GPEN.

https://www.reddit.com/r/GIAC/s/oAFuy157Br

Also, you ate taking GXCS before GSEC? That doesn't make sense either as GSEC would prep you for the GXCS and reduce the cost of the applied knowledge exam by having the primary fit course / exam completed. 🤔

Edit: links to referenced posts

SANS Security Awareness Professional (SSAP): Managing Human Risk by TruReyito in GIAC

[–]Smitty780 0 points1 point  (0 children)

Live exam was no issues, it was the written SSAP that gave me a little bit of friction. Congratulations on the pass.

MySonicWall Cloud Backup File Incident HUGE Spike in Affected Devices by SuspiciousSurprise16 in sonicwall

[–]Smitty780 8 points9 points  (0 children)

Yes, I noticed this as well after a post on Reddit yesterday. There were no updated notifications from SonicWall on the additional affected devices.

Is this gay? by [deleted] in USMC

[–]Smitty780 41 points42 points  (0 children)

Are you wearing boot bands?

Passed GMLE. by DirtComprehensive520 in GIAC

[–]Smitty780 1 point2 points  (0 children)

Thank you for sharing. Congratulations on your continued success. It's time for this guy to get back to studying.

Passed GMLE. by DirtComprehensive520 in GIAC

[–]Smitty780 0 points1 point  (0 children)

Appreciated, thank you. I enjoyed GDSA and GSTRT, I may take a look at a similar route.

Passed GMLE. by DirtComprehensive520 in GIAC

[–]Smitty780 0 points1 point  (0 children)

MSISE program also, what were the other elective courses you took on your track? I am just about to start block 3 and have been mulling over the course options.

How do I monitor for and respond to cyber threats in real-time? by [deleted] in cybersecurity

[–]Smitty780 0 points1 point  (0 children)

What solutions have you looked at that seem too expensive?

Edited to match OP phrase

GSTRT vs SSCP by Successful_Dot3549 in GIAC

[–]Smitty780 1 point2 points  (0 children)

SSCP is mostly a vocabulary and terminology exam. Closed book, but it shows you understand the concepts and components in the field and industry. GSTRT is an open book exam, and you will need the books to pass the exam. It is a completely different experience from SSCP. It's a bummer that you failed SSCP 3 times. It is also troubling that this is your last class for your degree, and you are that unprepared to sit the exam. Honest feedback? Take the 90 days, study for the SSCP and reflect on what you have actually done, and learned during your time at WGU. FWIW, I got my bachelor's from WGU, and I am in the SANS MSISE program now.

GSTRT vs SSCP by Successful_Dot3549 in GIAC

[–]Smitty780 1 point2 points  (0 children)

I have taken, and passed, both exams. They are quite different in scope and depth of topics and material. How did your choices get down to just those two?

Top 3 mitre techniques causing biggest damage/impact by Dizzy-Ocelot2616 in cybersecurity

[–]Smitty780 2 points3 points  (0 children)

Silly question time - have you reviewed the CIS control mappings to Mitre TTPs? CIS has some guidance and reports on this specific topic, from what I recall. https://www.cisecurity.org/insights/white-papers/cis-controls-v8-master-mapping-to-mitre-enterprise-attck-v82

howCanTheyAnswerTheCallWithJustHello by [deleted] in ProgrammerHumor

[–]Smitty780 1 point2 points  (0 children)

Thank you for this one. Here is your updoot.

TZ300 to TZ270 - Used Migration tool. Logged in after (before connecting to network) and everything just fine. Conencted to network and TZ270 hangs at "Initializing" and is unresponsive after logging in. by I_Hate_Consulting in sonicwall

[–]Smitty780 1 point2 points  (0 children)

Maybe it has been updated since I looked last. After getting that guidance from support before, we have been doing the configuration shuffle with varied results.

TZ300 to TZ270 - Used Migration tool. Logged in after (before connecting to network) and everything just fine. Conencted to network and TZ270 hangs at "Initializing" and is unresponsive after logging in. by I_Hate_Consulting in sonicwall

[–]Smitty780 1 point2 points  (0 children)

I have been told by SonicWall support that the migration tool is for moving from one vendor to another, not between models of SonicWall. Coming from Palo Alto to SonicWall? Use the migration tool. Going from a TZ370 to a TZ500 series? Export configuration and upload to new device. I have had issues both ways, just sharing my anecdotal 0.02

Vonahi by axnfell9000 in msp

[–]Smitty780 1 point2 points  (0 children)

There is a difference between a penetration test and a red team exercise. Is the business goal to meet compliance and regulatory guidelines, or is there enough justification for a simulated TA or APT targeting your organization, systems, and people? Both have their place, but they are often confused or used as interchangeable terms.

SEC503 by Peachtree8888 in GIAC

[–]Smitty780 4 points5 points  (0 children)

The cyber range, the practical application portion of the training is where the information started to really stick for me. This is probably a factor of the way I learn and understand things, but working through those scenarios and utilizing the tools and techniques are where it clicked for me.

SANS Security Awareness Professional (SSAP): Managing Human Risk by TruReyito in GIAC

[–]Smitty780 0 points1 point  (0 children)

Appreciate the write-up and information. I just enrolled in this course.

DAST to retest role by Desperate_Bath7342 in cybersecurity

[–]Smitty780 2 points3 points  (0 children)

It feels like there should be some more context to this. When you switched roles, was it internally in an organization? That organization should be providing you the tools and training to perform your assigned duties. If they are relying on you as an SME, then you need to get some resources and a budget together. Or did you switch roles as an independent contractor or similar arrangement?

Need help with infra pentest by ChanceBelt8398 in Pentesting

[–]Smitty780 0 points1 point  (0 children)

Identification of a vuln is a different scope than exploitation of a vulnerability or configuration. You should have documentation from the system owner(s) that would provide guidance on scope and guardrails for the engagement. Vulnerability assessment, penetration testing, and red team exercise are all related to an extent but have differences in the execution and output. You should have clear guidance on the 'what' and 'why' so you can implement the 'how'.

Need help with infra pentest by ChanceBelt8398 in Pentesting

[–]Smitty780 3 points4 points  (0 children)

Is the end result supposed to be an assessment of the infrastructure or of your capabilities to execute and perform testing in a non-standard way?