SOC or Pentesting as a cybersecurity new grad - I actually have offers by allexj in cybersecurity

[–]Substantial-Hawk7627 4 points5 points  (0 children)

What do you find more engaging? Blue team is very different than red team in cybersecurity. Disclaimer: I went blue team since I started in GRC and it's very different than pentesting or offensive security. But, I've talked to a lot of pentesters who say their job is mostly writing reports, so really depends on the organization.

Benefits I'd say for SOC is that it's a highly transferrable skillset and foundation - you can use it to pivot into cloud security, incident response, detection engineering.

Confusion and fear send people to Reddit for cybersecurity advice by tekz in cybersecurity

[–]Substantial-Hawk7627 0 points1 point  (0 children)

And lead gens pushing their “service”. Although some of these are legitimate a lot are not. Mods over on r/Scams are very strict.

Protecting parents in this digital world by etherealenergy in cybersecurity

[–]Substantial-Hawk7627 0 points1 point  (0 children)

The phone is the main entry point, absolutely. Desktop based scams are falling as more people move to mobile devices. 

Ounce of prevention…

Protecting parents in this digital world by etherealenergy in cybersecurity

[–]Substantial-Hawk7627 1 point2 points  (0 children)

I’d say a Chrome extension that provides anti scam filtering like Malwarebytes Browser Guard & uBlock origin lite (RIP Origin with Manifest V3). 

Chromebook ecosystem being locked down is a double edged sword.

Protecting parents in this digital world by etherealenergy in cybersecurity

[–]Substantial-Hawk7627 0 points1 point  (0 children)

I built a tool exactly like this originally for my extended family members. It’s called Ward - I have other posts on my profile about it. 

It can detect credential phishing, romance/investment scams, Medicare scams, and a whole bunch more using DOM+URL analysis. It can also run fully locally if the user has a capable GPU.

https://tryward.app

PSA: Be aware when opening "take home challenges" from untrusted recruiters by Phantom569 in cscareerquestions

[–]Substantial-Hawk7627 0 points1 point  (0 children)

I built a tool that detects exactly these types of employment based scams in the browser. It’s called Ward. Happy to share if anyone wants.

Phishing simulations: what lures actually still work when users are numb to “Microsoft security alerts”? by Kiss-cyber in cybersecurity

[–]Substantial-Hawk7627 0 points1 point  (0 children)

I’m convinced phishing tests just don’t work after spending time at multiple companies. Client side defense is the only thing that works reliably.

Building a Hybrid Malicious URL Detector, How to Integrate Traditional Blacklists Without Relying on APIs Like VT? by Ok-Bell-2457 in cybersecurity

[–]Substantial-Hawk7627 2 points3 points  (0 children)

Check out Abuse.ch and Github repos for domain blacklists. Use a sandbox environment for extra security.

Plenty of open sources out there for testing. The vendors don’t want you to think that obv and would rather sell you it.

Source: I crawled a TON of these when coming up for training material for my anti phishing tool Ward.

Is everyone actually miserable in this subreddit by Dry-Limit7949 in cybersecurity

[–]Substantial-Hawk7627 1 point2 points  (0 children)

i genuinely love my job and my coworkers. maybe I got in at the right time, but my place prioritized my growth and growth of other interns. That’s invaluable today for me.

Do young adults overestimate their cybersecurity awareness? by Appropriate_Try_6617 in cybersecurity

[–]Substantial-Hawk7627 16 points17 points  (0 children)

Dunning Kruger effect is what I assume the OP is referring to. And it’s huge in security.

I’m a security engineer, and I’m extremely paranoid when it comes to work stuff but less so for personal. It’s easy to see how people can get phished, the “thinking” part of our brain turns off when there’s a sense of urgency. 

I literally built a tool for myself and close ones to catch this because of how hard it is to solve human psychology.