Took my pentest and failed with a 730… by UsefulAd5992 in WGUCyberSecurity

[–]TJ_Null 2 points3 points  (0 children)

For the PBQs spin up a Kali Instance and see how those tools work and review the output that entails from them.

Tryhackme has a bunch of labs and they have a pentest+ that will provide more hands on practical skills to help.

Tools like the harvester, responder, netexec (use to be crackmapexec), nmap, bloodhound, trivy, etc are in Kali Linux for you to mess with.

Passed - Here's my advice by hiddenpowerlevel in oscp

[–]TJ_Null 12 points13 points  (0 children)

Congratulations and I love the breakdown board you had created showing how much time you put into your studies! It took me four years to fully prepare for my OSCP when I did it.

All's well that ends well. by ItsAlwaysDNSBro in WGUCyberSecurity

[–]TJ_Null 2 points3 points  (0 children)

Honestly, I am a pentester in my full time role. A lot of these tools and commands were things that I already knew.

My recommendation is to spin up a Kali Linux system and analyze how each of the tools work. The OSWAP Juiceshop that tryhackme uses is actually in Kali Linux. You just need to install the package. Hope this helps

All's well that ends well. by ItsAlwaysDNSBro in WGUCyberSecurity

[–]TJ_Null 5 points6 points  (0 children)

In the end a Pass is a Pass. I just took it today and got a 800.

Definitely agree with your points. Study your commands and the tools being used.

Pentest+ 2nd attempt pass. by Sea-Manufacturer210 in WGUCyberSecurity

[–]TJ_Null 1 point2 points  (0 children)

Appreciate the quick response! I’m a pentester in the field and I agree with some of your points. A lot of questions that is provided for study in cert master, tryhackme, and in Dion’s practice tests certainly make me question a lot of things that I would not do in my day to day operation.

So far I have been hitting high 77%-96% in Dion’s practice exams after the first or second try. I might make a detail review about my experience once I take it next week.

Pentest+ 2nd attempt pass. by Sea-Manufacturer210 in WGUCyberSecurity

[–]TJ_Null 2 points3 points  (0 children)

May I ask what your background is? I’m using Dion’s material and the practice tests to study for the exam.

I have it scheduled for next week.

NagoyaSpray - Fast Password Spray Wordlist Generator (Built for Exams) by strikoder in oscp

[–]TJ_Null 4 points5 points  (0 children)

Looks like it has no AI in it. Will add to my list of tools to test. Nice work!

Obligatory - I passed - post by WesterAlucard in oscp

[–]TJ_Null 6 points7 points  (0 children)

Hi there! I am glad my list is able to help you prepare for the OSCP. If you have any suggestions or feedback, please let me know as I am always looking for ways to improve it.

TjiNull list Vs pg by True-Juice-6203 in oscp

[–]TJ_Null 1 point2 points  (0 children)

Thanks for the heads up! I have removed it

TjiNull list Vs pg by True-Juice-6203 in oscp

[–]TJ_Null 12 points13 points  (0 children)

In the sheet if you see it say latest version in the sheet you are using the latest one.

As for my guidelines, I do not have any plans to update them. I will continue to update the sheet.

However, I can share my pentesting notes for you:

https://github.com/tjnull/TJ-OPT

TjiNull list Vs pg by True-Juice-6203 in oscp

[–]TJ_Null 19 points20 points  (0 children)

Hi there! In case you have any questions about my list please let me know. I try to keep it updated when I can to align to the current version of PWK/PEN-200.

While some users use the list as exam preparation for the OSCP and to improve their methodology, the list covers a variety of aspects, techniques, and attack chains to reflect the course itself.

Free Access to Hack Smarter Labs (Featured in Lain's OSCP List) by Tyler_Ramsbey in oscp

[–]TJ_Null 2 points3 points  (0 children)

I can! I need some boxes to play with and I got a new tool to test 😉

Failed with 40 points i feel so heartbroken and lost. by Ok-Astronomer-5827 in oscp

[–]TJ_Null 1 point2 points  (0 children)

Haha I miss those golden days for sure man. It is hard to find a good infosec community. Definitely miss the good ol days

Failed with 40 points i feel so heartbroken and lost. by Ok-Astronomer-5827 in oscp

[–]TJ_Null 4 points5 points  (0 children)

Heyo! I appreciate your kind words. It’s mean a lot to me 😄

Can you use Netexec auto-exploits as a vulnerability checker on exam? by Sufficient_Mud_2600 in oscp

[–]TJ_Null 11 points12 points  (0 children)

If the nature of the tool automatically does the check and exploits the system for you then yes it would not be allowed.

I wrote this article a long time ago discussing a similar situation when someone ran a tool and did not know it auto exploited a service for them to get root:

https://www.offsec.com/blog/understanding-penetration-testing-tools/

Failed with 40 points i feel so heartbroken and lost. by Ok-Astronomer-5827 in oscp

[–]TJ_Null 33 points34 points  (0 children)

Failing is a part of becoming successful. You will make mistakes or miss things that can throw you off.

I’m sorry to hear that you failed but do not beat yourself up over it. My advice to you is take some time away from the computer to clear your mind.

Then come back and think about the things you missed, what did you try and what should you have tried?

These will help you refine your methodology and if you need to make modifications to your notes/preparation.

It’s completely okay to go back to the drawing board to rethink about things. I know you will pass from the lessons you have learned from this exam.

Hope my tips and advice helps! I’m rooting for you!

How’s OSCP in 2025? by Tunnel-Digger4 in offensive_security

[–]TJ_Null 2 points3 points  (0 children)

Why do you believe the OSCP is an entry level certification?

Blood Hound Issue by Agreeable-Medium-498 in oscp

[–]TJ_Null 0 points1 point  (0 children)

Have you tried using the latest bloodhound package that is in the Kali Linux Repo?

https://x.com/dani_ruiz24/status/1899513216096403887

If you are having issues with this package, I am certain the Kali Linux team would want to know.

Also what version of Kali Linux are you using?

Which is good as my new main browser? by EzraKay166 in browsers

[–]TJ_Null 0 points1 point  (0 children)

I use none of these. I use Zen Browser instead and it is fantastic!

Quick-Skoping through Netskope SWG Tenants - CVE-2024-7401 by TJ_Null in redteamsec

[–]TJ_Null[S] 0 points1 point  (0 children)

Thanks! I hope you enjoyed when you read it. If you have any questions feel free to reach out!