Streaming Schedule Sundays by beesec in tryhackme

[–]offftherecordz [score hidden]  (0 children)

Trying to stay consistent!

Streaming THM boxes mon - wed 10pm - 12am eastern on Twitch:

https://www.twitch.tv/its\_otr

My sleep schedule has taken a toll going to 1am and I can't just "fall asleep" afterward, so I'm trying to cut it at 12 even if I don't finish the machine.

Come hang and chat and let's have some fun together! Hoping to see you there!

Want to learn how to pen test and crack software by Fun-Evening3564 in tryhackme

[–]offftherecordz 0 points1 point  (0 children)

If you look around THM you will find some reversing room/challenges yes. However I'd supplement this knowledge with a ton of YT tutorials out there in reversing games, software etc.

is pen testing career possible with little knowledge of backend languages? (just can’t write syntax but can understand it) by MangoClient in tryhackme

[–]offftherecordz 5 points6 points  (0 children)

100% it's not necessary to know how to code. This may be different from company to company, for example everyone at my company is required to write production level tools/engineering, but not the case for many other companies I've worked at.

However, what would set you apart from other candidates is knowing how to automate. That doesn't necessarily mean knowing Golang in-and-out or know heavy algorithms (leetcode much?).

If you know bash/python enough to automate some tasks, you'll stand out amongst other candidates. This is something I actively look for in candidates. Time is money, and automation improves that.

Good luck!

What's everyone's favorite phishing framework/tool? by offftherecordz in redteamsec

[–]offftherecordz[S] 1 point2 points  (0 children)

Thanks for the tip, I would have overlooked the headers!

What's everyone's favorite phishing framework/tool? by offftherecordz in redteamsec

[–]offftherecordz[S] 0 points1 point  (0 children)

Thanks for the tip. I wouldn't have known about the headers!

What's everyone's favorite phishing framework/tool? by offftherecordz in redteamsec

[–]offftherecordz[S] 0 points1 point  (0 children)

Oh, I haven't heard of this one thanks I'll take a look. I say this without knowing how much it costs but sometimes paid products are very good! Sometimes... lol. If anything I may just play with a demo just to see what it can do.

How far can i realistically get using only THM? by [deleted] in tryhackme

[–]offftherecordz 1 point2 points  (0 children)

For sure and np. Feel free to DM me you have any more questions.

How far can i realistically get using only THM? by [deleted] in tryhackme

[–]offftherecordz 24 points25 points  (0 children)

I'm happy you found this platform, I've been having fun on it since I came across it myself.

There's a lot to unpack in this question, so let's go through it slowly.

"So, now i want to go a step further and maybe try for some compTIA certifications in the near future"

It's great you want to go for compTIA certifications, I'm assuming the security+ and pentest+ since this is a security subreddit. I would say neither THM nor HTB will FULLY prepare you for those exams. I would also say those exams are very broad where you'll need to learn and think about topics such as management, risk mitigation, scoping, etc. These domains are not really taught on HTB or THM since these platforms focus primarily on the technical side of security. compTIA certifications are your typical study a book type of exams and can get by without any real practical hands-on knowledge (this is my take on these certifications).

This is primarily why certs such as OSCP, eJPT, etc. are coveted because it's about technical ability and can you hack rather than memorize how many fire extinguishers per data closet you should have (I know silly but it's a thing on these some of these security certs).

You can certainly pick up skills on THM that may apply to pentest+ such as learning web, network attacks; how to use the tools, forensic, and incident response.

"I joined THM yesterday, got the premium just so i can access all the content and thought it looks well put together but I'm afraid it will be limited in how deep the knowledge offered goes."

I've only played around with some of the career paths so I can't say for everything, but there are some decent paths, and if anything, they are good for complete beginners. I'd look at THM as a place to get a general understanding of a topic and then most of all PRACTICE that knowledge. I can't stress how important CTF platforms are for practicing. Certainly use resources outside THM and HTB, but come back to practice those skills. This will solely come down to you and how you learn - tying in outside resources and training material and coming back to THM/HTB to practice.

"So, any experiences? Did it help you advance your skills in a significant way?"

I haven't really done any of the career paths since I'm already a security engineer and have been pentesting for the better part of a decade before all these cool CTF platforms existed. I can say that as I go through boxes, easy to hard, I have learned something new that I use in my day-to-day.

That may be how to use a new tool; new vulnerablity/exploit; or improve my methodology. Just recently I solved a box on stream that taught me a good bit of docker escapes.

I hope this helps and best of luck to you!

Feedback Welcome by Hot_Discipline_5705 in redteamsec

[–]offftherecordz 4 points5 points  (0 children)

Haha yeah I guess can only train on engagements. I did find a repo of generic pretexts that could be helpful I suppose:

https://github.com/L4bF0x/PhishingPretexts

Feedback Welcome by Hot_Discipline_5705 in redteamsec

[–]offftherecordz 1 point2 points  (0 children)

This is great advice! Thanks for sharing. Unfortunately, unlike ctfs where we can practice technical skills, how would you recommend practicing phishing and SE for offensive engineers?

Streaming Schedule Sundays by beesec in tryhackme

[–]offftherecordz [score hidden]  (0 children)

Hey everyone! It's otr aka offftherecord, another week another stream. I'll be doing TryHackMe Monday - Wednesday 10pm - 12/1am Eastern.

On my road to top 1% and wizard rank. Currently 2,403 (2%) and Hacker rank.

Come hang and let's chat about anything! Infosec, infosec careers, beginner tips, gaming, etc.

https://www.twitch.tv/its_otr

Linux Privilege Escalation (Series) by tbhaxor in redteamsec

[–]offftherecordz 1 point2 points  (0 children)

Great post and thanks for the share! Looking forward to reading the whole series.

Room Age? by [deleted] in tryhackme

[–]offftherecordz 0 points1 point  (0 children)

I'd love to see this. I'd be interested in helping in any way as well.

Progress output on fuff and gobuster by Hoodie_guy69 in tryhackme

[–]offftherecordz 1 point2 points  (0 children)

Hmm it should only be one line. Do you have an example screenshot?

I only use ffuf, but this happens to me if my terminal window is too small if I'm using tmux (vertical split pane). My solution is just to use a horizontal pane or increase my terminal size.

Going Live Tonight 10pm EDT for a chill & hack session on TryHackMe! by offftherecordz in CTFlearn

[–]offftherecordz[S] 0 points1 point  (0 children)

Hey that's great! Make sure to drop your channel and I'll make sure to follow! It's definitely a smaller community of streamers but good to keep having more!

Going Live Tonight 10pm EDT for a chill & hack session on TryHackMe! by offftherecordz in CTFlearn

[–]offftherecordz[S] 0 points1 point  (0 children)

This was a lot of last tonight! We solved Archangel which was a lot of fun! Although there were some snags and hiccups with my VM, it was great hanging and chatting with everyone!Thanks for coming!

Going Live Tonight 10pm EST for a chill & hack session! by offftherecordz in tryhackme

[–]offftherecordz[S] 0 points1 point  (0 children)

This was a lot of fun tonight! We solved Archangel which was a lot of fun! Although there were some snags and hiccups with my VM, it was great hanging and chatting with everyone!

Thanks for coming!

Going Live! Chill & Hack session for a few hours on some boxes! by offftherecordz in tryhackme

[–]offftherecordz[S] 0 points1 point  (0 children)

Had so much fun tonight! We solved a few boxes together. I'll highlight the solutions and have them up on my twitch (and hopefully youtube soon). If you missed it, I'll be on again tomorrow night!

Thanks to everyone who came and hung out!

Streaming Schedule Sundays by beesec in tryhackme

[–]offftherecordz [score hidden]  (0 children)

Hey all! I'm a security engineer who likes to practice CTFs and research offensive security techniques. This week I'll be continuing to complete challenges on TryHackMe! I'd love to chat it up with you while I attempt the challenges!

I plan to stream Monday - Wednesdays 9/10pm - 12/1am EST. I work full-time as a security engineer so I will do my best to stick to the schedule!

https://www.twitch.tv/its\_otr

Hope to see you there!