Это видео недоступно.
Сожалеем об этом.

How to Get Pentesting Experience

Поделиться
HTML-код
  • Опубликовано: 25 авг 2024

Комментарии • 36

  • @cauxxx2454
    @cauxxx2454 Месяц назад +38

    PROT TIP:
    I got m first job lying that I had 3 months of experience...
    5 years after, still no regrets

    • @dmanptrona
      @dmanptrona Месяц назад +6

      I think this the push I needed to actually do this! I've been thinking about doing it. Sucks when you know you can do the work but the fact that you don't have experience means you're nothing in the job market.

    • @luszczi
      @luszczi Месяц назад

      People like you get ahead of honest applicants, who chose not to lie. The fact that you have no regrets shows that you're lacking in sense or conscience.

    • @greatwhiteswag
      @greatwhiteswag Месяц назад +2

      NO REGERTS

    • @UnionRing
      @UnionRing Месяц назад +3

      Sadly that's what we all have to do to get started. I have been rejected many times for being honest and only when I decided that I am gonna lie about my experience I managed to get a job. Nobody cares about giving you the chance if you have no expereince.

    • @Thiccolo
      @Thiccolo Месяц назад +4

      Every single one of my friends in tech have gotten their first job by lying. Except for one person who is given a chance by pwc

  • @OriginalGumshoe
    @OriginalGumshoe Месяц назад +5

    Really great advice! This type of self-initiated planning for any job is a must for young and/or inexperienced people in today’s world arena. You show some great examples of how to do this and I am sure there are people who will become happy, successful, employed or self-employed workers due to your advice! Thank you!

  • @Cyb3r6h0st19
    @Cyb3r6h0st19 Месяц назад +4

    Love it, what about projects for SOC analyst since this is great for an entry level jobs in cybersecurity

    • @scorit-zq4yx
      @scorit-zq4yx Месяц назад

      You could use the first project as a SOC analyst project. Install the Elastic Stack. Configure Logstash to Process Honeypot Logs. Configure Kibana to Visualize the Data.

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  Месяц назад +1

      We outline a few ideas in this livestream recording with Andrew Prince aka our Blue Team Content Creator! ruclips.net/user/liveEECmpBBbn5Y

  • @Arken_666
    @Arken_666 Месяц назад +1

    Nice content! The funny thing is: Building a Honeypot is quite similar from creating a CTF.

  • @TheDarkPoopVadeee
    @TheDarkPoopVadeee Месяц назад +1

    Thank you so much.

  • @TheQA247
    @TheQA247 2 дня назад

    I love some of the ideas discussed but why is actual web application testing (QA) never discussed?
    Speaking from experience, there's a far greater set of skills gained from learning testing fundamentals over web dev.

  • @lastbenchers3647
    @lastbenchers3647 Месяц назад +1

    Thank you 😊👏

  • @cristophersoto1244
    @cristophersoto1244 Месяц назад

    Hey, any ideas on the honeypot project?

  • @mr.atomictitan9938
    @mr.atomictitan9938 Месяц назад

    This is a great video but I want to know where to start. I understand this video is general but say I don’t know how to setup/make a web app. Where would I look to start? What sources would be good to look into or repos to clone?

  • @CyberDavid2413
    @CyberDavid2413 Месяц назад +1

    Any projects that would help one who is trying to break in a SOC environment?

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  Месяц назад +1

      Some good ones would be setting up a virtual lab environment to simulate a SOC. And in that lab, deploy a SIEM (Splunk or the ELK Stack / Elasticsearch, Logstash, Kibana).
      Another option is Security Onion or Wazuh. There is a good series by HackerSploit on setting up Wazuh as a SIEM (ruclips.net/video/Hq58_yGJwHk/видео.html).A SIEM project like that would go a long way. Another project idea would be to deploy a PFSense firewall (www.pfsense.org/download) to learn how they work and how to create firewall rules. It also has built-in integrations with the Snort IDS/IPS.
      Also on the network side, even just deploying Snort or Suricata can be really beneficial in learning how an IPS or IDS works, and we actually cover this in the upcoming SOC 101 course.
      Other project ideas:
      To get EDR experience - look into LimaCharlie
      For event logging and log analysis, look into installing and configuring Sysmon or using DeepBlueCLI
      The best advice for doing any of these projects, is to document it somewhere. Even if it's just a blog post, or a README on GitHub. Something to document the steps you took, what your objective/goal was, any issues you ran into along the way (and how you solved them), and what you learned by completing the project.

  • @abadiallo709
    @abadiallo709 Месяц назад

    interesting content I like!!! and for ethical hacker projects??? THANKS

  • @VenkiVerse
    @VenkiVerse Месяц назад

    Hello sir, I'm interested and want to switch to cybersecurity field.. can you please explain the roadmap in your next video?

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  Месяц назад

      Hey! We're going to update this video for 2024, but this still has some solid pointers. ruclips.net/video/4JZjj_H4ei4/видео.html

  • @CL-tl3ez
    @CL-tl3ez Месяц назад

    Hi Sir can you suggest some good companies on where to apply for pentesting jobs around new york? Thank you very much would greatly appreciate it

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  Месяц назад

      Are you in our Discord server? Sometimes people share jobs there - would recommend checking it out! Here's a link to the server: discord.com/invite/tcm

  • @ragnarok55
    @ragnarok55 Месяц назад +1

    Make ctf videos

    • @LoneStarBassPursuit
      @LoneStarBassPursuit Месяц назад +1

      Pretty sure they did.
      Edit they did check like 3 months back in videos.

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  Месяц назад +1

      Here's a recent one we did: ruclips.net/video/8QCWgMrqrFk/видео.html

    • @LoneStarBassPursuit
      @LoneStarBassPursuit Месяц назад

      @TCMSecurityAcademy yep there it is. Thanks big bro.

  • @d3layd
    @d3layd Месяц назад +2

    1.25x is good, but you could listen to this at 1.5x pretty easily if you wanted

  • @Nahiyan_The_Cyber_Expert
    @Nahiyan_The_Cyber_Expert Месяц назад +9

    Who is become a ethical hacker..? First me 🖐️

  • @wandering-jew
    @wandering-jew Месяц назад

    First comment

  • @GodlyTank
    @GodlyTank Месяц назад

    Second

  • @saksham1283
    @saksham1283 Месяц назад

    Fourth comment

  • @abdirahmanmohamedsaid6201
    @abdirahmanmohamedsaid6201 Месяц назад

    Third comment

  • @krishjha2913
    @krishjha2913 Месяц назад

    Fifth comment