Pentest 1
Pentest 1
Pentest 1
The Hacker Mindset takes time and repetition to develop and is best
developed by hands on hacking experience.
Pentester Blueprint: Formula
Technology Knowledge
+
Security Knowledge
+
Hacker Knowledge & Mindset
Pentesting Education
Developing a Plan: Your Personal Pentester
Blueprint
• Skills Inventory
• Skill Gap Analysis
• Create a Plan to Address Skills Gaps
Pentesting Education: Learning Resources
• SANS Institute: sans.org
• OffSec (formerly Offensive Security): offsec.com
• Antisyphon Training: antisyphontraining.com
• Virtual Hacking Labs: virtualhackinglabs.com
• Pentester Academy: pentesteracademy.com
• INE (formerly eLearn Security): INE.com
• Zeropoint Security: zeropointsecurity.co.uk
• Pentester Lab: pentesterlab.com
• TCM Security Academy: academy.tcm-sec.com
• Hack The Box Academy: HackTheBox.eu
• Try Hack Me: TryHackMe.com
Pentesting Education: Free Learning
Resources
• Bugcrowd University: bugcrowd.com/university/
• HackerOne: hacker101.com
• HackingTutorials.org
• Web Security Academy: portswigger.net/web-security
• Try Hack Me: TryHackMe.com
Pentesting Education: Certifications
Entry Level Advanced
• CEH - EC-Council • GxPN – SANS/GIAC
• PenTest+ - CompTIA • OSCE – Offensive Security
• eJPT - INE Web App
Intermediate • GWAPT – SANS/GIAC
• PNPT – TCM Academy • Burp Suite Certified Practitioner -
• GPEN – SANS/GIAC (now includes Portswigger
Azure) • OSWA – Offensive Security
• OSCP – Offensive Security • OSWE – Offensive Security
• GWAPT – SANS/GIAC Cloud
• eCPPTv2 - INE ● GCPN - Cloud Pentesting
Pentesting Education: Certifications
Red Team
• CRTO - ZeroPoint Security
• SEC565: Red Team Operations and
Adversary Emulation (no cert yet)
Pentesting Education: Certifications
Determining which certification to get
• Research job listings to see which certifications are more in demand.
• CEH and PenTest+ are DoD Directive 8570 certifications and can be
helpful for government jobs, whether working directly for the
government or through contracting and consulting.
Pentesting Education: Certifications
Certification Tips
• Learn the skills and not just prepare to pass the exam. This will help
your probability of success and give you skills needed for pentesting
roles. The better you know the content of the certification education
content, and it will help during interviews.
Lab Environment: Home Lab
Lab Targets
• Virtual Systems - Purposely Vulnerable Systems
• Physical Hardware - Servers, Clients, Routers, Switches
• Vulnerable VMs
• Metasploit 2 & 3
• Vulnhub.com
Hacking System
• Virtual System
• Physical Hardware
• Hacking OS
• Linux - Kali, Parrot OS
• Windows - Commando VM, Flare VM (by Madiant)
Lab Environment: Online Lab
• Try Hack Me
• Hack The Box
• Proving Grounds Labs (OffSec): offsec.com
• Antisyphon Cyber Range: antisyphontraining.com/cyber-range/
• Over The Wire CTF: overthewire.org/wargames/ (Linux)
• Under The Wire CTF: underthewire.tech/index.htm (Windows)
Pentesting Education: Books
Penetration Testing:
A Hands-On Introduction to Hacking
Operator Handbook
The Security Content Automation Protocol uses CVE, and CVE IDs are listed on
Mitre's system as well as in the US National Vulnerability Database.[4]
ref: https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures
Hands-on Pentesting Experience:
CVE Learning Resources
• Bobby Cooke aka Boku - Beginners Guide to 0day/CVE AppSec
Research https://0xboku.com/
2021/09/14/0dayappsecBeginnerGuide.html
• Joe Helle aka The Mayor - I Was Bored One Night and Found Two CVEs
https://medium.themayor.tech/how-i-was-bored-one-night-and-
found-two-cves-4233c3719194
Demonstrating & Documenting Skills
• Writing
• CTF, HTB, and THM write ups
• Articles and blog posts on GitHub, Medium, or other blog platforms
• CVE IDs - list under publications on LinkedIn (link to CVE) and resume
• Tool and technique demos and hacking walkthrough videos on
YouTube
• Scripts or programs on GitHub
Build a Personal Brand
• Content Creation
• Streaming
• Video - YouTube, Vimeo, Instagram, TikTok, Facebook
• Writing
• Public Speaking
• Conferences
• Cybersecurity Meetings
• Webinars & Podcasts
• Social Media
• LinkedIn
• Twitter
Professional Networking
• LinkedIn
• Cybersecurity Group Meetings (ISSA, ISACA, (ISC)2, DEFCON Groups,
OWASP Chapters, college clubs)
• Conferences
• Online Communities (Discord, Slack, etc.)
• Twitter
Job Hunting Tips
• Prepare for interviews
• Know the OWASP Top 10
• Be able to explain the basics like 3-way TCP handshake and OSI Model
• Infosec Job Hunting w/ BanjoCrashland https://youtube.com/playlist?
list=PLqz80p7f6dFumNG0wU4Ql41PvhzamHO3_
• How to Create a Better Infosec Resume (with@jhaddix)!
https://youtu.be/Zs28J_SDXYQ
Questions
?
Contact Me
thehackerfactory.simplecast.com
/ln/PhillipWylie
TheHackerMaker.com
@PhillipWylie
youtube.com/@PhillipWylie