Currently working as a Senior Consultant at Netcompany spending my full-time job solving the SharePoint riddles. In the free time I'm expanding my understanding of cybersecurity through hacking activities. Git fanboy.
Recently, I was able to advise a few people on how they can start to learn cybersecurity through offensive security and pentesting. I realized that instead of repeating myself, I can write that down in an article, so it can be shared with anyone interested in expanding their itsec skills. I'll keep this article updated.
">
β 1. Understand what it means to hack ethically.
This is crucial to understand that without a purpose, tools are neutral. They are neither bad nor good - with a kitchen knife one can slice an onion, or wound somebody. The same rule applies to every pentesting tool that you are going to use. You must have that in mind, that only you are responsible for the consequences of your actions.
π§ 2. Hand-on experience, AKA keep your hands dirty.
β For a starter, take the free courses on TryHackMe and HackTheBox Academy - both are the first places I would learn from. THM have Complete Beginner Path and HTB Academy starts with Introduction Module. I haven't completed all available modules yet, but I feel like I know so much more and have that knowledge structuralized.
On July 2021 TryHackMe released a Pre Security Learning Path. It's a good way to start, but remember that on THM you almost always need a subscription to complete whole modules - for free are the first couple of rooms from a module.
π‘ 3. When hands are tired - watch meaty online courses.
β As for video lessons, I would recommend joining Dev Essential program from Microsoft. You should have found there time-limited access to the Pluralsight - if so, take the [Ethical Hacking CEH Preparation](https://app.pluralsight.com/paths/certificate/ethical-hacking-ceh-prep-2018 path).
β Sometimes you can also acquire the 3 months of LinkedIn Learning access - for example, I found mine voucher on the Visual Studio Subscription associated with my company account. From this site I recommend both Learning Kali Linux and Become an Ethical Hacker.
All these materials are the top-notch theoretical ones in my opinion.
If you can spend a few bucks (or wait for the occasional discounts) this is a well put course on OWASP Top10 made by The XSS Rat.
π 4. Use vulnerables to practice live example scenarios.
Vulnerables are purposely crafted vulnerable applications or even whole operating systems like Metasploitable that you can use in your isolated internal network or play with them on a Docker.
Are you a sports fan? Do you like watching online tournaments? Even if not, trust me in this one. I can't count how many times I have eagle-eyed something that get me that one level higher in my proficiency. Things like stabilizing shell, multitasking terminals or just overall approach in documenting my findings.
π Amazing David Bombal and Neal Bridges YouTube playlist - talks about starting ethical hacking, red/blue teaming, certificates and pentester software.
π 6. Subscribe and watch others that are on the similar level.
For this, I recommend following my #CyberEthical contents on Instagram and on LinkedIn. Add your mail to the mailing list on this site - you will be notified only on a new content on my blog.