Press J to jump to the feed. Press question mark to learn the rest of the keyboard shortcuts
Found the internet!

AccessCyber

r/AccessCyber

11
pinned by moderators
Posted by6 months ago
11
8 messages

Live Chat

2
Crossposted by7 days ago
Posted by7 days ago
Tree Hug

Information technology and cyber security require a strong technical foundation in knowledge and skills. Most employees learn about the basics in school, on the job, or through training or certifications. After mastering the foundations and becoming a professional in IT and cyber security, how does one improve their knowledge? They need hands-on technical training in an isolated and secure lab environment in order to stay current and improve their technical skills. The most effective strategy for doing this is to build virtualized hacking laboratories. The CYBERSOC HACKLAB PROJECT can provide specialized training, be used to prepare employees for a scenario, and help employees in improving their technical abilities, making them better all-around technical staff. You may learn how to build your own hacking lab on this channel.

Subscribe to our Channel at https://bit.ly/3D1HkcN Thank you for your support and God Bless!

0 points
2
0 comments
1
Crossposted by9 days ago
Posted by9 days ago

GET 12 MONTHS PLURALSIGHT SUBSCRIPTION FREE with Pluralsight ONE + Code.org

Subscribe: https://linktr.ee/cybersocitlibrary


Pluralsight ONE + Code.org
2 points
1
0 comments
1
Posted by24 days ago
1
1 comment
2
Crossposted by25 days ago
Posted by25 days ago

I hope this helps someone looking to break into either or both fields. Please respond with your own lessons learned and the lessons you disagree with.

  1. For HTB/OSCP/THM: The harder the box, the more realistic it is.

  2. Certs are far more effective for personal morale/the will to stay in the field than being a resume must-have. This field will drain you and certs can recharge you.

  3. Windows gets larger and clunkier with each new version. Expect unwanted features.

  4. Windows Defender is not terrible. It's market exposure means more scrutiny from sec professionals.

  5. Your NMAP skill will never stop evolving. There is no ceiling to improving one's enumeration.

  6. Threat Hunters: Never assume Port 443 is encrypted.

  7. Pen Testers: Learn to defend and threat hunt. Experience limitless value.

  8. Anonymous logon (SMB) is common in Active Directory and should never be written as a misconfig.

  9. Anonymous logon with full read/write access is another thing.

  10. If you have credentials, you can logon a Windows device using RPC alone.

  11. Working on AD and lost the domain name? Run an NMAP Script scan on LDAP really quick.

  12. When training, its better to not use WIN/LINpeas so that you can train your human eyes to find the Priv Esc route. That way, when you use these for an exam, you'll have the extra power of your human eyes to find the Priv Esc as a backup. (Probably why I passed the OSCP).

  13. Don't obsess over the HTB difficulty ratings. Just go with the flow and accept any box. Sometimes, you'll get major wins on Insane boxes while getting very stuck on Easy. So, why limit yourself?

  14. Don't drop the Bloodhound executable on the victim. Run python-bloodhound remotely.

  15. Its much better to work on Retired Machines by timing yourself as if you were taking an exam than trying to move up in rank with Active machines. When you are ready, however, please have at the active machines (HTB).

  16. Its better to learn ethical hacking in a group with a shared goal.

  17. In the workforce, we dont care if you can hack. We want you hack AND recommend fixes.

  18. Its not as common or as easy to gain SYSTEM on a Windows machine as you think and with Credential Guard you can only dump LSASS as SYSTEM, not Adminstrator.

348 points
2
0 comments
6
Posted by1 month ago
6
2 comments

About Community

Preparing Digital Defenders by providing cybersecurity career, training and education resources: AccessCyber.org
Created May 14, 2020

2.3k

Members

10

Online

Moderators

Moderator list hidden. Learn More
Reddit and its partners use cookies and similar technologies to provide you with a better experience.By accepting all cookies, you agree to our use of cookies to deliver and maintain our services and site, improve the quality of Reddit, personalize Reddit content and advertising, and measure the effectiveness of advertising.By rejecting non-essential cookies, Reddit may still use certain cookies to ensure the proper functionality of our platform.For more information, please see our Cookie Notice and our Privacy Policy .