My First 6 Months as a Penetration Tester

Поділитися
Вставка
  • Опубліковано 7 січ 2025

КОМЕНТАРІ • 126

  • @rickjames3034
    @rickjames3034 3 роки тому +40

    Nice one mate, starting my first pentesting job in Feb.
    As you mentioned I have 0 experience but I did get OSCP, had 2 job offers from 2 interviews. It can be done guys

    • @andyli
      @andyli  3 роки тому

      Very nice, well done!

    • @b.m.robertson5959
      @b.m.robertson5959 2 роки тому +1

      @Rick James.... OSCP w/o any experience!!!??? That's crazy lol! Any study material advice would be greatly appreciated

    • @SharpSh00terMedia
      @SharpSh00terMedia Рік тому

      💯

    • @TheamazingPK
      @TheamazingPK 10 місяців тому

      Can you tell us more details?

  • @joshbuxton8249
    @joshbuxton8249 3 роки тому +19

    This is great content. Slow and steady wins the race I’ve been slowly learning from free resources for the past 5 years. After graduating college and getting an entry level Cert (PNPT) I landed my first junior role. People need to realize that you need to put in the hours on the keyboard. On the onset your growth will be slow just like anything new. But if you continue doing it for years, you get faster and more knowledgeable. Everything you do starts to compound and grow exponentially the more consistently you work. Great video! I’m only just now starting to see the results from the fruits of my labor

    • @andyli
      @andyli  3 роки тому

      Well said, congrats on your first role and great job keeping it consistent over 5 years. I'm glad it finally paid off for you

    • @mogr488
      @mogr488 3 роки тому

      Did you get PNPT before or after collage ?

    • @joshbuxton8249
      @joshbuxton8249 3 роки тому

      @@mogr488 After

    • @b.m.robertson5959
      @b.m.robertson5959 2 роки тому

      Would you say that the PNPT is a better entry level cert (I'm going for a junior pentester position) than the eJCPT? I ask because I am deciding which is more profitable as a base cert to go after. Thanks.

    • @joshbuxton8249
      @joshbuxton8249 2 роки тому +1

      @@b.m.robertson5959 This is a hard one given the climate of debate for certain entry level "pentesting exams". In my opinion, best bang for your buck is PNPT. But you need to supplement heavily with personal research/projects. PNPT has opened a lot of doors for me. Even at my current job.

  • @ivanzhao4068
    @ivanzhao4068 3 роки тому +6

    Hi Andy, happy new year! Thanks for sharing your experience and thoughts, it's great for someone like me at the begining of pentester journey. Keep up the good work bro. Sub and liked.

    • @andyli
      @andyli  3 роки тому

      Thanks! Glad it helped

  • @ghsinfosec
    @ghsinfosec 3 роки тому +5

    Great stuff Andy, very motivating. I agree with you in having a physical hobby to balance the time in the office. I'm not a pentester, but I have eJPT and I'm going for eCPPT currently. I hope to do OSCP afterwards, but as you pointed out the burnout can be a real drag. Thanks for the great content, I love your channel.

    • @andyli
      @andyli  3 роки тому

      Thanks, good luck on your studies

  • @gareth82
    @gareth82 3 роки тому +13

    I start my very first junior pentesting role next week, super excited and super nervious. Thanks for your videos

    • @andyli
      @andyli  3 роки тому

      Cool, I am sure you will enjoy it!

    • @saharaflower9173
      @saharaflower9173 2 роки тому +1

      How goes the new job!?

  • @deutschmitvkEins
    @deutschmitvkEins 3 роки тому +5

    It was fun watching this and other videos on what is it like to be pentester and what you do on actual pentest..
    Btw its late but congrats on passing OSCP and best of luck on CRTO.

    • @andyli
      @andyli  3 роки тому +1

      cheers, CRTO exam next week!

  • @iskitcha5153
    @iskitcha5153 3 роки тому +5

    I love your content
    Dear from Morocco. Continue bro!

  • @rajmendon6411
    @rajmendon6411 3 роки тому +5

    Hey Andy, I appreciate your work and it has helped me a lot in my journey. It would be super awesome and helpful if you made a video where you explained how you got your first pentesting job without OSCP. Cheers!

    • @andyli
      @andyli  3 роки тому +2

      I put on my CV the prep I have done for the OSCP and was ready to take it right away

    • @Hukaro
      @Hukaro 3 роки тому

      @@andyli
      Hey Andy,
      Good job on your progress and well done on the OSCP pass!
      I’m also preparing for the OSCP and I feel like I have a pretty decent knowledge and able to do some easy level CTFs but I’m struggling writing my CV properly.
      Is there a chance I could have your pre OSCP CV for comparison?

    • @andyli
      @andyli  3 роки тому

      Yeah I can do a CV video, it is on my to-do list

  • @TechLifeForLife
    @TechLifeForLife 3 роки тому +2

    Great video Andy. Thanks for all the information.

  • @Unknownhunter4u
    @Unknownhunter4u 3 роки тому +3

    Thankyou for sharing your experience with us. Keep it up :-)

  • @theybecameus
    @theybecameus 3 роки тому +3

    It will be very helpful if u make a dedicated video on how u manage work hobbies and cybersec studies through ur system.

    • @andyli
      @andyli  3 роки тому

      pretty much go at things at your own pace, slow and consistent over the long term is the way to go

  • @adtz123
    @adtz123 3 роки тому +1

    Thank you for sharing Andy!

  • @qifanguo5549
    @qifanguo5549 3 роки тому +2

    Ha I have started doing bjj for six months now as well and happy new year to you Andy .

    • @andyli
      @andyli  3 роки тому

      nice one, happy new year!

  • @andylau6969
    @andylau6969 3 роки тому +3

    Appreciated😁 for your sharing, it is always good to hear form you that situtaiton you facing when you being a newbie pen tester. i guess everyone who works hard for OSCP would worry about their situation with no experience for a pentester job, worry on if they've learned sufficient knowledge to be cope with career needs. And wonder, generally if a pentestor would possibly busier than a software engineer(means OT)?

    • @andyli
      @andyli  3 роки тому

      OSCP translates surprisingly well to a job, even with no prior experience.
      I am not sure about how busy pentester vs software dev. My current role feels pretty normal 9-5, not particularly busy overall.

    • @andylau6969
      @andylau6969 3 роки тому +1

      @@andyli good to hear, thx

  • @BlackPanther-vi5um
    @BlackPanther-vi5um 3 роки тому +2

    Happy to learn from u ❤️

  • @kareemsamir3800
    @kareemsamir3800 3 роки тому +6

    I have started my career in cyber security 2 months ago .This week, I have watched almost all your videos especially OSCP .
    Please, put the links to your twitter and linked in account so I can follow you.
    Great videos

    • @andyli
      @andyli  3 роки тому

      thanks, I have links in the about section on my channel

    • @onkar5506
      @onkar5506 3 роки тому +1

      Hey bro, I'm new to this can you suggest how to start?

    • @andyli
      @andyli  3 роки тому

      TryHackMe.com

    • @onkar5506
      @onkar5506 3 роки тому

      @@andyli is it free?

    • @andyli
      @andyli  3 роки тому

      Yes

  • @chidemenot
    @chidemenot 3 роки тому +2

    Regarding OSCP exam, which parts very tough & made you think for while before attempting..

    • @andyli
      @andyli  3 роки тому

      The exploits for the exam were not hard, it was a matter of finding them and time management.
      I made a video of my OSCP journey if you want to know more.

  • @hexbrokers9115
    @hexbrokers9115 2 роки тому +2

    randomly I found your channel such a great explanation of real-world scenarios I just want to get into cyber as a pentester can you please help mp for that how can I apply from Pakistan. in Australia for the pentester onsite job and the company will give me visa residence for work

    • @andyli
      @andyli  2 роки тому

      I am not sure how to go about getting sponsorship. Some people study here first, transition into a work visa, then to a sponsorship visa

  • @Ruffgemm
    @Ruffgemm 2 роки тому +1

    Try cloud later on in your career…way broader. There’s so much to experience plus it’s the future so it’s innovation is endless.

    • @andyli
      @andyli  2 роки тому

      good suggestion

  • @faran_siddiqui-d3t
    @faran_siddiqui-d3t 3 роки тому +4

    I'm a fresh grad with 0 exp in pentest and tech. But after clearing my oscp will I get junior PT job with minimum salary as per market ? (Got the answer, watched the video to end)

    • @andyli
      @andyli  3 роки тому +1

      Yes it is possible, practice some interview skills too

  • @stevejackson1039
    @stevejackson1039 2 роки тому +1

    Andy how do you go about on choosing your salary average amount or higher or do some research then be ready to make a decision?

    • @andyli
      @andyli  2 роки тому

      Definitely do some research around market rates online.
      Another good way to find out about salaries is to speak to a recruiter in the field you are looking to get into. Generally they will tell you the exact salaries

  • @powerstock9464
    @powerstock9464 2 роки тому +1

    Great to hear about your story I am starting in this feild with non IT background I am from Australia can you suggest any tips ? Where I can Start I have started with Hack The Box at the moment done my basics of linux and python I come from NON IT background so it is a bit difficult in times for me Thanks much appreciated mate !

    • @andyli
      @andyli  2 роки тому

      TryHackMe is probably easier to start with. I went from tryhackme > hackthebox > OSCP, then landed a pentester job.

    • @powerstock9464
      @powerstock9464 2 роки тому

      @@andyli What Path would you suggest with THM (Try Hack Me) and Hack the Box

    • @andyli
      @andyli  2 роки тому

      @@powerstock9464 I didn't really follow a specific path, just went from easy rooms to medium difficulty and so on

  • @syedafzal4409
    @syedafzal4409 3 роки тому +1

    Are expected to work 24hrs to 48 hrs non stop as the precedent is set by OSCP exams. How many pentesters do you see with life style related diseases ?

    • @andyli
      @andyli  3 роки тому

      You are definitely not expected to work for 24 hours straight on an actual job, it is just like a normal 9-5 job.
      It is only for CTFs and Exams, it seems pretty standard to have a 24 hour challenge.

  • @raycrew
    @raycrew 2 роки тому +1

    Hi Andy, Awesome video very well done, and informative. I am starting my very first junior pen test role in four weeks time, so super excited! Do you have any advice for the first couple of months in the role? What should I focus on in that time to succeed, and to contribute to the company?

    • @andyli
      @andyli  2 роки тому +1

      Congrats on the role! Just keep doing what you have been doing to land this role.
      You will learn a lot during the first few months. Take notes and focus on areas you are weak on, learn the general methodology that other people use and try not to get overwhelmed with the amount info.

  • @sajid.muntasir
    @sajid.muntasir Рік тому

    Hey, Andy. Was a great video to watch because of you sharing your overall honest experience as a pen tester. I'm curious to know the name of the company that you work for. Subscribed to your channel for future videos just like this.
    Good day mate.

    • @andyli
      @andyli  Рік тому +1

      Thanks, I was working at CyberCX

  • @eyonglouise8798
    @eyonglouise8798 Рік тому

    Hello Andy,watched your video was very informative, am really interested diving into this career but don't know how to go about it. Am an undergraduate student studying computer science in 3rd year

    • @andyli
      @andyli  Рік тому +1

      CompSci is a good background for cyber. Take a cybersecurity course if there is one and do some practical exercises on tryhackme.com

  • @drivegoogle4350
    @drivegoogle4350 2 роки тому +1

    Hello sir!!! This video was so helpful for me!!! Thank you very much…
    But still i can’t understand how to start learning this cyber security based job…
    Could you please tell me where i should start it and what are the basics of this career?
    And what kind of knowledge i should have?
    So could you please briefly give me a description how should i figure out the roadmap for this job

    • @drivegoogle4350
      @drivegoogle4350 2 роки тому

      Sir an another thing…i’m still learning in grade 11 in my school

    • @andyli
      @andyli  2 роки тому

      tryhackme.com

  • @ASMRaphael
    @ASMRaphael 3 роки тому +2

    So epic and superb :) I love it :)

  • @shakuntalam3884
    @shakuntalam3884 3 роки тому +2

    hi sir i am nitesh kumar from india plz tell me about what package we can get as a entry level penetration tester
    and how much it can go after 2 to 3 years of experience
    plz tell me

    • @andyli
      @andyli  3 роки тому

      I could be wrong but, entry level maybe 60-80k, after 2-3 years it is probably double that

  • @ike9
    @ike9 Рік тому

    Have you taken the CEH yet? And what is the highest cert u plan to attain?

  • @mahtabmehek
    @mahtabmehek 3 роки тому +1

    Can you point out the pricing structure of the pentests?

    • @andyli
      @andyli  3 роки тому

      Sorry, can't say. It is expensive 😬

  • @gnmcilgnmcil4348
    @gnmcilgnmcil4348 3 роки тому +5

    Am new in cybersecurity

  • @CyberTom
    @CyberTom 3 роки тому +1

    What helped you more THM or HTB?

    • @andyli
      @andyli  3 роки тому +1

      Both, THM is good for getting started, HTB for more exposure to the types of exploits that are possible

    • @CyberTom
      @CyberTom 3 роки тому

      @@andyli did you do proving grounds as well?

    • @andyli
      @andyli  3 роки тому

      Yes, check out the OSCP study guide video for a full list of resources

  • @adamtucker127
    @adamtucker127 2 роки тому

    Hello Andy great to hear about your experience with pen testing. I do have a question. I’m looking at starting a career in this field and looking at doing the ejpt certification first. Is there anything else you recommend to get started down this path?

    • @andyli
      @andyli  2 роки тому

      I have not done the ejpt, but to learn pentesting in general I would recommend start practicing on tryhackme.com. For information about ejpt specifically, there are a lot of videos on youtube where people talk about how they passed the exam.

  • @IamNicoGreen
    @IamNicoGreen Рік тому

    Hey dude! your just like me hahah.
    - get obesessed with things 1-2 yers
    - train bjj
    - currently studying for BSCP
    Enjoy your career in cyber dude

  • @s0vpy
    @s0vpy 3 роки тому +1

    Sir I have a question which programming language should we learn? The language we love or the language industry needs.. Example:Industry needs python but I love Go.

    • @andyli
      @andyli  3 роки тому +1

      Go is a good language, I wouldn't be too stressed at which one to learn, programming skills are transferable

  • @stevejackson1039
    @stevejackson1039 2 роки тому

    What were the extra things you had to learn for your pen test job

    • @andyli
      @andyli  2 роки тому

      More certifications, doing CTFs and homelab new exploits

  • @frankopokukoduah194
    @frankopokukoduah194 2 роки тому +1

    Can you get remote job or it’s always onsite?

    • @andyli
      @andyli  2 роки тому

      There are plenty of remote jobs available

  • @codesaif8075
    @codesaif8075 3 роки тому +1

    Is degree important for cybersecurity/ Ethical hacker?, i am persuing a non-tech degree. So earning certifications will be enough or should i switch degree i am really confused.

    • @andyli
      @andyli  3 роки тому

      Self learning and experience count for more than a degree.

    • @codesaif8075
      @codesaif8075 3 роки тому

      @@andyli so my degree dosen't matter until i have experience?

    • @andyli
      @andyli  3 роки тому +1

      It is hard to get a job with a degree by itself. You should supplement it with practical skills such as doing CTFs or practical certifications

    • @codesaif8075
      @codesaif8075 3 роки тому

      @@andyli okay ok i got it now can you make which certification should a beginner prepare for and then after more certification/diploma can make a list this would be really hellp ful. "sorry for bad english"

  • @jayv9073
    @jayv9073 Рік тому

    me.. I force myself to go to the gym twice a day to avoid DVT's lol CARDIO at 6am and gym again with my wife at 5

  • @raghad1252
    @raghad1252 Рік тому

    can the pen tester work as a freelancer?

  • @rishabhgupta7632
    @rishabhgupta7632 3 роки тому +1

    Why dont you go for OSWE?

    • @andyli
      @andyli  3 роки тому

      That is on the to-do list, maybe late 2022

  • @theoden2209
    @theoden2209 2 роки тому

    Did you programming with some language before?

    • @andyli
      @andyli  2 роки тому

      yeah Java/python

  • @wtfgeis
    @wtfgeis 3 роки тому +2

    Currently working a (not so great) gig as an associate security consultant, but pentesting has been what I've wanted to do for years. Do you think there are particular skills that will really open that particular door? I have heard that AD is a big one, so I've worked pretty hard learning how to break that, but I would love to hear your thoughts.

    • @andyli
      @andyli  3 роки тому +1

      You can get into pentesting by studying AD or AppSec (bug bounty), these would be the two big areas you could focus on. You could also just get the OSCP, very likely you will be able land a job after that since you already have security experience

  • @my-te-ch-cruise4733
    @my-te-ch-cruise4733 2 роки тому +2

    1.5x highly recommended but seems normal 🤣

    • @andyli
      @andyli  2 роки тому +1

      lol good call

    • @my-te-ch-cruise4733
      @my-te-ch-cruise4733 2 роки тому

      @@andyli just for fun 😇🤗 and i'm a noob in ethical hacking 😁

  • @are223
    @are223 2 роки тому

    What is the salary of an eJPT certified pentester?

    • @andyli
      @andyli  2 роки тому

      salaries are different for each country, have a look at entry lv pentester salaries in your country

  • @powerball200
    @powerball200 2 роки тому

    How much you are earning per day or per month?

    • @andyli
      @andyli  2 роки тому

      I made another video on pentester salaries

    • @powerball200
      @powerball200 2 роки тому

      @@andyli link plz

  • @ben-cb5er
    @ben-cb5er 2 роки тому +3

    Hey thank you for sharing your experiences :) can you give me some pointers on where to start? I know you mentioned tryhackme which I'm doing now but did you get any other courses? Like INE, cbt nuggets or tcm courses? Or any good comprehensive course while I'm doing tryhackme just to learn better and faster. I'm pretty new but I do have fundamental knowledge of py and ccna and basic Linux commands but 0 when it comes to bash.... Pls give me some advice on where to go or what to study after or besides tryhackme. Thank you

    • @andyli
      @andyli  2 роки тому +1

      I would recommend TCM if you want more structured courses. Go through his free videos on UA-cam first.

    • @ben-cb5er
      @ben-cb5er 2 роки тому

      @@andyli getting TCM courses now! lol thanks Andy oh and please if you do come up with some ideas about good resources to study and stuff please do make some videos :)