Exploit and Chill

>Slidin' in the DMZ

Taking on the most challenging cert of my career: OSCP

Once my employer approves the training through Learn One, I’ll begin my preparation. I already have some offensive security experience from earning the eJPT, PNPT, and GCIH, but the OSCP is on a completely different level. I’m not entirely sure what to expect. It’s a 24 hour exam followed by…

Once my employer approves the training through Learn One, I’ll begin my preparation. I already have some offensive security experience from earning the eJPT, PNPT, and GCIH, but the OSCP is on a completely different level. I’m not entirely sure what to expect. It’s a 24 hour exam followed by another 24 hours to write the penetration test report. Your job is to compromise three standalone boxes and then compromise an entire AD environment. I’m excited but genuinely nervous, because I know how challenging this exam is. There’s a reason it’s considered the gold standard for penetration testing positions. You either know how to hack or you don’t. There’s no faking your way through this one, and no amount of memorizing or guessing will save you.

I only intend on being a blueteamer, mainly because I work for the Government of BC, Canada, and they do not have any red team positions available, so the OSCP is definitely overkill. However, I have really enjoyed offensive security so far, and it definitely makes me a more skilled defender too. If you know how attackers think, and what they look for once they gain initial access, you can predict their movements, and cut them off before they do any significant damage. I have already used a lot of my offsec knowledge to build KQL Detection queries in Defender and that’s the sort of thing that really helps identify threats in practice.

I’ll share more as I continue prepping, including walkthroughs and tips along the way, but for now I’m just working through OSCP prep material on Pluralsight.

Leave a comment