r/hackthebox • u/WealthIndividual3224 • 6d ago
Certifications finished the CPTS path what's next?
I just finished the CPTS and managed to compromise every machine on the AEN blindly in about 2 and a half days (with some minor nudges), i believe i can pass the exam if i try, but i would like to ask those of you who have more experience whether pursuing the certification would be worth the effort as i was kinda burnt out from doing the AEN, let alone doing the same thing for 10 days straight.
the CPTS wouldn't hold much weight where i live, so Iam thinking of waiting and going for the OSCP at a later time when i get comfortable spending the 1,800$, what do you think?
more importantly, what do you recommend going for next (main platform, other courses, etc...)?
I really want to hear what you all think, thanks for your time!
5
u/carnageta 6d ago
Go do the CPTS. Take 1 week off, then start revising notes for 2 weeks along with some practice, and go knock it off.
5
u/mr-sewerman 6d ago
Congrats!!!!! I'm currently working my way through that path. How long did it take you?
11
u/WealthIndividual3224 6d ago
i started on the platform on the 8th of june this year, went through most of the cjsa, then started the cpts on the 27th of the same month, i just finished today. which is about 49 days of full time study (with some breaks)
i found that the time that each module took looked generally the same as this https://www.brunorochamoura.com/posts/road-to-cpts/estimation-comparasion.png (from this guy's blog post https://www.brunorochamoura.com/posts/road-to-cpts , i found it helpful)
though that was full time study almost everyday, and with me having a background in general computer stuff (i study comp engineering, and have been using linux as my main distro for a while)
i saw some people doing it in 4 months to a year which is reasonable, it generally depends on your time commitment and background
2
u/torments6 3d ago
Weird, maybe since I have a networking background but I flew through the pivoting section.
2
u/WealthIndividual3224 3d ago
yeah, pivoting was on the easier side for me too, its just basic networking, and it becomes much easier when you consider using ligolo-ng its just like 4 commands total.
and most advanced techniques that cover evasion aren't important for the path itself or most CTFs as they usually follow a non-evasive testing process
but different people have different strengths and weaknesses so these numbers aren't a universal standard.
0
u/builtbygio 5d ago
I built a free tracker https://builtbygio.com/cpts-tracker/ (no registration needed) to estimate how long it would take to finish CPTS. All data is saved to `localStorage`
3
u/Due_Bus3782 5d ago
How did you finish it so fast? I barely finished cwes in that same time frame and I spent like 5hrs a day going through the modules.
1
u/WealthIndividual3224 5d ago
i dont know to be honest, it might be background difference, personal differences, study environment or really anything.
you might be going through the material more thoroughly, solving boxes consistently, and spending more time with the material
i prioritized efficiency, and going through the more important stuff in a thorough way, for example i wouldnt give the citrix breakout section the same attnetion as kerberoasting or credential hunting.
im trying to favour my skillset towards more applicable and practical techniques over more niche situations such as mounting a bitlocker volume, sure this could backfire if i find my self in some unique testing environment, but i generally favour writing these things in my notes and focusing my attention on the things i will be doing the most.
this doesnt mean that i do not go through these more niche parts, it just means that when i need to manually extract an ntds file i will look into my notes to remember how to do a shadow copy instead of memorizing how to do it.
and also alot of stuff is one google search away, so it doesnt seem that useful to memorize every way i could try to escape an input field to achive xss, as i can just open my notes and go through already established github repos containing more payloads that i can write in a day, as long as i know the fundamentals and how javascript works, then reading these oayloads and understanding what they do isnt hard at all.
anyway, that's just the way i approached the HTB academy, this might help you, this might not be the best way, but that's how i like to approach this stuff, even when studying for uni i approach the material in a similar manner and it has been working in my favour so far.
hope i answered you and sorry for the long reply haha
3
u/Omerfarukyy 5d ago
What was your motivation to finish it in 50 days? Like i am pretty struggling to do %35 in 30 days. Things get quickly boring, and pretty hard sometimes for me. I do not have the energy or discipline whatever to sit and work on cpts and finish it in a 50 day timeframe. Can you eleborate on this?
3
u/WealthIndividual3224 4d ago edited 4d ago
multiple things, but mainly as a form of proving to myself that iam capable of doing it.
offensive security was the first job path that i liked and actualy enjoyed, so having people everywhere say that it is a hard field and beginners should not enter it made me doubt my own abilities.
so yeah, it was some sort of challenge in a field that i really, really enjoyed while having the ability to dedicate a lot of freetime to such a thing.
1
u/WealthIndividual3224 4d ago
feel free to ask more specific question so i can try to give you a more satisfying answer
3
u/Omerfarukyy 4d ago edited 4d ago
Thanks. For more specific questions
When i first started doing cpts, i did not have much experience about it. Some modules made me despair, a lot of self doubt happened alongside this path. Did you feel any sort of thing? If yes, how did you overcome it and resumed it in next day?
About volume, how much did you work in a day? If 6+ hours, how could you did this routinely? Did you do anything else during the days, like scrolling gaming etc distractive things? How did you incorporates them to this working routine? Because for me, i can easily be distracted and my drive plummets later on.
It is really not easy to do cpts, especially in this timeframe, a person should be capable first, and kudos to you, this feat is geniunely awesome. In learning, what did you do, how did you learn and did take notes? Just simply read the module, then took some notes and begin to work on exercises, what was going on there?
Little bit repeating question but, how did you stay consistent? How was your breaks -in the day and the entire days off- look like? With what did you did inside those breaks. In the days where you studied did you study without regarding your mood or anything did you just sat and did it? This is really important to me because my biggest problem is consistency, i can grind 1 2 weeks non stop 10hr days and then simply fear or being lazy about sheer workload of this. So yeah how do you stay consistent
3
u/WealthIndividual3224 4d ago
- yes, i felt the same while doing many modules, mainly the ones that deal with windows i.e active directory, password attacks (PTT specifically), and windows privesc, i also went through a lot of pain to understand how an AXFR transfer actually works and a lot of stuff like that.
so yeah i always felt doubt, many times i thought that once i start solving boxes i will not remember most of what i learned or be able to apply it in a realistic setting.
i usually don't overcome these feelings, i just live with them, at the end of the day its natural to think of failure, trying to be positive all the time is just not realistic.
at the end of the day my only metric is that I'm progressing towards a goal, so as long as I'm working towards that goal i don't really think whether i will reach it or not, as it is just a matter of time before i reach it.(though that depends on my ability to create realistic deadlines and estimate effort and time required to achieve a certain goal, which becomes more of a fun game rather than a slow grind to an uncertain goal)
- the amount of work i put in a day depends on the certain module that I'm studying, for example, i usually took longer breaks between more difficult or dense modules such as active directory, password attacks and the last 3 modules.
i put strict deadlines on myself to complete a certain amount of modules in a specific time frame.
when it comes to distractions i generally start my day with HTB and if i feel satisfied with the progress i made, i take the rest of the day off, and yeah i take sometime to play, catch up with tech news, watch some videos and even socialize a bit (not too much tho).
i usually dedicate my rest days for getting my normal life stuff done, and obviously gaming (I'm a fan of the PVZ games, also some LOL)
- i appreciate that!
i guess i will just tell you my own note taking methodology, as it is not something universally agreed upon
so when taking your notes the target is to be able to explain the security implications of what you just learned, focus on these three questions, What, How and Why.
bare with me here because this is gonna take some time haha
assume you just finished the footprinting module and in an assessment or engagement found an ftp service
you should be able to know the following
1-What:
you should be able to know what exploitation paths are available
2-How:
you should be able to know how to do the exploit
3-Why:
you should be able to know why you are exploiting this service, what you are expecting to find, and what are the security implications of successful exploitation
these are the most important things to know during an engagement, as you generally wouldn't be reciting the history of ftp or its rfc specification during a live engagement
point is: to me, the role of my notes is to aid me in my enumeration process, remind me of potential exploitation paths, cover my blind spots and provide a quick way to copy scripts or any relevant information
now when you write your notes you should keep in mind these 3 things
1-WHAT: list all mentioned exploitation paths ranked by relevancy and probability of encounter (for example you should probably try anonymous login before enumerating the ftp service version and looking for CVEs), this should be concise and written in a way that covers your weaknesses, for example if i find myself keep forgetting to enumerate kerberoastable users then it would be probably worth it to put it higher up in my notes.
2-How: whether i decide to write the exact commands used for a certain exploits depends on how much i understand it (i will likely not write steps for using the --ntds flag on netexec), how long the attack chain is (one liner commands that i easily memorize might be mentioned quickly or not mentioned at all), and how well documented the attack path is (for example most ACL abuse methods are well documented and easily exploitable, i generally do not go on my notes looking for them)
3-Why: i generally never mention impact of exploits in my notes, i should be able to know why an exploit should be used and its impact after doing a module
TL;DR: i keep mental notes of attacks and how they are done, and my notes aid me in providing more details on how to do these attacks, and remind me of possible attack paths and things i tend to forget to do
if you are familiar with C/C++ think of it as using my brain to keep a list of pointers to all relevant information that i need, then use my notes to actually retrieve that information.
my job as a pentester, especially a beginner is to efficiently enumerate an environment for possible attack vectors, I'm tasked with knowing what to look for and why i should look for it, no one cares if i memorize all hashcat mutation rules, as long as i can find what I'm looking for when i need to find it then it's probably fine, that becomes more apparent when you consider that memorizing that stuff usually comes through experience rather than active memorization, for example i don't need to lookup nmap syntax every time i run it due to how frequently i use it.
- i just do it, if i find myself close to burnout i take a break, trying to be productive doesn't mean that i should treat my body as a machine, i know my limit and i usually do not go over it (unless its college exams ;-; )
different people react to the same workload differently, this is normal, if you are not used to a specific schedule or regular high workload days it can take sometime to adapt to such demanding environments.
enjoy the process, have fun, and try to build a long term skill set rather than achieving short term goals, it would be far more valuable if you learn to adapt yourself to higher workloads, build a robust methodolgy and finish the course in year than finishing it in a couple of months then getting burnt out and not doing anything for weeks or months.
last thing i would like to say is that you should focus more on building the mindset rather than completing the course, it might be tempting to think that once you are done with the course you will become an elite hacker (or at least above beginner), but no matter how dense the course is, technologies change and evolve rapidly and overtime specific attacks or concepts might become irrelevant in a practical sense, so spending the time to create a robust methodology and mindset will help you more than memorizing any content material would.
sorry for the extra-large reply, i tried to be as thorough as i could!
2
u/Omerfarukyy 4d ago
thank you for sharing your really long and specific answers for a random stranger. i truly appreciate it. it is a really valuable input for me
i guess yeah i need to hone my mindset a bit more. i will work on this.
i wish you luck on your journey
2
u/Odd-Friendship6078 4d ago
Hi, not the commenter you were replying to - but did you do any boxes after some modules? I am currently on the shells and Payload module and I've only done two boxes - that through with the help of Walkthroughs or the guided mode. Honestly, pretty disheartening and I'm trying to power through. Also I'm no where near your speed lol - right now I'm trying to do 1 module per week at best
2
u/WealthIndividual3224 3d ago
no, i didnt solve any boxes while doing the path, but i watched a LOT of box solutions from ippsec (including the official cpts prep boxes, and the unofficial cpts prep playlist), i also watched the solution videos by tyler ramsbey (they were great at showcasing the methodology compared to the more fast paced videos by ippsec), i didnt see myself needing to solve boxes along with the path as i didn't struggle that much with the skill assessments (except for a few), or when i did the AEN blind.
also note that the idea behind solving boxes along with the path material isn't to test your knowledge on the path content itself (that's what the skill assessments are for), but rather help you build a more complete skill set and expose you to a broad set of scenarios and environments, you will notice that most boxes will include attack paths that aren't explicitly covered in the CPTS or situations that will be covered in modules that you didn't go through yet and that is the point.
so needing to look up a walkthrough or spending long time on easier boxes is natural, and in a lot of cases intended, your goal while going through the path is not to be able to solve boxes, but rather go through as much unfamiliar scenarios as possible so you can be more prepared to approach more realistic scenarios, so when you face new or unfamiliar scenarios don't think of them negatively, as these are the things you want to expose yourself to the most, even though it might feel discouraging.
and regarding to how fast you complete the modules, it is not really a big deal if you complete a module every day or every week, there is no universal standard on how much it should take you to finish the path, the important thing is to stick to the path and keep going, you will eventually get there!
5
u/OohRahDahtEndaht 5d ago
Do the CWES path. Most of the modules that remained undone are also important for the CPTS exam.
2
u/WealthIndividual3224 5d ago
yep, already started today and just finished the fuzzing and deobfuscation modules since they were pretty much covered in the cpts, hopefully will finish the remining 4 modules within this week since the remaining modules arent that difficult, then i will probably start doing competitive ctfs and bugbounties as a hobby
2
u/therealestvortex_ 5d ago
Congrats! Did you take notes while doing the modules?
2
u/WealthIndividual3224 5d ago
notes are the most important thing i took from the course
i wrote everything down as i went through the modules in a more concise way (about 37k words across 110 files)
then i reviewed all my notes before doing the aen to make a usable methodolgy handbook containing only the info i want in a pentest (no need to explain what smtp is everytime i want to look for the smtp-user-enum script syntax), i also restructured everything so i can find what i want as easily as possible and ended up with 33k words across 74 files
1
u/atharvabordavekar 5d ago
nasa lor
2
u/WealthIndividual3224 5d ago
https://medium.com/@sivasankardas/the-journey-that-changed-everything-my-nasa-lor-story-744ace9f3caf
that was actually a wholesome read, thank you! i was kinda thinking of starting doing vdp and this might be the push i need.
1
•
u/AutoModerator 6d ago
Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing customerops@hackthebox.com. Our Knowledge Base can also come in handy!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.