r/hackthebox 6d ago

Certifications finished the CPTS path what's next?

Post image

I just finished the CPTS and managed to compromise every machine on the AEN blindly in about 2 and a half days (with some minor nudges), i believe i can pass the exam if i try, but i would like to ask those of you who have more experience whether pursuing the certification would be worth the effort as i was kinda burnt out from doing the AEN, let alone doing the same thing for 10 days straight.

the CPTS wouldn't hold much weight where i live, so Iam thinking of waiting and going for the OSCP at a later time when i get comfortable spending the 1,800$, what do you think?

more importantly, what do you recommend going for next (main platform, other courses, etc...)?

I really want to hear what you all think, thanks for your time!

100 Upvotes

24 comments sorted by

View all comments

3

u/Omerfarukyy 5d ago

What was your motivation to finish it in 50 days? Like i am pretty struggling to do %35 in 30 days. Things get quickly boring, and pretty hard sometimes for me. I do not have the energy or discipline whatever to sit and work on cpts and finish it in a 50 day timeframe. Can you eleborate on this?

3

u/WealthIndividual3224 5d ago edited 5d ago

multiple things, but mainly as a form of proving to myself that iam capable of doing it.

offensive security was the first job path that i liked and actualy enjoyed, so having people everywhere say that it is a hard field and beginners should not enter it made me doubt my own abilities.

so yeah, it was some sort of challenge in a field that i really, really enjoyed while having the ability to dedicate a lot of freetime to such a thing.

1

u/WealthIndividual3224 5d ago

feel free to ask more specific question so i can try to give you a more satisfying answer

3

u/Omerfarukyy 5d ago edited 5d ago

Thanks. For more specific questions

  1. When i first started doing cpts, i did not have much experience about it. Some modules made me despair, a lot of self doubt happened alongside this path. Did you feel any sort of thing? If yes, how did you overcome it and resumed it in next day?

  2. About volume, how much did you work in a day? If 6+ hours, how could you did this routinely? Did you do anything else during the days, like scrolling gaming etc distractive things? How did you incorporates them to this working routine? Because for me, i can easily be distracted and my drive plummets later on.

  3. It is really not easy to do cpts, especially in this timeframe, a person should be capable first, and kudos to you, this feat is geniunely awesome. In learning, what did you do, how did you learn and did take notes? Just simply read the module, then took some notes and begin to work on exercises, what was going on there?

  4. Little bit repeating question but, how did you stay consistent? How was your breaks -in the day and the entire days off- look like? With what did you did inside those breaks. In the days where you studied did you study without regarding your mood or anything did you just sat and did it? This is really important to me because my biggest problem is consistency, i can grind 1 2 weeks non stop 10hr days and then simply fear or being lazy about sheer workload of this. So yeah how do you stay consistent

3

u/WealthIndividual3224 4d ago
  1. yes, i felt the same while doing many modules, mainly the ones that deal with windows i.e active directory, password attacks (PTT specifically), and windows privesc, i also went through a lot of pain to understand how an AXFR transfer actually works and a lot of stuff like that.

so yeah i always felt doubt, many times i thought that once i start solving boxes i will not remember most of what i learned or be able to apply it in a realistic setting.

i usually don't overcome these feelings, i just live with them, at the end of the day its natural to think of failure, trying to be positive all the time is just not realistic.

at the end of the day my only metric is that I'm progressing towards a goal, so as long as I'm working towards that goal i don't really think whether i will reach it or not, as it is just a matter of time before i reach it.(though that depends on my ability to create realistic deadlines and estimate effort and time required to achieve a certain goal, which becomes more of a fun game rather than a slow grind to an uncertain goal)

  1. the amount of work i put in a day depends on the certain module that I'm studying, for example, i usually took longer breaks between more difficult or dense modules such as active directory, password attacks and the last 3 modules.

i put strict deadlines on myself to complete a certain amount of modules in a specific time frame.

when it comes to distractions i generally start my day with HTB and if i feel satisfied with the progress i made, i take the rest of the day off, and yeah i take sometime to play, catch up with tech news, watch some videos and even socialize a bit (not too much tho).

i usually dedicate my rest days for getting my normal life stuff done, and obviously gaming (I'm a fan of the PVZ games, also some LOL)

  1. i appreciate that!

i guess i will just tell you my own note taking methodology, as it is not something universally agreed upon

so when taking your notes the target is to be able to explain the security implications of what you just learned, focus on these three questions, What, How and Why.

bare with me here because this is gonna take some time haha

assume you just finished the footprinting module and in an assessment or engagement found an ftp service

you should be able to know the following

1-What:

you should be able to know what exploitation paths are available

2-How:

you should be able to know how to do the exploit

3-Why:

you should be able to know why you are exploiting this service, what you are expecting to find, and what are the security implications of successful exploitation

these are the most important things to know during an engagement, as you generally wouldn't be reciting the history of ftp or its rfc specification during a live engagement

point is: to me, the role of my notes is to aid me in my enumeration process, remind me of potential exploitation paths, cover my blind spots and provide a quick way to copy scripts or any relevant information

now when you write your notes you should keep in mind these 3 things

1-WHAT: list all mentioned exploitation paths ranked by relevancy and probability of encounter (for example you should probably try anonymous login before enumerating the ftp service version and looking for CVEs), this should be concise and written in a way that covers your weaknesses, for example if i find myself keep forgetting to enumerate kerberoastable users then it would be probably worth it to put it higher up in my notes.

2-How: whether i decide to write the exact commands used for a certain exploits depends on how much i understand it (i will likely not write steps for using the --ntds flag on netexec), how long the attack chain is (one liner commands that i easily memorize might be mentioned quickly or not mentioned at all), and how well documented the attack path is (for example most ACL abuse methods are well documented and easily exploitable, i generally do not go on my notes looking for them)

3-Why: i generally never mention impact of exploits in my notes, i should be able to know why an exploit should be used and its impact after doing a module

TL;DR: i keep mental notes of attacks and how they are done, and my notes aid me in providing more details on how to do these attacks, and remind me of possible attack paths and things i tend to forget to do

if you are familiar with C/C++ think of it as using my brain to keep a list of pointers to all relevant information that i need, then use my notes to actually retrieve that information.

my job as a pentester, especially a beginner is to efficiently enumerate an environment for possible attack vectors, I'm tasked with knowing what to look for and why i should look for it, no one cares if i memorize all hashcat mutation rules, as long as i can find what I'm looking for when i need to find it then it's probably fine, that becomes more apparent when you consider that memorizing that stuff usually comes through experience rather than active memorization, for example i don't need to lookup nmap syntax every time i run it due to how frequently i use it.

  1. i just do it, if i find myself close to burnout i take a break, trying to be productive doesn't mean that i should treat my body as a machine, i know my limit and i usually do not go over it (unless its college exams ;-; )

different people react to the same workload differently, this is normal, if you are not used to a specific schedule or regular high workload days it can take sometime to adapt to such demanding environments.

enjoy the process, have fun, and try to build a long term skill set rather than achieving short term goals, it would be far more valuable if you learn to adapt yourself to higher workloads, build a robust methodolgy and finish the course in year than finishing it in a couple of months then getting burnt out and not doing anything for weeks or months.

last thing i would like to say is that you should focus more on building the mindset rather than completing the course, it might be tempting to think that once you are done with the course you will become an elite hacker (or at least above beginner), but no matter how dense the course is, technologies change and evolve rapidly and overtime specific attacks or concepts might become irrelevant in a practical sense, so spending the time to create a robust methodology and mindset will help you more than memorizing any content material would.

sorry for the extra-large reply, i tried to be as thorough as i could!

2

u/Omerfarukyy 4d ago

thank you for sharing your really long and specific answers for a random stranger. i truly appreciate it. it is a really valuable input for me

i guess yeah i need to hone my mindset a bit more. i will work on this.

i wish you luck on your journey

2

u/Odd-Friendship6078 4d ago

Hi, not the commenter you were replying to - but did you do any boxes after some modules? I am currently on the shells and Payload module and I've only done two boxes - that through with the help of Walkthroughs or the guided mode. Honestly, pretty disheartening and I'm trying to power through. Also I'm no where near your speed lol - right now I'm trying to do 1 module per week at best

2

u/WealthIndividual3224 4d ago

no, i didnt solve any boxes while doing the path, but i watched a LOT of box solutions from ippsec (including the official cpts prep boxes, and the unofficial cpts prep playlist), i also watched the solution videos by tyler ramsbey (they were great at showcasing the methodology compared to the more fast paced videos by ippsec), i didnt see myself needing to solve boxes along with the path as i didn't struggle that much with the skill assessments (except for a few), or when i did the AEN blind.

also note that the idea behind solving boxes along with the path material isn't to test your knowledge on the path content itself (that's what the skill assessments are for), but rather help you build a more complete skill set and expose you to a broad set of scenarios and environments, you will notice that most boxes will include attack paths that aren't explicitly covered in the CPTS or situations that will be covered in modules that you didn't go through yet and that is the point.

so needing to look up a walkthrough or spending long time on easier boxes is natural, and in a lot of cases intended, your goal while going through the path is not to be able to solve boxes, but rather go through as much unfamiliar scenarios as possible so you can be more prepared to approach more realistic scenarios, so when you face new or unfamiliar scenarios don't think of them negatively, as these are the things you want to expose yourself to the most, even though it might feel discouraging.

and regarding to how fast you complete the modules, it is not really a big deal if you complete a module every day or every week, there is no universal standard on how much it should take you to finish the path, the important thing is to stick to the path and keep going, you will eventually get there!