Nice one mate, starting my first pentesting job in Feb. As you mentioned I have 0 experience but I did get OSCP, had 2 job offers from 2 interviews. It can be done guys
@andyli2 жыл бұрын
Very nice, well done!
@b.m.robertson59592 жыл бұрын
@Rick James.... OSCP w/o any experience!!!??? That's crazy lol! Any study material advice would be greatly appreciated
@SharpSh00terMedia Жыл бұрын
💯
@TheamazingPK8 ай бұрын
Can you tell us more details?
@joshbuxton82492 жыл бұрын
This is great content. Slow and steady wins the race I’ve been slowly learning from free resources for the past 5 years. After graduating college and getting an entry level Cert (PNPT) I landed my first junior role. People need to realize that you need to put in the hours on the keyboard. On the onset your growth will be slow just like anything new. But if you continue doing it for years, you get faster and more knowledgeable. Everything you do starts to compound and grow exponentially the more consistently you work. Great video! I’m only just now starting to see the results from the fruits of my labor
@andyli2 жыл бұрын
Well said, congrats on your first role and great job keeping it consistent over 5 years. I'm glad it finally paid off for you
@mogr4882 жыл бұрын
Did you get PNPT before or after collage ?
@joshbuxton82492 жыл бұрын
@@mogr488 After
@b.m.robertson59592 жыл бұрын
Would you say that the PNPT is a better entry level cert (I'm going for a junior pentester position) than the eJCPT? I ask because I am deciding which is more profitable as a base cert to go after. Thanks.
@joshbuxton82492 жыл бұрын
@@b.m.robertson5959 This is a hard one given the climate of debate for certain entry level "pentesting exams". In my opinion, best bang for your buck is PNPT. But you need to supplement heavily with personal research/projects. PNPT has opened a lot of doors for me. Even at my current job.
@ghsinfosec2 жыл бұрын
Great stuff Andy, very motivating. I agree with you in having a physical hobby to balance the time in the office. I'm not a pentester, but I have eJPT and I'm going for eCPPT currently. I hope to do OSCP afterwards, but as you pointed out the burnout can be a real drag. Thanks for the great content, I love your channel.
@andyli2 жыл бұрын
Thanks, good luck on your studies
@iskitcha51532 жыл бұрын
I love your content Dear from Morocco. Continue bro!
@andyli2 жыл бұрын
Cheers!
@ivanzhao40682 жыл бұрын
Hi Andy, happy new year! Thanks for sharing your experience and thoughts, it's great for someone like me at the begining of pentester journey. Keep up the good work bro. Sub and liked.
@andyli2 жыл бұрын
Thanks! Glad it helped
@deutschmitvkEins2 жыл бұрын
It was fun watching this and other videos on what is it like to be pentester and what you do on actual pentest.. Btw its late but congrats on passing OSCP and best of luck on CRTO.
@andyli2 жыл бұрын
cheers, CRTO exam next week!
@gareth822 жыл бұрын
I start my very first junior pentesting role next week, super excited and super nervious. Thanks for your videos
@andyli2 жыл бұрын
Cool, I am sure you will enjoy it!
@saharaflower91732 жыл бұрын
How goes the new job!?
@TechLifeForLife2 жыл бұрын
Great video Andy. Thanks for all the information.
@andyli2 жыл бұрын
👍
@rajmendon64112 жыл бұрын
Hey Andy, I appreciate your work and it has helped me a lot in my journey. It would be super awesome and helpful if you made a video where you explained how you got your first pentesting job without OSCP. Cheers!
@andyli2 жыл бұрын
I put on my CV the prep I have done for the OSCP and was ready to take it right away
@Hukaro2 жыл бұрын
@@andyli Hey Andy, Good job on your progress and well done on the OSCP pass! I’m also preparing for the OSCP and I feel like I have a pretty decent knowledge and able to do some easy level CTFs but I’m struggling writing my CV properly. Is there a chance I could have your pre OSCP CV for comparison?
@andyli2 жыл бұрын
Yeah I can do a CV video, it is on my to-do list
@Unknownhunter4u2 жыл бұрын
Thankyou for sharing your experience with us. Keep it up :-)
@andyli2 жыл бұрын
Cheers
@adtz1232 жыл бұрын
Thank you for sharing Andy!
@andyli2 жыл бұрын
:)
@theybecameus2 жыл бұрын
It will be very helpful if u make a dedicated video on how u manage work hobbies and cybersec studies through ur system.
@andyli2 жыл бұрын
pretty much go at things at your own pace, slow and consistent over the long term is the way to go
@BlackPanther-vi5um2 жыл бұрын
Happy to learn from u ❤️
@andyli2 жыл бұрын
🤗
@andylau69692 жыл бұрын
Appreciated😁 for your sharing, it is always good to hear form you that situtaiton you facing when you being a newbie pen tester. i guess everyone who works hard for OSCP would worry about their situation with no experience for a pentester job, worry on if they've learned sufficient knowledge to be cope with career needs. And wonder, generally if a pentestor would possibly busier than a software engineer(means OT)?
@andyli2 жыл бұрын
OSCP translates surprisingly well to a job, even with no prior experience. I am not sure about how busy pentester vs software dev. My current role feels pretty normal 9-5, not particularly busy overall.
@andylau69692 жыл бұрын
@@andyli good to hear, thx
@qifanguo55492 жыл бұрын
Ha I have started doing bjj for six months now as well and happy new year to you Andy .
@andyli2 жыл бұрын
nice one, happy new year!
@chidemenot2 жыл бұрын
Regarding OSCP exam, which parts very tough & made you think for while before attempting..
@andyli2 жыл бұрын
The exploits for the exam were not hard, it was a matter of finding them and time management. I made a video of my OSCP journey if you want to know more.
@stevejackson10392 жыл бұрын
Andy how do you go about on choosing your salary average amount or higher or do some research then be ready to make a decision?
@andyli2 жыл бұрын
Definitely do some research around market rates online. Another good way to find out about salaries is to speak to a recruiter in the field you are looking to get into. Generally they will tell you the exact salaries
@faran_siddiqui-d3t2 жыл бұрын
I'm a fresh grad with 0 exp in pentest and tech. But after clearing my oscp will I get junior PT job with minimum salary as per market ? (Got the answer, watched the video to end)
@andyli2 жыл бұрын
Yes it is possible, practice some interview skills too
@syedafzal44092 жыл бұрын
Are expected to work 24hrs to 48 hrs non stop as the precedent is set by OSCP exams. How many pentesters do you see with life style related diseases ?
@andyli2 жыл бұрын
You are definitely not expected to work for 24 hours straight on an actual job, it is just like a normal 9-5 job. It is only for CTFs and Exams, it seems pretty standard to have a 24 hour challenge.
@Ruffgemm2 жыл бұрын
Try cloud later on in your career…way broader. There’s so much to experience plus it’s the future so it’s innovation is endless.
@andyli2 жыл бұрын
good suggestion
@kareemsamir38002 жыл бұрын
I have started my career in cyber security 2 months ago .This week, I have watched almost all your videos especially OSCP . Please, put the links to your twitter and linked in account so I can follow you. Great videos
@andyli2 жыл бұрын
thanks, I have links in the about section on my channel
@onkar55062 жыл бұрын
Hey bro, I'm new to this can you suggest how to start?
@andyli2 жыл бұрын
TryHackMe.com
@onkar55062 жыл бұрын
@@andyli is it free?
@andyli2 жыл бұрын
Yes
@hexbrokers91152 жыл бұрын
randomly I found your channel such a great explanation of real-world scenarios I just want to get into cyber as a pentester can you please help mp for that how can I apply from Pakistan. in Australia for the pentester onsite job and the company will give me visa residence for work
@andyli2 жыл бұрын
I am not sure how to go about getting sponsorship. Some people study here first, transition into a work visa, then to a sponsorship visa
@ike910 ай бұрын
Have you taken the CEH yet? And what is the highest cert u plan to attain?
@powerstock9464 Жыл бұрын
Great to hear about your story I am starting in this feild with non IT background I am from Australia can you suggest any tips ? Where I can Start I have started with Hack The Box at the moment done my basics of linux and python I come from NON IT background so it is a bit difficult in times for me Thanks much appreciated mate !
@andyli Жыл бұрын
TryHackMe is probably easier to start with. I went from tryhackme > hackthebox > OSCP, then landed a pentester job.
@powerstock9464 Жыл бұрын
@@andyli What Path would you suggest with THM (Try Hack Me) and Hack the Box
@andyli Жыл бұрын
@@powerstock9464 I didn't really follow a specific path, just went from easy rooms to medium difficulty and so on
@gnmcilgnmcil43482 жыл бұрын
Am new in cybersecurity
@andyli2 жыл бұрын
nice
@adamtucker127 Жыл бұрын
Hello Andy great to hear about your experience with pen testing. I do have a question. I’m looking at starting a career in this field and looking at doing the ejpt certification first. Is there anything else you recommend to get started down this path?
@andyli Жыл бұрын
I have not done the ejpt, but to learn pentesting in general I would recommend start practicing on tryhackme.com. For information about ejpt specifically, there are a lot of videos on youtube where people talk about how they passed the exam.
@mahtabmehek2 жыл бұрын
Can you point out the pricing structure of the pentests?
@andyli2 жыл бұрын
Sorry, can't say. It is expensive 😬
@raycrew2 жыл бұрын
Hi Andy, Awesome video very well done, and informative. I am starting my very first junior pen test role in four weeks time, so super excited! Do you have any advice for the first couple of months in the role? What should I focus on in that time to succeed, and to contribute to the company?
@andyli2 жыл бұрын
Congrats on the role! Just keep doing what you have been doing to land this role. You will learn a lot during the first few months. Take notes and focus on areas you are weak on, learn the general methodology that other people use and try not to get overwhelmed with the amount info.
@eyonglouise8798 Жыл бұрын
Hello Andy,watched your video was very informative, am really interested diving into this career but don't know how to go about it. Am an undergraduate student studying computer science in 3rd year
@andyli Жыл бұрын
CompSci is a good background for cyber. Take a cybersecurity course if there is one and do some practical exercises on tryhackme.com
@shakuntalam38842 жыл бұрын
hi sir i am nitesh kumar from india plz tell me about what package we can get as a entry level penetration tester and how much it can go after 2 to 3 years of experience plz tell me
@andyli2 жыл бұрын
I could be wrong but, entry level maybe 60-80k, after 2-3 years it is probably double that
@drivegoogle43502 жыл бұрын
Hello sir!!! This video was so helpful for me!!! Thank you very much… But still i can’t understand how to start learning this cyber security based job… Could you please tell me where i should start it and what are the basics of this career? And what kind of knowledge i should have? So could you please briefly give me a description how should i figure out the roadmap for this job
@drivegoogle43502 жыл бұрын
Sir an another thing…i’m still learning in grade 11 in my school
@andyli2 жыл бұрын
tryhackme.com
@sajid.muntasir Жыл бұрын
Hey, Andy. Was a great video to watch because of you sharing your overall honest experience as a pen tester. I'm curious to know the name of the company that you work for. Subscribed to your channel for future videos just like this. Good day mate.
@andyli Жыл бұрын
Thanks, I was working at CyberCX
@CyberTom2 жыл бұрын
What helped you more THM or HTB?
@andyli2 жыл бұрын
Both, THM is good for getting started, HTB for more exposure to the types of exploits that are possible
@CyberTom2 жыл бұрын
@@andyli did you do proving grounds as well?
@andyli2 жыл бұрын
Yes, check out the OSCP study guide video for a full list of resources
@ASMRaphael2 жыл бұрын
So epic and superb :) I love it :)
@andyli2 жыл бұрын
:)
@raghad12529 ай бұрын
can the pen tester work as a freelancer?
@stevejackson10392 жыл бұрын
What were the extra things you had to learn for your pen test job
@andyli2 жыл бұрын
More certifications, doing CTFs and homelab new exploits
@s0vpy2 жыл бұрын
Sir I have a question which programming language should we learn? The language we love or the language industry needs.. Example:Industry needs python but I love Go.
@andyli2 жыл бұрын
Go is a good language, I wouldn't be too stressed at which one to learn, programming skills are transferable
@frankopokukoduah1942 жыл бұрын
Can you get remote job or it’s always onsite?
@andyli2 жыл бұрын
There are plenty of remote jobs available
@codesaif80752 жыл бұрын
Is degree important for cybersecurity/ Ethical hacker?, i am persuing a non-tech degree. So earning certifications will be enough or should i switch degree i am really confused.
@andyli2 жыл бұрын
Self learning and experience count for more than a degree.
@codesaif80752 жыл бұрын
@@andyli so my degree dosen't matter until i have experience?
@andyli2 жыл бұрын
It is hard to get a job with a degree by itself. You should supplement it with practical skills such as doing CTFs or practical certifications
@codesaif80752 жыл бұрын
@@andyli okay ok i got it now can you make which certification should a beginner prepare for and then after more certification/diploma can make a list this would be really hellp ful. "sorry for bad english"
@IamNicoGreen Жыл бұрын
Hey dude! your just like me hahah. - get obesessed with things 1-2 yers - train bjj - currently studying for BSCP Enjoy your career in cyber dude
@andyli Жыл бұрын
Haha nice
@wtfgeis2 жыл бұрын
Currently working a (not so great) gig as an associate security consultant, but pentesting has been what I've wanted to do for years. Do you think there are particular skills that will really open that particular door? I have heard that AD is a big one, so I've worked pretty hard learning how to break that, but I would love to hear your thoughts.
@andyli2 жыл бұрын
You can get into pentesting by studying AD or AppSec (bug bounty), these would be the two big areas you could focus on. You could also just get the OSCP, very likely you will be able land a job after that since you already have security experience
@theoden22092 жыл бұрын
Did you programming with some language before?
@andyli2 жыл бұрын
yeah Java/python
@are2232 жыл бұрын
What is the salary of an eJPT certified pentester?
@andyli2 жыл бұрын
salaries are different for each country, have a look at entry lv pentester salaries in your country
@rishabhgupta76322 жыл бұрын
Why dont you go for OSWE?
@andyli2 жыл бұрын
That is on the to-do list, maybe late 2022
@my-te-ch-cruise47332 жыл бұрын
1.5x highly recommended but seems normal 🤣
@andyli2 жыл бұрын
lol good call
@my-te-ch-cruise47332 жыл бұрын
@@andyli just for fun 😇🤗 and i'm a noob in ethical hacking 😁
@powerball2002 жыл бұрын
How much you are earning per day or per month?
@andyli2 жыл бұрын
I made another video on pentester salaries
@powerball2002 жыл бұрын
@@andyli link plz
@jayv9073 Жыл бұрын
me.. I force myself to go to the gym twice a day to avoid DVT's lol CARDIO at 6am and gym again with my wife at 5
@andyli Жыл бұрын
nice
@ben-cb5er2 жыл бұрын
Hey thank you for sharing your experiences :) can you give me some pointers on where to start? I know you mentioned tryhackme which I'm doing now but did you get any other courses? Like INE, cbt nuggets or tcm courses? Or any good comprehensive course while I'm doing tryhackme just to learn better and faster. I'm pretty new but I do have fundamental knowledge of py and ccna and basic Linux commands but 0 when it comes to bash.... Pls give me some advice on where to go or what to study after or besides tryhackme. Thank you
@andyli2 жыл бұрын
I would recommend TCM if you want more structured courses. Go through his free videos on KZbin first.
@ben-cb5er2 жыл бұрын
@@andyli getting TCM courses now! lol thanks Andy oh and please if you do come up with some ideas about good resources to study and stuff please do make some videos :)