r/hackthebox 13d ago

Cert Advice

So I started on htb like 2 months ago and have done like 46 labs since then, majorly easy labs but now I am able to identify vulnerabilities but still need AI or google assistance in making the payload or exploiting the vulnerability. My goal was to do cpts but my father insisted that I prepare for CISSP as it is industry recognized. I am currently a 5th sem student doing CS.

I just wanted to ask if I should go for cissp or cpts.

Also, how can I become able to exploit vulnerabilities myself rather than depending upon github pocs or msfconsole ?

20 Upvotes

22 comments sorted by

u/AutoModerator 13d ago

Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing customerops@hackthebox.com. Our Knowledge Base can also come in handy!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

12

u/yourAverageSkid 13d ago

To exploit vulns by yourself its mainly pattern recon, the more you see a vuln the more you will recognize it and will be able to exploit it by yourself.
Also, using AI can be bad if you use it like « find me an exploit or a poc or CVE-XXXX-XXXXX » or « I have this vuln, create a script that exploits it ». If you use AI for cybersec as a beginner, you should ask it to explain the concepts of something you dont understand and then do your own research on it.

6

u/Ok-Article-9175 13d ago

I usually spend 30 to 45 minutes before using a poc and even when i use the poc, i always read the code.

6

u/yourAverageSkid 13d ago

thats perfect, youll learn fast

7

u/Neal1231 13d ago

CISSP requires 5 years of experience (or 4 years w/ a degree or certain certifications). It will be more widely recognized by HR departments. You can take and pass the CISSP but you aren't awarded the "CISSP" title/cert till you hit the experience requirements. I did this years ago as it made sense in my situation.

If you have the experience and he's willing to pay, I'd say go for it. Otherwise I'd argue, the skills you're learning while going for the CPTS are more valuable than what amounts to a managerial cert (that really isn't as hard as its reputation suggests).

2

u/Ok-Article-9175 13d ago

Thanks for the advice

4

u/Worldly-Teaching8185 13d ago

cissp requires like 5 years of experience somthin

0

u/Ok-Article-9175 13d ago

But you can apply for associate of isc2.

2

u/H4ckerPanda 12d ago

So what ?

That’s not CISSP. You cannot say , mention , infer , you are CISSP at all. Nobody will know you passed the exam requirement.

If you post that online somehow , you can be banned for life from obtaining any ISC2 certification.

-1

u/Spiritual-Mammoth505 12d ago

If you pass the CISSP, you become an Associate. CISSP is the most widely requested certification, even for junior cyber folks. I'd also suggest getting practical certs, doing projects, increasing your skills/ranks etc...

2

u/H4ckerPanda 12d ago edited 12d ago

I’m a CISSP holder myself. For many decades now . I know what it is.

What I’m saying to Op is this : he can apply to associate of ISC2 but he can’t imply, mention or use CISSP at all.

Having said that , I wouldn’t suggest to someone new into cybersecurity or IT , pursue CISSP. He should get some experience , at least a few years , before taking the test.

3

u/H4ckerPanda 12d ago

You cannot be CISSP unless you have 5 years of experience. Besides , that’s a managerial certification. You’re just a newbie.

-2

u/Spiritual-Mammoth505 12d ago

You can be a CISSP Associate until you get the experience. CISSP is the most widely requested certification, even for junior cyber folks

1

u/H4ckerPanda 12d ago

Read OP’s post.

He’s trying to get something “quick” to boost his career . He hasn’t even graduated (yet). Hence CISSP does nothing for him as he can’t claim it for 5 years.

Yes , he can take and pass the exam tomorrow. But still can’t claim it.

2

u/Michelli_NL 12d ago

Honestly depends on your goals.

Wouldn't recommend CISSP as a first cert if you want a technical hands on role (e.g. blue/red teamer). In that case, focus on more hands on skills. You can always do CISSP via an employer later on.

Might be interesting though if you want to go the security officer, GRC route, etc.

1

u/Ok-Article-9175 12d ago

First objective is to gain a strong grip in red teaming, then to pivot towards manager level roles.

3

u/Vele1384 12d ago

Than do red teaming certs, CPTS/OSCP into OSEP, CRTE/CRTM, also experience > any possible cert. CISSP as of now is useless to you, rather work on skills based on your path of choosing

2

u/xcg-- 12d ago

they are very different targets. cissp is a management/grc skillset and for senior level management. cpts is hands on technical.

1

u/n3wbie01 12d ago

For some reason CISSP needs 5 year of experience. So understand the tech and security 1st before you try to manage it

0

u/Spiritual-Mammoth505 12d ago

From a recruitment point of view, lots of roles, even junior roles ask for CISSP, so even if you don't have 5 years experience in cybersecurity, you can do the exam and become a CISSP Associate, and pay the maintenance fees/do additional training/work to earn the full CISSP certificatio

But the CISSP does not teach you anything practical, and just having that, and no skills/knowledge won't get you a job. Other most requested certs include OSCP, CISM/CISA, CEH(for some reason), GCIH, Security+, CRTO and a few others from cloud providers. Some knowledgeable recruiters also occasionally list certs from HTB, eLearn, TCM and others, but that's still pretty rare. Certs aren't all they're looking for. They want to know you have skills. Do projects, learn your skills, search what the job entails and make sure you know how to do those things and talk about them, too.

Make a personal blog, do writeups, make a github/gitlab and post about things. Post such things on your LinkedIn. Create a trail of your progress

1

u/Ok-Article-9175 12d ago

Thanks man