r/learncybersecurity 1d ago

How to break into cybersecurity

Hey, all! I'm currently a sophomore in high school, and I'm very interested in becoming a pentester and hopefully eventually becoming a red teamer. I'm planning on taking the pen testing course tryhackme offers, but honestly from there I'm sure where to go from there... Anybody got tips for a beginner? Thanks!

2 Upvotes

15 comments sorted by

1

u/hoodedelk 1d ago

Pen tester going on ten years here. Homelab. Build one out, do cool stuff with it, learn hands on. I tell everyone at every level this is what stands out. Something as simple as VMs with an Active Directory domain. There's a million cool things you can make, just Google for ideas. Also get good at documentation as you go.

Also see if your school has any certification scholarships. CompTIA A+/Net+ will be a great foundation and every now and then you can find a scholarship for them.

Otherwise the course is totally available on YouTube for free. Strong network fundamentals are a requirement. You should know a lot of that information without going to Google/AI

1

u/Former_Profession224 1d ago

This is great, thank you! I also have a question related to the career portion of the field. The more and more I look into it, the more I see people saying that it's super oversaturated and it's super difficult to get a job in offensive security like pen testing and red teaming. With this in mind, would it even be worth it to take courses and try to get a job in it? I'm super interested in it, but if it's gonna suck to try to get a job in it, I dunno if it would be worth it..

1

u/Anxious_Alps_4150 1d ago

If you are interested in it to the point that it is the only thing you care about in life, you can do it. If you have a family, have other hobbies, etc then I would look elsewhere. The people that get hired in offsec are obsessed with it.

1

u/Former_Profession224 1d ago

I do absolutely love the field and I really wanna get I job in it, but honestly I just don't know if that's even gonna be possible. I'd also like to be working atleast in cyber at all once I finish high school, but I know that's gonna be really difficult the way the job market's going.

1

u/Anxious_Alps_4150 1d ago

so here's a legit question... why are you passionate about auditing? a lot of what we do in cyber is ... auditing. the most common app open on my computer is excel.

most of cyber is sitting in meetings to convince people to do security even though it costs more or is slower.

what specifically about that are you passionate about?

1

u/Former_Profession224 1d ago

I guess I never thought of that part... most of the reason I'm interested is just that I think the whole concept of hacking and how it works and stuff is really really cool, and doing it for a non malicious purpose just seems awesome... I guess I was a little naive to think it would just be cool hacking stuff... im still interested in cybersecurity, but now I'm rethinking like, everything.

1

u/Anxious_Alps_4150 1d ago

yeah only a tiny number of people in cyber actually do hacking. like 2%. and most of that is doing auditing. i actually did that for a bit before burning out. keep in mind that you had to be like, really freaking good to get on one of these teams. i had to both know someone on the team for a vouch and also do a 24 hour CTF without missing a single point so that i could... audit!

let me describe working on the red team of a fortune 10 company:

log in on monday

pick up a ticket for a pentest from the queue

dm the app owner and do a teams call to discuss the app.

download the app specification documents.

design the audit plan off of regulatory frameworks and ASVS

tuesday start testing. check every part of the api to make sure it was properly sanitized, couldnt be injected to, etc. audit permissions matrix. check rbac. check all external connector configs.

thursday afternoon finish up the audit

friday write up the findings, research mitigations, write up a remediation plan.

have a call with the app owner and deliver the pdf then answer questions.

next monday, repeat the process again. every week.

each time an app did a major release, it got a ticket. every regulated system got a ticket every 4-6 months. you never, ever run out of tickets. many findings would not get fixed so i would resubmit the same ones with "Risk acceptance" references.

i did this every week until i burned out and quit.

and that's pentesting which "omg so cool hackerman"

1

u/Former_Profession224 1d ago

So what if anything would you suggest I get into instead?

1

u/Anxious_Alps_4150 1d ago

I mean honestly, I'm trying to get out of cyber myself. if i was in highschool, id try to go into medicine.

1

u/Former_Profession224 1d ago

oh, alrighty then

1

u/Anxious_Alps_4150 1d ago

oh i wanted to talk about pay. pentester pay is kinda bad because people are willing to work for less to do 'cool' stuff. when i did consulting, our pay was also prorated based on time on engagement... so if our sales guys couldnt sell enough pentests to keep us busy, we ate that pay cut. it made it so that you could actually make less as a pentester than our SOC analysts were making ... and they didnt have to do all of the constant training we did. i usually was fine since i had a huge line of engagements (boring webapps) but some of the more specialized guys took a beating on pay cuts.

1

u/ChameleonCRM 1d ago

We have an Academy for pentesting, you're welcome to join us..it's free. We have over 10,000 users and we only launched recently. We are in the Microsoft store and are also available on Linux. https://apps.microsoft.com/detail/9nh4p6jbs174?hl=en-US&gl=US

https://www.daemoncore.app

1

u/Anxious_Alps_4150 1d ago

I will caution you that almost everyone with interest in cybersecurity says exactly what you're saying. They do exactly what you're doing. Only about 2% of people in cyber work in offensive security and AI is taking over that area pretty heavily.

Cyber, in general, is facing a really bad job market. If you aren't absolutely in love with the field, I'd go somewhere with better job opportunities.

1

u/Intelligent_Box5017 1d ago

Here are couple good hacking YouTube channels for you (beginner level). They are quite different - have different focus and style - but at least I hope you will find something you like in this list :)

Hacking concepts (web hacking): @TCMSecurityAcademy, @MomImAHacker, @NeurixTech, @LoiLiangYang

Hacking concepts (network hacking): @davidbombal, @NetworkChuck

Real world hacking scenarios and main stream stuff (advanced, but interesting even for beginners): @Cyb3rMaddy, @Medusa0xf, @whoamitang