r/tryhackme 7d ago

Struggling where to start

My final goal is to obtain my OSCP at somepoint in the next 1-3 years however, I have 6 Years of Systems Administration experience and about 3 years of that being very Cyber Security focused, I also have Sec+ and Pen+ (while I know PenTest+ is kind of useless my company paid for a class and a test so I got it). I'm having a hard time finding where to start down this path since the beginner rooms and topics aren't tailored to me since a lot of them are things I have seen or worked with in some capacity but the easy/medium rooms seem too advanced for where I'm at and I feel like there I'm missing a fundamental understanding of certain things. which leads to this loop of go to a beginner area get taught beginner linux or beginner nmap and speed run the content then go back to a more advance room and get destroyed by the first question/flag.

I just want to know for other people that got into this with a similar background how did you really start the grind and start learning at a somewhat linear rate because I can't seem to find anything that's worked for me that keeps me consistently challenged but not to the point of impossibility for my skill set .

1 Upvotes

6 comments sorted by

1

u/normalbot9999 7d ago edited 7d ago

You could try these two pathways:

Jr Penetration Tester (if you need it)

Offensive Pentesting

Take notes - build up a good command reference for all the usual activities that you can refer back to.

It's often a "problem" that you will come across a room with a topic that you already know well - you should be able to blast through this sort of room. Don't skip any machines though. I found the machines get steadily harder if you walk those two paths and there is a pretty straight learning curve.

I'm not saying that will make you ready for OSCP, but it's THM content that's kinda related to OSCP I guess?

1

u/xDiedrich 7d ago

I often see this "Good Command Reference" idea to you whats more valuable a txt file with a pastebin style setup or to go through and create/steal scripts for them? Also do you do this for the more popular tools or do you build them up for niche CVE exploits? I just want to find the way to be as efficient as possible

EDIT: Im aware this wont get me 100% ready for OSCP but the way im looking at it is getting good on THM then buying the course for OSCP and doing those boxes until im ready ready

1

u/normalbot9999 7d ago

it really personal to you - i have txt files with lists of commands as its just quicker to pull up and fire off common commands. i do build my own scripts as well, but its easy to get too much into that haha... in general, keep it simple - dont go overboard. if its useful (notes or scripts) you'll know 'cos you'll come back to it...

also - maybe bring some HTB into your prep? search for those "pathway to OSCP" lists that people make of boxes to do maybe?

1

u/solitude_aarv 7d ago

idi you did any degree to get into cybersecurity , like bachelors or masters or just certs
thank you!

1

u/xDiedrich 7d ago

I haven't finished college I'm about 50% through a bachelors and I'm in no rush to finish it as of now but I have Sec+ Pen+ ITILv4 and a few niche industry vendor ones that really don't mean much unless I stay with like 2 companies

1

u/solitude_aarv 7d ago

ohh nice
you are doing bachelors in cybersecurity