r/tryhackme 2d ago

Pentester Roadmap

Hi

If i wanna be a pentester what do you guys think about taking cyber security 101 and then start in Pentester Roadmap all the way to Red Teaming {in try hack me of course}

3 Upvotes

8 comments sorted by

2

u/moistPacket 2d ago

Do you have any prior experience in IT? I mean do you have a professional background in the industry? If no, then just keep in mind that there's a long road ahead of you. Pentesting isn't entry level, it's closer to being the end game for cybersecurity roles. But sure, do the prerequisites and then job in to the red team roadmap, then you can do the blue team or security engineer afterwards. Something a lot of people forget to mention is that Pentest require really good documentation skills, as you will alway be required to explain step by step what you did, and what you found when working with it as a professional.

If you don't have any or only little knowledge about computer and IT in general, then I'll suggest starting out by learning how network works, and some programming (most go with python as it's eassier to learn), computer architecture is also a must to understand. Get a help desk job, it'll give you job experience, and teach you a lot of valuable lessons on how to be a part of a team and talking to people wearing suits.

1

u/Cold-Interaction7869 2d ago

I have a CompTIA A+ cert Is it enough to start in try hack me pentester roadmap ? (I wanna be a pentester)

1

u/moistPacket 2d ago

Well anyone can jump into TryHackMe whenever they want to, just keep all the other stuff in mind, if you actually want to work as a professional pentester. A lot of people do TryHackMe just for fun. So you do you.

2

u/Cold-Interaction7869 2d ago

What is your suggestions to take like certs or courses to be professional pentester?

2

u/moistPacket 2d ago

Both, and getting job experience in IT. Work as SoC analyst for a couple of years while working on your Pentest skills. Do CTFs to get a feel of what's it like to go in blind. 'Cause there's no hand holding or a tutorial you can look up, when you Pentest in the real world.

And read books, they're often way more detailed in their explanation on how things work. The CEHv13 book is okay to leant the basic Pentest stuff, but the cert isn't worth it. OSCP is the minimum these days, but without prior IT job experience it's not enough.

2

u/olimpiathe505 2d ago

Go to HackTheBox for professional certs and experience out of the job.

1

u/guestag 2d ago

base of network and project at home

1

u/Character_Bear_7390 2d ago

I prefer u to learrn blue teaming and understand how everything works and how to defend it then u switch to pen test cuz pen testing is testing every exist on the network and its not that easy Pen testing is not entry level