Is this weird offensive (or defensive, I'm not sure) security idea even possible? Or is this sci-fi already?

So I am still a beginner in cybersecurity, tbh I still don't know whether to specialize in defensive security or offsec operations; my passion is obviously in offsec operations (and I'm pretty sure a large majority of us as well), but defensive security is where job stability is. I am interested in both, just with passion and my weird curiosities learning towards offsec.

So I was just thinking of random stuff awhile ago like some interesting things I want to be able to do after having years of experience of self-studying and experience, in either defensive or offensive security, just for fun. Maybe I could even make it as a research project if I do graduate studies, or something. But primarily I just thought of this just for fun but I was also wondering if at the same time, if it is still within the bounds of computing (?)

Is it possible for like, for example, if I send someone a text message in a message app (messenger, telegram, line, whatever), or to make it simpler I guess we could use email, if someone opens that, but it contains maybe a simple message, or random gibberish, or a content, but the person just views it, marks it as spam, doesn't do anything with it but opened it. But it turns out, the (malware? is it right to call malware?) already has started, like maybe the OS has been tricked and it executed now? And the person does not know this, like the attacker can maybe see "everything" what the user is doing, being able to control it is an extra like maybe go beyond it, but that's the general idea. Maybe it could be used for espionage or something.

Idk how to describe it really, but like for those professionals reading this, is this even real and possible? I thought maybe this delves into sci-fi now or I don't know; I lack the vocabulary and knowledge yet to explain these things, nor I don't even know what to search for this without putting that bunch of explanation, but any help is appreciated.

reddit.com
u/ArdnyX — 2 days ago

What is a wise decision if I want to have a potential in GRC, and also get involved in interesting technical stuff (maybe internationally)

I know these are technically two different pathways that doesn't even converge, but the reason I want into GRC is that I want to be able to work as a cybersecurity officer in our country's central bank (low chance, given that I have bad connections as of now and I am not from a prestigious school either, but I know I will have to put in the work either way). Which is, GRC work.

And also because I have a chance to work in a public bank (referral) so I'm just refining skills on IT operations and defensive security ops. Maybe after graduation or even as simple as an internship.

In hindsight, I am more passionate into the very heavily technical side of things (for defensive, that would be DFIR and threat intel/hunting. For offensive, that would be binary exploitation, penetration testing, websec kind of stuff). I am leaning heavily towards offensive and low-level security though, as a passion.

But would it be more wiser to specialize in defensive security and IT operations in general and just make offsec as my hobby (and as time goes by, maybe I get the exposure that I want)

Or should I focus solely on offsec and let the job find me instead and be really good at it, (trust the process). Because I feel like the latter is just immature and unrealistic (and as part of adulting, I think I need to make some compromises). But any thoughts?

I was thinking this because delving deep into offsec and low level in general gets that immense technical depth and potential to be recruited by high profile people internationally if I play my cards right, and I think if I get into managerial and officer roles it would be better since I came from an attacker background.

reddit.com
u/ArdnyX — 3 days ago

How much is the actual take home pay after graduation in PMA?

Much better if those actual graduates: I'm just curious, over millions ba since napupunta sainyo after grad? Since from what I know, lahat ata sa bank accounts yung monthly salary * 4 years, tapos wala naman masyado maraming gastusin din while in there right?

reddit.com
u/ArdnyX — 14 days ago

Why security professionals have such plain profiles/portfolios on social networking apps (like LinkedIn)

And particularly just in general social media apps.

I notice that when someone is specializing (niche) in fields like software engineering, data science, fullstack, etc., their networking profiles / socials, github portfolios, look so good, have a lot of content, and those people I know at the same batch as me but in different universities, they have a lot of hackathon competitions, conferences, speakers in (something), creating startup, holding chief executive positions, and sooo many credentials, especially on their LinkedIns. Like it's intimidating to the point that its safe to assume they must be getting such high end internships.

While on the niche that I want to pursue (low level and security), things involving reverse engineering so malware analysis, forensics, exploitation (not really a huge field but you get the point), when I see one on a social network like LinkedIn, their profiles are plain as fuck. A project, a couple of certs usually < 5, and just their work experiences. And a couple of reposts. That's it. How are they marketing themselves with that?

I mean, maybe they do have a busy github and some projects and maybe some portfolio and writeups through blogs. But they don't expose/flaunt it out that much (?) Why?

reddit.com
u/ArdnyX — 2 months ago

Found myself not excelling in software development work. I found reverse engineering so much easier to work with.

Which is ironic, because reverse engineering is technically harder due to being involved with low-level concepts. And I found myself being more fascinated with the methodologies and process of doing malware analysis or digital forensics (which are two of the careers which have market within the reverse engineering discipline).

For reference, I am still a 4th year Computer Science student. Dear fucking shit, I can't develop a fullstack software. My colleagues can, they know the technicalities, the tools to use, I cannot. I blank out. The only way I get progress is with AI. With anything reverse engineering, I already know what to do. I know what to do first, I know what to observe, I just know how to progress and my brain just locks tf in.

Edit: I'm Southeast Asian, if that context matters for giving advice.

Although, I have yet to do my first real malware analysis. I just did try to do one blindly, downloaded a malware from a shady website, ran it (found out it was an adware), and then researched along the way while the adware was pushing annoying notifications, got no progress, but at least I got my hands dirty and never blanked out. This led me to know how the gaps I was missing, and what are the things I should learn next to develop a proper methodology.

This didn't happen when I was trying to develop software (web mostly).

My experience is just doing RE through medium-level CTFs, using gdb, Ghidra/IDA.

But even then, I know this is not okay because this field is so niche I probably won't get an entry-level job with this, there is so much potential and internship opportunities for anything software development, even AI-assisted software development, there are internship opportunities, but my colleagues are getting interviews in here while I tried applying for what they applied, I get no replies.

It's just so frustrating.

reddit.com
u/ArdnyX — 2 months ago

I need resources to understand these AI LLM models (not for developing one), but because I'm curious how they are able to produce "judgments" that sound so convincing and feels right.

TLDR: I need resources to watch or read to understand AI, better if there is an order? No I don't need it to develop an AI/ML model. Because I tried using it like a human I can talk to a few weeks ago until now about foresights, opinions, recommendations (which it technically can do, but it's not meant for that use) so I'm curious about the underlying technology behind it.

I am an upcoming 4th year computer science student. I have tackled the "maths" to essentially know the foundations of AI during my 1st and 2nd years but I just felt like I was learning them for the sake of passing and didn't understand the essence of studying them. But I want to delve deeper into this now.

Because for the past few weeks or so, I've been asking LLMs (Gemini 3.1 Pro Extended & Claude Sonnet 4.6 Medium/High) for some opinionated (?), idk if that's the right term, but I've been asking it things I would've been extremely shy on asking forums or people about. Thoughts about the future, what it would suggest on <something>, things like that. I've been doing this in multiple different chats, in different phrasings, sometimes same but adjacent topics. Mostly it's about foresight.

And while there were some similarities across different chats and the different models, I noticed that there are some times it would be completely ironic in its justifications and stands. I would be glad to provide examples to show what I am trying to do and why I came to this curiosity but holy shit I am extremely embarrassed of what I am asking it.

But this is exactly also the reason why I am curious about the underlying infrastructure of these LLMs, why it's giving me those kinds of answers, why it's able to give me those kinds of answers specifically, why the AI agrees that that is the best answer to give me. And I am asking it about foresights, judgments, advices, opinions, stuff like that.

I am not looking to create a machine learning model or AI from scratch, as I want to specialize in low level (leaning towards cybersecurity), I just want to understand it, to the point that I'll know the reason why talking to these chatbots about opinions and foresights are a "can do" but not "should do", but they work anyway.

reddit.com
u/ArdnyX — 2 months ago

Cybersecurity aspirant, but do you think mas maganda gumawa ng generalist projects or i-cater ko na yung mga projects ko sa niche na gusto ko talaga?

2 years left before graduation (Feb 2028).

Personally, mas leaning ako towards security (and low-level (security-leaning), but I think that's a specialization na I think mas better geared once I have years of exp in the industry, pero kung makakakuha ng entry level role, why not!).

May dilemma ako whether to create projects na may pang software-engineering, may pang-data, may pang ML/AI, pang cloud computing and general other stuff just to show na after graduation, I can start from any role and specialize to cybersecurity from there.

Or start focusing sa security niche (pero wag ko muna i-focus sa reverse engineering/malware analysis or low-level security stuff), pero primary focus ko yung things that will get me in that door like IT troubleshooting, junior network administration/engineering, linux administration, SOC-analyst, incident response, so mga projects tulad ng homelabbing, server experimenting, malware analysis writeups (para nandun parin yung drive ko sa low-level security). Although ito, much less on programming nga lang, pero siguro pwede ako mag systems programming na security leaning parin kahit papaano?

Ayun nga lang kung yung path 2 yung gagawin ko, wala ako magiging alam sa tools and frameworks na commonly nakikita sa fullstack, data, software engineering, like React, Node, Next.js, mga API, etc., kaya minsan naiinggit ako sa kaklase ko na nagsspecialize ngayon sa backend (or fullstack ata), panay gawa ng app. Ang magiging stack ko lang siguro is Wireshark, IDA, Ghidra, x64dbg, mga SIEM or automation tools.

Sa mga nasa industry ngayon, what's the better decision to make?

reddit.com
u/ArdnyX — 3 months ago
▲ 4 r/ccna

Using CCNA reviewers for studying networking even I am not taking exam? Just for the sake of giving myself practical networking knowledge.

Do you think using CCNA reviewers (which are very famous like Jeremy's IT Lab) would be good just for the sake of studying networking (and because we have a research project that could potentially involve heavy networking, and my knowledge of networking is extremely shallow right now), and because I do plan on specializing in cybersecurity.

or would I be better off using other kinds of networking resources? Because I am suspecting CCNA reviewers might be more into "passing the exam", though I do hope it's not the case

Well I do plan on taking CCNA someday, but I'm still 2 years away from graduation (2028)

reddit.com
u/ArdnyX — 3 months ago

Anong entry-level roles ang pwede sa mga nagsspecialize ng low-level concepts? (security-leaning)

May around 1 year left pa ako before graduation (Feb 2028), and I think ito na talaga yung niche na naibigan ko: low-level security (exploitation, binary analysis, etc., under the reverse engineering umbrella).

Nagstart ako mag-aral ng C last January, then diretso x86-64 assembly. Then more readings ng computer systems and then later on OS, and then inoonti-onti ko ang networking.

Sa ngayon, ang pinaka-achievement ko na related dito is naka-solve ako ng 3 ctf reversing challenges (picoCTF). Natuto ako magstatic/dynamic analysis kahit basic palang; nakakaproud na baby steps kaya nabuhayan talaga ako at nainspire na i-go ko na yung niche na to

Pero iniisip ko rin, sa field na 'to parang wala ako masyadong tech-stack tools na maipapakita di tulad sa mga SWE or fullstack roles na may mga frameworks, devops tools, automation, etc., eh dito sa field na 'to proficiency sa assembly, C/C++, tapos disassembling/debugging. Baka wala akong makuhang entry-level job? Or siguro aim muna ako ng L1 or SOC jobs?

Sabi rin kasi na "usually", yung mga available roles na ganito ay para sa mga may years of experience na talaga, kumbaga veterans or seasoned na.

reddit.com
u/ArdnyX — 3 months ago

Wala bang market sa low-level development nowadays?

Well, not limited to development, pero siguro sa security narin.

Ito kasi yung nahanapan ko ng interest ngayong graduating na ako. Narabbit hole ako ng OS internals, assembly, C, binary analysis, debugging, etc., puro low-level concepts leaning towards security. Tapos kahit leaning ako towards security, gusto kong makapagdevelop ng tangible output (yung parang fullstack apps/websites), pero low-level so mga drivers, kernel development or hypervisors, mga ganoon.

Pero iniisip ko kung itutuloy ko pa siya kasi parang wala akong nakikitang point kung wala or sobrang bihira sa market?

Kasi kung tutuusin, kung ipupursue ko yung passion ko dito, unlike sa majority mas marami silang tools na alam, like frameworks, mga automation tools, etc., which is malaki yung market; kaso iba talaga yung drive ko pag low-level concepts na.

reddit.com
u/ArdnyX — 3 months ago

I am stuck in a wall of "I want to do something with (topic)".

This all started when I encountered "Hypervisor Bypass" a couple of months ago in terms of game piracy. I thought, "*technically yes, this is not a crack, but a bypass. But how the fuck did these people even discover this?*". And I fell into the low-level rabbit hole. My priority really is reverse engineering, anything cybersecurity, and delving deeper into exploitation.

But recently, I also wanted to do "forward" engineering alongside this; like creating a tangible, visible low-level output just like how we see in fullstack / software development. So now, I'm stuck in this wall of "I want to do something with (topic)" but in my case, it's Hypervisors.

I am saying I am stuck in this wall because, I literally cannot move forward from it. This is how I've approached creating projects before but this time, I'm stuck because I only have the high-level knowledge of the topic I want, and I cannot name the "What do I specifically want?". There have also been times when I did have a conceptual understanding of a topic, but I still cannot name a something I want to create because I think I wired myself to be obsessed to always aim to create something innovatively absurd.

Can I not name anything because I don't have a knowledge of that area yet? What is this really and how can I approach this (dilemma?)

I have Learnt C for the past 3 months, and now studying Assembly through OST2. After this, I plan on reading and doing really deep work on OSTEP (people say its projects & activities are really rigorous too). Maybe after that, I can have more ideas?

reddit.com
u/ArdnyX — 3 months ago

For some reason, my head and eyes feel so much worse despite having this ambient light during night time. What's the explanation why?

Every single time, it feels so much worse than just having everything closed and just have the laptop screen turned on (but that's also bad).

But even with this kind of ambient light, I find myself feeling so much worse, I don't know why. Could it be the orientation of the large flourescent light? The flourescent light is too strong? It hurts my eyes so much (do take note that when I'm working normally, I don't see the flourescent light, its much like the 1st pic pov).

u/ArdnyX — 3 months ago

For some reason, my head and eyes feel so much worse despite having this ambient light during night time. What's the explanation why?

Every single time, it feels so much worse than just having everything closed and just have the laptop screen turned on (but that's also bad).

But even with this kind of ambient light, I find myself feeling so much worse, I don't know why. Could it be the orientation of the large flourescent light? The flourescent light is too strong? It hurts my eyes so much (**do take note that when I'm working normally, I don't see the flourescent light, its much like the 1st pic pov**).

u/ArdnyX — 3 months ago