r/offensive_security
How can i get my first penetration testing role
Hi , i am currently studying for the cpts and i am wondering if i could get a job after i pass the cpts exam, so could you tell how did you get your first pentesting role and if you actually had a prior job experience in any it role .and i heard from people that it is “impossible “ to get a job as a junior pentester so you need to get an it job first like IT help desk and then climb your way to a penetration testing role , is this right?
Note: i am 17 years old and i live out of the us and i have some experience in bug bounty.
Day 1 of my 10-Day Red Team Series is live 🔴
I put together a free PDF covering the fundamentals of red teaming — not just the tools, but the mindset and methodology behind an actual red-team operation.
Inside Day 1:
- Red Team vs Pentest
- The red-team mindset
- Attack lifecycle
- Objectives & attack paths
- Rules of engagement
- Operator workflow
- A realistic red-team scenario
- Day 1 challenge
The goal is to build the thinking first. Tools come later.
📖 Day 1: Red Teaming Fundamentals
I’m sharing the PDF below for anyone who wants to follow the series.
More practical cybersecurity learning, labs, CTFs and resources:
https://codelivly.com
Deeper books and playbooks:
https://resources.codelivly.com
Day 2 will move into Reconnaissance & OSINT.
Would love to hear how others approach the first stage of a red-team engagement.
Any study buddy available?
I did the OSCP in April and I want to get done with OSWE by next year.
I have a good grasp of web basic attacks, etc and I have started to learn the different languages that I saw in the program's syllabus.
I'm also pretty new to python programming, but I think that it's easy since I have started scripting little things regularly now.
I would be buying the 3 month voucher and before that, I want to be as prepared as possible for the course, and I would be grateful if someone would come along on the journey.
If someone is interested, they can message me directly. Thanks!!
Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt.
For full disclosure I'm part of the security engineering team at Escape and our AI pentesting engine Cascade recently got a production AI agent to return its entire system prompt, just by wrapping the ask in a different pretext - framing it as a documentation request instead of an attack.
The agent then handed over everything: full tool list, calling rules, citation format, and session IDs.
What I found really interesting is there's nothing technical that broke because we didn't bypass the guardrail with a cleverer string but because the request just sounded reasonable to the agent.
The Cascade engine, after being refused when asking for the prompt directly, simply adjusted the framing to get the agent to give up the informaiton.
Thought this would be an interesting insight for the community and curious to hear if anyone else has seen similar discoveries in agents in prod?
If you want to see more about the reproduction and write-up you can find it here
Can I realistically complete OSCP in 3 months with a cybersecurity background but limited hands-on offensive experience?
my hands-on experience with offensive security is quite limited. I understand concepts like enumeration, web attacks, privilege escalation, AD attacks, lateral movement, etc., but I haven’t actually done much practical work with them.
I’m considering buying the 90-day PEN-200/OSCP access and dedicating 25–30 hours per week, potentially more if needed.
My question is: Is it realistic for someone in my position to start PEN-200 directly and become exam-ready within those 3 months?
I’m not expecting the exam to be easy, but I’m wondering whether 300+ hours of focused hands-on practice is enough to go from mostly theoretical knowledge to OSCP-level practical skills.
Would you recommend:
Starting PEN-200 directly and using the 90 days intensively, or
Spending 3–4 weeks building practical fundamentals first and then starting the 90-day access?
I’d really appreciate input from people who have actually gone through OSCP/PEN-200, especially those who came from a blue-team/SOC background.
OSCP Report Submission Error – Has anyone experienced this?
Hello everyone,
I’d like to know if anyone has experienced a similar issue with the OSCP exam platform.
Today, I tried to upload my OSCP exam report, but I received the following error:
“Time elapsed
We are sorry to inform you that the time allotted for files submission has elapsed. We won't be able to grade your exam.”
The problem is that I still had around 4 hours left before my actual deadline. Shortly after, I also received an email stating that I had failed the exam because I did not submit my required documentation.
I have already opened a support ticket with OffSec, and I’m waiting for their response. I’m mainly posting here to find out if this is a known/common issue with the platform or if this might be an isolated case.
I have evidence showing that my report was already completed before the deadline, so hopefully support can review the situation.
Has anyone experienced something similar recently?
19, BCA student, cleared OSCP after 3 years of prep. Now I'm burnt out and don't know if I should stay in pentesting or shift to defensive security. Need honest advice.
I need genuine career advice from people working in the industry. Not "follow your passion" or generic motivation. I want real talk about what makes sense practically and financially.
My background:
· 19 years old
· BCA, currently 5th semester (degree not complete yet)
· Spent roughly 3 years heavily preparing for cybersecurity/pentesting
· Cleared OSCP
· Hands-on experience with Linux, Windows, Active Directory, networking, enumeration, privilege escalation, web attacks
· Done HTB/OffSec labs and technical write-ups/documentation
· No full-time work experience
· No other certifications
· No SIEM/SOC experience
What I enjoy:
· Working with computers
· Technical documentation — taking complex technical information and organizing/documenting it
· Independent work
· Structured, process-oriented work
What I don't enjoy / am unsure about:
· I don't know if I want hardcore programming/development
· I have very little customer-facing experience and don't particularly want a client-facing role
· I don't know if I want to stay in pentesting long-term
The core problem:
I'm not sure I actually like pentesting enough to do it as a career for years.
After 3 years of grinding for OSCP, I'm exhausted. I don't necessarily hate cybersecurity — I can probably work in it. But I genuinely don't know if pentesting is what I want, or if I'm just attached to it because of sunk cost.
I'm scared that if I leave pentesting, the 3 years, the money spent on OSCP, and everything I built becomes useless. That fear is keeping me stuck.
At the same time, the idea of having to constantly chase new tools, techniques, and certs just to stay employable in pentesting sounds exhausting long-term. I'm already tired and I haven't even started my career yet.
What I want from my career (in order of priority):
High income / strong earning potential
Career growth
Status/respect in the industry
Possibility of remote work
Financial stability — I don't want to constantly worry about money
Quick employment — I don't want to spend several more years preparing
Work that involves computers and technical thinking
Documentation and structured work
NOT a career that requires me to constantly learn every new technology just to stay relevant
Low customer-facing interaction
If money wasn't a concern, I'd want freedom, the ability to grow my money, and to never worry about finances again. That's it. I don't have a "passion" that I'd do for free.
My question to this community:
Given my situation:
Should I push through the burnout and stay in pentesting because OSCP gives me a head start, or should I shift to defensive security (SOC, detection engineering, etc.) where I might be happier long-term?
Does OSCP actually hold significant value for SOC/defensive roles, or am I coping by telling myself it transfers? I need the unfiltered truth.
Practically speaking, which path has better income potential, stability, and quality of life in the long run — offensive or defensive — for someone with my personality (likes documentation, structured work, low client interaction, doesn't want constant learning pressure)?
Am I making a mistake by considering leaving pentesting before I've even tried working in it, or is my hesitation itself a sign that I already know it's not for me?
If I choose defensive — SOC L1 as entry point — what are my realistic chances of getting hired in India within 6 months with BCA + OSCP + some SIEM self-study? And what salary range is realistic?
Most importantly: if you were 19, with an OSCP, burnt out from pentesting prep, and cared primarily about money, stability, and remote work — what would you do over the next 6–12 months?
Additional context that might matter:
· I'm in India. Willing to work remotely for international employers.
· I've been told my OSCP is an advantage for SOC because I understand attacks. But I don't know if that's actually true in the real hiring market or just something people say.
· I care about money and status. I'm not going to pretend otherwise. I want to know which path pays better and is more respected.
I'm not asking for emotional reassurance. I'm asking for a practical decision framework from people who've been in this industry longer than I have.
What would you do?
---
TL;DR: 19, BCA student, OSCP certified, 3 years of pentesting prep. Burnt out and unsure if I actually want pentesting as a career. Considering shifting to SOC/defensive security. Scared of wasting OSCP. Want high income, stability, remote work, low client interaction. Should I stay offensive or go defensive? What's the realistic best move for the next 12 months?
unable to connect to offsec labs in windows
in kali i can opevpn and reach machines fine after i changed my mtu a couple times per trouble shooting///. but when i connect with open vpn with windows i can ping the vpn but not reach ping or ssh into a box with windows it times out and does not connect does anyone know what can help me. i have to have windows connectivity to use the windows tools for active directory correct i am studying for the OSCP