home.social

#offsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #offsec, aggregated by home.social.

fetched live
  1. We are excited to have OffSec on board as the Platinum Sponsor of Adversary Village at @defcon 34!
    OffSec is a leading cyber security training and certification company, known for its hands-on, adversarial approach to developing world-class offensive security professionals.
    A huge thank you to the OffSec team for their incredible support and commitment to the offensive security community. We are proud to have them helping bring Adversary Village at DEF CON 34 to life.
    More about OffSec: offsec.com/
    For more information about Adversary Village at DEF CON 34: adversaryvillage.org/adversary
    #OffSec #DEFCON34 #AdversaryVillage #OffensiveSecurity #CyberSecurity #PenetrationTesting #RedTeam #SecurityTraining

  2. We are excited to have OffSec on board as the Platinum Sponsor of Adversary Village at @defcon 34!
    OffSec is a leading cyber security training and certification company, known for its hands-on, adversarial approach to developing world-class offensive security professionals.
    A huge thank you to the OffSec team for their incredible support and commitment to the offensive security community. We are proud to have them helping bring Adversary Village at DEF CON 34 to life.
    More about OffSec: offsec.com/
    For more information about Adversary Village at DEF CON 34: adversaryvillage.org/adversary
    #OffSec #DEFCON34 #AdversaryVillage #OffensiveSecurity #CyberSecurity #PenetrationTesting #RedTeam #SecurityTraining

  3. New blog post!

    I recently completed the OffSec Expert Penetration Tester (OSEP) certificate.

    Here are my thoughts on it:

    ti-kallisti.com/infosec/certs/

    #InfoSec #RedTeam #RedTeaming #EDR #Offsec #Metasploit

  4. New blog post!

    I recently completed the OffSec Expert Penetration Tester (OSEP) certificate.

    Here are my thoughts on it:

    ti-kallisti.com/infosec/certs/

    #InfoSec #RedTeam #RedTeaming #EDR #Offsec #Metasploit

  5. My private discord server is coming along great. I have CTF announcement feeds from most of the major CTF platforms, bug bounty feeds, a Def Con feed, CVE RSS feeds for Debian and Ubuntu (even though Ubuntu is a Debian-flavored distro), and an Arch RSS feed. I just wish I had a way to stream BSides feeds into it but they are all run locally rather than a single national convention like Def Con.

    Once I get my home lab running, I am going to run Suricata using log2ram, a Python script to sanitize the output, and then send it to a private feed on my private discord server using web hooks.

    I have to say, this journey has been amazing and its still just the beginning. Going from an average gamer/nerd to a cybersecurity major that has a very solid foundation in InfoSec, and now exploring a journey in ethical hacking training, has been an absolutely amazing journey!

    I've wrestled with imposter syndrome but I've also had some very enlightening light bulb moments.

    #cybersecurity #opsec #infosec #ethicalhacking #offsec

  6. CW: ⚠️ InfoSec / CTF Disclaimer / Snapped - HTB / For Educational Purposes Only⚠️

    ⚠️ Disclaimer: For educational use only. All activities shown were performed legally on an authorized CTF platform. Unauthorized access to systems is illegal and carries severe criminal penalties.

    This video demonstrates a Time-of-Check to Time-of-Use (TOCTOU) race condition exploit (CVE-2026-3888), which was a key component of the "Snapped" machine on Hack The Box.

    "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS" (Common Vulnerabilities and Exposures, 2026).

    cve.org/CVERecord?id=CVE-2026-

    #EthicalHacking #offsec #penetrationtesting #Linux #cybersecurity

    :ablobcatbongokeyboard: :cyber_hacking: :galaxy_brain:

  7. Current Cybersecurity and OffSec Personal Library:

    • Linux Bible

    • The Hacker Playbook 3

    • Linux Basics for Hackers

    • Operator Handbook: Red Team + OSINT + Blue Team

    • RTFM v2

    #cybersecurity #OffSec #OSINT #Linux #EthicalHacking
    :cyber_hacking: :pixel_skull:

  8. Current Cybersecurity and OffSec Personal Library:

    • Linux Bible

    • The Hacker Playbook 3

    • Linux Basics for Hackers

    • Operator Handbook: Red Team + OSINT + Blue Team

    • RTFM v2

    #cybersecurity #OffSec #OSINT #Linux #EthicalHacking
    :cyber_hacking: :pixel_skull:

  9. Your last pen test was outdated before the report was even delivered.
    At BSides312, Paul Petefish is introducing the Continuous Penetration Testing Methodology (CPTM), a framework that transforms pen testing from an episodic checkbox into an always-on security function.
    20+ years in offensive security. He wrote CPTM because the old way stopped making sense.
    May 16th. Chicago.
    🎟️ bsides312.org
    #BSides312 #InfoSec #CyberSecurity #PenTest #OffSec #ContinuousSecurity #Chicago

  10. Your last pen test was outdated before the report was even delivered.
    At BSides312, Paul Petefish is introducing the Continuous Penetration Testing Methodology (CPTM), a framework that transforms pen testing from an episodic checkbox into an always-on security function.
    20+ years in offensive security. He wrote CPTM because the old way stopped making sense.
    May 16th. Chicago.
    🎟️ bsides312.org
    #BSides312 #InfoSec #CyberSecurity #PenTest #OffSec #ContinuousSecurity #Chicago

  11. Не ради сертификата: мой опыт HTB CWES

    Сразу обозначу: это не райтап. Тут не будет пошагового разбора экзамена, спойлеров по машинам или каких-то секретных техник. У меня нет красивой истории про призвание, мечту всей жизни или про то, как я с детства шёл именно к этому. Мне просто нравится становиться сильнее в том, что я делаю, и видеть, как это даёт результат. Это скорее мой личный взгляд на HTB CWES (Certified Web Exploitation Specialist): почему я вообще туда пошёл, как проходило обучение, что чувствовал на экзамене и какие выводы для себя сделал. Отдельный интересный вопрос — как вообще всё это успевать, когда у тебя работа, семья, дети и собака, которой тоже почему-то всегда что-то нужно именно в тот момент, когда ты сел спокойно позаниматься. Думаю, многим эта история знакома. Если говорить честно и не быть лицемером, моя основная мотивация довольно простая — это деньги 😂. Деньги через рост в карьере, через опыт и усиление как специалиста . Чем ты сильнее в профессии, тем больше у тебя возможностей: интереснее проекты, выше стоимость на рынке, больше вариантов для роста.

    habr.com/ru/articles/1026188/

    #Pentest #offsec #htb #cwes #cwee #security #education

  12. Системной подход к сдаче OSWE в 2025

    Offensive Security Web Expert ( OSWE ) – продвинутая сертификация offsec по безопасности WEB приложений. Причем ключевым отличием от менее известного Offensive Security Web Assessor ( OSWA ) является упор на анализ исходного кода приложения, то есть поиск уязвимостей в формате «белого» ящика. Окончательное решение сдавать этот экз я принял на бизнес съезде в Турции, когда познакомился с предпринимателем, который проходил ironman (ссылка) дважды. Мой поздний достигатель сразу загорелся идеей о стремительной подготовке. Однако товарищ председатель кооператива задал мне закономерный вопрос: «А OSWE сдать ты не хочешь?». 9 апреля 2025 года, в своём телеграм-канале PathSecure я опубликовал новость о приобретении курса :)

    habr.com/ru/articles/1024100/

    #pentest #offsec #oswe #web #security #education

  13. 🎯 Passed the OSCP+! :oscp:

    After a lot of late nights, practice labs, and more failed shells than I'd like to admit — I finally have the cert in hand.

    Some words for the family: Thank you — the late nights would have been much harder without your patience and understanding.

    On to the next one. 🔐 🤐 🙈

    #OSCP #OffSec

  14. 🎯 Passed the OSCP+! :oscp:

    After a lot of late nights, practice labs, and more failed shells than I'd like to admit — I finally have the cert in hand.

    Some words for the family: Thank you — the late nights would have been much harder without your patience and understanding.

    On to the next one. 🔐 🤐 🙈

    #OSCP #OffSec

  15. Are we better off building Kali Linux on top of Debian? Seriously any arguments are welcome.

    #offsec #linux #debian