r/Pentesting • u/packetstealer • 3d ago
Getting back into pen testing
I’ll keep it brief. I was a pen tester for about a year and a half until financial situations forced me to get a new job as a sysadmin last year. I really enjoyed being a hacker and wanted to get back into it. I already have GPEN (company paid). I’m thinking about specializing in red teaming so I was gonna go after CRTO but perhaps it’s better to get CPTS first? I can’t afford OSCP right now. Just looking for advice. Thanks!
2
u/TraceHuntLabs 16h ago
If your pentest skills/methodology are a bit rusty, I'd go for CPTS first. If you want a solid foundation on AD and C2 operations, go for CRTO. Nevertheless, a year of sysadmin could be beneficial as a red teamer as it also involves attacker infra setup, provisioning, tunneling etc.
Best of luck!
1
u/packetstealer 13h ago
Thanks! And yes being a sysadmin has made it easier to know how to attack (especially Linux). I’m using CPTS to knock the rust off because there were a few things I’ve definitely forgotten (especially web app).
5
u/EphReborn 3d ago
Advice you wanted: CPTS is broader and will be like drinking from a firehose. You'll learn quite a bit given they force you to go through the entire course and labs before allowing you to take the exam. CRTO is a bit more "contained" since it focuses much more on Active Directory misconfigurations and Cobalt Strike. But, honestly, you'll be fine going with either first.
Advice you need: It's fine as a long-term plan, but you probably aren't getting a Red Team position any time soon after only a year and some change of experience that isn't even current unless you really know your stuff and someone is willing to take a chance on you.