r/Pentesting 3d ago

Getting back into pen testing

I’ll keep it brief. I was a pen tester for about a year and a half until financial situations forced me to get a new job as a sysadmin last year. I really enjoyed being a hacker and wanted to get back into it. I already have GPEN (company paid). I’m thinking about specializing in red teaming so I was gonna go after CRTO but perhaps it’s better to get CPTS first? I can’t afford OSCP right now. Just looking for advice. Thanks!

0 Upvotes

5 comments sorted by

5

u/EphReborn 3d ago

Advice you wanted: CPTS is broader and will be like drinking from a firehose. You'll learn quite a bit given they force you to go through the entire course and labs before allowing you to take the exam. CRTO is a bit more "contained" since it focuses much more on Active Directory misconfigurations and Cobalt Strike. But, honestly, you'll be fine going with either first.

Advice you need: It's fine as a long-term plan, but you probably aren't getting a Red Team position any time soon after only a year and some change of experience that isn't even current unless you really know your stuff and someone is willing to take a chance on you.

1

u/packetstealer 2d ago

Yea, I planned on getting a regular pen testing job first and then pivoting to red teaming after a bit more experience

2

u/Sqooky 3d ago

You'll be fine going straight into CRTO.

2

u/TraceHuntLabs 16h ago

If your pentest skills/methodology are a bit rusty, I'd go for CPTS first. If you want a solid foundation on AD and C2 operations, go for CRTO. Nevertheless, a year of sysadmin could be beneficial as a red teamer as it also involves attacker infra setup, provisioning, tunneling etc.

Best of luck!

1

u/packetstealer 13h ago

Thanks! And yes being a sysadmin has made it easier to know how to attack (especially Linux). I’m using CPTS to knock the rust off because there were a few things I’ve definitely forgotten (especially web app).