seggewiss

Learning IT security in public — eJPT, CPTS, OSCP, and what actually happens along the way.

Why I'm Learning Pentesting in Public

I am Sebastian. Since a few months I spend my evenings with INE’s eJPT material — port scans, Metasploit, privilege escalation, the whole entry into offensive security. eJPT is almost done now, the only module I did not touch yet is web application testing. After that comes HTB Academy’s CPTS, then OffSec’s OSCP. When those are done I want to work freelance as a penetration tester.

That is the roadmap. This blog is what happens on the way there.

Why write this publicly

I already keep a private study journal — a daily, unfiltered log of what I did and what went wrong. Most of it is not readable for anybody else: half finished thoughts, wrong guesses, shorthand that even I only understand for about an hour after writing it. A few weeks ago I lost an embarrassing amount of time in a pivoting exercise because I misread a subnet mask. I did the math in my head instead of on paper, got it wrong, and only saw it after resetting the lab twice and blaming the network instead of myself. That story is useful for somebody else only when it becomes a real explanation of how you read a netmask, not three frustrated lines in a journal. That is the job of this blog: take what really happens while studying and make something out of it that a stranger can learn from.

There is a second reason, less noble but just as real. In one or two years I want people to hire me for security work, and nobody hires a stranger. Writing publicly now — while I am still learning, still getting things wrong, still able to be corrected — is a longer and more honest track record than a certification page that appears in the same week I start looking for clients.

What this blog will be, and what not

It will not be walkthroughs of graded labs or exam content. INE’s skill checks, HTB’s active machines and everything around the OSCP exam are off the table. Not as a style choice, but because publishing that stuff is against the rules of the platforms that made it, and breaking that trust is not a great first move for a security career. Instead I write the generalized version: how a technique actually works, what the concept behind it is, what mistake I made and what I would tell somebody to check before they make the same one. If I ever write about a specific box, it will be one that is officially retired, following HTB’s own policy.

Expect a mix: technique explainers (the kind of thing I wished existed when I first tried to understand pivoting), methodology posts (the checklists I really use, not the ones that look good on a course slide), and sometimes posts for a non-technical reader — because at some point people will read this to decide if they hire me, not to copy my commands.

What comes next

Roughly in this order: a post about reading netmasks without guessing (the CIDR story from above, this time done properly), one about a habit that saved me more than once from a specific kind of silent Metasploit failure, and a methodology post about the recon checklist I really use. After that it depends on what eJPT’s web application module and CPTS bring up.

Nothing here gets published without me reading it first. This is a real name on a real career, and I post rather less often and am right.