Address
304 North Cardinal St.
Dorchester Center, MA 02124
Work Hours
Monday to Friday: 7AM - 7PM
Weekend: 10AM - 5PM
Address
304 North Cardinal St.
Dorchester Center, MA 02124
Work Hours
Monday to Friday: 7AM - 7PM
Weekend: 10AM - 5PM
I wanted to share a quick filler post about my status, certifications, and a few posts that I have in the works.
If you couldn’t already tell, this post was already a few days late. I’ve been a bit slammed with this long-term engagement for work, among other personal reasons.
That said, I wanted to keep my post streak going, so this will end up being more of a filler post. Feel free to reach out about anything, or new posts ideas!
Work wise, I’ve been working on a multi-month red team assessment that’s been quite interesting. This is a very hardened target, and we’ve done some interesting (and slow) work during the course of it. I’m hoping to maybe release one tool or technique by the end, but we will see.
I’ve also been dealing with some mental health and personal issues recently. This is nothing that I want/need to talk about openly, but I’m always reachable if you need someone to talk to! I appreciate your support, and I definitely plan on continuing to post.
Other than that, things are going great with this job, and I’m coming up on my 2 year anniversary in February. If I make it there, it will mark the longest that I’ve ever had any job! We’re still hiring for my team, so reach out to me if you like a pentesting referral.
I finished up my SLAE course a few weeks ago, and got my passing notification last week!
This was a great course, and I’ll have one more review/exam post about it soon.
For my next certification, I decided to finally start the OSCE. I got my materials on 21 October, along with 60 days of lab access. If I knock everything out in time, then there is a chance that I can finish before the beginning of 2019! If not, then I will knock it out in Q1 pretty easily.
I’m hoping to automate everything during the course, so we’ll see how much longer that takes me.
Other than that, I’m still trying to narrow down my certifications for next year.
If you have any comments or suggestions, then definitely let me know!
I attended BSidesRDU last weekend, and I’m hoping to get my post for that finished as soon as possible. Additionally, I have about 4 or 5 write-ups from the https://twitter.com/EverSecCTF that I helped run.
Beyond that, here is a list of posts that I’ve at least started writing so far.
There are some more in the works, but I’m always open for ideas or suggestions.
There are a few other things that I wanted to mention, that don’t really fit in with the above categories.
First, I’m looking at ways to possibly monetize this blog. If you’ve ever talked to me in person, you know that one of my dreams is to have a 100% research/development or blogging role. While I don’t think that this blog can currently replace my salary, I’d love to get started.
If you have any suggestions for methods or platforms, then I’d love to hear them. If you’ve ever made your entire salary from blogging, then please reach out to me!
There has also been a lot of negativity and toxicity in our industry as of late. Dave does a better job of summing up his feelings on this than I could. I still plan on staying active in the community and social media, but I will be more aware of any potential negativity.
Finally, I’ve been working on setting up a lab environment for better infrastructure, learning, and hunting myself. I’ve got the Server 2016 images partly built (Packer post coming soon). I’ve also got the HELK installation already setup. That said, I still have a lot of learning to do to use Terraform for the instrumentation. I’m hoping to have a fully configured Windows domain to test and learn new red team TTPs, as well as how they appear to the blue side. If you’d like to help, then reach out to me (especially if you’ve used Terraform before).
I’m hoping to have some time this week to work on more of the above blog posts. That said, at least this post is only a week or so late.
If you would ever like to talk about my job, my blog, or anything else, then you can always reach me here or at Twitter.
I still plan on posting once a week once I catch up and backdate, plus I’m approaching my 200th post in a row!
Ray Doyle is an avid pentester/security enthusiast/beer connoisseur who has worked in IT for almost 16 years now. From building machines and the software on them, to breaking into them and tearing it all down; he’s done it all. To show for it, he has obtained an OSCE, OSCP, eCPPT, GXPN, eWPT, eWPTX, SLAE, eMAPT, Security+, ICAgile CP, ITIL v3 Foundation, and even a sabermetrics certification!
He currently serves as a Senior Staff Adversarial Engineer for Avalara, and his previous position was a Principal Penetration Testing Consultant for Secureworks.
This page contains links to products that I may receive compensation from at no additional cost to you. View my Affiliate Disclosure page here. As an Amazon Associate, I earn from qualifying purchases.
Great article indeed!
Do you have any plan to take OSWE? I have questions/career guide from you.
Little introduction to myself. I am Eric from singapore and have over 2 years of experience in pentesting. I do have OSCP certification. But I want to take next step in my career.
Which certification should I take? My career goal is to increase my income more and can say that I am curretly under paid in singapore. My current role is senior penetration tester at some local company.
Thank you in advance,
Thanks! I don’t currently plan on taking the OSWE, as web tends to not be my primary focus. That said, now that it’s online, maybe I’ll get to it eventually.
It depends on what you are currently looking to do. As far as Senior Penetration Tester is concerned, or even higher roles, then the OSCP is great. If you wish to get into management etc., then you might want to look into the CISSP. Other penetration testing certs will definitely make you look better, but might not be as recognized.
That said, you might also want to look around at other potential companies to increase your salary. That tends to be the best bet, especially already having your OSCP.
Good luck!
Hey man,
How is ur health update? Hope you’re fine. I m ur fan. Please continue keep updating blog.
So far i got advice from you. Recently, got company sponsor so thinking to buy ecptx course. I checked there are only 4 labs which make me disappointed. And, heard exam is tough and materials not enough to prepare for it. Should i buy it now or wait for new update version?
I also looking into ewpt and emapt instead of ecptx.
Let me know
Cheers
Hi, it’s going well, and slowly getting over the burnout/back to posting!
I will do, and thanks for the support.
Awesome, and I haven’t actually started the eCPTX yet myself. That said, it looks like an incredible course, and I’m really looking forward to getting around to it. That said, some of their courses include the free upgrade, so you might not need to worry about that. It’s a pretty new course though, so they probably won’t be updating it too soon.
eWPT/eWPTX are great if you’d rather work on your web skills though, it’ll just depend on which side you want to focus on for now.
Good luck!
[…] going to cover some simple bulk badge cloning this week, as I’m still a little behind on my OSCE and […]