Everyone Is Confused About the OSCP+

แชร์
ฝัง
  • เผยแพร่เมื่อ 20 ธ.ค. 2024

ความคิดเห็น •

  • @AnonyMous-eq7iq
    @AnonyMous-eq7iq 2 หลายเดือนก่อน +3

    Just to a small correction, retaking OSCP in the UK does NOT enable you to do the so-called "Government work", it allows you to get the CRT if you also pass CPSA, which IS the normal requirement, however, you must specifically pass the CREST CRT exam, if you want the government work, rather than passing OSCP and CPSA

    • @Tib3rius
      @Tib3rius  2 หลายเดือนก่อน

      Appreciate the correction, that's my bad for misreading the conditions. You are correct, while the OSCP can be renewed to get CRT via the equivalency program, this kind of CRT cannot be used for the CHECK scheme.

  • @zephyfoxy
    @zephyfoxy 3 หลายเดือนก่อน +13

    I can't see non-federal employers suddenly valuing OSCP+ over OSCP out of the blue. I remember when I got my first pentesting job, everyone was more concerned about whether or not I had OSCP, they didn't really seem to factor in that I had OSEP, an arguably "higher level" cert. OSCP is so firmly cemented as the standard that it feels like employers hardly even take notice of new certs. And if any employer "required" me to go get OSCP+, and maintain it, they'd almost certainly be paying for it anyway.

  • @mortymerio
    @mortymerio 2 หลายเดือนก่อน +1

    Hello! I'm new here, I found out about the channel thanks to Tyler last night! I want to tell you that the amount of information you are making available to everyone is amazing! Thank you very much!!!

    • @Tib3rius
      @Tib3rius  2 หลายเดือนก่อน

      Thank you!

  • @DarrenReevell.
    @DarrenReevell. 3 หลายเดือนก่อน +4

    Thank you for taking the time to explain this.

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน

      Glad it was helpful!

  • @mustangjay559
    @mustangjay559 หลายเดือนก่อน

    I agree with allot of what you stated, I have conducted allot of internal only tests that are in isolated environments. Many organizations do not want to pay the hefty price of a black box test or red team event. So they would rather white card a two week event to characterize as many vulnerabilities as possible and then use that cost savings for regression testing in the future.
    I actually just submitting my OSCP + report today lol and even though I did not have my OSCP prior. I was very disappointed in the AD, while it was very straight forward, it was also overly to simple. I understand its an entry level exam, but there was a few missed opportunities within my lab to make it more fun.

  • @droidh4x0r6
    @droidh4x0r6 2 หลายเดือนก่อน

    Thank you for taking a time to do this.

  • @eljanhuseynov
    @eljanhuseynov 3 หลายเดือนก่อน +5

    Thank you for clarification!

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน +1

      Thanks for watching!

  • @Joeprrr
    @Joeprrr 3 หลายเดือนก่อน +11

    I think this change will devaluate the OSCP for people who got it years ago because we did the old "easymode" OSCP version. I think once HR learns about this I think we would have to defend ourselves for not updating it. I would be ok to get CPE credits for keeping my cert active but I think it's unfair to let old OSCP holders recertify beforehand. I will not go back into months of studying for this.
    I think it would be fair to just upgrade everyone's OSCP to OSCP+ one time and people can then choose to let it expire. Imagine if you passed the OSCP a couple months ago and you hear you have to go through all of it again to get the best version of this cert. That is just ridiculous imho.

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน +2

      True. This is a good point, especially about very recent OSCP passes.

    • @dj_chateau
      @dj_chateau 3 หลายเดือนก่อน

      I think it definitely feels like a ladder pull by those who got to do the exam somewhat easier. Not being afforded the same opportunities as previous exam takers feels unfair in practice.

  • @gordona.freidman7308
    @gordona.freidman7308 2 หลายเดือนก่อน +1

    Thank you for sharing

  • @ralphandre4438
    @ralphandre4438 3 หลายเดือนก่อน +3

    Great video!

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน

      Thanks!

  • @DarkDonnieMarco
    @DarkDonnieMarco 3 หลายเดือนก่อน +4

    As a UK based tester, I really hope OSCP+ could replace the nonsense that is CREST.
    I would much rather do the OSCP again than the CPSA and CRT.

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน +2

      CREST needed replacing 10 years ago. 😅

    • @DarkDonnieMarco
      @DarkDonnieMarco 3 หลายเดือนก่อน +2

      @@Tib3rius 100% but their position has actually been strengthened by the UK Cybersecurity Council. They are now one of two bodies that grant chartered and principal membership. Which will be necessary for CHECK team membership.

  • @JeffRocksBad
    @JeffRocksBad 3 หลายเดือนก่อน +1

    Assumed breach is actually very common. Where I work 90% of pentests are assumed breach both infrastructure and webapp pentests.

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน

      Interesting. I'm not sure I agree it's "very common" in the industry as a whole. That would be news to me. Web app is different, of course. Always has been assumed breach, but internals being assumed breach as a regular thing I have not heard of.

    • @null.ru.1337
      @null.ru.1337 3 หลายเดือนก่อน

      @@Tib3rius The old school of blue team thinking is not assume breach. Assum breach is one of the best says to train your team to threat hunt and remediate quickly.

    • @null.ru.1337
      @null.ru.1337 3 หลายเดือนก่อน

      Also the fact that most compromises start with a phishing email. Chances are, your blue team are going to see user account compromises all the time.

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน

      @@null.ru.1337 agreed, no question it's likely more informative for the customer, but I was mostly doubtful about it being "very common". I actually asked this on Twitter earlier and judging by the responses there, it's not that common but seems to be increasingly popular: x.com/0xTib3rius/status/1830998396921942067

  • @firosiam7786
    @firosiam7786 3 หลายเดือนก่อน +2

    I dont think oscp + will be a thing like when someone reaches a particular level like yourself u know u have the work experience and skills that you dont have to take an exam over and over again every 3 years maybe only for those who are looking to get into a job that requires this at that time after getting into that job only if the job requires him to take it over and over again will someone be taking the oscp + other wise i think majority of people will get the + removed after 3 years and continue with there job happily being the regular Oscp itself

  • @GLOVENT
    @GLOVENT 3 หลายเดือนก่อน +1

    I won't be surprized if HR/ATS will reject the application/resume thinking tht OSCP+ is not the "original" OSCP cert.

  • @singhgagandeep955
    @singhgagandeep955 2 หลายเดือนก่อน +1

    What is the chances of getting job after OSCP?

    • @Tib3rius
      @Tib3rius  2 หลายเดือนก่อน +2

      That's a a really difficult question to answer unfortunately. It depends on where you live, what the job market is like, etc. OSCP is still a good cert to have because it looks good on a resume, but it's not a guarantee of a job. It will at least make you stand out a little bit.

  • @DelaDirty
    @DelaDirty 3 หลายเดือนก่อน +2

    Problem is people didn’t read the email it states your oscp is indefinite and if you get oscp+ and let it lapse it stays as oscp

    • @randallvargas4457
      @randallvargas4457 3 หลายเดือนก่อน +1

      Precisely. Thank you for saying it.

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน +1

      I didn't get the email so I couldn't comment on it, but I did hear that it was in there. A lot of people found out because the link was shared on social media and the page itself didn't immediately mention that the OSCP cert itself wasn't changing.

    • @DelaDirty
      @DelaDirty 3 หลายเดือนก่อน

      @@Tib3rius that makes a lot of sense. I’ve also seen people who have gotten the email and decided to screenshot JUST the part that many people were complaining about without showing the whole thing.

  • @zeroordie453
    @zeroordie453 3 หลายเดือนก่อน +1

    Dude why does the government care about certs that expire lol

    • @Tib3rius
      @Tib3rius  3 หลายเดือนก่อน +3

      I imagine it's to ensure that people are still "skilled" and maintaining them. I don't think it makes any sense either, but that's how it works in US DoD and in the UK as well.

  • @anputhegod246
    @anputhegod246 3 หลายเดือนก่อน +1

    "Everyone knew that OffSec's main goal years ago was to break into the DoD sector and use the OSCP as their gateway. Now that they’ve made it into the U.S. government sector, do you think they care about our opinion? (Hell no)." I am just being real no offense..

    • @kcnl2522
      @kcnl2522 3 หลายเดือนก่อน

      Not american, how did they get into gov?