This next chapter is titled ‘the power of completion’. I may have gotten slightly derailed in ticking off some my quarterly goals but now is a good time to push and get things over the line. Go get ‘em🐯
Dear Cyber Security Wannabe, Here are 9 Tools you need to learn to Become a Penetration Tester.
Learning = Job Security.
1. Kali Linux - an OS specifically designed with tools for ethical hacking. More tools exist within Kali than you will ever need, but it has a ton of great packages.
2. Metasploit - This is a great penetration testing framework that provides different exploits and payloads to test vulnerabilities.
3. Nmap - a great tool used for network scanning and reconnaissance. This tool has been around forever, but it's one of my favs.
4. Burp - Sounds gross, but it truly is a great software package for testing vulnerabilities and doing penetration tests against web applications. You can test for the OWASP 10 Top with Burp. There is also complete documentation on usage on Portswigger's website.
5. Wireshark - The entire internet runs off of TCP/IP. Nothing gets done on the internet without network packets. This tool will allow you to inspect network packets and truly understand what is going on inside your network.
6. Aircrack-ng - This is a suite of tools that allow you to do wireless penetration testing. It might seem complex to learn, but is very fruitful once you understand it.
7. Nessus / OpenVas / or other Scanners - These allow you to scan for vulnerabilities on a network. Learn to understand CVEs and different vulnerabilities and how they can impact a business.
8. Maltego - This is a great data mining tool used for OSINT (Open Source Intelligence)
9. Social Engineering Toolkit (SET) - a very well known toolkit used by social engineers.
These tools are only a start, but are very common tools that professionals use every single day.
By getting familiar with the items above, you have a much greater chance of a very successful career in this field.
I worked as a penetration tester for years. I can tell you that it was one of the most rewarding parts of my career that I've ever had. If you are looking to become a penetration tester, these above will be a great start.
Remember, stay ethical - and only test your own environments.
If you want weekly tips from me on how to get into this field, you can subscribe to my email list at ➡https://t.co/mGllVkoQ5i⬅.
#cybersecurity #informationsecurity #infosec #leadershipbyexample
If you’re interested in learning CYBERSECURITY AND ETHICAL HACKING, here’s a FULLY LOADED MATERIAL for you, all FOR FREE.
Courses: https://t.co/KUhXgZ9Jkg
Books: https://t.co/y1RwFBh1up
Feel free to share, someone might need this on your TL.
Here’s how I used AI to clone a 60 Minutes correspondent’s voice to trick a colleague into handing over her passport number. I cloned Sharyn’s voice then manipulated the caller ID to show Sharyn’s name with a spoofing tool.
The hack took 5 minutes total for me to steal the info.
@nakulpapreja I did a lab based course aimed at teaching the fundamentals of implementing security in a CI/CD pipeline using principles such as SCA, SAST, DAST, IaC, CaC, Vulnerability management, etc.
You can find more info here on their website: https://t.co/5NklmrWt1h
🧙♂️JWT Simplified✨ by @sec_r0 <3
In this flyer you will learn two very simple and basic attacks with them. Go give it a read.
Share if you like 🖖
Download : https://t.co/284iP56Q0j
#infosec#appsec#technology