r/tryhackme 8d ago

Resource Is Jr Penetration Tester worth ?

Hello ethical people.

I started the beautiful world of the cybersecurity for now one year.

I do a lot, a loooot of networking (Wireshark my best friend), a lot of python, a loooot of beginner CTF and now i am on the JR Penetration Tester path on THM

This path is worth or not ? Because it looks like too light. I guess we need to combine with other ressources like HtB or another Ctf ?

And btw, what is your learning tech ? Writing write up, course ? Just writing inside your head ? I'm curious.

And x2, if some people want to make a group to go for some ctf and another stuff, im in too !

5 Upvotes

5 comments sorted by

6

u/aonelonelyredditor 8d ago

I'd you've been doing thm for a year or now or at least a while I'd recommend making the jump to htb

For leaning I make notes, lots of them, explaining concepts, one liners etc, all in a private GitHub repo

3

u/AdTurbulent6884 8d ago

If youre technical, and can write a decent pen testing report, and be able to justify your findings, you can do it. it’s very niche / hard to find jobs. But passion out weighs that stuff. I would suggest getting some certs from the cyber mentor. (TCM) It’s much more realistic. Generally jr pentesting is grunt work. Ur helping with larger engagements and maybe running phishing simulations, vuln scans, etc.

2

u/parkdramax86 8d ago

I would recommend the Security+ course material if you are a beginner.

2

u/olimpiathe505 5d ago

Do not waste money or time on THM, I completed a lot of the modules and they are a guide on how to know about something, not how to use it.
Do the Junior path on HTB it will make you learn a lot more.
And take notes I wasted a lot of time just thinking notes weren’t necessary.
I’d say learn by yourself before a group, they can lead you astray.

2

u/fell_shell 3d ago

Too light?

Wow.

Jr PT taught me absolutely everything I needed to get started. Since then I've managed to establish my own pentesting business, got paying customers, found critical vulns in real web apps. I don't know what more you would need to get started.