Cube Talks: August 14th, 2026
Disclaimer: This transcript was generated with AI assistance and has been manually reviewed and edited. Despite best efforts, some inaccuracies may remain — please use your best judgement when referencing specific statements.
TL;DR / TL;DL: Panelists discuss AI’s impact on pen testing, certifications, Active Directory, and career advice for new security professionals.
Watch on YouTube: Cube Talks – August 14th, 2026
Listen on Spotify: Cube Talks – August 14th, 2026
FalconSpy: Hi, everyone. Welcome to this week’s Cube Talk. I am your host, FalconSpy. This is your opportunity to ask our panel of staff and volunteers any questions you might have about any of the services we offer here at Hack the Box, as well as InfoSec in general. We’ll do the best we can to answer as many questions as we can within the next hour. You could use the forward slash cubetalk command to ask your question, as well as upvote questions that are already in the queue. Questions are typically first in, first out, unless they are upvoted and stated otherwise. If a question comes in related to things we’re working on or deadlines, we typically do not disclose deadlines or anything we’re working on in case we miss said deadline or we don’t want to give anything away to competitors who can ask the question anyway, but we’ll typically fall back on the disclaimer. We’ll introduce everyone here on the panel, who they are, what they do, in case you have any targeted questions. Then I’ll do a broken record again with the command, and we’ll go to the questions. So in no particular order, we’ll start off with ChadB.
ChadB: Hey, good morning or afternoon, everyone. I’m ChadB. I am a current red team operator. I’ve been a SOC analyst and a pen tester in the past, and these guys just saw me hang around so much, they just let me in.
Emmax0: Hey, Emma. My name is Emma. I’m a senior community operations specialist here. I’ve been here for the last five and some years. I’m not the newest intern, as some of you are discussing in chat, but yeah. Hi.
FalconSpy: And then we got ippsec.
ippsec: What’s going on, everyone? I’m ippsec. I’m a lab architect. Just floated around various departments trying to help out where I can. Also do a lot of the videos where you personally know me from.
FalconSpy: I am one of the community specialists here, and also a full-time red teamer elsewhere. All right. So broken record part. It’ll also be in the chat, how to use the command, but forward slash cubetalk. You can use that command to ask your question, as well as upvote other questions that are already in the queue. Again, they are first in, first out, unless a question has been upvoted. All right. Without further ado, we’ll go straight to our questions here. All right. Not sure if this person had worded things correctly to become a box creator, but how do you design a box that feels difficult because of reasoning rather than because of obscurity, some random or weird thing to access?
ippsec: It’s a tough one. It mainly just goes into, I guess, creative thinking and like reading various posts online about what people have done in the bug bounty scene or just exploits in general, and then thinking of a way to apply it. I have a box. I want to say it is Support. I forget the exact name. It was like two to three years old, but that was one where a lot of bug bounty people were hacking like Slack and other things by companies that had help desks. And that became important back when SaaS started becoming a thing because a help desk generally gives you an email address with that company name, because it’s like ticket at hackthebox.com or whatever. And a lot of SaaS products just treat company emails as valid employees. So I just thought, okay, well, I can make a box like this. I can stand up my own email server. Instead of Slack, I can use Mattermost, that’s what most people use, and start joining those processes. And it’s no longer technically difficult, but it’s just a bunch of logic steps to exploit. So I guess it’s just more of how you apply what you read online.
FalconSpy: Next question here. What security assumption do you personally trust much less now than you did five years ago? I don’t think there’s a wrong answer to that.
ippsec: I mean, five years ago, I would trust that custom exploits and things like that wouldn’t be thrown against me. Maybe like early days and stuff wouldn’t be wasted against my personal infrastructure types of things like that. But now that LLMs can create all that stuff, it’s probably likely. So the average sophistication targeting non-large companies, I think has gone up.
Emmax0: I think as an extension of that, the “oh, this project’s small, no one’s going to take the time to dig through this entire codebase to find vulnerabilities.” Well, now AI does that automatically. So time is no longer as much of a saving grace in security.
FalconSpy: I can’t honestly think of anything right now. Sorry, I’m still kind of in a DEF CON vlog myself. I think everyone else answered pretty much. So we’ll move on to the next question here. Someone’s basically just asking what’s planned for our Android job role path. I can’t say if there is one or isn’t. If there is one, pay attention to social media. If there is one, we’ll post about it. And if there isn’t one, then you’ll never see a social media post about it.
ippsec: I also wouldn’t think a job role path would be specific to Android. I would just think it’s more mobile-specific. There isn’t a lot of differences, I think, between Android and iPhone until you get into the actual hardware hacking. And I wouldn’t think we’d be showing hardware hacking just because it’s very hard to do virtually.
FalconSpy: Right. This next question was upvoted. Is pen testing dead with AI being available, especially entry level positions?
Emmax0: I wouldn’t say it’s dead, but it will change like everything else does and evolves over time. I think that the lack of junior level positions is a very temporary thing personally, as even though AI will maybe take some of those roles, there still is a need for that pipeline of getting senior people. They all start as juniors. So there’s always going to be a need. And it just really depends on how that fluctuates out and how the job market as a whole goes.
ChadB: My constant answer to this everlasting question is that no, pen testing and red teaming is not dead because of AI. We just have to know how to, and maybe as an entry level person, just know how to leverage AI as a tool, because for us, that’s what it is. It’s a tool to be leveraged and also to be broken when asked to. No, pen testing is not dead.
ippsec: I also think a lot of people just take how advanced AIs are in CTFs and think that translates perfectly well to the real world. Keep in mind, pen test agents really do dangerous things quite often. The guardrails in cyber aren’t done well yet. There was a blog post just a couple of days ago, or maybe it was a Reddit post, of someone who was trying to join a gym, got on a waitlist, and then asked Claude to try to move them up on the waitlist. And then Claude found a vulnerability in the booking system that removed the people above them. And then they were like, “I didn’t want you to remove people.” And I was like, “Well, I can’t re-add them. So mission accomplished. You’re first on the list.” Like once you pass the guardrails once, it’s not really good at going back in time. So AIs make a lot of mistakes to please whatever the user asks. And that becomes very dangerous when doing it in the real world. I got nothing else to add that hasn’t already been said. I will go to the next one.
FalconSpy: Here, this one’s an upvoted question. What do you make of the CPTS being more HR-friendly, like the OSCP certification? Do you think CPTS will be included in most job requirements?
ChadB: I can say that my job right now, I don’t have either one, but my job right now favors the CPTS specifically. We have actually told people, at least two people that were hired prior to myself, didn’t have all of the qualifications. They were told to go get the CPTS. They did. And now they’re my coworkers. The answer to the question is yes, CPTS will become a little more recognized.
ippsec: I also think a lot of that just takes time. People forget how long other certifications have been around. I want to say OSCP is almost two decades old at this point. It’s been around a very, very long time. It was around before Kali Linux was even a thing. So it just takes a long time to get approved by HR and become the norm. That being said, I don’t think certifications are the best way in the door. It’s the way most people think about it because it’s the simplest to comprehend. But in reality, as long as you know people, have friends, and have a big social network, you’ll probably get jobs without certifications. It’s just to bypass the HR firewall. If you get a referral, you can generally bypass it without having all the actual requirements, unless you’re in a government role or something that handles court cases, things like that. Most of the time you probably don’t want those jobs anyways.
Emmax0: I will say just from a business sense, we have a lot of increased adoption with a lot more jobs working for it. There’s a lot of adoption in the technical space, technical people. And as more people get it, more candidates get it, more people working for companies get it, we’re continuing to see it expand, as well as working with our enterprise clients to show the value and have them include it with their companies. TL;DR, time. That’s what I’ve said.
FalconSpy: Our next question here is an upvoted question. What do you think of Active Directory, more precisely, how to deal with the volume of information required?
ippsec: I don’t know what you mean by volume of information required. I know Active Directory is big, but I actually think it’s relatively small and easy to use. Like if you’ve tried to use Kerberos manually, tried to do what Active Directory can do on Linux, you’ll find out how much more complex it can get. I also think Active Directory is kind of dying out in favor of cloud things, like group policies going away in favor of Intune. And I think it’s becoming smaller over time.
FalconSpy: I don’t really ever touch Active Directory where I work outside of Hack the Box. I mean, no secret, I’ve said it before, at Oracle we don’t really deal with Active Directory. So all of my Active Directory skills have gone down the toilet. If you don’t use it, you lose it. Anyone else? Otherwise I can move on. Cool. All right. Our next question here is an upvoted question. How to prepare for the CPTS? Are you able to find any roadmaps to pass? This is someone in their third year at university and was hoping for a roadmap.
ChadB: I would say just specifically go through the modules in order. Do the CJCA path if you don’t have a background first, but go through the modules in order and try to blindly do the Attacking Enterprise Networks module, which I believe is the last module. And if you can get through that, maybe one or two of the Pro Labs, just go for it. I don’t think there’s a solid roadmap to do it other than to go through the modules, take good notes, and be able to do that final module. That’s unless maybe ippsec has a better answer than me on that one.
ippsec: I don’t really think in roadmaps or things like that. Generally I just set time aside and just try to learn, and generally that has worked out. All right. Our next question here is another upvoted question. So the submitter thinks it might be a stupid question, but since AI is removing most of the junior roles in the cybersecurity field, what advice or roadmap will you have, or can you give to people who are studying for cybersecurity or interested in joining the field?
ippsec: Again, I dislike the word roadmap. I would just experience AI, use it and learn it. It’s not removing junior. It’s just changing the bar, right? There’s still always going to be a junior. This is also why I hate the difficulty ratings of boxes like easy, medium, hard, insane. It’s all subjective to the person. An easy box to me is probably not an easy box for Falcon or anyone on this panel. And sometimes he may say something’s easy. Maybe he’s good at mobile pen testing. I’m really bad at mobile pen testing. So that difficulty always just changes. He’s saying no, he’s not. Okay. Maybe if it’s in Oracle-specific cloud, cause I’ve never touched that, he’s much better than me. But it’s always subjective. So the junior title for a job is also going to be subjective. As long as you can use AI, your skills will increase. It may not be the 10x that everyone says, but it’s somewhere high up there where you actually become much better. So you’ll be able to do more than what a junior can do today if you learn it. And this is also kind of why I don’t like roadmaps. If I just pick something and say, “You know what, I’m going to experiment in this because this seems interesting to me,” I typically motivate myself more to play with it because it’s things I wanted to learn to begin with. And then it gets me where I wanted to go anyways. So just set time aside, play with technology, learn it. And I think you’ll do better than if you spent hours trying to find the best way to learn.
ChadB: I’ll follow ippsec. I think this is the third AI question. Not a stupid question, but AI isn’t removing. Like ippsec said, AI is not removing junior roles. It is another thing to learn and leverage. Don’t tell it to do it for you. Ask it how to do it, or ask it to explain stuff, or learn how to break it, or learn how to use it effectively as a force multiplier. It is just another thing. It will not remove all of our jobs. It will just change things for a while. It might make things harder for a while, but this whole AI marketing term is going to start to die down and it will just be another thing. And if Ryan was here, man, I would spit him right on up, but AI is not taking the jobs. It’s not removing things. It’s another thing to learn on the way in. So the way I look at AI, right?
FalconSpy: Yes. I’ve referred to it as a junior red team operator before. I will still consider it a junior red team operator, junior pen tester. It’s not going to take the junior roles. I mean, it’ll be there. I call it a junior role and I treat it like a junior role just because you have to babysit the thing. You don’t want it to go off and just start hacking and be a lone cowboy, if you will, and start going off and doing whatever it wants. Basically don’t ever run it in yellow mode. You basically want to read and try to understand every little command it’s going to try to run before it runs it, especially if it’s touching production, which in our case, when we’ve used it, it is touching production. So we never run it in yellow mode. We actually have to sit there and watch all the commands that it’s going to run. And then we make it record everything it’s doing. So, you know, juniors, actual juniors, not AI juniors, they will learn, they will upskill. AI, yes, it’ll upskill based on the different things that they feed to it, when they go to train the model. But it should always still be treated like a junior pen tester or a junior red teamer for those exact reasons. You don’t want it to just go and do whatever it wants to do because it sees a vulnerability. You want to make sure it’s doing and touching things that it should, that are a part of scope only. It’s not a replacement. That’s how I would hear that.
FalconSpy: All right. Anyone else? Otherwise we’ll move on. Do we have any student discounts for our courses for people who are under 18?
Emmax0: We don’t have anything specifically for those who are under 18, but we do have a discount for students on Academy, which is all of tier two and below. You just need a student email, student ID, whatever form of way to prove you’re a student. And that applies to high school students, college students, university students. So if you are still in school, you can use that as an option. However, just to note that if you are under 18, there is a parental consent form required for use of the platform.
ippsec: Also, if you just play seasonal content, there are rewards based upon how far you progress in the season and that can get you cubes and a bunch of other things. So nothing specific to people that are under 18. However, if you just use the platform, we have a lot of ways to just get rewards and it’s not just being the best. It’s just using the platform.
FalconSpy: To follow on what ippsec was just saying, you need silver or up. So that’s only four flags, that’s two easy machines or pick and choose. But if you’re having difficulty with the harder content, yeah, it’s just two easy machines. And then we do giveaways here on Discord. There’s one currently going on now. There’s also another kind of giveaway for wrong answers only. We just started doing this. You know, we post a question, you have to give your best wrong answer to the question, and let others upvote it, and maybe you can win stuff there. All right. Next question here is an upvoted question. This person feels like there is a lack of labs on our platform. They’re thinking of submitting their own machine. How long does it usually take for a submission to be reviewed and published?
ippsec: It’s the famous “it depends” answer. If you submitted a machine today, it probably won’t be up on the platform until next year because the season is either just started or starting soon. And we pretty much have that all set in stone of what machines we are releasing. That being said, since AI started helping people create boxes, we’re getting a lot more boxes than we can physically publish if we just keep to a one box a week thing. So maybe we’ll think of something to do to release more than one box a week. I really don’t know. The best thing to do if you want a box to get published sooner is to use time-specific vulnerabilities. So if it’s a really hot CVE, those are when we generally publish out of cycle already.
FalconSpy: All right. Are we planning to add video content into Academy? Short answer is no. Zayad has said and explained it in previous Cube Talks. Basically, we regularly update the content. So it’s easier to update text than it is to update videos. For that reason, we typically don’t have videos. You’re definitely welcome to use the forward slash feedback command and state why you think it would be beneficial to have videos in there, and maybe you can convince management, or Zayad, to start editing videos. But for now, videos will not be added.
ippsec: Yeah. Right now, I think they’re still working to get the text to speech done very well. I think that’s on the public community as well, Academy as well. I know it’s on the enterprise platform. And since we’re kind of struggling to get the voice to text to be a good experience, I don’t see us using AI to create videos. And even if we did use AI to create videos, so it’s easy to change, I’m sure we’d get a lot of backlash just because we’re using AI in that way. So it’s a weird situation.
ChadB: I use Speechify on Academy. I use a text to speech app. The only problem with it is it’s paid. Having said that, it is very good. You can choose your voice and speed. I usually listen to Academy modules at like 2x or 2.5x speed, but I didn’t know you guys were working on it. Cool. All right. Next question here is another upvoted question. Is there a release date or rough timeline for releasing Shiva on Pro Labs? I don’t believe so. And I think the holdup for Shiva specifically is, if I remember correctly, that is actually using Azure as part of the lab, like it’s a hybrid joint domain. And right now we don’t have any good tie-ins for the community platform and public clouds. Everything we do is pretty much on-premise.
FalconSpy: Next question here. We, sorry. We have a path for cloud security. General disclaimer here, pay attention to social media. If we are going to release anything like that, you’ll see it there. We won’t actually announce anything here unless you decide to bribe Zayad and he decides to answer it. I don’t keep talks and yeah. All right. Next question here, very similar. Are we going to release a cloud pen testing path or module on how to attack cloud environments in the future? Again, pay attention to social media or just keep checking on Academy. If we do release any modules or anything, social media. Another upvoted question. The red teaming path is focused on attacking large language models. Well, it’s cool. Why is the course structured like this? Do you think there are or will be LLM pen tests, but isn’t agentic pen testing more mainstream?
ippsec: It’s two different things, right? So using an LLM to pen test and pen testing an LLM. Am I understanding your question right? Yeah. They’re basically asking,
FalconSpy: right. You know, “Hey, attacking LLMs is cool, but why is the course structured that way? Rather than using LLMs for pen tests, like using agentic agents for pen testing. Why are we structuring it the way we did?”
ippsec: I think attacking LLMs is more future-proof than creating agentic pen testing things, mainly because attacking LLMs, you’re going into a specific technology, and that’s just attacking chatbots in general. And it doesn’t change that much between models. How models work is they advance some type of capability. And that’s very similar to binary exploitation. Like as we started learning binary exploits, things like DEP, the memory, read-only areas, ASLR, canaries, all those things get added, and it’s still beneficial to know all the steps each way. In terms of using AI to attack an application, it just changes so much, and learning it doesn’t help you that much going incremental. Like for the people that used Opus 4.3, it was trash. Then Opus 4.7 came out. I think that’s when all the hype started. And even then, whenever the big models change, the whole workflow just changes. I think even Boris who does Claude was like, “You know what, Opus 5, maybe you should just delete all your Claude.md files and let it regenerate, because how it does 4.7 is no longer that great.” So I think the workflow just changes so much and you’re at danger of your course just becoming irrelevant. And I know that a lot of the people on Udemy and other things that created AI courses, they were complaining, “Oh my God, we created this course. We’re using this -P flag. You’re removing -P and that’s going to render everything we did obsolete.” It just changes too much. I agree with everything I’ve said.
FalconSpy: All right. We’ll go to our next question here. Another upvoted question. Will reverse engineering and malware analysis die with AI like Claude and Gemini evolving? No. Next question.
ChadB: No. AI is again just a tool to be leveraged. People still need to know how to leverage it and how to understand the results, how to understand that they didn’t just make the results up. It’s just a tool to be leveraged. It may set the bar higher than it is now, as it can maybe process things faster, but we, as the human, still have to understand what it has found and, better yet, how it found it. The answer to the question is still no.
ippsec: I think reverse engineering and malware analysis will just change. Those fields will never die, but it is going to change drastically. I forget the article. I’m sure if you Google “Nintendo 64 AI reverse decompilation,” the video game scene is doing some really cool things with AI reverse engineering, building one-to-one source code replicas, AI rebuilding games. It is scarily good at taking decompiled output, testing if all the functions match one-to-one with what was compiled, and then saying “no, it doesn’t, I’m going to create new source code,” and then do that 5,000 times until it gets a one-to-one match. AI is becoming really good at just decompiling. That being said, I don’t think reverse engineering and malware analysis was a large field to begin with. That’s a very niche field. I don’t think any company really needs reverse engineers and malware analysts on staff, unless you’re a government agency, things like that, just because I don’t see those fields being that beneficial. And I also don’t think it’s beneficial for a lot of companies to have red teams or pen testers internal. The answer should just be do better defense. And then you don’t need those roles. I think a lot of people just go for those roles because they’re sexy and cool. And if you did better fundamentally, you’d be in a better state than just paying for the really advanced thing.
FalconSpy: I think some people actually want to go for those roles. I’ll just say, I do know some people who like to do reverse engineering and malware analysis. They love doing it because they like trying to figure out what some of these different things are doing. This person did work at one of the EDRs and antivirus companies. That was the thing they want to do. That was their passion.
ippsec: And that’s a niche. That’s a very small number of employment opportunities. Most of the time when a company gets a red team, if they just got a pen test, it would point out the same things the red team found, probably a little bit more, because when a red team engagement happens, they find one big vulnerability, they exploit it to the limits, and that’s pretty much it. Whereas a pen test kind of looks at all the potential vulnerabilities.
FalconSpy: All right. Anyone else? We’ll move on. Cool. All right. Another question. Do you believe that open weight models are the future for cyber, as you don’t have to figure out how to bypass guardrails?
Emmax0: I mean, we have seen Anthropic have a verification system that removes some of their safeguards. And I think that’s probably what we’re going to see a lot more of, with every one of them having some way to say, “Hey, I’m doing this legit.” And as the safeguards improve, they’ll be able to hopefully tell the difference between an ethical or non-ethical request. There probably still will always be some people using them, whether it’s people using them for legal purposes or whatever. But I do see that as a whole, there will be more commercial options available.
ippsec: I don’t think open weight models become successful because of guardrails. Again, cybersecurity is a very small niche. Most people using AI don’t really care about guardrails to begin with, and they never hit them in their life. Even with me, I don’t really hit the guardrails that often when I use GPT or Opus. So I don’t think that’s going to be why companies go to open weight. The reason to go open weight is to control the data. And right now, open weight models are just too big for companies to even run on their own because GPU prices and memory prices and everything is just absolutely bonkers right now. But I think over time, more companies will run their own internal AI clusters and then use open weights, so they’re not sending customer data to the cloud. And then, because the world goes in circles and what’s old is new again, we’re going to find a lot of companies just get breached because they started doing all the processing on themselves and they shouldn’t be trusted to hold that data. And then they go back to SaaS products, like cloud AI companies, like Anthropic, OpenAI. And we just kind of go in this weird circular pattern. I don’t think there’s a good answer either way. I also think open weight models will have guardrails, because most companies won’t run their open weight models themselves. So it’d be on places like Hugging Face or OpenRouter or things like that to implement guardrails so they can use the latest GLM or whatever. I think Reflection is a US-based open weight model company. I don’t know what their AI is called, but they probably will publish guardrails to use with their model. It is up to the routers to implement them.
FalconSpy: I don’t have too much to add. Most of the time, like I’ve said and others, it’s because you want to control the data. You want it there. These open weight models, they do have their own guardrails. There’s plenty of open weight models that also have no guardrails. They’re called obliterated models. You can probably find them on Hugging Face. Is it obliterated or liberated?
ippsec: Obliterated. Really? I thought it was liberated.
FalconSpy: Obliterated. No, I did the same thing you did. Yeah, obliterated. That means the model is dead. Liberated is you made the model free.
Emmax0: That’s what they want to use for that. It’s like the same thing. It’s just, you know,
FalconSpy: it’s in different contexts. I know, but like obliterated, right? They destroyed the guardrails. I guess that’s like their thought process on it. I think it’s both. I think it’s kind of
ippsec: like a tabs versus spaces thing right now. And I am very hard on “liberated,” not “obliterated.” You obliterated the Death Star’s cooling system, and now there is no more Death Star. Obliterated is full out destruction. I obliterated the guardrails. I mean,
FalconSpy: you just destroyed the model. Congratulations. The guardrails are gone, but there is no more model.
ippsec: Look, it’s not like Exodia is coming out here. You know, it’s Exodia Obliterate. It’s like, we’re not obliterating the Blue Eyes White Dragon and Seto Kaiba. Yes, I like anime. We’re obliterating the guardrails.
FalconSpy: If I obliterate your GPU, do you think only your GPU and your computer is impacted? Or do you think my obliteration of your GPU goes into other portions? Maybe your motherboard got fried. Maybe your processor. Maybe the fire happened on the GPU and you no longer have a computer.
ippsec: I mean, you could fry a GPU without killing the rest of your computer. It’s not like I’m setting
FalconSpy: the thing on fire. That’s not obliterate. You literally just used the word “fried.”
FalconSpy: Hold on. Let me see how many questions are in the queue. If we actually want to keep going with this, there’s like 21 questions in the queue with 15 minutes left. Let’s see how many we can get through. And if we do somehow get through all of them, we’ll come back to this. But I don’t know. They’re called obliterated. You could obliterate, obliterate, literate, whatever. All right. Next question. If I want to get really good at infra security, which courses or challenges do you recommend doing?
ippsec: I don’t know if we have any specific challenges or anything like that that would be like, “Hey, this is how you get better with infra.” There might be a couple of modules on standing up services and securely doing them. I don’t remember off the top of my head. Outside of that, if you want to get good at doing infrastructure security, start learning a couple of the different things out there like Terraform and Ansible and Puppet and Chef. These will stand up the infrastructure for you. It’ll configure it the way you want. If your configurations start to drift, you can bring it back. So making sure your configurations are all tight, the same across the board, and as soon as something starts drifting, it brings it back. So if someone makes a change, you could bring it back. I don’t have anything else on that.
FalconSpy: Chad, Emma, you guys want to add anything? No, I got nothing. Cool. All right. Next question. What would you say is the thing people struggle with most while getting into pen testing?
ippsec: I would say probably the mindset. That is always the toughest thing, learning how to think critically, because a lot of pen testing isn’t really taught by courses. And I know that seems kind of odd considering we have all the courses to learn this, but once you get into the actual field, you’ll find out every pen test is just learning a bunch of languages or things you don’t know and how quickly you can adapt and use pieces of information in a unique way. So a lot of the courses, at least introductory, are more about trying to build the mindset to think outside the box.
ChadB: Learning to understand that you learn a set of skills and you’re setting yourself up to learn something you’ve never seen before, maybe on the spot. And I do also know that there’s at least one person that struggles with, let’s say the ethics of doing what we do, breaking things. But mostly it’s the mindset of learning that you’re going to see something and it’s vulnerable and you have to learn what that is, very quickly on the spot in most cases, when you’re across something new, and otherwise just having that methodology to use what you know to get to that point.
Emmax0: I think for a lot of really new people, especially those without a technical background, one of the biggest struggles is picking where to start, because ultimately it’s a very, very broad field. Where do you begin? And I feel like that’s kind of the value that a lot of courses provide is that initial direction of where to go. What do I learn? Because ultimately one of the most important skills in cybersecurity is learning how to learn, learning where to go. And then as you progress, you get more experience to know, “Oh, this is what I’m interested in. This is what I’m good at.” So I would say that’s the hardest part I’ve seen for a lot of people, and just to do stuff and find something that you like and enjoy. There’s no right way,
FalconSpy: no right path. All right. Next one. Are we the same moderators of Let’s Defend? If yes,
Emmax0: any updates on ongoing platform issues? We do own Let’s Defend as a company. We did acquire them. However, I don’t think any of us here are overly familiar with that. If you’re having issues with the platform, reach out to support and support would be more than happy to assist you.
FalconSpy: All right. Next person. They say they are struggling with depression and don’t know what they experienced passion for an interest like other people do. How do you maintain discipline to learn things when motivation fails, and how do you decide on what to learn in the first place?
ippsec: Talk to a professional. Yep. I wish I could answer that. Everyone is different. Before security, I would go into a custom StarCraft game for probably three to four hours a day, just practicing marine splitting, which is one of the most mundane things you could ever do. And I just did that until I got really good at it. I never was satisfied and just kept doing it for a very large portion of my day. So the five seconds in a match in StarCraft, I could do that really well. And then I translated that hyper focus into security. So find something that motivates you and stick with it.
ChadB: First off, I want to say, I hope that you’re getting adequate help for the depression part of it. But as far as finding passion, you’re here now. There’s at least interest to know that you like security and you’re in this one place that studies security and we happen to be here meeting. So welcome. We do wish you the best, but after taking all those steps, find something that’s interesting to you. There’s a lot here, there’s a lot of directions to choose from, blue or red in this field. So just look around, do some modules, in my case, find something that’s interesting for you and go for it. If it doesn’t, the world is still wide open. But we do wish you the best.
FalconSpy: Next question here. Currently it takes about four months to get challenge feedback when you submit one to the platform. That could be a long time. Are there any plans to hasten how long it takes to get feedback, especially when you are rejected so you can rework it? I don’t think we have anyone from the challenge team here. So shoot me a DM with the name of your challenge, or send an email to community at hackthebox.com. We can always look into it and try and get back to you once we reach out to the team. There is also submissions
Emmax0: at hackthebox.com, which is directly to the content team who handles content submissions. I would give them a try first and they should be able to answer any questions.
FalconSpy: What Emma said. All right. Next question is an upvoted question with the addition of Let’s Defend being added into Academy. Is there a higher tier defensive cert like CAPE or CWEE in the works? Disclaimer here. Yep. No one can speak to that. Disclaimer. Pay attention to social media. Maybe you can bribe idna and he’ll tell you if anything is happening, but I wouldn’t hold your
ippsec: breath. I don’t think because of the acquisition of Let’s Defend we’d go for a higher tier, just because I don’t remember there being a lot of higher tier content in Let’s Defend that would qualify itself for a tier three cert. I think I’m using the terminology correctly. Maybe that’s tier four, but yeah, I think most of the Let’s Defend stuff was geared towards more of the
Emmax0: coursework we already have. If there is any new content, there is several people whose job it is to make sure that we will make sure we communicate with our content. Where’s Chad?
FalconSpy: How do I, Emma, how do I know? We will make sure you know. All right. Moving on. Career opportunities in OT/ICS security. Is it worth exploring?
Emmax0: I mean, it certainly is a more niche field.
ippsec: I was just going to say, if it interests you, then yes, it is worth exploring. If that is what interests you, then I’d say go for it.
Emmax0: Mine’s the same thing, of interest, you go for it. It’s a more niche field. So you’re probably gonna have a little bit more struggle than some other areas in finding resources, affordable access to hardware and education, finding a job. So it is a little bit worse in that regard, but being a niche field, while it is harder to get initially into, you generally end up having a lot more opportunities as you’re one of the few people who does specialize in that. And that is a very important area these days.
FalconSpy: All right. Just a little bit of quick timekeeping here. We have about over five minutes left. We have about 18 questions in the queue. I doubt we’ll get to all of them, but we’ll try to get through as many as we can. Next question here is an upvoted one. What are the rules on using AI on the Academy modules and
ippsec: labs? The terms of service state, if you tell the AI to interact with a platform or spawn content, unless it is specifically stated you’re allowed to do that, it is against the terms. That being said, just remember, anytime you have AI do something for you, chances are you’re not learning as much. If you’re just testing its capabilities, then I’d say go for it. Just make sure you don’t do anything stupid and say, “You know what, go solve all this for me and get 500 solves in a day.” Chances are we won’t catch you or anything like that. But just keep in mind, anytime you tell the AI to interact with a platform, you’re breaking the terms of service. And if you end up on our radar, you can get banned. You’ll probably hear from us, but yeah.
FalconSpy: TL;DR, play stupid games, win stupid prizes. All right. Next question here. This person is in their forties, have about 20 years of software dev experience. Any insights to people changing career paths into InfoSec? Is it more favored with the previous experience? If they were good at pen testing, is it easier to get work? I’m understanding that with 20 years
ChadB: of software dev experience, you will probably come in at a more advanced level than other people. Age doesn’t matter. You’re coming in at 40, I am 50. Yeah, I’m saying you’re probably in a very good position to come into the field, especially with that background. I don’t
FalconSpy: imagine you will have many problems. Yes. You could offer questions, people, if you really want to see other questions get answered. Will Active Directory, speaking of which, this one’s another question, will Active Directory pen testing die in the future? No. Next question. Emma, do you want to answer that as well? Or are we just basic? No.
ippsec: I don’t think AD pen testing is going to go away. Even if AD pen testing went away, learning AD still gives you a head start, a way to learn the cloud, because what Azure does is very similar to AD. It’s not like they just completely reinvented the wheel. They just moved the wheel to their house. So you’ll still be able to learn Azure pretty quickly if you learn AD.
Emmax0: And we all know, I’m sorry, go ahead. I was going to say just maybe eventually if it gets discontinued 30, 40 years later, after that, we might start seeing it disappear. But with how prevalent it is in companies, companies don’t deprecate those systems very quickly. I mean, we’re still seeing XP and Windows 7 around. So maybe many, many, many moons in the future, after it’s deprecated, it’ll eventually go away, but not within our lifetimes at this point.
ChadB: I don’t think AD is going away. Mostly, just like Windows, I’ve seen Windows 2000 live in the field. People are going to keep the machines that do what they want to do working. If somebody doesn’t want to buy something new, it’s not going to go away. That’s it. We can trade that on forever.
FalconSpy: All right. Next question is an upvoted question. Since you said Active Directory would be seen less during engagements, what are some other domains that we should look into other than web, since web is very common?
ChadB: Azure, GCP, and the other one, AWS. Everyone should have a pretty broad understanding of all of these things, but I would say have a good understanding of probably in this order: Azure first, then AWS, then GCP. A lot of hiring companies will use the next one down the line as a failover. I’ve seen one company that leveraged all three as backups for one another, but I would say have a solid understanding of each one of those technologies starting with probably Azure.
FalconSpy: I think their question is kind of asking what other domain could we see. Like IAM, right? Like you’re talking about cloud, what specifically in cloud should they focus on as a domain, so like identity and access management. I think that’s what they’re asking for, but I might be interpreting their question wrong. I agree with you on IAM.
FalconSpy: I mean, I only picked IAM because I work in cloud and honestly, I think IAM is probably the, you know, if you own a cloud company’s identity and access management system, you will own pretty much the network or at least a bunch of tenancies and other things. So I would definitely say study up on your IAM skills, your different experiences that you have in the different cloud providers. They all pretty much operate very similar. So knowing IAM is pretty helpful. Anyone else? Cool. All right. I think this will be our last question. It is an upvoted question. Suppose this looks like it was written by an AI, but here we are. Suppose you’re all interviewers who are conducting an interview to hire people in the cybersecurity field, any field, like for red team, blue team, GRC. Candidates include experience, so on and so forth. What will you look out for in a candidate and how will you evaluate them in this current era?
ChadB: Motivation. Thought process. I’d say their motivation. Of course, you know, their background. I would examine what they did to get to the point where I was interviewing them and dig into that. At this day and time, that’s probably a referral. So yeah, motivation and how interested they seem in the field. Surprisingly enough, some people get into the interview and the interviewer feels like they didn’t want to be there. So I would look for probably their motivation and, like I said, their thought process, maybe problem solving abilities. Emma, you want to add anything on that as we can look to
Emmax0: wrap up? I would say just kind of the same thing. Thought process, motivation. The industry changes a lot. It’s about learning to learn. So you need to have that drive. You need to have that thought process. How do you tackle problems? How is your approach? How do you work through things? No matter where you are, like even if you’re inexperienced, you can still say, “Oh, if I don’t know this, how would I go about looking that up? How would I find that information?” Versus a more experienced one, you’d walk through how you would do it as a full. So just see where they’re at mentally, see how they process things.
FalconSpy: And ippsec is relying on AI. So look at ippsec’s AI answers.
ippsec: Essentially, AI can make everyone sound intelligent and plausible. So it becomes tough. You can’t judge a book by its cover.
FalconSpy: Thank you everyone for joining us for this week’s Cube Talk. We will see you next week. You can take a look at the top of Discord at our events section to see when these happen in your local time zone. If you’re interested in future sessions, you can say you’re interested and receive an alert when these do go live. These are recorded. So the recording should be posted on both YouTube and Spotify on Tuesdays. So pay attention to the announcements channel for the recording to go live. We also have some other events coming up. So a quick shout out on Monday, we have a Cube Cast recording with Gillette. They have appeared a couple of times here on our Cube Talk. They are a Grid Teamer at Huntress Labs, where John Hammond works. They’ll be talking about their career, how they joined the field. And at the end of the recording, they’ll be available to answer some questions. And then a little bit further down the road, we have our Home CTF. It will be one of our blue team CTFs. So if you’re interested in that, that’ll be in September, all in the events section. But thank you everyone. And we will see you next week.
