@offsectrainingi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Empowering the world to fight cyber threats with indispensable cybersecurity skills and resources. Support queries: https://nitter.cf/t.co/HtFpqjjlRZ
Joined April 2010
- Tweets6K
- Following117
- Followers331K
- Likes1.1K
Pinned Tweet
#OSAI is officially here! π£πΊ
OffSecβs newest certification for hands-on offensive operations against AI-enabled systems is now available for purchase with Learn One, Course & Cert Bundle, and Learn Enterprise.
Built for practitioners who want to apply an adversary mindset to modern AI systems and stay ahead as the attack surface evolves.
π offsec.com/courses/OSAI/
Ready to master web exploitation with Kali Linux? ππΎ
WEB-200 teaches you to manually find and exploit XSS, SQLi, SSRF, and more using the industry's top tools. No multiple-choice testsβjust a grueling 24-hour practical exam to earn your OSWA certification.
Embrace the Try Harder mindset. Prove you have what it takes.
π offsec.com/courses/web-200/
#OffSec #KaliLinux #OSWA #WebSecurity #TryHarder #AppSec #BugBounty
Recon is everything. Don't rush the exploit. ππ
HackTrack for OSCP prep continues this Saturday with a deep dive into Gallery. Learn how to uncover hidden attack surfaces through disciplined enumeration.
This week's focus:
π SNMP Enum
π vHost Discovery
π SQLi
π€ File Upload Attacks
π
Saturday, September 26, 2026 @ 16:00 GMT
Claim your spot: hubs.li/Q04rTkqs0
#OffSec #OSCP #PenTesting #CyberSecurity #TryHarder
#TryHarder
As cyber pressure and cybersecurity budgets rise, what should that investment deliver?
π Earlier detection.
β‘ Faster containment.
π€ Teams ready to protect financial operations under pressure.
OffSec helps financial institutions build and validate the hands-on capabilities behind those outcomes, before a real incident puts them to the test.
Prepare your cyber workforce with OffSec: bit.ly/4h6hjMp
Some people just need a deadline. β³π―
If you are the type of learner who thrives under pressure and wants to fast-track your next career milestone, the OffSec 90-Day Course & Cert Bundle is designed for you.
Instead of a year-long subscription, you get exactly what you need for a focused, intensive sprint:
β
90 days of access to a single 200 or 300-level course.
β
Hands-on lab access.
β
One exam attempt.
β
50+ bonus Proving Grounds Play labs.
Whether you are looking to earn the industry-standard OSCP, master web exploitation with the OSWE, pivot to defense with the OSDA, or tackle the new AI attack surface with OSAI, your path is ready.
Lock in your next goal and start the clock.
Explore the bundle options here: bit.ly/4bkUXER
#OffSec #CyberSecurityTraining #OSCP #OSWE #OSAI #CareerGrowth #PenetrationTesting
Automated tools are great, but chaining them with manual enumeration is how you get root. ππ οΈ
If you are currently studying for your OSCP (ahem, now is the time to register for Hack Track) or just want to level up your Linux Privilege Escalation skills, check out our newest video walkthrough. We demonstrate exactly what to do after you get that initial www-data shell.
Key takeaways from this session:
π Managing Noisy Tools: How to use the timeout command to run pspy efficiently without locking up your terminal.
β°οΈ Leaving No Stone Unturned: Why reviewing processes reveals credentials (like a rogue MySQL dump) that standard checks might miss.
π Exploiting Misconfigurations: How finding a writable app .py script with sudo execution rights allows for a simple OS module injection to spawn a root shell.
Stop guessing and start enumerating. Watch the full breakdown here: bit.ly/4xFQzZq
#Linux #PrivilegeEscalation #OffSec #RedTeam #OSCP #CyberSecurityTraining #TryHarder
We can speak to how great we think our Live Training is, but hear it from the people in the room instead π
π Ready for your own live training experience? Request a scoping call to chat with our team: lnkd.in/eRJytBZi
π° Black Hat and DEF CON generate a lot of noise - the good, the weird, and AI.
A month later, what actually stuck? π€
From cheaper offense and AI agents to attack paths, AppSec, and the changing role of security teams, we pulled out 10 lessons that could shape how defenders work next.
π Read 10 Lessons Reshaping Security After Black Hat and DEF CON 2026: bit.ly/4hDJUtR
π§ͺπ€ WEEKLY LAB DROP! Are you up to the challenge?
β€΅οΈ Did you know that OffSec loads new labs every week into our platform? Depending on your subscription, you have access to rotating and permanent labs that will help you keep your skills fresh.
Here are a few of the NEW labs in your inbox:
Learn Enterprise β‘οΈ bit.ly/4f2eCft
π CVE-2025-64507 (level 200, 20 points, about 1 hour): A multi-stage Linux machine built on CVE-2025-64507, combining exposed internal tooling, binary reverse engineering, and memory corruption to reach privileged application access.
βοΈ Sutekh (level 200, 3 hosts): A hybrid environment that combines Kubernetes, RabbitMQ, and Active Directory, including an exposed Kubelet and gMSA authentication. A new hybrid cloud and Active Directory surface.
π· Defend CVE-2026-68771 (level 200, about 2 hours): Secure a vulnerable version of ComfyUI, an open-source AI media-creation engine, against a command-execution vulnerability (CVE-2026-68771). A new AI-infrastructure defensive scenario.
AMP β‘οΈ bit.ly/4ulvdjb
π΄ CVE-2026-25887 (level 200): Exploit an authenticated remote code execution vulnerability (CVE-2026-25887).
π· Defend Wp2shell (level 200): Defensive lab covering two WordPress Core vulnerabilities (Wp2shell).
π Privy (level 200): Exploit CVE-2024-1991, a privilege-escalation flaw in a WordPress plugin.
Sign up or register now to get access to the newest labs on scene!
#oscp #tryharder #labdrop #cybersecurity #osai
πΊ π Missed the first few weeks? There's still plenty of time to join HackTrack and prepare for OSCP!
Join fellow PEN-200 learners as you continue building the skills and confidence needed for OSCP success. (Not registered for the training and certification yet? Check out options here! offsec.com/courses/pen-200/)
This Saturday join our mentors for a walkthrough of #BitForge.
Sometimes the path forward is hidden in the details. This week, OffSec Student Mentors will demonstrate how to uncover overlooked attack paths, troubleshoot web exploits, and identify opportunities for privilege escalation.
This weekβs focus:
π Enumerating .git
π Discovering VHosts
π Troubleshooting Web App Exploits
β¬οΈ Analyzing sudo Privileges
Build a stronger methodology for finding the opportunities others might miss.
π
Saturday, September 19, 2026
π 16:00 GMT
Register Now: hubs.li/Q04rTkqs0
#TryHarder
π 25 OffSec certifications. β
One fully certified cybersecurity team.
In one year, π‘οΈ Titan Shield built recognized capability across penetration testing, SOC operations, incident response, threat hunting, and secure web application development.
The result is bigger than the certification count. Titan Shield can show prospective clients that expertise extends across the team, strengthening its credibility as it grows in Palestine and across the region.
Read the full case study: offsec.com/resources/case-stβ¦
You got the badge. You proved you can hack it. So... what's next? π―
The "Try Harder" ethos isn't a one-time event; it's a lifelong mindset. Whether you want to master Advanced Web Attacks (WEB-300), AI Red Teaming (AI-300), or Threat Hunting (TH-200), we've mapped out the exact path to get you there.
Find your next challenge and keep climbing:
π bit.ly/4ungymX
#OffSec #TryHarder #CyberSecurity #PenetrationTesting #RedTeam #BlueTeam
π οΈπ§ Theory is great, but execution is what matters.
The AI Blind Spot breaks down why traditional security fails against modern AI systems. But how do you actually attack and defend these pipelines in the real world?
π΄ Enter AI-300: Advanced AI Red Teaming and OSAI.
Take the concepts from the whitepaper (like manipulating embeddings and exploiting multi-agent workflows) and drop into live, hands-on labs to practice them.
Understand the threat: bit.ly/4v3owTh
Hack the threat: bit.ly/4a2t5oo
#OSAI #OffSec #AISecurity #RedTeam #Infosec #TryHarder
π More than 100 technology and cybersecurity companies are calling for urgent action as AI accelerates cyber threats.
AI can compress parts of the attack and defense workflow, but speed alone does not create capable operators.
Security professionals still need to understand attack paths, validate AI output, and adapt when an approach fails. That makes practical expertise more valuable than ever.
Read more on this: offsec.com/blog/are-securityβ¦
π οΈπ Struggling to make your Nmap outputs look good for your OSCP report?
During OffSec's Hack Track: Moonwalk (Week 4 for OSCP learners), our experts talk about how documentation is just as important as exploitation. Check out this quick tip from our latest session on using xsltproc to effortlessly convert messy XML scan outputs into clean, readable HTML files.
Your future self (and your grader) will thank you.
Register for the next Hack Track β‘οΈ hubs.li/Q04rTkqs0
#HackTrack #OffSec #TryHarder #Moonwalk #PenetrationTesting
Ready to move past automated scanners and master white-box web testing? ππ»
WEB-300: Advanced Web Attacks and Exploitation teaches you how to perform deep analysis and exploitation of modern web app vulnerabilities, from deserialization RCE to advanced SSRF.
Pass the grueling 48-hour exam, earn your OSWE certification, and prove you can craft custom exploits in real-world environments.
Level up your web security skills: offsec.com/courses/web-300/
#OSWE #OffSec #AppSec #BugBounty #CyberSecurity
ππ Ransomware doesn't operate on an annual compliance schedule. Your team's training shouldn't either.
A point-in-time training seminar isn't enough to stop modern Advanced Persistent Threats (APTs) or ransomware syndicates.
π Protecting financial assets requires Continuous Readiness.
With OffSec Learn Enterprise, your security teams get always-on access to the constantly updated OffSec Learning Library and live Cyber Ranges. Keep your team's skills as dynamic and adaptable as the adversaries targeting your perimeter.
Stay ready. Stay secure: bit.ly/4h6hjMp
#Fintech #CyberDefense #Ransomware #ContinuousLearning #OffSec #RiskManagement
Want to fast-track your team's skills? Bring OffSec instructors directly to your teams.
Get expert, hands-on instruction for our most in-demand certifications:
β
PEN-200 (OSCP)
β
AI-300 (OSAI
Build a stronger team, faster.
Learn more and book your private cohort: bit.ly/43HITJD
#OffSec #CyberSecurity #LiveTraining #OSCP #OSAI #EnterpriseTech
ππ» Tired of missing out on the latest CVEs and new lab drops? Or not receiving info on programs like Hack Track?
We are constantly pushing fresh, hands-on scenarios to the OffSec platform. If you want to be the first to know when new challenge labs and exploits drop, make sure you are on our list. Sign up β‘οΈ offsec.com/community/#join
β‘ Already registered? Check your preference center and ensure marketing emails are turned ON so you don't miss the next drop!
#OffSec #CyberSecurity #CVE #PenetrationTesting #InfoSec
ππ Stop waiting for the SIEM to alert you. Start hunting the threats that slipped past it.
TH-200/OSTH: Foundational Threat Hunting teaches you to proactively track adversaries using industry tools and behavioral analysis.
Here is what you will master:
π΅οΈββοΈ Identifying behaviors and profiling advanced threat actors (including ransomware groups like LockBit and ALPHV).
π» Leveraging enterprise tools like CrowdStrike Falcon and Splunk to correlate data and track anomalies.
π¦ Analyzing network and endpoint Indicators of Compromise (IoCs) to uncover stealthy intrusions.
Pass the 8-hour practical exam, earn your OSTH certification, and prove you can find the hidden threats before they execute.
Are you ready to #TryHarder on the defensive line?
Start hunting: offsec.com/courses/th-200/
#OSTH #OffSec #BlueTeam #ThreatHunting #CyberSecurity
You're halfway through HackTrack!
HackTrack returns this Saturday with a walkthrough of π Snoops.
Enhance your skills in identifying misconfigurations, credential exploitation, and privilege escalation through script manipulation.
π’ SNMP Enumeration
π SSH Key Access
πͺ Backdoor the Cron
π
Saturday, September 12, 2026
π 16:00 GMT
Register Now: hubs.li/Q04rTkqs0