LSCP Challenging Cyber Resilience

What Certification Next?

This is a short outcome-focused review of the certification vendors Sam Lyhin had a chance to work with.

Offensive Security 

As result, the certified employee would tend to:

In the case of adversity, they probably would say: “I’ll do that” and will try harder until they die, and then they would try it again. 

The key points for effective learning from OffSec:

INE/eLearnSecurity

As result, the certified employee would tend to:

In the case of adversity, they probably would say: “Look, there are the top 4 techniques for it, let’s try them all”. If this fails, they might go cry in the bathroom just like OffSec specialists would do if no one helps them at the right time.

The key points for effective learning from eLearnSecurity:

PortSwigger 

As result, the certified employee would tend to:

In the case of adversity, they would ask their friends for help. 

The key points for effective learning from PortSwigger:

SANS/GIAC

As result, the certified employee would tend to:

In the case of adversity, they probably will say: “I feel like I know how to fix it; please give me X (four) hours to suggest a decision we should make”, and they will return with a couple of choices, sometimes however while making mistakes. 

The key points for effective learning from SANS:

EC-Council (CEH)

As result, the certified employee would tend to:

In the case of adversity, they probably will say: “do you really care about this? hey man, you just need XXX, come on. Oh, this will not work? I don’t know how to help you. Please ask someone else. Oh, you think I’m responsible for that? alright, I’ll do my best”. And they will do their best. 

The key points for effective learning from EC-Council:


Part of the LSCP Responsible Disclosure Lab archive. Fresh threat intelligence, monthly – subscribe to the newsletter.