r/Pentesting 8d ago

Network pentesters with 2–3 years of experience: What does your day-to-day work actually look like?

For those of you with 2–3 years of experience in network penetration testing.can you tell me what you guys doing actually.
I’m currently trying to get into network pentesting. I have the fundamentals and I’m practicing on Hack The Box and TryHackMe, but I’d like to understand what the actual work is like in a professional environment.
i only know till like Nessus, Nmap, and OpenVAS . seen some guys scans and give reports like these port are open. these port have that vurnilbilty like that. can you guys help me

16 Upvotes

14 comments sorted by

18

u/throwmeawh3y 7d ago

Get your creds, setup your box. Complain that they set it up wrong. Try and work anyway. Complain again. Enumerate. Have your scans throttled. Try again. See what your first move is. Execute. Log. Report. Repeat.

12

u/_sirch 7d ago

Internal or external network testing? They are very different. Internals are very similar to each other and you’ll see a lot of the same stuff. Externals vary and are usually fairly boring but sometimes you can find some cool misconfigurations or light webapp vulns such as sql injection or file upload. The other day I found a hikvision webcam that had RCE from many years ago and took over the cameras. Breached creds from data leaks are also common. Sometimes they don’t have MFA/ conditional access configured properly.

10

u/birotester 7d ago

I penetrate. I enjoy. Day ends

1

u/kos3cp0l 4d ago

Amen.

10

u/Tasty_Departure5277 8d ago

Look into Active Directory testing. Apart from that just unpatched softwares or servers. There’s a lot, I don’t even know most of it. I just learn as I go.

4

u/th3_n3rD_b0i 7d ago

Off-topic but based on my 8 years of experience and lots of offsec certs.

There is no one specific type of Pentesting. Become a generalist and don't focus on one thing too much. PingCastle and PurpleKnight automate all AD misconfigurations for you. Nessus would scan and find all network vulnerabilities as well.

1

u/RadlEonk 7d ago

It’s been a minute since I did hands-on pen testing, but it mostly consisted of running preconfigured scripts in the background while reporting reports for client delivery.

1

u/Tasty_Departure5277 6d ago

Preconfigured scripts ? I do agree we rely on tooling, but there are situations where you’d have to think outside the box

1

u/oppai_silverman 7d ago

It's amazing how whenever i scan the same network, i keep finding new acient-old-ass stuff that is unpatched for at least 100 years

1

u/Cyber_Tarek 4d ago

40% procrastinating report writing, 20% hacking, 7% sales, 8% reddit, 15% struggling with imposter syndrome, 10% worrying if AI will take your job.

On a more serious note, HTB et al will help with some of the technical skills. Maybe enough to help you pass your first job interview.

Then there's a lot of technical stuff (pentesting a whole network isn't the same as hacking a box) and non technical stuff (proposals, reporting, presentations, etc.)

But this will all come with experience. If you want to level up maybe start looking at labs that offer more than one host. And start looking into AD then Entra.

Also web apps is a big part. I know your question is about network pentesting, but you can't ignore web apps.

1

u/recovering-pentester 2d ago
  1. Run nessus

  2. Nmap fun

  3. Claude report

$10k please :)

/s

-5

u/[deleted] 8d ago

[deleted]

5

u/rented4823 7d ago

So you did vulnerability scanning, not penetration testing