Video summary

Become A Red Teamer Not A Pentester!

Main summary

Key takeaways

Technology

Video Purpose (High Level)

The speaker argues that anyone aiming to become an offensive security / red team professional should move training away from “classic” junior penetration tester paths and toward red-team operator skills—especially by leveraging autonomous/AI-assisted pentesting and agent-building. They also claim that many vulnerability scanner–only roles are becoming less relevant.


Core Training Guidance / Career Analysis

Adjust Your Training Plan for Offensive Security

  • Start with Linux, networking, and penetration testing basics.
  • Then shift toward red team operator skills (rather than treating “junior pen tester” as a long-term endpoint).

Why “Junior Pen Tester” Roles May Decline

The speaker claims enterprise organizations will reduce/replace pure junior pentesting roles due to ROI and automation. Instead of compliance-style scans, organizations increasingly need adversary-style/red teaming outcomes.

ROI / Business Framing

  • The speaker references “travel and staffing math” (example: large enterprises needing 40–60+ pen tests per period).
  • They argue AI/autonomous platforms can reduce time/man-hours while increasing value through clearer results (e.g., more actionable evidence).

Review / Comparisons of Offensive / Automation Tooling

The speaker compares multiple autonomous pentesting / red teaming platforms, positioning them by “where they work” and where humans still matter.

1) Horizon (Autonomous AI / Autonomous Pentesting)

The speaker has used it for 4+ years and says it aligns with where offensive security is going.

Claimed strengths

  • Reduces false positives compared to traditional scanners.
  • Produces POCs with screenshots showing exploitation, not just alerts.

Pricing / positioning

  • Described as middle cost, with implied price increases.

Agent-building

  • Claims you can build your own agents (cloud + deployment via GitHub CI/CD).
  • Mentions a security practice such as package/dependency validation so untrusted NPM packages don’t reach the repo.

2) Pentera (“OG”)

Claimed strengths

  • An “umbrella platform” with many plugins/tool sets.
  • Automation integrations/workflows such as Jira and Snow (per the speaker’s description).
  • Mentions acquisitions focused on automation (timeline referenced as “Black Hat timeframe”).

Coverage / limitations

  • The speaker says it has “a lot” of capability, but not everything—implying humans are still needed for gaps.

3) AEV (From BreachLock) (“Up-and-Comer”)

Described as newer than Pentera/Horizon.

Claimed strengths

  • Strong focus on autonomous testing.
  • Includes a web application suite for autonomous web app pentesting.

Pricing / positioning

  • Presented as cheapest/up-and-coming relative to others.

Development focus

  • Mentions “heads down” development and strong web automation.

Additional / Adjacent Tool Mentions

  • CrowdStrike integration: the speaker claims another tool will be integrated with CrowdStrike (unnamed at the time).
  • Mentions the Cobalt Strike ecosystem and C2 (command-and-control) as part of later red-team training recommendations.

Attack vs. Scanner Mindset (Key Argument)

The speaker argues that pen testing is trending toward a model similar to “compliance vulnerability scanning.” In response, AI/autonomous platforms can replace much of what scanners currently do.

They criticize scanning tools (examples listed):

  • Nessus / Nexpose / Rapid7
  • Acunetix

Criticisms

  • False-positive heavy
  • Less cost-effective due to licensing and scanning overhead

Preferred outcome

  • Tools that produce actionable evidence, such as POCs and screenshots.

Tutorial / Training Recommendations (Explicit Platforms)

The speaker provides a concrete learning path and discourages alternatives.

Recommended Platforms / Training (Top 3)

  1. Hack The Box

    • Start with their beginner path/certs.
    • Mentions CB PH and later a CPTS-style credential (names partially unclear from subtitles).
  2. White Knight Labs

    • Recommended as “best” for making the red teaming jump.
    • Claimed to teach real-world red teaming “straight out the gate.”
    • Training content mentioned:
      • Cobalt Strike
      • Terraform
      • Multiple course tracks (acronym-heavy; subtitles include references resembling “ARTOC/AR TOC,” plus supply chain/offensive development)
  3. Zero Point Security

    • Suggested as especially relevant for enterprises and Cobalt usage.
    • Notes it was purchased by Fortra.
    • Mentions tools such as Outflank (via acquisition mention) and training/capabilities around C2, including “own C2.”
    • Positioned as still worthwhile despite the acquisition.

Suggested Follow-On Certs / Modules

  • Mentions taking CAPE or an Active Directory–focused module after the main path.
  • Refers to HTB AI route and notes it is “extremely hard” and harder than “Pwn Labs” (as described).
  • Mentions Pwn Labs positively, but suggests it’s not as “advanced/kick” as White Knight Labs’ cloud path.

Courses the Speaker Says to Avoid

TryHackMe

  • Says they would “go straight to Hack The Box.”
  • Also mentions personal reasons (e.g., a ban from an “Advent of Cyber” challenge).

Mainstream Credentials (General Critique)

The speaker claims CompTIA / OSCP / mainstream certs are not necessary for offensive/red-team skill acquisition, except they note some federal/government requirements might apply.

Specific OSCP critique (as stated):

  • OSCP is described as “irrelevant,” likened to “a glorified PJPT,” especially after OSCP+ changes.

They also mention recruiters/managers sometimes use certs lazily.


Red Team Role Structure (How Jobs May Evolve)

Predicted trajectory

  • More junior/intermediate red team operator roles
  • Plus senior/advanced red team offensive engineer/operator roles
  • And management layers above

The speaker claims consulting firms may still hire for junior roles, but large enterprises will likely shift toward adversary-style work.


Blue-Team Alignment (Threat Hunting as Part of the Path)

The speaker strongly emphasizes building blue-team capability alongside red-team skills:

  • Autonomous threat hunting
  • Threat hunting agent concepts using adversary behavior/IOCs/IOAs
  • Building custom detections and lab workflows

They cite familiarity with enterprise products (examples mentioned):

  • SentinelOne
  • Darktrace
  • CrowdStrike
  • Corelight
  • Splunk
  • Exabeam
  • ZeroFox
  • Cybereason

Why this matters

  • Enterprise exposure helps red teamers understand how defenders respond (war rooms, detections, tool integrations).

Practical “How to Build” Concepts Included

  • Build autonomous agents (red-team and blue-team):

    • Use cloud + deploy via GitHub CI/CD
    • Add controls like dependency legitimacy checks (avoid malicious NPM packages)
  • Integrate with CrowdStrike enterprise licensing:

    • The speaker cites pricing and claims it enables threat hunting agent work and report usage.
  • Create labs using:

    • IOCs/IOAs
    • hashes (MD5 mentioned)
    • Detection evasion ideas

Main Speakers / Sources (As Referenced)

  • Primary speaker: the YouTube channel host (unnamed in subtitles; personal first-person perspective throughout).

Companies/tools referenced as sources for capability claims

  • Horizon, Pentera, AEV (BreachLock)
  • CrowdStrike
  • Training platforms: Hack The Box, White Knight Labs, Zero Point Security (and Outflank mentioned via acquisition)
  • Toolset mentioned: Cobalt Strike (plus related red-team C2 references; no specific external “source video” cited)

Original video