Forum
ยป
Accepted a new position - Measly reps till I'm out
- Results 1 to 11 of 11
-
Page 1 of 1
07-14-2022, 04:36 AM
-
#1
Accepted a new position - Measly reps till I'm out
Age 27. I work in cyber security. Always been in a type of role that was like responding to security incidents / issues. New role is a bit more specialized for investigations for insider threats.
1-3 years ago I thought I wouldn't break $100k base pay by 30, srs. Then inflation got crazy, rent's going up 20% this month, and I decided going up 3-5% per year from the company's typical annual bump is NOT acceptable. I got inspired to get out of the comfort zone and get into theDANGER ZONEafter watching Top Gun: Maverick.
Old Job:
- $85k base, paid hourly, 10% annual bonus, 10% extra for working evening hours
- 5x8 schedule, shift rotates every 2-3 months
- Worked a chit load of overtime, including every corporate holiday, cuz I wanted to get as close to $120k gross as possible
- 95% remote, went into office once a month
New Job:
- $110k base, paid hourly, 10% annual bonus, 10% extra for working evening hours
- 4x10 schedule, no shift rotations. Still working out which days though, if I can work Sundays then I'll get a ~30% premium that day of every week, on top of the other bonuses/differentials.
- Overtime eligible, I suspect less overtime opportunities in general though
- 100% remote
After 401k + taxes, my take home is going up by like $1600/mo because of this movement.
1-3 years ago I thought I wouldn't break $100k base pay by 30, srs. Then inflation got crazy, rent's going up 20% this month, and I decided going up 3-5% per year from the company's typical annual bump is NOT acceptable. I got inspired to get out of the comfort zone and get into theDANGER ZONEafter watching Top Gun: Maverick.
Old Job:
- $85k base, paid hourly, 10% annual bonus, 10% extra for working evening hours
- 5x8 schedule, shift rotates every 2-3 months
- Worked a chit load of overtime, including every corporate holiday, cuz I wanted to get as close to $120k gross as possible
- 95% remote, went into office once a month
New Job:
- $110k base, paid hourly, 10% annual bonus, 10% extra for working evening hours
- 4x10 schedule, no shift rotations. Still working out which days though, if I can work Sundays then I'll get a ~30% premium that day of every week, on top of the other bonuses/differentials.
- Overtime eligible, I suspect less overtime opportunities in general though
- 100% remote
After 401k + taxes, my take home is going up by like $1600/mo because of this movement.
07-14-2022, 04:39 AM
-
#2
07-14-2022, 04:42 AM
-
#3
- SonOfAesthetics
- Registered User
-
- SonOfAesthetics
- Registered User
- Join Date: Dec 2011
- Location: United States
- Age: 33
- Posts: 1,255
- Rep Power: 2728
-
-
Negged
ASMR Crew
Arsenal Crew (repped on sight)
Not socially retarded crew
07-14-2022, 05:10 AM
-
#4
07-14-2022, 05:12 AM
-
#5
07-14-2022, 05:13 AM
-
#6
07-14-2022, 05:14 AM
-
#7
07-14-2022, 05:14 AM
-
#8
- hendrixfreak70
- My eyes are up here.
-
- hendrixfreak70
- My eyes are up here.
- Join Date: Feb 2016
- Location: United States
- Posts: 29,358
- Subscribers: 16
- Rep Power: 748157
-
-
I accept you.
07-14-2022, 05:17 AM
-
#9
- DesiredUserphag
- 1:12TilTheDayIFukinDie
-
- DesiredUserphag
- 1:12TilTheDayIFukinDie
- Join Date: Sep 2014
- Posts: 40,176
- Rep Power: 397140
-
-
Grats boyo! I somehow made it over 100k before I turned 30 without a degree. IT is where it's at if you have a brain and are good at troubleshooting SRS
๐ฃ๐จ๐ฅ๐๐๐๐ข๐ข๐
ฯฯัโโ ััฮฑฮฝัโัั ศผััฯ โ โ/โโโ
๐ฌ๐๐๐๐๐๐๐๐๐๐๐๐ ๐ฎ๐๐ ๐ธ๐๐๐๐๐ ๐ฝ๐๐๐ ยฎ
แชIแแแIแฐIแแฉTIOแ EแญแแชแแIOแ IแแชOแTแIแแฉTIOแ
07-14-2022, 05:47 AM
-
#10
- MyBaddBrah
- u wot m8
-
- MyBaddBrah
- u wot m8
- Join Date: Apr 2013
- Posts: 19,318
- Rep Power: 61930
-
-
How would you spot encoded malware on an endpoint?
*Hole is Life Crew*
*Meditation Crew*
07-14-2022, 06:28 AM
-
#11
Originally Posted By Bodhy⏩
My last paycheck, which had a tiny bit of overtime and was from "old job" as mentioned in OP, is $3722 gross and $2650 net. This includes 6% going into 401k. I live in USA, in a state that doesn't have any state income taxes.Just out of interest and comparison to my country's tax rates and comparable salaries, what is thegrossincome you receive weekly/monthly after tax?
Originally Posted By MyBaddBrah⏩
Haha I'll give you the interview answers. IDK how well I'd execute it in practice though.How would you spot encoded malware on an endpoint?
- View running processes. If there's a process I'm unsure of, that's in itself a potential indicator. Outside of that, malware typically masquerades as other expected processes, so check that nothing is running from a weird file path. Lastly on this topic, if there's heavy resource utilization corresponding to a weird process, that's a sign too. Then you'd check file hashes of anything that's weird against OSINT sources to make sure it's truly the process it's claiming to be. Note that you can also use powershell / wmic to get the commandline and parent files associated with a running process.
- Check scheduled tasks / chron jobs. Threat actors like to put malware executables set to either a trigger, timer, or something else like on startup, as a scheduled task in the OS. Easier to identify if you have logging of scheduled task modifications to spot anomalies, otherwise just check what the current scheduled tasks are if you're suspicious about a host.
- Registry modifications. This one can be underrated. All it takes is changing a single value in a register to do things such as, completely disable antivirus software, change the DNS server or proxy to be a threat actor's DNS/proxy, store credentials in memory, and many many more scary things.
- Command history. In linux you can check what's called the bash_history file to see previous bash commands. THIS is where you'd actually find the "encoded" commands associated with malware. I believe Mac also has the same "bash_history" file. Can't remember what Windows has. This is where you'd see attempts to do things like recon, download and install files, exfiltrate data, setup connectivity to external servers, etc. Threat actors tend to clear corresponding audit files so the command history isn't known. This in itself is its own huge warning sign if it was cleared, you should have alerts to detect when users delete their command history in general.
- Endpoint security software and alerting. This is the ultimate answer to your question. Just get good anti-malware, log everything, create alerts, have security devices such as IPS/IDS, firewalls, etc.
Bookmarks
-
- Digg
-
- del.icio.us
-

- StumbleUpon
-
-
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts