依加講緊入行前,唔係講緊入行後
的確總有一日都要學埋red同blue,我依加都係學緊少少blue
但問題係,學幾深?學幾淺?
相當於SOC都要識睇red少少既野(唔係點睇alert?)
即使係red都要識諗firewall既structure,同埋SPF係咩(唔係點做red teaming?phishing assessment?)
即使係做IR都要識少少RE,都要識dump memory,識睇少量hex/assembly/deobfuscation,識playbook(唔係點keep record做forensics?)
即使係blue都要識平常既MITM既手法,都要諗少少wireless coverage既問題(唔係點做prevention?點防止樓下有人攪你wireless..唔通真係靠.1x打世界?)
但問題係,red同blue兩者差距咁大同埋一樣咁深,邊可能有人識哂?
如果有人話佢識哂,我反而會懷疑佢到底係唔係真係知道blue同red係可以去到幾deep...
更重要既係,連方向都未決定到既時候,格硬話要學兩樣,咁就更加只會兩頭唔到岸啦,係咪先?

btw,師兄係唔係做big 4呢?
