Compare cert salaries and plan your next career move
My main criticisms are:- no memory forensics. The EDR addition should have opened up this option, but they're probably saving it for a dedicated course- no AD. In the most advanced incident response course of the world, you're looking at standalone hosts. I did not expect this. There are sections going over event logs and the like, but this is where the labs needed to shine! Go over lateral movement in the enterprise, compromised DCs, attacks against Exchange, AD recon, all these practical bits that are relevant to a modern enterprise environment are missing from the labs.@SleepyLCTL - How did you find the PTX content? In retrospect, and after reading other reviews, that one or the Threat Hunting course might have been a better choice for me.
ConstantSage said: I have done the PTS course and enjoyed it but I am more interested in blue team. After reading through this thread it seems like most people have come away slightly unimpressed with the courses eLearnSecurity is putting out. That being said, could someone recommend a decent alternative? I'm mainly looking for a lab environment with some instruction mixed in. A home lab is not an option for me right now due to space limitations primarily.
Skyyyyy2001 said: SleepyLCTL said: SexyLemur said: @SleepyLCTL wait they credited you for a different course? I was going to ask to get credit to take the ecppt instead. I asked for refund, did not get that, however he offered me with an alternative to choose something else. I chose ecpx as I already have ecppt. I find it fair. I have done the same as well and ask for a refund or change to another course and I'm a very unhappy customer at this point in time. I hope Armando is looking at this thread.
SleepyLCTL said: SexyLemur said: @SleepyLCTL wait they credited you for a different course? I was going to ask to get credit to take the ecppt instead. I asked for refund, did not get that, however he offered me with an alternative to choose something else. I chose ecpx as I already have ecppt. I find it fair.
SexyLemur said: @SleepyLCTL wait they credited you for a different course? I was going to ask to get credit to take the ecppt instead.
jeremy_dfir said: Just got my eCIR cert. What a crazy exam that was!!! For anyone taking the course, make sure you read literally everything. You will have to combine everything to figure out the attack path. If I find some time I will post a detailed review...
dirtscout said: As I get deeper into the course it seems a lot better than my first impressions. My original post was probably a bit of sticker shock built in there. I think eLearn shines with the labs, DFIR and IHRP. They really do help reinforce the material. So far so good. Luckily I am now a Threat Intelligence Group Analyst with a great company that's all about training "apprentices". Have a great mentor and team to grow with. They love eLearn, so I am lucky to be able to expense the cost (if I pass)
dirtscout said: I am about a quarter of the way through, my days have been a lot more busy. Make sure you have the slides/material open as you work through the labs, it really has helped me out. My goal is to get the exam in by the end of May, but that might not happen if my schedule doesn't slow down.
chrisone said: Small bump, I will be taking the eCIR exam on the following weekend May 16-17. In all honesty the material is pretty good, I have been enjoying it. There is a lot to learn here, I am 3/4's done with the content. That is all I will say for now, since I am not entirely done with the content and do not want to comment prematurely on the overall experience. I will have a full review that week depending if I get my results that same week, I would like to also share a spoiler free testing experience, along with the results (pass or fail). Sigh .... I still owe you guys a VHL and OSCP review lol
chrisone said: Thanks @TimBaker I did notice topics coming from other courses but that is 100% needed and proves this course is on a deeper level. I was glad they went into red team techniques and describe a lot of the windows AD red team TTPs focus on. Thank you for the link, the review was spot on and I agree 100% with the author.I am done with the content slides and wrapping up the Splunk and ELK labs today. With that said I will start building my **** sheets of queries\syntax, methodologies, pcap analysis\wireshark filters, windows event IDs, etc. I will also be practicing and doing the labs over and over again for the next 8 days until I start the exam. The course is good, even if you are a tier 2-3 analyst\incident responder\security engineer. The course is amazing if you are just getting into cyber security analyst positions. If you were to cover the same topics using SANS courses, it would cost you a fortune as you would need to take the followingSEC450: Blue Team Fundamentals: Security Operations and AnalysisSEC455: SIEM Design & ImplementationSEC503: Intrusion Detection In-DepthSEC504: Hacker Tools, Techniques, Exploits, and Incident HandlingFrom a generalized high level view, Yes the IHRP course covers mostly what these courses cover. I hear people complain about death by slides....but isnt that technically what SANS courses mostly are? Physical books of slides? Yes they have VMs and labs, but so does elearn and to balance this stand off, the SANS tests are multiple choice questions as opposed to a live active hands on test that elearnsecurity tests you on, plus a report. Sorry for the quick rant and I get it these are trigger\fighting words for some hahaha
u1tras said: Just checked out last year's discounts from eLS. There was about 40% off for the new launched THP course and $200 gift card for other courses. Hope they'll repeat it again:)
Compare salaries for top cybersecurity certifications. Free download for TechExams community.