7 minJun 21, 2024

Synack Red Team Veteran Interview with TitoSantana00

What does it mean to be a part of the Synack Red Team (SRT) community, and why should cybersecurity/IT veterans consider joining? In this video, U.S. military veteran and Synack Red Team (SRT) member @TitoSantana00 discusses his prior service and journey to ethical hacking. Hear…

@TitoSantana00 SRT, Veteran, Synack Red Team

Overview

What does it mean to be a part of the Synack Red Team (SRT) community, and why should cybersecurity/IT veterans consider joining? In this video, U.S. military veteran and Synack Red Team (SRT) member @TitoSantana00 discusses his prior service and journey to ethical hacking. Hear him speak on what inspired him to pursue a career in IT, which targets are his favorite to test and how the SRT veteran community provides a sense of belonging. 

Full transcript

Read transcript

Hi. My name is John Pedaway. My hacker handle is Tito Santana zero zero. I am a veteran, and I am part of the SYNAPRA team. Served in the US Army for nine years, six years in active duty and three years in reserves. My last duty station was for Polk, Louisiana, And now I'm located in North Carolina.

West was an IT specialist. So that's pretty much a generalist of all things IT. So as an IT specialist, you'll serve in roles such as the help desk, you'll be a SIS admin, you'll be a network administrator. And then my final role before I got out, I was doing CommSec. I've always had a passion for anything computer related or IT, even cybersecurity. When I was younger and my mom, she bought us a Compaq computer, which I don't think Compaq's even around anymore.

But we got a compact computer and I was mainly the only person ever on that computer just from visiting forums such as After Dawn, which is kind of like similar to a Reddit style based forum. But I was always in the PSP hacking forum, which is typically where they learn about kernel exploits and they teach different things. And I even got into like, I downloaded LimeWire and of course a bunch of viruses on my computer. And then I was very fascinated like what viruses actually were. And just to find out it's just computer code.

So later on down the line, while I was in the military, was getting my undergrad degree in computer science, which led me to learning more about computer security and everything and programming. When I decided to pivot into cybersecurity, always heard of the company SYNNAC and the SYNNAC Red Team. I've always heard that it's like the pinnacle of what, like the hacker pinnacle of just security researchers. Like if you're on the Cenac Red team, you were good.

You good to go. So I definitely made it my mission to want to get on the Cenac Red team and become a member. When I initially applied, I took the assessment. I didn't make it. I feel pretty badly, but after that I took a year to just learn more, research different topics and just get better and hone my craft. So then a year later I applied again, I took the assessment and I passed. Testing on the web and APIs,

it's just so much more interesting to me. I'm starting to learn cloud myself on my spare time. But I mainly focus on the web targets only because I just have such a passion for websites and web applications. It's bad. It's to the point where I'll be just be browsing casually on a website and I'll see like a parameter in the URL. And I'm like, oh man, what can I do with this? But luckily for the SYNACK red team, I'm able to ethically hack on different targets and earn money doing what I love at the same time.

I felt like it was my place to be, to be a part of a team of elite hackers and people that are security researchers. And I felt like it's a great place where a person like me as a veteran also to hone my skills. And then also found out that there's a veteran community within SYNNAC on SYNNAC Red Team. And I thought it's just home for me, just talking and communicating with other veterans. We bounce ideas off each other. There's playful banter between the different branches and everything.

It's just a great place to be if you're a veteran and also you enjoy The SYNNAC Red Team is a community, but the veterans within SYNNAC is like a community within a community. I think a lot of the US based researchers are all veterans. And like I say, it's just like you can bond already just from your experience of being in the military. But I feel like with the veterans, can bond even more the fact that you're hacking, you're a veteran.

And it just feels like you feel like a sense of which word I'm looking for? Like bonding with other veterans. It's great. Something you definitely have to experience to believe it. It's awesome. I've met some really skilled, cool people just from being the snack on the red team and their veterans channels. My most recent engagement where I was hacking on this government site and there was a bunch of highly sensitive

documentation that was leaked on the site that definitely should not be out in the public at all. So I disclosed it to SYNNAC. I was paid for it. And then it was just really interesting to see different There's a different technology that different government agencies work on and what they have and it was a lot of fun. But you can see some pretty interesting things for sure. I would suggest to find out what you want to do

within cybersecurity. Cybersecurity is such a vast and very broad field. And just find out what you want to do, whether it be the red team, blue team, whether you want to do incident response, GRC, just different things. You're gonna excel in whatever your passion is. So if you want to do the red team, there are sites like TryHackMe, there's Portswigger, there's Hack the Box, Pentester Lab. There's a bunch of different sites that you can subscribe to and learn Red Team.

But also, shameless plug, I'm part of a nonprofit organization called Blackstone Cybersecurity based out in the DC metro area. And within Blacks in Cybersecurity, I'm part of the veterans community, where it's a community of veterans who essentially just help each other out, whether it be navigating the healthcare system, resume writing, just filing claims, cybersecurity training. We also give out exam vouchers for different certifications

where our members can take free exams and get certified. We just wanna help each other out as veterans and try to help other veterans get further. If you're a veteran, if you're a hacker, definitely join the SYNACK Red Team. It's an awesome group, it's an awesome community. You're gonna enjoy it. It's definitely an experience and you're gonna meet a lot of cool people, a lot of very smart people. And I think a person would be very happy there.

Speakers

@TitoSantana00

Synack Red Team

SRT, Veteran

Next step

Run the test instead of evaluating the idea.

Define a scope, run a Sara AI pentest against it, and see which findings are confirmed as real and exploitable. Then compare that with what your current testing returns.