-3 karma · joined April 27, 2025
There's not going to really be a great "bootcamp", but if you wanted some credentials you could grab a SANS cert if your company is willing to fund it, or HTB has two levels of AppSec certs too. The makers of the OSCP also have the OSWE, but these are all very offsec focused training for pentesters.
In terms of more defensive certs, I think Amazon has some that involve DevSecOps, same with Azure and GitHub, so those might be good things to snag along the way.
Different devices also enable this, as mentioned in the comments. Smarthome / IoT devices, cable-brand router/APs, etc. There are also services for rotating residential proxies, that are essentially breaking the ToS of the companies in charge of them, but they trade/buy new IPs constantly.
The larger scale a site is indexed at, the more you'll see this traffic pick up. CloudFlare has rules that can help with it, and you can get stricter with them if you know your audience / customer base via whitelists; geo (can be circumvented ofc, but quiets the noise), user-agent, http version, etc. For the more broad ones, just immediately prompt a challenge if you don't want to outright drop/block them.
It's been this way for a while, LLMs have made it worse, but there was already a ton of garbage requests / scanning going on.
Next big sale is going to be something like "Chrome Fork + AI + integrated inter-app MCP". Brave is eh, Arc is being left to die on its own, and Firefox is... doing nothing.