How much of pentesting is just repetition and experience?

** Disclaimer **
I am not a professional pentester either.

What I did do is spend a lot of time and money in graduate school studying this. I hope that I can say this without being disrespectful, but I found it to be of very little use.

I was 100% lost when I started HTB. But if you’re taking a break between Netflix shows, or put down the Call of Duty for a second, it’s a great thing to put some music on in the background and start some enumeration. Then you see something odd… which leads you to another something odd… then you get user. It’s also been about 4 hours and you didn’t even notice it.

It’s not so much memorizing things rather than discovering the techniques and procedures that work for you. Get your method. Assemble the tools you like. Rock it.

Give yourself permission to browse the forums for hints. Ask for help. No one knows everything, but in bunches, you start to get the idea. In most cases you’re closer than you think.

Pretty soon, people start asking you for help. You’ve gotten better and didn’t even realize it.