1 What is PNPT?
PNPT by TCM Security is a practical, affordable alternative to OSCP. Created by Heath Adams (TheCyberMentor), it focuses on real-world penetration testing skills with an emphasis on Active Directory attacks.
What makes PNPT unique is the live debrief-you present your findings to a panel just like a real client engagement. This simulates actual pentest work better than any other certification.
2025 Update: PNPT now costs $499 (includes all courses, exam, free retakes, and debrief). Military and veteran discounts of 20% are available. The certification never expires-no renewal fees or recertification required.
The Good
- ✓ Incredibly affordable ($499)
- ✓ Real-world methodology focus
- ✓ Unique live debrief experience
- ✓ Heavy Active Directory focus
- ✓ Excellent community support
- ✓ Free retakes included
The Tough
- ✗ Less recognized than OSCP
- ✗ Newer certification
- ✗ Limited to network pentesting
- ✗ Debrief can be nerve-wracking
💡 Bottom Line: Best bang for your buck. The debrief experience is invaluable for real pentesting jobs.
Real Exam Experiences (2025-2026)
What's it actually like to take the PNPT? Here's what recent test-takers experienced.
Anonymous Reviewer
InfoSec Writeups, 2026
"I failed because I wasn't ready. I knew the attacks, I knew how to hack Active Directory, but I didn't have a good methodology on how to perform a penetration test."
Key Lesson:
Knowing attacks ≠ knowing methodology. The exam tests your process, not just your hacking skills.
Pr0tag0nist
Medium, 2025
"You only need the course material to pass (no fancy exploits) and 'keep it simple.' That sounded too good to be true, but after passing, I can confirm it's true."
Timeline:
Day 1-2: No progress. Day 3: Breakthrough. Day 4: Compromised DC. Days 5-7: Report.
VulnKraft
Medium, 2025
"The exam itself isn't 'technically' difficult, but it can get VERY frustrating. Getting stuck multiple times really tests patience."
Reality Check:
Expect to hit walls. Step away, rest, come back with fresh eyes. You have 5 days for a reason.
0xHanzala
Personal Blog, 2025
"You don't need to be a pentesting guru to pass. I hadn't done a pentest before, but I passed the exam by truly understanding the course content."
Encouragement:
The exam is designed to validate learning, not gatekeep. If you put in the work, you can pass.
Typical Exam Timeline (from real experiences)
Day 1
Enumeration, getting bearings, maybe initial foothold
Day 2
Frustration peaks, pivoting, finding paths
Day 3
Breakthrough usually happens here
Day 4
Domain compromise, finish exploitation
Day 5
Buffer day or start report
Day 6
Report writing
Day 7
Polish & submit
2 Exam Structure
Penetration Test (5 days)
Compromise an Active Directory network from external to domain admin. Full scope pentest simulation.
Report Writing (2 days)
Write a professional penetration test report with findings, risk ratings, and recommendations.
Live Debrief (15 min)
Present your findings to a panel-just like a real client meeting! This is what sets PNPT apart.
🎯 Key Skills Tested:
- • OSINT & External Recon
- • Active Directory Attacks
- • Privilege Escalation (Win/Linux)
- • Post-Exploitation & Pivoting
- • Lateral Movement
- • Professional Report Writing
3 Required Courses
The PNPT requires completing these TCM Security courses (included with exam purchase):
Practical Ethical Hacking
The core course - 25+ hours of content
ESSENTIALLinux Privilege Escalation
Comprehensive Linux privesc techniques
Windows Privilege Escalation
All Windows privesc vectors
Open-Source Intelligence (OSINT)
OSINT fundamentals for recon
External Pentest Playbook
External network testing methodology-critical for the exam
Practice Labs & Machines
⚠️ Important Note from PNPT Passers
"Extra practice machines weren't helpful during my exam-I wasted time trying techniques from HTB that were outside the PNPT course scope. If you truly understand the 5 courses, you're ready." - Multiple reviewers confirm: the course material is sufficient. Practice labs are for building confidence, not learning new techniques.
TryHackMe
Best for guided learning
Multi-network pivoting, AD basics
Full AD network, multiple domains
Enterprise AD environment
Full engagement simulation
~$10/month for premium access
HackTheBox
More challenging, less guided
AS-REP roasting, BloodHound intro
User enum, DCSync attack
GPP passwords, Kerberoasting
Azure AD Connect exploitation
Kerbrute, PFX certs, AV evasion
~$25/month for VIP+ access
Build Your Own Lab
Best learning experience
The PEH course includes a section on building your own AD lab. This skill is invaluable for:
- Testing tools safely before the exam
- Practicing attacks repeatedly until muscle memory
- Understanding AD from defender's perspective
- Future pentesting career skill
Minimum Requirements:
- • 16GB RAM (32GB recommended)
- • Windows Server 2019 eval ISO
- • Windows 10/11 Enterprise eval
- • VMware or VirtualBox
Cost: FREE (eval licenses)
🎯 Key AD Skills to Practice (from the courses)
Enumeration
- • BloodHound pathfinding
- • LDAP queries
- • SMB enumeration
- • User/Group recon
Initial Access
- • Password spraying
- • AS-REP roasting
- • LLMNR/NBT-NS poisoning
- • SMB relay attacks
Lateral Movement
- • Pass-the-hash
- • Kerberoasting
- • Token impersonation
- • WinRM/PSExec
Domain Takeover
- • DCSync attack
- • Golden ticket
- • Pass-the-ticket
- • Delegation abuse
4 Cheatsheets & Study Resources
CyberCert Reviews Cheatsheets
Free, comprehensive cheatsheets for PNPT preparation.
PNPT Essentials
External Study Resources
TheCyberMentor YouTube
Heath Adams' free content covers many PNPT topics. Great supplement to the courses.
FREEHack The Box (HTB)
Practice AD attacks on Dante, Offshore, and other Pro Labs. Great for building muscle memory.
VIP Sub RecommendedTryHackMe AD Paths
Holo, Throwback, and Wreath rooms provide guided AD attack practice.
FREE/PremiumReport Writing Practice
Practice writing reports for every box you do. Use TCM's template to build the habit.
CRITICALReport Writing Guide
The report is 50% of your PNPT success. A technically perfect pentest means nothing if you can't communicate findings professionally.
Required Report Sections
Executive Summary
1-2 pages max. Non-technical overview for leadership. Risk posture, critical findings, business impact.
Technical Findings
Each finding: title, severity (CVSS), description, proof-of-concept, impact, remediation.
Attack Narrative
Step-by-step walkthrough from external foothold to domain admin. Tell the story.
Recommendations
Specific, actionable remediations. Not "patch your systems" but exact fixes.
Pro Tips from Passers
Draft your template BEFORE the exam
Have all sections ready. Just fill in findings during the exam.
Screenshot EVERYTHING
Every command, every output. You'll thank yourself during report writing.
Don't rush the report
You have 2 days. Use them. A polished report > a hasty one.
Read real pentest reports
Study public reports to understand professional formatting.
Debrief Preparation
The 15-minute live debrief is what makes PNPT unique. It simulates a real client meeting and tests your communication skills.
What Happens During the Debrief
Setup (1-2 min)
Join the video call. TCM staff acts as "the client's security team." They've read your report.
Your Presentation (5-8 min)
Walk through your attack chain. Explain what you found, how you exploited it, and why it matters to the business.
Q&A (5-7 min)
They ask about your methodology, why certain approaches, remediation priorities. Think like a consultant.
Debrief Survival Tips
- ✓ Know your report inside out
- ✓ Practice explaining technical concepts simply
- ✓ Prepare a 5-min attack summary
- ✓ Anticipate "why" questions
- ✓ Dress professionally (yes, really)
- ✓ Have your report open for reference
- ✗ Don't read from a script
- ✗ Don't panic if you don't know an answer
Common Debrief Questions (Be Ready For These)
"Walk us through your attack path"
Have a clear narrative: external recon → initial access → privilege escalation → lateral movement → domain compromise.
"What's the most critical finding?"
Know your severity rankings and be able to justify them from a business risk perspective.
"Why did you choose X approach?"
Explain your methodology. They want to see you think like a professional pentester.
"How should we prioritize fixes?"
Quick wins vs. long-term fixes. Consider effort, impact, and business constraints.
Common Mistakes to Avoid
Over-Preparing
Doing tons of HTB/THM boxes outside course scope. Multiple reviewers confirm: the course material is enough. Extra practice can actually confuse you with techniques not relevant to the exam.
Poor Note-Taking
Not documenting what you tried during the exam. You'll waste time repeating failed attempts. Use Obsidian, CherryTree, or similar to track every command and result.
Skipping OSINT/External
Jumping straight to internal pentesting. The exam simulates a real engagement-you start external. Don't skip the External Pentest Playbook course.
Ignoring Report Writing
Waiting until after the pentest phase to think about your report. Draft your template before the exam. Know exactly what sections you need.
Tool Tunnel Vision
If a tool isn't working, try another that does the same thing. Don't spend hours debugging when you could use an alternative. Have backups ready.
No Debrief Prep
Assuming you can wing the debrief. Practice explaining your attack chain out loud. Record yourself. It's 15 minutes that can make or break your certification.
✓ What Successful Candidates Do Instead
- ✓ Complete all 5 courses thoroughly
- ✓ Take detailed notes with screenshots
- ✓ Build their own AD lab and practice
- ✓ Prepare report template before exam
- ✓ Snapshot their attack VM before starting
- ✓ Take breaks when stuck (you have 5 days)
- ✓ Practice verbal explanations for debrief
- ✓ Trust the methodology from the courses
5 PNPT vs Other Certs
| Aspect | PNPT | OSCP | CPTS |
|---|---|---|---|
| Cost | $499 | $2,749/yr | $490+ |
| Exam Time | 5 days | 24 hours | 10 days |
| Retakes | Free | Included | $200 |
| Debrief | Yes (Live) | No | No |
| Recognition | Growing | Gold Standard | Growing |
| Best For | Budget-conscious | Career advancement | HTB enthusiasts |
6 FAQ
Is PNPT accepted by employers?
Yes, and growing. More employers recognize PNPT each year, especially for junior/mid-level roles. The live debrief proves real consulting skills. For HR-gated positions at large companies, OSCP may still be required.
What's the debrief actually like?
A 15-minute video call where you present your findings to TCM staff acting as clients. They ask questions about your methodology and findings. It's nerve-wracking but excellent practice for real pentest debriefs.
Should I get PNPT or OSCP?
If budget is a concern, start with PNPT. The skills transfer well, and you can add OSCP later. If you need the certification for a specific job requirement or want maximum career impact, go straight for OSCP.
How long to prepare for PNPT?
Complete beginners: 3-4 months working through the courses. With some background: 1-2 months. The courses are comprehensive-focus on understanding the methodology, not just memorizing commands.
Community Resources & Links
Comprehensive review and advice for the PNPT certification
Cheatsheet and preparation guide for the examination
Notes in preparation for the PNPT Certification Exam
Detailed study notes and comprehensive review
📝 Recent Exam Reviews (2025-2026)
Join the TCM Security Discord
The official TCM Security Discord is the best place to ask questions, find study partners, and get real-time help from the community.
Join Discord