PNPT
PRACTICAL
Intermediate Penetration Testing Best Value

PNPT

Practical Network Penetration Tester

Cost

$499

Exam

5 Days

Difficulty

Medium

Format

Report+Debrief

Quick Info

Vendor: TCM Security
Creator: Heath Adams
Format: 100% Practical
Debrief: Live (15 min)
Retakes: Free
Focus: Active Directory
Report: Required
Training: 80+ hours
Last Updated: July 27, 2026

Look, We Get It

You want the OSCP on your resume. Everyone knows it. It's the gold standard. But it's also $2,749/year, and if you're just starting out-or trying to break into pentesting without draining your bank account-OSCP might not be realistic right now.

That's where PNPT comes in. For $499, you get everything OSCP teaches about practical network penetration testing, plus a unique live debrief that actually simulates real client work. No gimmicks. No vendor lock-in. And you know what? More employers are starting to recognize it.

If you've done eJPT and want to level up without selling a kidney, PNPT is your move. If you're eyeing OSCP eventually, think of PNPT as the best warm-up you can get. Let's break down what makes it worth your time (and money).

What is PNPT Certification?

The Practical Network Penetration Tester (PNPT) is an intermediate-level certification created by TCM Security that tests your ability to perform real-world penetration testing from external reconnaissance to Active Directory domain compromise.

Cost

$499

Exam Time

5 Days

Difficulty

Intermediate

What makes it unique: Unlike most certs, PNPT requires a live 15-minute debrief where you present your findings to a panel-just like a real pentest engagement. This simulation of actual client work is what makes PNPT stand out.

1 What is PNPT?

PNPT by TCM Security is a practical, affordable alternative to OSCP . Created by Heath Adams (TheCyberMentor), it focuses on real-world penetration testing skills with an emphasis on Active Directory attacks.

What makes PNPT unique is the live debrief -you present your findings to a panel just like a real client engagement. This simulates actual pentest work better than any other certification.

2025 Update: PNPT now costs $499 (includes all courses, exam, free retakes, and debrief). Military and veteran discounts of 20% are available. The certification never expires -no renewal fees or recertification required.

The Good

  • Incredibly affordable ($499)
  • Real-world methodology focus
  • Unique live debrief experience
  • Heavy Active Directory focus
  • Excellent community support
  • Free retakes included

The Tough

  • Less recognized than OSCP
  • Newer certification
  • Limited to network pentesting
  • Debrief can be nerve-wracking

💡 Bottom Line: Best bang for your buck. The debrief experience is invaluable for real pentesting jobs.

PRO TIP

Don't Overcomplicate It

The biggest mistake PNPT takers make? Trying to use advanced techniques they learned from Active Directory exploitation guides or HTB boxes. The exam is designed to test methodology, not ninja-level hacking. Stick to the course material. If you're reaching for Kerberoasting with delegation abuse or NTLM relay chains, you're overthinking it. Simple enumeration > fancy exploits.

Real Exam Experiences (2025-2026)

What's it actually like to take the PNPT? Here's what recent test-takers experienced.

PASSED - 2nd Attempt

Anonymous Reviewer

InfoSec Writeups, 2026

"I failed because I wasn't ready. I knew the attacks, I knew how to hack Active Directory, but I didn't have a good methodology on how to perform a penetration test."

Key Lesson:

Knowing attacks ≠ knowing methodology. The exam tests your process, not just your hacking skills.

PASSED - 1st Attempt

Pr0tag0nist

Medium, 2025

"You only need the course material to pass (no fancy exploits) and 'keep it simple.' That sounded too good to be true, but after passing, I can confirm it's true."

Timeline:

Day 1-2: No progress. Day 3: Breakthrough. Day 4: Compromised DC. Days 5-7: Report.

THE FRUSTRATION

VulnKraft

Medium, 2025

"The exam itself isn't 'technically' difficult, but it can get VERY frustrating. Getting stuck multiple times really tests patience."

Reality Check:

Expect to hit walls. Step away, rest, come back with fresh eyes. You have 5 days for a reason.

BEGINNER SUCCESS

0xHanzala

Personal Blog, 2025

"You don't need to be a pentesting guru to pass. I hadn't done a pentest before, but I passed the exam by truly understanding the course content."

Encouragement:

The exam is designed to validate learning, not gatekeep. If you put in the work, you can pass.

Typical Exam Timeline (from real experiences)

Day 1

Enumeration, getting bearings, maybe initial foothold

Day 2

Frustration peaks, pivoting, finding paths

Day 3

Breakthrough usually happens here

Day 4

Domain compromise, finish exploitation

Day 5

Buffer day or start report

Day 6

Report writing

Day 7

Polish & submit

2 Exam Structure

1

Penetration Test (5 days)

Compromise an Active Directory network from external to domain admin. Full scope pentest simulation.

2

Report Writing (2 days)

Write a professional penetration test report with findings, risk ratings, and recommendations.

3

Live Debrief (15 min)

Present your findings to a panel-just like a real client meeting! This is what sets PNPT apart.

🎯 Key Skills Tested:

  • • OSINT & External Recon
  • • Active Directory Attacks
  • • Privilege Escalation (Win/Linux)
  • • Post-Exploitation & Pivoting
  • • Lateral Movement
  • • Professional Report Writing
WARNING

The Debrief Will Stress You Out

Let's be real: the live debrief is nerve-wracking. You'll present your findings to actual humans over Zoom, and they'll ask questions. If public speaking isn't your thing, this will push you outside your comfort zone. But here's the thing-this is exactly what you'll do in real pentesting. Client debriefs are standard. Practice explaining your exploits to non-technical friends. Record yourself. Get comfortable with the awkwardness now, because employers want pentesters who can communicate, not just hack.

3 Required Courses

The PNPT requires completing these TCM Security courses (included with exam purchase):

Practical Ethical Hacking

The core course - 25+ hours of content

ESSENTIAL

Linux Privilege Escalation

Comprehensive Linux privesc techniques

Windows Privilege Escalation

All Windows privesc vectors

Open-Source Intelligence (OSINT)

OSINT fundamentals for recon

External Pentest Playbook

External network testing methodology-critical for the exam

Practice Labs & Machines

⚠️ Important Note from PNPT Passers

"Extra practice machines weren't helpful during my exam-I wasted time trying techniques from HTB that were outside the PNPT course scope. If you truly understand the 5 courses, you're ready." - Multiple reviewers confirm: the course material is sufficient . Practice labs are for building confidence, not learning new techniques.

THM

TryHackMe

Best for guided learning

Wreath FREE

Multi-network pivoting, AD basics

Pivoting AD
Throwback VIP

Full AD network, multiple domains

AD Multi-Domain
Holo VIP

Enterprise AD environment

Enterprise AD
Red Team Capstone VIP

Full engagement simulation

Capstone

~$10/month for premium access

HTB

HackTheBox

More challenging, less guided

Forest Easy

AS-REP roasting, BloodHound intro

Kerberos AD
Sauna Easy

User enum, DCSync attack

DCSync AD
Active Medium

GPP passwords, Kerberoasting

GPP Kerberoast
Monteverde Medium

Azure AD Connect exploitation

Azure AD
Search Hard

Kerbrute, PFX certs, AV evasion

Certs Advanced

~$25/month for VIP+ access

Build Your Own Lab

Best learning experience

The PEH course includes a section on building your own AD lab. This skill is invaluable for:

  • Testing tools safely before the exam
  • Practicing attacks repeatedly until muscle memory
  • Understanding AD from defender's perspective
  • Future pentesting career skill

Minimum Requirements:

  • • 16GB RAM (32GB recommended)
  • • Windows Server 2019 eval ISO
  • • Windows 10/11 Enterprise eval
  • • VMware or VirtualBox

Cost: FREE (eval licenses)

🎯 Key AD Skills to Practice (from the courses)

Enumeration

  • • BloodHound pathfinding
  • • LDAP queries
  • • SMB enumeration
  • • User/Group recon

Initial Access

  • • Password spraying
  • • AS-REP roasting
  • • LLMNR/NBT-NS poisoning
  • • SMB relay attacks

Lateral Movement

  • • Pass-the-hash
  • • Kerberoasting
  • • Token impersonation
  • • WinRM/PSExec

Domain Takeover

  • • DCSync attack
  • • Golden ticket
  • • Pass-the-ticket
  • • Delegation abuse

4 Cheatsheets & Study Resources

CyberCert Reviews Cheatsheets

Free, comprehensive cheatsheets for PNPT preparation.

External Study Resources

TheCyberMentor YouTube

Heath Adams' free content covers many PNPT topics. Great supplement to the courses.

FREE

Hack The Box (HTB)

Practice AD attacks on Dante, Offshore, and other Pro Labs. Great for building muscle memory.

VIP Sub Recommended

TryHackMe AD Paths

Holo, Throwback, and Wreath rooms provide guided AD attack practice.

FREE/Premium

Report Writing Practice

Practice writing reports for every box you do. Use TCM's template to build the habit.

CRITICAL
REAL TALK

PNPT Won't Replace OSCP (Yet)

Let's not sugarcoat it: OSCP is still the industry standard. Most job postings that list certifications will mention OSCP first. PNPT is gaining traction, especially among smaller firms and teams that value practical skills over brand names, but it's not universally recognized yet.

Think of PNPT as your proof of competence while you build up to OSCP. It's also a fantastic cert if you're already working in security and want to validate your pentesting skills without the OSCP price tag. Just manage your expectations-this isn't a golden ticket, but it's a damn good stepping stone.

Report Writing Guide

The report is 50% of your PNPT success. A technically perfect pentest means nothing if you can't communicate findings professionally.

Required Report Sections

1

Executive Summary

1-2 pages max. Non-technical overview for leadership. Risk posture, critical findings, business impact.

2

Technical Findings

Each finding: title, severity (CVSS), description, proof-of-concept, impact, remediation.

3

Attack Narrative

Step-by-step walkthrough from external foothold to domain admin. Tell the story.

4

Recommendations

Specific, actionable remediations. Not "patch your systems" but exact fixes.

Pro Tips from Passers

Draft your template BEFORE the exam

Have all sections ready. Just fill in findings during the exam.

Screenshot EVERYTHING

Every command, every output. You'll thank yourself during report writing.

Don't rush the report

You have 2 days. Use them. A polished report > a hasty one.

Read real pentest reports

Study public reports to understand professional formatting.

Debrief Preparation

The 15-minute live debrief is what makes PNPT unique. It simulates a real client meeting and tests your communication skills.

What Happens During the Debrief

1

Setup (1-2 min)

Join the video call. TCM staff acts as "the client's security team." They've read your report.

2

Your Presentation (5-8 min)

Walk through your attack chain. Explain what you found, how you exploited it, and why it matters to the business.

3

Q&A (5-7 min)

They ask about your methodology, why certain approaches, remediation priorities. Think like a consultant.

Debrief Survival Tips

  • Know your report inside out
  • Practice explaining technical concepts simply
  • Prepare a 5-min attack summary
  • Anticipate "why" questions
  • Dress professionally (yes, really)
  • Have your report open for reference
  • Don't read from a script
  • Don't panic if you don't know an answer

Common Debrief Questions (Be Ready For These)

"Walk us through your attack path"

Have a clear narrative: external recon → initial access → privilege escalation → lateral movement → domain compromise.

"What's the most critical finding?"

Know your severity rankings and be able to justify them from a business risk perspective.

"Why did you choose X approach?"

Explain your methodology. They want to see you think like a professional pentester.

"How should we prioritize fixes?"

Quick wins vs. long-term fixes. Consider effort, impact, and business constraints.

Common Mistakes to Avoid

Over-Preparing

Doing tons of HTB/THM boxes outside course scope. Multiple reviewers confirm: the course material is enough. Extra practice can actually confuse you with techniques not relevant to the exam.

Poor Note-Taking

Not documenting what you tried during the exam. You'll waste time repeating failed attempts. Use Obsidian, CherryTree, or similar to track every command and result.

Skipping OSINT/External

Jumping straight to internal pentesting. The exam simulates a real engagement-you start external. Don't skip the External Pentest Playbook course.

Ignoring Report Writing

Waiting until after the pentest phase to think about your report. Draft your template before the exam. Know exactly what sections you need.

Tool Tunnel Vision

If a tool isn't working, try another that does the same thing. Don't spend hours debugging when you could use an alternative. Have backups ready.

No Debrief Prep

Assuming you can wing the debrief. Practice explaining your attack chain out loud. Record yourself. It's 15 minutes that can make or break your certification.

✓ What Successful Candidates Do Instead

  • Complete all 5 courses thoroughly
  • Take detailed notes with screenshots
  • Build their own AD lab and practice
  • Prepare report template before exam
  • Snapshot their attack VM before starting
  • Take breaks when stuck (you have 5 days)
  • Practice verbal explanations for debrief
  • Trust the methodology from the courses

5 PNPT vs Other Certs

Aspect PNPT OSCP CPTS
Cost $499 $2,749/yr $490+
Exam Time 5 days 24 hours 10 days
Retakes Free Included $200
Debrief Yes (Live) No No
Recognition Growing Gold Standard Growing
Best For Budget-conscious Career advancement HTB enthusiasts

6 FAQ

Is PNPT accepted by employers?

Yes, and growing. More employers recognize PNPT each year, especially for junior/mid-level roles. The live debrief proves real consulting skills. For HR-gated positions at large companies, OSCP may still be required.

What's the debrief actually like?

A 15-minute video call where you present your findings to TCM staff acting as clients. They ask questions about your methodology and findings. It's nerve-wracking but excellent practice for real pentest debriefs.

Should I get PNPT or OSCP?

If budget is a concern, start with PNPT. The skills transfer well, and you can add OSCP later. If you need the certification for a specific job requirement or want maximum career impact, go straight for OSCP.

How long to prepare for PNPT?

Complete beginners: 3-4 months working through the courses. With some background: 1-2 months. The courses are comprehensive-focus on understanding the methodology, not just memorizing commands.

Do I need experience before taking PNPT?

Basic IT knowledge helps, but no prior pentesting experience is required. The included courses teach everything from scratch. If you've done eJPT or have networking fundamentals down, you're already ahead.

Community Resources & Links

Join the TCM Security Discord

The official TCM Security Discord is the best place to ask questions, find study partners, and get real-time help from the community.

Join Discord