PNPT
PRACTICAL
Intermediate Penetration Testing Best Value

PNPT

Practical Network Penetration Tester

Cost

$499

Exam

5 Days

Difficulty

Medium

Format

Report+Debrief

Quick Info

Vendor: TCM Security
Creator: Heath Adams
Format: 100% Practical
Debrief: Live (15 min)
Retakes: Free
Focus: Active Directory
Report: Required
Training: 80+ hours

1 What is PNPT?

PNPT by TCM Security is a practical, affordable alternative to OSCP. Created by Heath Adams (TheCyberMentor), it focuses on real-world penetration testing skills with an emphasis on Active Directory attacks.

What makes PNPT unique is the live debrief-you present your findings to a panel just like a real client engagement. This simulates actual pentest work better than any other certification.

2025 Update: PNPT now costs $499 (includes all courses, exam, free retakes, and debrief). Military and veteran discounts of 20% are available. The certification never expires-no renewal fees or recertification required.

The Good

  • Incredibly affordable ($499)
  • Real-world methodology focus
  • Unique live debrief experience
  • Heavy Active Directory focus
  • Excellent community support
  • Free retakes included

The Tough

  • Less recognized than OSCP
  • Newer certification
  • Limited to network pentesting
  • Debrief can be nerve-wracking

💡 Bottom Line: Best bang for your buck. The debrief experience is invaluable for real pentesting jobs.

Real Exam Experiences (2025-2026)

What's it actually like to take the PNPT? Here's what recent test-takers experienced.

PASSED - 2nd Attempt

Anonymous Reviewer

InfoSec Writeups, 2026

"I failed because I wasn't ready. I knew the attacks, I knew how to hack Active Directory, but I didn't have a good methodology on how to perform a penetration test."

Key Lesson:

Knowing attacks ≠ knowing methodology. The exam tests your process, not just your hacking skills.

PASSED - 1st Attempt

Pr0tag0nist

Medium, 2025

"You only need the course material to pass (no fancy exploits) and 'keep it simple.' That sounded too good to be true, but after passing, I can confirm it's true."

Timeline:

Day 1-2: No progress. Day 3: Breakthrough. Day 4: Compromised DC. Days 5-7: Report.

THE FRUSTRATION

VulnKraft

Medium, 2025

"The exam itself isn't 'technically' difficult, but it can get VERY frustrating. Getting stuck multiple times really tests patience."

Reality Check:

Expect to hit walls. Step away, rest, come back with fresh eyes. You have 5 days for a reason.

BEGINNER SUCCESS

0xHanzala

Personal Blog, 2025

"You don't need to be a pentesting guru to pass. I hadn't done a pentest before, but I passed the exam by truly understanding the course content."

Encouragement:

The exam is designed to validate learning, not gatekeep. If you put in the work, you can pass.

Typical Exam Timeline (from real experiences)

Day 1

Enumeration, getting bearings, maybe initial foothold

Day 2

Frustration peaks, pivoting, finding paths

Day 3

Breakthrough usually happens here

Day 4

Domain compromise, finish exploitation

Day 5

Buffer day or start report

Day 6

Report writing

Day 7

Polish & submit

2 Exam Structure

1

Penetration Test (5 days)

Compromise an Active Directory network from external to domain admin. Full scope pentest simulation.

2

Report Writing (2 days)

Write a professional penetration test report with findings, risk ratings, and recommendations.

3

Live Debrief (15 min)

Present your findings to a panel-just like a real client meeting! This is what sets PNPT apart.

🎯 Key Skills Tested:

  • • OSINT & External Recon
  • • Active Directory Attacks
  • • Privilege Escalation (Win/Linux)
  • • Post-Exploitation & Pivoting
  • • Lateral Movement
  • • Professional Report Writing

3 Required Courses

The PNPT requires completing these TCM Security courses (included with exam purchase):

Practical Ethical Hacking

The core course - 25+ hours of content

ESSENTIAL

Linux Privilege Escalation

Comprehensive Linux privesc techniques

Windows Privilege Escalation

All Windows privesc vectors

Open-Source Intelligence (OSINT)

OSINT fundamentals for recon

External Pentest Playbook

External network testing methodology-critical for the exam

Practice Labs & Machines

⚠️ Important Note from PNPT Passers

"Extra practice machines weren't helpful during my exam-I wasted time trying techniques from HTB that were outside the PNPT course scope. If you truly understand the 5 courses, you're ready." - Multiple reviewers confirm: the course material is sufficient. Practice labs are for building confidence, not learning new techniques.

THM

TryHackMe

Best for guided learning

Wreath FREE

Multi-network pivoting, AD basics

Pivoting AD
Throwback VIP

Full AD network, multiple domains

AD Multi-Domain
Holo VIP

Enterprise AD environment

Enterprise AD
Red Team Capstone VIP

Full engagement simulation

Capstone

~$10/month for premium access

HTB

HackTheBox

More challenging, less guided

Forest Easy

AS-REP roasting, BloodHound intro

Kerberos AD
Sauna Easy

User enum, DCSync attack

DCSync AD
Active Medium

GPP passwords, Kerberoasting

GPP Kerberoast
Monteverde Medium

Azure AD Connect exploitation

Azure AD
Search Hard

Kerbrute, PFX certs, AV evasion

Certs Advanced

~$25/month for VIP+ access

Build Your Own Lab

Best learning experience

The PEH course includes a section on building your own AD lab. This skill is invaluable for:

  • Testing tools safely before the exam
  • Practicing attacks repeatedly until muscle memory
  • Understanding AD from defender's perspective
  • Future pentesting career skill

Minimum Requirements:

  • • 16GB RAM (32GB recommended)
  • • Windows Server 2019 eval ISO
  • • Windows 10/11 Enterprise eval
  • • VMware or VirtualBox

Cost: FREE (eval licenses)

🎯 Key AD Skills to Practice (from the courses)

Enumeration

  • • BloodHound pathfinding
  • • LDAP queries
  • • SMB enumeration
  • • User/Group recon

Initial Access

  • • Password spraying
  • • AS-REP roasting
  • • LLMNR/NBT-NS poisoning
  • • SMB relay attacks

Lateral Movement

  • • Pass-the-hash
  • • Kerberoasting
  • • Token impersonation
  • • WinRM/PSExec

Domain Takeover

  • • DCSync attack
  • • Golden ticket
  • • Pass-the-ticket
  • • Delegation abuse

4 Cheatsheets & Study Resources

CyberCert Reviews Cheatsheets

Free, comprehensive cheatsheets for PNPT preparation.

External Study Resources

TheCyberMentor YouTube

Heath Adams' free content covers many PNPT topics. Great supplement to the courses.

FREE

Hack The Box (HTB)

Practice AD attacks on Dante, Offshore, and other Pro Labs. Great for building muscle memory.

VIP Sub Recommended

TryHackMe AD Paths

Holo, Throwback, and Wreath rooms provide guided AD attack practice.

FREE/Premium

Report Writing Practice

Practice writing reports for every box you do. Use TCM's template to build the habit.

CRITICAL

Report Writing Guide

The report is 50% of your PNPT success. A technically perfect pentest means nothing if you can't communicate findings professionally.

Required Report Sections

1

Executive Summary

1-2 pages max. Non-technical overview for leadership. Risk posture, critical findings, business impact.

2

Technical Findings

Each finding: title, severity (CVSS), description, proof-of-concept, impact, remediation.

3

Attack Narrative

Step-by-step walkthrough from external foothold to domain admin. Tell the story.

4

Recommendations

Specific, actionable remediations. Not "patch your systems" but exact fixes.

Pro Tips from Passers

Draft your template BEFORE the exam

Have all sections ready. Just fill in findings during the exam.

Screenshot EVERYTHING

Every command, every output. You'll thank yourself during report writing.

Don't rush the report

You have 2 days. Use them. A polished report > a hasty one.

Read real pentest reports

Study public reports to understand professional formatting.

Debrief Preparation

The 15-minute live debrief is what makes PNPT unique. It simulates a real client meeting and tests your communication skills.

What Happens During the Debrief

1

Setup (1-2 min)

Join the video call. TCM staff acts as "the client's security team." They've read your report.

2

Your Presentation (5-8 min)

Walk through your attack chain. Explain what you found, how you exploited it, and why it matters to the business.

3

Q&A (5-7 min)

They ask about your methodology, why certain approaches, remediation priorities. Think like a consultant.

Debrief Survival Tips

  • Know your report inside out
  • Practice explaining technical concepts simply
  • Prepare a 5-min attack summary
  • Anticipate "why" questions
  • Dress professionally (yes, really)
  • Have your report open for reference
  • Don't read from a script
  • Don't panic if you don't know an answer

Common Debrief Questions (Be Ready For These)

"Walk us through your attack path"

Have a clear narrative: external recon → initial access → privilege escalation → lateral movement → domain compromise.

"What's the most critical finding?"

Know your severity rankings and be able to justify them from a business risk perspective.

"Why did you choose X approach?"

Explain your methodology. They want to see you think like a professional pentester.

"How should we prioritize fixes?"

Quick wins vs. long-term fixes. Consider effort, impact, and business constraints.

Common Mistakes to Avoid

Over-Preparing

Doing tons of HTB/THM boxes outside course scope. Multiple reviewers confirm: the course material is enough. Extra practice can actually confuse you with techniques not relevant to the exam.

Poor Note-Taking

Not documenting what you tried during the exam. You'll waste time repeating failed attempts. Use Obsidian, CherryTree, or similar to track every command and result.

Skipping OSINT/External

Jumping straight to internal pentesting. The exam simulates a real engagement-you start external. Don't skip the External Pentest Playbook course.

Ignoring Report Writing

Waiting until after the pentest phase to think about your report. Draft your template before the exam. Know exactly what sections you need.

Tool Tunnel Vision

If a tool isn't working, try another that does the same thing. Don't spend hours debugging when you could use an alternative. Have backups ready.

No Debrief Prep

Assuming you can wing the debrief. Practice explaining your attack chain out loud. Record yourself. It's 15 minutes that can make or break your certification.

✓ What Successful Candidates Do Instead

  • Complete all 5 courses thoroughly
  • Take detailed notes with screenshots
  • Build their own AD lab and practice
  • Prepare report template before exam
  • Snapshot their attack VM before starting
  • Take breaks when stuck (you have 5 days)
  • Practice verbal explanations for debrief
  • Trust the methodology from the courses

5 PNPT vs Other Certs

Aspect PNPT OSCP CPTS
Cost $499 $2,749/yr $490+
Exam Time 5 days 24 hours 10 days
Retakes Free Included $200
Debrief Yes (Live) No No
Recognition Growing Gold Standard Growing
Best For Budget-conscious Career advancement HTB enthusiasts

6 FAQ

Is PNPT accepted by employers?

Yes, and growing. More employers recognize PNPT each year, especially for junior/mid-level roles. The live debrief proves real consulting skills. For HR-gated positions at large companies, OSCP may still be required.

What's the debrief actually like?

A 15-minute video call where you present your findings to TCM staff acting as clients. They ask questions about your methodology and findings. It's nerve-wracking but excellent practice for real pentest debriefs.

Should I get PNPT or OSCP?

If budget is a concern, start with PNPT. The skills transfer well, and you can add OSCP later. If you need the certification for a specific job requirement or want maximum career impact, go straight for OSCP.

How long to prepare for PNPT?

Complete beginners: 3-4 months working through the courses. With some background: 1-2 months. The courses are comprehensive-focus on understanding the methodology, not just memorizing commands.

Community Resources & Links

Join the TCM Security Discord

The official TCM Security Discord is the best place to ask questions, find study partners, and get real-time help from the community.

Join Discord