My PNPT Exam Experience — image 1

I want to preface this by stating that the course material is more than enough to pass the exam. Don’t stress, all your learning material is centralized, you won’t need to outsource a million resources in order to pass the exam. With that being said, let’s go over what the PNPT exam is and if it’s a certification that you or your team should explore. The Practical Network Penetration Tester™ or better known as the PNPT is an “ethical hacking certification exam that assesses a student’s ability to perform an external and internal network penetration test at a professional level.”

PNPT Overview

My PNPT Exam Experience — image 2

In order to receive the certification, a student must:

“Perform Open-Source Intelligence (OSINT) to gather intel on how to properly attack the network

Leverage their Active Directory exploitation skillsets to perform A/V and egress bypassing, lateral and vertical network movements, and ultimately compromise the exam Domain Controller

Provide a detailed, professionally written report

Perform a live 15-minute report debrief in front of our assessors, comprised of all senior penetration testers.”

The PEH or Practical Ethical Hacking course provided by TCM goes over all the topics covered in the exam and then some. You’ll be introduced to Linux CLI, Networking Basics, Python, Active Directory Initial Enumeration & Attack Vectors, Active Directory Enumeration, Active Directory Post-Compromise Enumeration & Attacks, and Web Vulnerabilities just to name a few. Additionally, you’re also given the option of building out an Active Directory lab which enables you to follow along with the course video examples, you could add this lab into your resume as well! Once you reach the end of the course, TCM concludes by giving you some career advice in addition to some report writing tips and tricks.

Some of my favorite techniques the PEH goes over are Pivoting and Domain Enumeration via Bloodhound, Powerview, etc. Did I succeed? Did I fail miserably? Did I smash my monitors? We’ll find out in the next section.

Exam Experience

My PNPT Exam Experience — image 3

At the beginning of October after minimal planning I decided it was time to tackle the PNPT…once AGAIN. Now, if you’re assuming, “Enleak, there must be some context missing” then you’re absolutely correct. In order to clear things up we have to start by briefly mentioning when my PNPT journey started. After failing my OSCP exam last year, I set my eyes on the PNPT exam, considering that multiple blogs and Reddit posts listed it as a great pre-requisite, especially after the addition of AD machines to the OSCP. After failing my initial attempts I moved on, always keeping the desire for this credential burning bright. It wasn’t until recently where I decided to review the material and simply sit down and take the exam. With some additional preparation done, I felt like it was all or nothing. That being said, I sat down for the exam, immediately read the updated letter of engagement and started gathering important information. I had an idea of what initial access looked like because of my previous attempts; the updates did make it a bit trickier, but nothing that is not included in the course. After initial access and some additional reconnaissance, I was able to breach the network and eventually access their internal network and devices. From this point on, I was pretty much using the course as a guideline and then opening half a million tabs in order to supplement any additional attempts at info gathering and escalating privileges. With some machines compromised and the momentum building up, there was nothing to halt my monitor staring activities….until I got stuck for about 2 days. As I squeezed all the techniques and tooling I had in my arsenal as a last-ditch effort, “something has to work” I reminded myself. Nothing. Nothing. Nothing. Adding this additional failure seemed to be the grim reality but I’m Enleak. I failed this more than once before, I'm familiar with the feeling so like many suggest, I stepped away and distracted myself with other activities. With the mental reset I started scavenging for additional leads and BOOM! Turns out I was overthinking the whole time, it’s not a CTF, there's no flag or root.txt waiting on the other side…this is mimicking a real engagement. With the additional findings I was able to compromise the Domain Controller and use some persistence techniques in order to finalize the exam, curate and submit the report. With the screenshots organized as needed, the exam was ended. The TCM team responded swiftly and scheduled the debrief, I kept it simple and used the report in order to articulate my findings. I verbally received the “You Passed, you should receive your credentials in your email” confirmation and was relieved. Shortly after, I was warmly greeted in a private discord channel in the TCM discord for all PNPT holders. WE DID IT!!

Final Tips

My PNPT Exam Experience — image 4

  • Complete the Active Directory labs and follow along with the attack simulations (you’ll enjoy using tools like CrackMapExec in order to perform Kerberoasting, Password Spray Attacks, etc)
  • Familiarize yourself and practice with the tools that will be used (the course mentions the main tools that will be used during the exam).
  • PNPT is an open-book, open-internet exam so any cheatsheets, notes, videos, etc that you believe will be of assistance maybe be used during the exam. Google, google, google :).
  • Take your time and have fun. The course has fully prepared you to succeed, it won’t be long until you fully immerse yourself in the exam.

Resource Hub

My PNPT Exam Experience — image 5

I want to preface this by mentioning that EVERYTHING needed to pass is provided in the course, these are simply _Additional_resources to consider:

Pivoting

Explore Hidden Networks With Double Pivoting

SSH & Meterpreter Pivoting Techniques

Pivoting Techniques with THM Wreath

TryHackMe | Lateral Movement & Pivoting

Active Directory

Attacking Active Directory: 0 to 0.9

Wreath

Attacktive Directory

VulnNet: Active

Post-Exploitation Basics

VulnNet: Roasted

Enterprise

RazorBlack

BurpSuite

Burp Suite: The Basics

Portswigger

Community Discord Servers

My PNPT Exam Experience — image 6

It is crucially important to build up your social network as it can open doors to opportunities. I recommend joining Discord servers that align with your interests. Specifically, the following ones have really aided in preparing for this exam. Please note that this is not an exhaustive list, so I encourage you to explore and join other Discord servers that are best suited for you:

Cyberwox Academy: Join

TCM Security: Join