Skip to content

Latest commit

Β 

History

History
78 lines (57 loc) Β· 3.75 KB

File metadata and controls

78 lines (57 loc) Β· 3.75 KB

🟣 PNPT β€” Study Hub

A source-grounded study hub for the TCM Security PNPT

Engagement workflow, real diagrams, and exam prep β€” a fully practical network penetration test: OSINT β†’ external β†’ Active Directory β†’ report β†’ a live debrief.

Provider Exam Style Diagrams Use


Warning

Educational & authorized use only. Offensive techniques are explained conceptually for understanding, methodology, and defense β€” no weaponized step-by-step playbooks or exploit code. Use them only against systems you own or are explicitly authorized in writing to test. See the CEH hub's legal & ethics.

Note

Unofficial & no fabrication. Not affiliated with or endorsed by TCM Security. Exam specifics are from TCM's official PNPT page; volatile items (price, exact structure, voucher terms) should be re-checked there. Compiled 2026-06-21.

πŸ“‹ At a glance

Item Detail
Provider TCM Security Β· vendor-neutral
Exam 5-day practical assessment + 2-day report + a live 15-minute debrief
Style Fully practical β€” no multiple choice, no capture-the-flag flags
Signature The live debrief: present & defend your methodology like a consultant
Included 1 attempt + 1 free retake, bundled training; non-expiring (verify on TCM)

Full details: exam structure.

πŸ“¦ What's inside

Section Contents
Overview What is PNPT Β· Exam structure
Engagement phases The PNPT workflow, phase by phase
Exam prep Study plan β€” lab build, workflow practice, the debrief

The engagement phases

# Phase Page
1 OSINT & reconnaissance 01-osint-and-reconnaissance.md
2 External penetration testing 02-external-penetration-testing.md
3 Active Directory exploitation 03-active-directory-exploitation.md
4 Lateral movement & pivoting 04-lateral-movement-and-pivoting.md
5 Reporting & the debrief 05-reporting-and-the-debrief.md

🧭 Where it fits

The PNPT is the budget-friendly, engagement-style practical cert:

  • A realistic lead-in or alternative to OSCP; more report- and consultant-focused than the knowledge-based CEH.
  • Defender's mirror β†’ its AD-compromise and lateral-movement focus is exactly what the attack β†’ defense matrix and WALLIX / PAM hub exist to prevent and audit.

πŸ”— Quick links

PNPT, PJPT and TCM Security are trademarks of TCM Security, used here for identification and educational purposes only.