Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

PNPT exam: Active Directory, reporting and live debrief

PNPT mirrors a professional pentest without CTF flags. Understand the five-day assessment, OSINT, Active Directory, report and live debrief.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
20 June 2026
READING TIME
9 min read
TOPIC
Careers and Certifications
PNPT exam: Active Directory, reporting and live debrief

PNPT is TCM Security’s practical assessment designed like a penetration-testing engagement rather than a CTF. Candidates receive five full days for testing and two more for a professional report. There are no flags or multiple-choice questions.

Skills assessed

The scope combines OSINT, external testing, Active Directory, AV and egress bypass, lateral and vertical movement, ending with domain-controller compromise. A 15-minute live debrief follows the report.

This changes priorities. Candidates must explain the path, impact, evidence and remediation to technical and business audiences.

Five-day method

Use day one for attack-surface mapping and hypotheses. Spend the middle on access, identity graphs, credentials and lateral movement. Reserve a final block for validation, cleanup and missing evidence.

Maintain findings during testing with title, asset, evidence, impact, root cause and fix. The reporting period should be editing time, not historical reconstruction.

Live debrief

Prepare a short narrative: objective, key chain, risk and three remediation priorities. Answer from evidence and state explicitly when something was not confirmed.

TCM says PNPT does not expire, vouchers last 12 months and include one retake. Tools including AI are allowed, but use must be disclosed in the report. Re-check rules before starting.

Compare PNPT with other practical routes in the OSCP vs PNPT vs CPTS guide.

The opening hours: scope and environment map

Before intensive enumeration, organise the targets and constraints from the exam documentation. Separate internet-facing assets, internal hosts, domains, accounts and OSINT findings. Record the source and confidence level for each discovery. This prevents the report from mixing public information with technically validated access.

In Active Directory, work from a dependency graph: user, group, session, host, privilege and next resource. Re-test available services after each new credential, but never assume that a valid password grants identical rights everywhere. Record failed attempts, lockout risk and every security-context change as well.

Writing the report during the assessment

Five days allow deep analysis, but make postponing documentation tempting. At the end of each stage, capture the prerequisite, exact steps, evidence, gained privilege, business impact and recommendation. Name screenshots by host and sequence. Keep commands as text so the reader does not have to transcribe them from an image.

The executive section should explain the chain in plain language: where access began, why successive controls did not stop it and which final asset was exposed. The technical section preserves full reproducibility. Prioritise remediation by points that break the chain, not merely by discovery order.

A full rehearsal

Complete at least one multi-day lab with a defined scope and a hard reporting deadline. Use the same directory tree, note template and toolset planned for the exam. Then deliver a 15-minute debrief to another person, or record it and review whether facts, risk and recommendations remain clearly separated.

You are ready when you can discover a path in an unfamiliar environment, recover from a dead end and defend conclusions with evidence. Knowing AD techniques is insufficient without communication and scope control.

Pre-submission quality checklist

Read the report from three perspectives. An executive should understand impact and priorities without tool names. An administrator needs the system, account, vulnerable condition and concrete fix. A tester must be able to reproduce the steps from commands, parameters and evidence.

Check addresses, hostnames, users and time across the complete timeline. Remove contradictory screenshots and unnecessary credentials. Each finding needs a problem-focused title, impact, evidence, reproduction and recommendation. A domain chain should also identify the independent fixes that break it earliest.

Prepare one page for the live debrief with a diagram, the three leading risks and remediation order. Do not read the report slide by slide. The presentation explains decisions and impact while technical detail remains available for questions.


Source: TCM Security — PNPT.

SHARE / COPY