PT1 Certification Achieved!
Overview
I’m thrilled to announce that I’ve earned the PT1 (TryHackMe Junior Penetration Tester Level 1) certification! 🎉
I scored 813/1000 on my first attempt, and completed the exam—including the full report writeup—in just 10 hours and 46 minutes, well under the 48‑hour permitted window.
What the Exam Entails
The PT1 certification is a fully hands-on, industry-designed, 48-hour practical assessment across three domains:
- Web Application Testing (40%)
- Network Penetration Testing (36%)
- Active Directory Exploitation (24%)
Importantly, the exam requires you to submit a written HTML‑style report via the exam platform, with clear documentation, CVSS scoring, remediation recommendations, and business context—graded automatically using AI tools
Why PT1?
This certification stood out for simulating a real-world penetration testing engagement from start to finish—discovering vulnerabilities, exploiting systems, moving laterally across the environment, and crafting a professional report. It covers every critical phase of a pentest, from enumeration to post-exploitation and documentation,
Key Skills Demonstrated
- Reconnaissance & Enumeration
- Web App Exploitation (e.g. SQLi, XSS, SSRF, authentication bypass)
- Network Pentesting and lateral movement (SMB, FTP, RDP, brute-forcing, pivoting)
- Active Directory Attacks (Kerberoasting, AS‑REP roasting, Pass‑the‑Hash/Ticket, LDAP abuse)
- Privilege Escalation on Linux/Windows targets
- Professional Reporting: clear write-up with CVSS scoring, risk prioritization, and actionable remediation.
Challenges & Highlights
The real challenge was time management—balancing thorough testing in all three domains and structuring a comprehensive report under a 48-hour deadline. Completing everything in less than half the timeframe was demanding but highly rewarding. The AI‑graded write-up system also pushed me to be precise and clear in documentation.
Conclusion
The TryHackMe PT1 certification offers an authentic and demanding hands-on pentest experience—from external web app testing to internal AD exploitation and professional reporting. If you want a certification that reflects real-world pentesting—from exploitation to executive-level documentation—this is an excellent one to pursue.
Scored well. Finished quickly. Learned tons. On to the next challenge! 💻🔐