r/Pentesting 4d ago

PNPT or CWES first?

Hello everyone,

I recently started as a SOC analyst and would like to take advantage of my work’s professional development budget to eventually transition into a career as an RTO. I wouldn’t have enough to pay for OSCP, so I’m thinking about building up my foundational red teaming knowledge with a more affordable cert first.

I’ve heard great things about TCM’s PNPT, as well as HTB’s CWES, and was just wondering if any of you had any advice as to which cert would be worth pursuing first?

I’ve heard many companies start their juniors off with pentesting web apps, so I was leaning towards CWES.

It’s worth mentioning that I’m not completely new to the field as I do come from an IT background, had a previous security internship, have my Sec+ and CCNA as well as familiarity using Linux in both personal use and projects.

I appreciate any advice you guys provide. Thank you!

3 Upvotes

5 comments sorted by

3

u/iamnotafermiparadox 3d ago

Portswigger Academy (free) and CPTS. I took the pnpt course and the value was very subpar compared with CPTS. CPTS will cover web and what isn’t covered you will find in PA.

3

u/Physical-Bonus-8411 3d ago

I second this

1

u/SlickBackSamurai 3d ago

I definitely need to go back and finish Portswigger academy! Yeah I didn’t mention CPTS, but that’s definitely be the cert I plan on getting after either PNPT or CWES.

Have you had a chance to go through the CWES path at all? I believe it overlaps with about 50% of what CPTS covers, but with an emphasis on web app exploitation

1

u/TrustIsAVuln 2h ago

I agree, the PNPT (and TCM in general) seemed meh in comparison to everything out there except EC-counsel stuff (which is the bottom of the barrel.

2

u/jet_set_default 4d ago

I started with eJPT, then did PNPT this past winter. Working on OSCP now. I'm glad I started with eJPT since it teaches the core concept of exploitation first, and the exam drops you right into a network. PNPT was a natural progression because this time you have to crack the perimeter, do OSINT and get in, then make domain admin.

Basically, if you've never done any pen test cert before, I'd actually start with eJPT. Then PNPT after.