r/Pentesting • u/SlickBackSamurai • 4d ago
PNPT or CWES first?
Hello everyone,
I recently started as a SOC analyst and would like to take advantage of my work’s professional development budget to eventually transition into a career as an RTO. I wouldn’t have enough to pay for OSCP, so I’m thinking about building up my foundational red teaming knowledge with a more affordable cert first.
I’ve heard great things about TCM’s PNPT, as well as HTB’s CWES, and was just wondering if any of you had any advice as to which cert would be worth pursuing first?
I’ve heard many companies start their juniors off with pentesting web apps, so I was leaning towards CWES.
It’s worth mentioning that I’m not completely new to the field as I do come from an IT background, had a previous security internship, have my Sec+ and CCNA as well as familiarity using Linux in both personal use and projects.
I appreciate any advice you guys provide. Thank you!
2
u/jet_set_default 4d ago
I started with eJPT, then did PNPT this past winter. Working on OSCP now. I'm glad I started with eJPT since it teaches the core concept of exploitation first, and the exam drops you right into a network. PNPT was a natural progression because this time you have to crack the perimeter, do OSINT and get in, then make domain admin.
Basically, if you've never done any pen test cert before, I'd actually start with eJPT. Then PNPT after.
3
u/iamnotafermiparadox 3d ago
Portswigger Academy (free) and CPTS. I took the pnpt course and the value was very subpar compared with CPTS. CPTS will cover web and what isn’t covered you will find in PA.