<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>TCM Security on MidwestSec</title><link>https://midwestsec.com/tags/tcm-security/</link><description>Recent content in TCM Security on MidwestSec</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Thu, 17 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://midwestsec.com/tags/tcm-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Passing the PNPT: 39 Hours, 70 Pages, and a 15-Minute Debrief</title><link>https://midwestsec.com/blog/passing-the-pnpt/</link><pubDate>Thu, 17 Sep 2026 00:00:00 +0000</pubDate><guid>https://midwestsec.com/blog/passing-the-pnpt/</guid><description>&lt;p&gt;I officially passed the Practical Network Penetration Tester (PNPT) certification from TCM Security.&lt;/p&gt;
&lt;p&gt;The PNPT isn&amp;rsquo;t a multiple-choice exam where you memorize enough material, pick the right answers, and walk away with a certification. It is designed around performing a penetration test, documenting what you found, and then explaining your work.&lt;/p&gt;
&lt;p&gt;For me, that meant 39 hours to compromise the network, a 70-page penetration testing report, and a 15-minute live debrief explaining my findings.&lt;/p&gt;
&lt;p&gt;It was a blast!&lt;/p&gt;
&lt;h2 id="the-exam"&gt;&lt;a href="#the-exam" class="header-anchor"&gt;&lt;/a&gt;The Exam
&lt;/h2&gt;&lt;p&gt;Going into the PNPT, one of the things I was most excited about was the format.&lt;/p&gt;
&lt;p&gt;You&amp;rsquo;re given a target environment and an objective. From there, it&amp;rsquo;s up to you to figure out how to approach it.&lt;/p&gt;
&lt;p&gt;There isn&amp;rsquo;t a checklist telling you which technique to use next. You have to enumerate, develop leads, determine which ones are worth pursuing, recognize when something isn&amp;rsquo;t working, and adjust your approach.&lt;/p&gt;
&lt;p&gt;That made the exam feel much closer to an actual engagement than a traditional certification exam.&lt;/p&gt;
&lt;p&gt;I ultimately compromised the network in approximately 39 hours.&lt;/p&gt;
&lt;p&gt;That number includes sleep and spending time with my family. I didn&amp;rsquo;t lock myself in a room for 39 straight hours and stare at Kali.&lt;/p&gt;
&lt;p&gt;I intentionally approached the exam in a way that was sustainable. I worked the assessment, stepped away when I needed to, spent time with my family, slept, and came back to it.&lt;/p&gt;
&lt;p&gt;In some ways, stepping away was part of the process. There were several times when looking at a problem with fresh eyes was more useful than continuing to hammer away at it.&lt;/p&gt;
&lt;h2 id="compromising-the-network-was-only-part-of-the-job"&gt;&lt;a href="#compromising-the-network-was-only-part-of-the-job" class="header-anchor"&gt;&lt;/a&gt;Compromising the Network Was Only Part of the Job
&lt;/h2&gt;&lt;p&gt;Getting the technical objective wasn&amp;rsquo;t the end of the PNPT.&lt;/p&gt;
&lt;p&gt;Then came the report.&lt;/p&gt;
&lt;p&gt;I spent a considerable amount of time turning my notes, screenshots, evidence, attack path, findings, and remediation recommendations into a professional penetration testing report.&lt;/p&gt;
&lt;p&gt;The finished report came in at approximately 70 pages.&lt;/p&gt;
&lt;p&gt;Writing it reinforced something that is easy to overlook when practicing penetration testing:&lt;/p&gt;
&lt;p&gt;Finding a vulnerability isn&amp;rsquo;t enough.&lt;/p&gt;
&lt;p&gt;A penetration tester needs to be able to explain what happened, demonstrate the impact, preserve evidence, communicate the attack path, and provide useful recommendations for fixing the underlying problems.&lt;/p&gt;
&lt;p&gt;A technically impressive attack that can&amp;rsquo;t be clearly communicated isn&amp;rsquo;t nearly as valuable to a client.&lt;/p&gt;
&lt;p&gt;The reporting portion was something I took especially seriously this time around. When I attempted the PJPT for the first time, I actually failed because of my report, not because I couldn&amp;rsquo;t complete the technical portion of the exam. That experience taught me pretty quickly that compromising a network is only part of the job.&lt;/p&gt;
&lt;p&gt;Going into the PNPT, I wasn&amp;rsquo;t going to make that mistake again. I spent a considerable amount of time making sure my findings were clearly documented, the attack path was easy to follow, the evidence supported what I was saying, and the remediation recommendations were useful.&lt;/p&gt;
&lt;p&gt;In a way, failing the PJPT because of my report ended up being one of the better lessons I could have learned before attempting the PNPT. It completely changed how seriously I approached documentation and reporting this time around.&lt;/p&gt;
&lt;h2 id="the-debrief"&gt;&lt;a href="#the-debrief" class="header-anchor"&gt;&lt;/a&gt;The Debrief
&lt;/h2&gt;&lt;p&gt;The final piece was the live debrief.&lt;/p&gt;
&lt;p&gt;I had approximately 15 minutes to explain my findings and walk through the compromise.&lt;/p&gt;
&lt;p&gt;This might have been my favorite part of the entire certification.&lt;/p&gt;
&lt;p&gt;Instead of simply submitting a report and waiting for a score, I had to actually talk through what I found and demonstrate that I understood the attack path.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s an important skill.&lt;/p&gt;
&lt;p&gt;In a real engagement, eventually someone is going to ask:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What happened?&lt;/li&gt;
&lt;li&gt;How did you get in?&lt;/li&gt;
&lt;li&gt;What did you gain access to?&lt;/li&gt;
&lt;li&gt;Why does this matter?&lt;/li&gt;
&lt;li&gt;What should we fix first?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Being able to answer those questions clearly is just as important as knowing the commands that got you there.&lt;/p&gt;
&lt;h2 id="four-years-five-cybersecurity-certifications"&gt;&lt;a href="#four-years-five-cybersecurity-certifications" class="header-anchor"&gt;&lt;/a&gt;Four Years, Five Cybersecurity Certifications
&lt;/h2&gt;&lt;p&gt;Passing the PNPT also marks another milestone for me.&lt;/p&gt;
&lt;p&gt;This is my fifth cybersecurity certification and seventh certification overall in the last four years.&lt;/p&gt;
&lt;p&gt;My cybersecurity certification progression now looks like:&lt;/p&gt;
&lt;p&gt;Security+ → CySA+ → CISSP → PJPT → PNPT&lt;/p&gt;
&lt;p&gt;Each certification has represented a different stage in my career.&lt;/p&gt;
&lt;p&gt;Security+ helped establish the foundation.&lt;/p&gt;
&lt;p&gt;CySA+ pushed further into defensive security and analysis.&lt;/p&gt;
&lt;p&gt;CISSP forced me to think about security much more broadly, beyond individual technologies and vulnerabilities.&lt;/p&gt;
&lt;p&gt;PJPT was my first real step into practical penetration testing.&lt;/p&gt;
&lt;p&gt;And now the PNPT took that practical offensive-security work considerably further.&lt;/p&gt;
&lt;p&gt;The biggest change isn&amp;rsquo;t really the certifications themselves, though. It&amp;rsquo;s how differently I approach a network today compared with four years ago.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m increasingly interested in understanding both sides of security: how we build and defend systems, and how an attacker can chain seemingly small weaknesses together to compromise them.&lt;/p&gt;
&lt;p&gt;That perspective directly affects how I approach my day-to-day work protecting SMB and local-government environments.&lt;/p&gt;
&lt;h2 id="preparation"&gt;&lt;a href="#preparation" class="header-anchor"&gt;&lt;/a&gt;Preparation
&lt;/h2&gt;&lt;p&gt;I didn&amp;rsquo;t prepare for the PNPT by trying to memorize every tool or command I might possibly need.&lt;/p&gt;
&lt;p&gt;A lot of my preparation came from simply spending time attacking networks.&lt;/p&gt;
&lt;p&gt;TCM Security&amp;rsquo;s training provided the foundation, and Hack The Box gave me environments where I could repeatedly practice enumeration, exploitation, privilege escalation, pivoting, and Active Directory attacks.&lt;/p&gt;
&lt;p&gt;Labs like Dante were especially useful because they forced me to think beyond compromising a single machine.&lt;/p&gt;
&lt;p&gt;I also documented much of that practice here on MidwestSec.&lt;/p&gt;
&lt;p&gt;Writing walkthroughs turned out to be part of the preparation itself. Explaining an attack forces you to understand why something worked rather than simply remembering that a particular command worked once.&lt;/p&gt;
&lt;p&gt;That became extremely valuable when it was time to write the PNPT report.&lt;/p&gt;
&lt;h2 id="the-most-important-lesson"&gt;&lt;a href="#the-most-important-lesson" class="header-anchor"&gt;&lt;/a&gt;The Most Important Lesson
&lt;/h2&gt;&lt;p&gt;If I had to reduce the entire experience to one lesson, it would be this:&lt;/p&gt;
&lt;p&gt;Enumeration wins.&lt;/p&gt;
&lt;p&gt;The flashy part of penetration testing is exploitation.&lt;/p&gt;
&lt;p&gt;The important part is understanding the environment well enough to know what should be exploited.&lt;/p&gt;
&lt;p&gt;When I got stuck during the exam, the answer usually wasn&amp;rsquo;t some obscure exploit or magical tool I hadn&amp;rsquo;t heard of.&lt;/p&gt;
&lt;p&gt;It was usually that I needed to look harder at information I already had, enumerate something more thoroughly, or reconsider an assumption I had made.&lt;/p&gt;
&lt;p&gt;That lesson applies far beyond the PNPT.&lt;/p&gt;
&lt;h2 id="a-shoutout-to-my-wife"&gt;&lt;a href="#a-shoutout-to-my-wife" class="header-anchor"&gt;&lt;/a&gt;A Shoutout to My Wife
&lt;/h2&gt;&lt;p&gt;None of this happens in a vacuum.&lt;/p&gt;
&lt;p&gt;Studying for certifications, spending mornings in labs, writing walkthroughs, disappearing into an exam environment, and then spending hours putting together a 70-page report takes a lot of time. And when you have a family, that time has to come from somewhere.&lt;/p&gt;
&lt;p&gt;So I need to give a huge shoutout to my wife. While I was buried in the exam, she was taking care of the kids and carrying more of the day-to-day load at home so I could stay focused. That continued while I worked through the reporting process and prepared for the debrief.&lt;/p&gt;
&lt;p&gt;Passing the PNPT might have my name on the certification, but getting there was absolutely a team effort. I&amp;rsquo;m incredibly thankful that she continues to support me through the studying, exams, and all the time that comes with chasing these goals.&lt;/p&gt;
&lt;p&gt;I definitely couldn&amp;rsquo;t keep doing this without her.&lt;/p&gt;
&lt;h2 id="whats-next"&gt;&lt;a href="#whats-next" class="header-anchor"&gt;&lt;/a&gt;What&amp;rsquo;s Next?
&lt;/h2&gt;&lt;p&gt;The PNPT isn&amp;rsquo;t the finish line.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s another step.&lt;/p&gt;
&lt;p&gt;My next major certification goal is the OSCP.&lt;/p&gt;
&lt;p&gt;Before jumping straight into the exam, I&amp;rsquo;m planning to continue working through TCM Academy and Hack The Box, with additional focus on the areas where I want more depth, particularly web application testing, Linux and Windows privilege escalation, Active Directory, and operating efficiently in larger environments.&lt;/p&gt;
&lt;p&gt;For now, though, I&amp;rsquo;m going to enjoy this one.&lt;/p&gt;
&lt;p&gt;The PNPT was challenging, practical, occasionally frustrating, and super fun.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s exactly what I wanted from it.&lt;/p&gt;
&lt;p&gt;39 hours. 70 pages. 15-minute debrief. PNPT complete.&lt;/p&gt;</description></item></channel></rss>