TryHackMe Junior Penetration Tester (PT1) AD Exam Review
TL;DR This is my review of the AD portion of TryHackMe’s new Junior Penetration Tester (PT1) exam. This is only a review of the AD portion. I’m not a webapps guy.
Exam Reviews
Altered Security Certified Red Team Professional (CRTP)
eLearn Junior Pentester (eJPT)
ISC2 Certified in Cybersecurity (CC)
Microsoft Applied Skills Administer AD DS
TCM Practical Junior Penetration Tester (PJPT)
Altered Security CRTP renewal exam
TryHackMe Security Analyst Level 1 (SAL1)
TryHackMe PT1, AD portion (PT1)
TryHackMe Cyber Security 101 (SEC1)
Background
TryHackMe had previously given me a free SAL1 exam voucher for holding CySA+. They recently gave me a free PT1 exam voucher for holding eJPT. PT1 costs $297 otherwise. It does include a free retake if needed, and a three month subscription to TryHackMe. If you are already a Premium subscriber to TryHackMe then you get 15% off.
I would say the price isn’t quite the screaming deals that CRTP, eJPT, and PJPT were, however it’s a good deal overall. CompTIA charges $392 for a Pentest+ voucher, and that’s a multiple choice test. That price does not include training either.
Designing and running environments for hands on exams requires quite a bit more effort and cost then writing some questions down, so I won’t knock TryHackMe on SAL1 or PT1’s price.
I just think they should have split PT1 up into three separate exams at $100 each, each with their own certification. If you pass all three then you’d get a stackable certification, CompTIA style, with a catchy name like PT1 Master.
The Good
Like CRTP, eJPT, PJPT, etc the exam is 100% hands on. TryHackMe provides you a *.ovpn file and you are then free to use the VM, OS, tools, etc of your choice. There’s no proctor staring at you awkwardly during the exam. Much like the other hands on exams I have taken, they seem to believe that if you have a friend help you then you’re really only cheating yourself.
The Bad
IMHO the AD portion wasn’t really an AD test. It mostly involved enumeration, initial access, local privilege escalation, post compromise ‘actions on the objective’ … and that was really it. I can’t say much about the exam itself obviously, and I definitely can’t write a walkthrough, but I only had to take one very simple AD related step after those ‘actions on the objective’ to own the entire domain.
There was no lateral movement, almost no AD enumeration needed, no twisting, winding escalation path to follow, and the connection between the DC and clients was rather janky. Many of the rooms on TryHackMe require more AD enumeration, lateral movement, and following escalation paths than this exam did.
The only tools I used besides builtin Kali ones like netcat were Mimikatz and SharpHound. However the escalation path, if I can even call it that, hardly needed BloodHound to enumerate. Mishky’s Red Team tool will find things that simple within seconds, and it only uses builtin PowerShell to run queries.
The Ugly
The PT1 is described as containing three sections:
- Web Application Pentest
- Network Pentest
- Active Directory Pentest
However all three sections, even the “AD” one, contained webapps. I don’t know why, perhaps whoever designed this exam at TryHackMe HQ is a ‘Webapps Guy or Gal’. That’s fine, we all have our niche, but they should clearly describe PT1 as primarily a webapps exam.
After all I don’t pretend that Mishky’s AD Range is anything but Windows. It even automatically spins up and configures on Hyper-V, as I have clearly described.
Overall Exam Scoring
- Web Application Pentest: 400 points
- Network Pentest: 360 points
- Active Directory Pentest: 240 points
The AI grading is similar to SAL1, in other words the more you copy/paste into the box the better. The AI simply seems to be looking for certain keywords. I wrote an actual summary in language that management might understand and the AI grader dinged me for it. I suspected it would, but I also knew I wasn’t going to pass the exam as a whole anyway.
Summary
PT1 was essentially a webapps exam. Hence if you are a ‘Webapps Guy or Gal’ then you will probably love TryHackMe’s Junior Penetration Tester (PT1).
However if you are a ‘Windows Guy’, a ‘Python Guy’, ‘Linux Guy’, etc then you might not. I knew going into it that I wasn’t going to pass the overall exam given it’s heavy focus on webapps. I started out with the AD portion and had Domain Admin pretty quickly, in about 3 hours. I finished PJPT faster, but CRTP and the CRTP Renewal Exams both took a LOT longer. Those exams also involved actually enumerating AD, moving laterally, and things like abusing DACLs, PTT, abusing MSSQL, abusing AD CS, etc.
SAL1 had SOC simulations included in TryHackMe’s regular subscription. These let you know what you were getting into and how TryHackMe’s AI graded you. PT1 lacks this.
That said, TryHackMe could easily fix this tomorrow, mostly, by splitting PT1 into three separate exams/certifications and then bestowing something like the ‘PT1 Master’ title on those who pass all three. This would also make three exams that could be 12–24 hours each rather than one 48 hour marathon session.
If they did that then they’d also have exams and certs that aren’t webapp focused.
Oh, and they should actually put some AD security into the Active Directory Pentest portion of the PT1 exam. My original intention in creating Mishky’s AD Range was to put it on TryHackMe. However they limit free rooms to only one VM, hence I put a mere shadow of the range in a TryHackMe room. The full version lives on GitHub.
References
PrintSpoofer explained: https://medium.com/@laurent.mandine/%EF%B8%8F-printspoofer-how-attackers-hijack-privileges-in-windows-networks-f188ff491e31
Dangerous Rights cheatsheet: https://happycamper84.medium.com/dangerous-rights-cheatsheet-33e002660c1d
Creating legitimate backups of NTDS.dit IOT dump them offline: https://medium.com/@happycamper84/securing-ad-backups-8804b31da9fd
