#pt1

1 messages · Page 7 of 1

worldly wadi
#

I will say some part is CTF-ish

#

as I passed it recently

sour portal
worldly wadi
#

It will sound like a rant

sour portal
#

yes plz

sour portal
worldly wadi
#

I start learning cyber sec last year in late Feb

#

So I finish 101, Pre Cyber, Jr Pent, Web, Web Pent, some part of Red Teaming in 3 months

#

I bought PT1 in May

#

but didn't take it, thinking I was not ready

#

so I took CRTO, got 100/100 after failing 4 times

#

got CRTP, CESP-ADCS, then 1 month prep for CBBH -> got CBBH

#

got Hackviser CAPT, CWSE -> then CRTA from CWL (it is the worst cert, don't bother)

#

then HTB CJCA -> CRTeamer

#

then I'm prepping for OSCP, as we are speaking

#

I figured, my PT1 voucher is expiring soon, so why not?

#

the curriculumn is the same for OSCP and PT1

#

I took it

#

the web pent is quite realistic

#

it is more akin to a Bug Hunting play ground

#

I like the web pent

#

basically you just think about what you don't supposed to do, and ask yourself like, wait, what if I can do that

#

and you try it, if it works? Grab flag.

#

web pent is the hardest

#

the Net Pent and AD is not hard but tricky/CTF-ish

worldly wadi
#

because I have prior prep and certification, it was kinda smooth for me, took less than 24h

#

but I suspect if you only do THM suggestion alone?

#

I don't know

sour portal
worldly wadi
#

like I said, it is very akin to OSCP, so not really a beginner thingy

#

the most beginner friendly right now is eJPT, heavily metasploit usage

sour portal
worldly wadi
sour portal
lime fulcrumBOT
#

Gave +1 Rep to @worldly wadi (current: #1761 - 3)

worldly wadi
keen sleet
#

If you have a #sal1 or #pt1 cert, contact me or a moderator to receive your special role!

humble needle
#

hello I have a suggestion to ask

#

actually I bought PT1 and hopefully after reviewing I will write my exam by next month ending

#

but the thing is that will I really get into a company with that

#

To build a strong foundation in cybersecurity, I proactively pursued hands-on experience through a 4-month internship at a local cybersecurity firm and a 2-month research internship under a professor. I also independently created and maintained a home lab environment to develop my technical skills. My primary focus is on continuous learning and growth within the field.

I am highly passionate about cybersecurity and deeply committed to building a career in it. As part of this commitment, I am going to obtained the pt-1 certification to validate my foundational skills.

I am now seeking an entry-level position where I can contribute to a team, learn from experienced professionals, and continue to develop. My goal is to join a company that will support my growth and enable me to pursue advanced certifications, such as the OSCP, in the future.

#

if anyone knows the answer then please do reply

#

thank you

north plank
humble needle
keen sleet
#

Skills, a degree, hopes and prayers. kek

lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #25 - 448)

jolly light
#

I am currently taking the PT1 exam and am unable to access the AppSec target.

Details:

Exam: PT1 (Web Application Pentest – TryBankMe)

Target: 10.200.150.100

Network state shows Healthy & Active

I have tried AttackBox (multiple restarts and full lab reset)

The web application does not load in the AttackBox browser

curl and browser access to http://10.200.150.100 consistently time out

I have waited sufficient time after resets and ensured only one connectivity method is used

It appears the AttackBox is not properly routed into the AppSec/DMZ network, despite the lab showing as active.

Could you please:

Reattach or reprovision my PT1 lab network
or

Advise on the correct fix if this is a known PT1 infrastructure issue

Thank you for your help.

keen sleet
#

The only reason this usually happens is if you spammed the network.

valid warren
valid warren
worldly wadi
#

Especially the blue section

valid warren
worldly wadi
valid warren
lime fulcrumBOT
#

Gave +1 Rep to @worldly wadi (current: #1422 - 4)

gritty trail
#

PT1 is hardest than VHL Pro 🤔 ?

silk verge
#

Tryhackme Just released a new beginner cert. Wow 😲

dull bronze
#

Is it necessary to remember commands if u want to go for certification exam.

loud belfry
#

i would say it would be good to remember them

pallid schooner
# humble needle but the thing is that will I really get into a company with that

There is no certification that will reasonably get you into the industry of cybersecurity on its own. Not even a degree will guarantee that except in a minority of circumstances. Companies hiring for cybersecurity generally want experience in other fields first (Helpdesk, sysadmin, NOC). The highest chance of getting straight into cybersecurity is SOC, but usually even there they want IT experience first. If you can, try to get into an entrylevel IT (or related) role while you take certifications.

humble needle
gray zinc
# humble needle So how to get into the industry

I’m not sure what your background is but start with the basics. Learn how operating systems work. Learn about basic network fundamentals. Then try to pass an entry level cert through CompTia or ISC2 CC. This might open a door for you to Try get a job at Best Buy (Geek Squad) or a Help Desk Tier 1 position with a company. If you don’t have any prior experience the best place to start is in one of those positions. Also, if you currently are working reach out to your companies IT dept and make friends with someone. Most companies are willing to trust their own employees if they don’t have any prior experience.

lime fulcrumBOT
#

Gave +1 Rep to @gray zinc (current: #3587 - 1)

gray zinc
# humble needle Thanks bro

You’re welcome. Two words of caution. Be careful of the certification trap. Too many people are chasing paper validation. While I believe certs are important they are really more foundational and built on rote memorization of theory. What we need the most is a combo of theory and practical skills. Second thing, don’t skip the basics. No really DON’T SKIP THE BASICS. Most people want to run right to hacking without a solid foundation in the basics. So regardless if your choice is the red pill or blue pill 🤣 you still need to understand how operating systems work. Kernels have vulnerabilities and to defend a companies network you need to understand how to research them and protect against them 🤓. You need to learn both Windows and Linux based operating systems. This will help you understand the folder structures, file management, registry entries, environment variables, bios, and firmware. You need some familiarity with hardware components hard drives, usb ports and ram! Also, you need to start learning to navigate the command line interface (cmd for windows and terminal for Linux). Learn how PowerShell commands work. You’re going to need them for either direction. Good luck my guy cheering you on!!!

loud belfry
peak elm
true fiber
#

Hello everyone, I'm currently doing my pt1, the AD section.
However, the host is down, is anybody having the same issue ?

#

@gritty lantern

keen sleet
#

You'll have to contact the support team. You pinged a bot.

true fiber
keen sleet
#

By the time they reply, it'll be done, but if it's really an infrastructure problem, they'll give you extra time.

true fiber
#

Well network completely unavailable now, hopefully they're fixing it now

#

Nevermind, still down 🙁

vale granite
#

yo guys what are ctfs/challenges i should complete before I do PT1

vale granite
worldly wadi
vale granite
#

what i found what i lesrnt etc, on a serperste nano file

worldly wadi
#

Hope is not a good strategy

#

Though

vale granite
worldly wadi
sour portal
worldly wadi
#

I gave a thought in about it, I think if you don't mind MCQ, maybe do Sec+ from Comptia

#

good for HR recognition

burnt pendant
#

MCQ is shit for exams though.

worldly wadi
tender flare
worldly wadi
#

Of course everyone wants OSCP, but I can't recommend it to newbies

tender flare
#

https://pwnedbyjt.github.io/

this is my honest opinion grind track hack (thm 1st) and then hack the box, i have had sec plus for years never helped, im not trying to bash but i am speaking from experience, if you can get comptia certs funded then i would do them then still prefer thm!

worldly wadi
#

like a global standard thingy

tender flare
#

^

sour portal
lime fulcrumBOT
#

Gave +1 Rep to @worldly wadi (current: #1210 - 5)

sour portal
#

probably why i don’t think ill ever go for CEH cuz id rather have 2 practical certs than 4 theory ones

worldly wadi
#

go for CEH Practical

sour portal
#

and with practicals it actually motivates me to keep studying since i get to tryout the stuff myself

worldly wadi
#

it is like PT1 but easier

sour portal
worldly wadi
#

the knowlegde is not, as I'm preparing it right now, it is like intermediate level

#

what is hard about it is that you have to go beyond what OffSec teaches you

sour portal
worldly wadi
#

and walk the walk

sour portal
#

i NEED this pt1 ngl

#

like NEED

worldly wadi
#

to prove to yourself you can do this huh?

sour portal
#

my course has a placement year, if by then i’ve stacked up certs already

#

there should be no doubt i’d be struggling to get a good job

worldly wadi
feral steppe
#

To anyone who passed PT1
Is JR penetration tester path enough to pass PT1 or do i need to study any additional stuff blobheart

golden rapids
# feral steppe To anyone who passed PT1 Is JR penetration tester path enough to pass PT1 or do...

While I don’t have PT1, I’ll still give my 2 cents

It’s made up of 3 sections

Network, Web App, and AD

Long story short, the Jr PenTester path is not enough. It helps with the basics of web app (and I think some of AD) but if you want a better time in the exam, go through the Web App paths and the Red Teaming Path (outdated and needs updating but is still very knowledgeable)

Would also recommend that you pair it all with home labs and supplemental learning*

lime fulcrumBOT
#

Gave +1 Rep to @golden rapids (current: #633 - 12)

worldly wadi
#

As I have recommend others to do this, I recommend you to do the same

feral steppe
lime fulcrumBOT
#

Gave +1 Rep to @worldly wadi (current: #1051 - 6)

worldly wadi
#

Can I say this ^ @keen sleet ?

worldly wadi
#

Them machines I recommended was good prep

#

I was able to finish the exam in 24h include sleeping time and slacking time

feral steppe
valid warren
lime fulcrumBOT
#

Gave +1 Rep to @worldly wadi (current: #944 - 7)

valid warren
lime fulcrumBOT
#

Gave +1 Rep to @worldly wadi (current: #864 - 8)

valid warren
worldly wadi
#

it is good prep

lime fulcrumBOT
#

Gave +1 Rep to @worldly wadi (current: #792 - 9)

balmy canopy
#

@valid warren I passed the PT1 three weeks ago, but I have only done 34% of the Web App Pentesting Path. So it is not required (I think most of the "new" techniques learned there are not necessary for PT1).

But it's hard to give generic advice on how to prepare without knowing what you have done before. I have been doing THM since AoC 2021 and finished a lot of rooms (350+) during the years. I think the most important thing, especially for web, is to get as much experience as possible (i.e. challenge rooms). So doing the whole Web App Pentesting path gives you more web hacking experience, so in that regard it is useful. But you may then need to learn new techniques in that path that is not needed on the exam (but of course useful later).

For my preparation I did all (and repeated some of) the rooms in Recommended Learning in the months before taking exam.

valid warren
lime fulcrumBOT
#

Gave +1 Rep to @balmy canopy (current: #3601 - 1)

past crypt
#

Guys, I need some push here, idk if im ready to start my pt1 exam. I will share what I have done so far -- hope you guys can judge if I am ready for it or still need practice

I finished portSwigger labs (85%)
Can pwn easy machines, would struggle a bit with medium machines
Scored in a VDP
Reported Crits in my company
AND finished Recommended path

I still feel insecure about taking the exam

pliant bear
past crypt
#

Yes

pliant bear
past crypt
#

Yh.... I can handle web, linux and windows machines. AD is what's got me thinking twice.

pliant bear
past crypt
#

Okay

burnt pendant
past crypt
burnt pendant
past crypt
#

Nice, atb man!

burnt pendant
past crypt
#

There's just alot to take in with AD

#

I've done some amount of machines in AD, and I'm still insecure if I'm good enough in it

burnt pendant
#

Oh I meant the exam.

past crypt
#

You started the exam?

#

Is AD hard? Or just a simple machine?

burnt pendant
#

I didn't find it challenging.

past crypt
#

How did you prepare? I mean how much prepration was enough?

#

Idk if I'm just over preparing at this point.

burnt pendant
#

Oh...

I've been hacking since the early 00's kekw

past crypt
#

Damn, holy. You must've shook hands with Jesus .

burnt pendant
#

Nah, I'm not that old.

#

I started young.

past crypt
past crypt
burnt pendant
past crypt
#

Hmm, I see.

#

Yh well, I'll take a leap of fath next week

#

I'm sure I'll figure it out.. but, still insecure yk. This would be my first ever certification.

burnt pendant
#

To help paint a picture, I'm a former room tester (and community mentor and mod) for thm, so I know how some of the employees do stuff.

Which helps.

past crypt
#

Ah I see

#

I can handle easy machines, i pentest my company's WebApps.

#

You sure I can handle it right?

#

🫠

burnt pendant
#

You'll find the web app a doddle then.

It won't be any different

past crypt
#

I scored in VDP's, and finished 85% portswigger labs thoroughly

#

Yh, I'll start next week.

#

Thanks for this push

#

🙂

worldly wadi
ivory widget
#

is PT1 procted like pen200?

keen sleet
rugged stratus
#

any updates on physical certs or the special package for the first 100 to pass?

burnt pendant
keen sleet
#

Nope, sadly I can confirm they were not. I'm part of the first 100, and I just had an email confirming I was part of the first 100 (after I emailed first), but then nothing ever after.

rugged stratus
#

Yeah i had my email from support confirming but no follow up

rose echo
#

Hello guys im interested to get PT1 any advices ?

deep mirage
lime fulcrumBOT
#

Gave +1 Rep to @deep mirage (current: #2342 - 2)

pearl ingot
#

does the name need to be written in english ?

pliant bear
pearl ingot
pearl ingot
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #24 - 474)

pearl ingot
tidal palm
pearl ingot
lime fulcrumBOT
#

Gave +1 Rep to @tidal palm (current: #3643 - 1)

pearl ingot
tidal palm
#

👍

burnt pendant
tender flare
#

What are all the resouces to pass PT1?

#

I hope this cert can act get me a job unlike sec+ and pentest+

worldly wadi
#

Only OSCP, maybe

#

Even OSCP might not

worldly wadi
worldly wadi
worldly wadi
#

PT1 was a good prep for OSCP though

rugged stratus
worldly wadi
#

at least in my experience

formal solar
#

pt1 vs cpts
which one i should choose?

keen sleet
#

2 different levels, you can't compare.

formal solar
#

which one is tougher?

left helm
#

CPTS is tougher but PT1 does a good job at pushing/testing your skills

#

PT1 does a good job at testing your breadth of skills. I think CPTS is just deeper for your network pentesting.

rugged stratus
umbral totem
#

Just to save me time, I did eJPT and have a really good understanding of web. Besides for report writing and AD, are there any topics I should be sure to hit before taking PT1

worldly wadi
left helm
#

@worldly wadiYeah I said it was. I just also said PT1 does a good job at pushing your skills.

left helm
#

All good

worldly wadi
#

Toughest of them all

#

OSCP is more like, HR filter

pliant bear
sterile geyser
thorn herald
#

Hi guys.
I don't know if I am ready to make my PT1 cert. Currently, I'm here. 75% I know what I'm looking for, etc. I'm also done with Love at First Breach CTF (not the advanced one... that was insane for me, or I overthink the whole "game"), and the same goes for The Advent of Cyber event. I'm transitioning from kitchen to cybersec, but I haven't had any luck finding a job.

rugged stratus
plain jasper
#

hi guys can anyone help? i won a 30% off for the pt1 and on the website there is a 20% off for the subscribers dose the discount stack?

burnt pendant
#

Probably not.

fierce cobalt
#

Hey guys, does this mean I got the cert for free?

#

Hello hernei7

You’ve got something coming your way. Not romantic. Just well earned:

PT1 Certification
Whether this was luck, skill, or just impeccable timing, consider it a small reminder that good things happen when you get involved.

keen sleet
fierce cobalt
#

The email also said this
No action needed from your side, we will reach out in the coming days with more details on receiving your prize.

#

I ve to wait, it was 2 days ago

rose echo
fierce cobalt
#

Yeahh I look up my name in the winners section and I was there I am so happy

rose echo
#

congratz mate !

rugged stratus
# quasi turtle Pt1 or pnpt?

Well this it is hard to recommend the PNPT at its price point when theres other certs at better prices points with better content

split pivot
#

so where’s the PT1 package update

thorn herald
sterile geyser
burnt iron
thorn herald
cedar latch
#

Wassup yall Good afternoon I am currently working towards my jr penetration tester certificate. I want to complete it in the next few months but I want it to show under my thm account that I am on the path to take the exam seeing that I paid for it any can help me understand why it doesnt automatically show when we pay for the exam ? or do I have to enroll in the path first.

rose echo
cedar latch
rose echo
cedar latch
ivory widget
#

querstion for pt1 if you've passed oscp is it much the same or eaiser?

worldly wadi
ivory widget
lime fulcrumBOT
#

Gave +1 Rep to @worldly wadi (current: #756 - 10)

worldly wadi
gaunt brook
#

o

wispy relic
#

Anyone who won the free cert, they already gave you it? I’m still waiting😅

merry bone
#

@novel coral @ebon creek hey .

Today I took the PT1 exam. However, TryHackMe’s system failed me. It rejected my valid reports and did not award me any points. If the points had been given correctly, I would have passed easily.
Please help me with this.

merry bone
#

Any other senior or manager email?

keen sleet
#

Of course you won't get a reply in under 24 hours, exam investigation might take weeks.

rose echo
tender flare
#

Just curious does htm box have a course for oscp?

ebon creek
#

I mean not specifically but some topics are covered in Jr.Pentester path

tender flare
#

would be nice if someone made one!

crystal coyote
#

When taking the PT1 exam, will we be able to complete the exam from the web-based Kali or Attackbox?

tropic fjord
ebon creek
crystal coyote
#

thank you both

regal moth
#

I'm trying to start the PT1 exam and the onfido verification process is failing immediately "Your verification has expired Please restart the process and try again." I have tried multiple devices

regal moth
#

I sent them an email. I saw in a previous message that support doesn't usually work on the weekends. Am I pretty much out of luck until Monday?

keen sleet
#

Unfortunatey, yes.

worldly wadi
#

I believe we talk about it before

#

yes THM has one of the path that designed for OSCP

#

this whole path was designed around old OSCP, with Buffer Overflow to new OSCP+ with AD pentesting

worldly wadi
# ebon creek No

yes actually, the BOF room in the learning path actually use a binary called OSCP.exe for each of its task.

keen sleet
#

That path was super easy, was that the level of OSCP back then?

worldly wadi
#

but the thing is - at least in my experience - OSCP is more like

#

Obscure vuln-ish ?

#

many things that you might not seen before

mint cipher
#

I am currently going to try for the PT1 certificate but want to make sure my skill are ready for it. Are their any specific rooms, CTF or B2R, that I can take to check if my skills are up to par?

burnt pendant
mint cipher
keen sleet
#

A machine that has everything for PT1 does not currently exist.

bleak tangle
#

starting my pt1 exam tommorow (1st attempt) and im anxious about having potential connectivity or similar issues. i'll be working on my own machine, since i hear i get a seperate .ovpn config for the exam, do i need to first connect to my account .ovpn and then to the one specific to the exam, or is the exam config file the only one needed?

#

also, i see resetting the network is an option, what should be my signal it's time to reset the network? don't wanna spam resets when unneeded
and if i accidentally overload the network and run into some issues not related to vpn, what would be the recommended action - leave the network chill for 20ish mins, reset it, switch to attackbox?
sorry for the too many questions, just anxious about tommorow and i wanna be ready for whatever may come

ebon creek
bleak tangle
#

you mean, when i start the exam i can download the exam-specific vpn config file and i dont need any other vpns? oh, and thanks for the reply! 🙂

bleak tangle
bleak tangle
#

good to know, thanks a lot

tender flare
#

will these three be good enough for pt1?

burnt pendant
worldly wadi
bleak tangle
#

I did some basic stuff with ligolo-ng on my exam now and immediately network state became inactive. And VPN is doing soft resets now...
Should I reset the network? Regenerate vpn config file? Just wait? contact support?
Will my flags become invalid now?

#

what is happening 😭 it still says network unavailable but i can easily access all the machines, even the flags remain the same

Refreshing dashboard gives: The network is currently unavailable. This may be due to maintenance or a temporary issue.

Please try again in 15 minutes. If the issue continues, contact support.

bleak tangle
# ebon creek Try to refresh webpage

refreshing didn't help. Even hopping between network, ad and appsec gives same result.
I can for now access all machines, the flags are the same, even the files i left on some machines are still there. What I'm worried about is that status on dashboard, last thing I would want is to write a full report and submit exam, just to get 0/1000 because flags regenerated or something...would love to get this sorted
I sent support a ticket, hopefully this gets sorted

bleak tangle
#

question, if i leave my network as-is: let the Network State: Inactive be as it is, and if I find the flags and write report, and submit exam before network goes up...will my flags be valid?

I mean, since every VM is working nicely and VPN isn't logging weird, and I can continue with the pentesting, I wouldn't want to reset the network and do crazy fixes unless the flags could be invalid

ebon creek
bleak tangle
#

if it's all good i'll open up another ticket to support to let them know they don't need to mess around with my prev. issue (since it's resolved) wouldn't want the possibility of them changing up something that's working

bleak tangle
#

Wow, I literally was just chilling at the dashboard and then network state changed to Restarting...after some time it again turned to Inactive
every machine, everything is working good.. why is the dashboard doing that bruh 😭

bleak tangle
#

One question, if I forget to submit my exam, what happens? Do I fail or does the latest saved report upload itself?

ebon creek
bleak tangle
lime fulcrumBOT
#

Gave +1 Rep to @ebon creek (current: #1 - 6126)

bleak tangle
#

thanks yall

pure pumice
#

How long can you have a purchased pt1 without doing it?

tropic fjord
pure pumice
#

Thanks!

crystal coyote
#

does the PT1 exam have one target for each webapp, netsec, and AD (3 in total?) or just one target?

tropic fjord
crystal coyote
tropic fjord
ebon creek
crystal coyote
ebon creek
tropic fjord
keen sleet
burnt pendant
tropic fjord
hallow lodge
#

hi, with pre-security, cyber 101 and jr pentreation tester paths it's enough to pass this exam?

hallow lodge
#

okey ty

ebon creek
crystal coyote
#

how fast does support@tryhackme.com usually respond? I'm having issues for several hours and I'm not hearing anything back so far

tropic fjord
crystal coyote
tropic fjord
burnt pendant
#

If you mail again, you'll get pushed back down the queue.

tropic fjord
crystal coyote
#

I haven't heard from support for 9 hours and this is regarding an issue within the PT1 exam. Should I follow up? @keen sleet @ebon creek

burnt pendant
#

Support won't start until 9AM GMT.

#

Even then, they'll have a queue of emails.

keen sleet
#

Yep, probably no replies until next week as well. It's Friday and they have other mails to respond to today.

tranquil meadow
#

Anyone living in Switzerland? 🇨🇭 would be awesome to link up with someone else trying to learn all this.

tranquil sorrel
#

hello anyone, I verified my identity with my passport, and the website is loaded, but I couldn't proceed to the PT1 exam guidelines agreement. what should i do?

tender flare
#

man i missed the 30 percent off, i was hoping it would of lasted until end of day today i just got my birthday money 🙁

jade cloud
#

Hi, I'm 18 from Afghanistan 🇦🇫
I practice exploitation and Metasploit every night.
Looking for a study partner to solve labs together.

tender flare
#

Can you use owasp zap on pt1?

ebon creek
night skiff
#

@ebon creek so the discounted exam vouchers which we receive in the mail, lasts for how long

#

Before i can redeem it

ebon creek
night skiff
proven compass
#

is it possible that I was tricked with a flag? I found a flag in the room, but it doesn't fit

keen sleet
#

No tricks.

ebon creek
shadow nest
#

Assuming there are some people here who already finished the PT1 certification: How long did it take you to finish the exam, candidly?

I'm planning to do the exam in the next months and I would be glad to know much time one needs for the actual assingnment.

burnt pendant
#

I finished the exam in 3.5 hours, however i spent longer verifying my findings, and ensuring my written report was top notch.

keen sleet
#

This is not allowed and breaks THM ToS. This gets you banned from here and the platform.

wispy relic
#

any recommended way to practice before taking the exam?
I completed the jr pentesting path long time ago and not sure if i remember much over there

clear hound
#

Hey, I'm having an issue with the PT1 exam check-in. When I reach the Onfido ID verification step and click "Start verification", it says "Your identity verification has expired" and I can't proceed. I've already submitted a support ticket but wanted to flag it here too. Has anyone faced this? Any help appreciated! 🙏

ebon creek
clear hound
wanton adder
#

Can I give a promo code that I won

ebon creek
night skiff
#

Cool

lyric topaz
#

Hi! Probably a stupid question however I read some reviews where it was stated that eJPT holders can sometimes get Pt1 vouchers for free. Is this actually true or some internet gibberish 😅

prime valley
lyric topaz
#

Thanks!

lyric topaz
dusty siren
#

I was about to try and take the PT1 test, and it say that I should use a desktop. Is it okay if I take it on my laptop?

lyric topaz
#

@ebon creek can I shoot you a DM real quick for some clarification?

ebon creek
lyric topaz
#

Not an issue, just a clarification on what can be posted on blogs/write ups after cert compeltions ( Medium for example )

#

If permitted at all

lyric topaz
burnt pendant
#

That would be ok, otherwise thm would have taken blogs like that down.

stuck jolt
#

Not that that's an answer dump, granted.

burnt pendant
pearl ingot
#

can i upload screenshots during the PT1 report ??

#
  • what are the working times that the support respond in ?
pearl ingot
#

wish me luck i'm taking the pt1 tomorrow cri

ebon creek
lime fulcrumBOT
#

Gave +1 Rep to @ebon creek (current: #1 - 6162)

pearl ingot
#

i sent email containing the parental consent and i won't click accept in the guidelines until they answer

#

do they respond in email the same as in tryhackme bot thing

#

?

#

@ebon creek

#

@keen sleet

#

i dont know what im supposed to do until they respond

keen sleet
#

You probably wait until then, you'll also get an email

pearl ingot
#

oh so it takes from the time ?

#

😢 @keen sleet ?

#

i dont understand it takes or not

keen sleet
#

Shouldn't take :]

pearl ingot
#

thanks

brisk canyon
#

Helo I had PT1 Voucher received during the launch of the Certification since i was ejpt certified and due to some personel reasons i couldnt take the PT1 Exam and the voucher got expired. is there any option to avail this offer now. Any help would be greatly appreciated

keen sleet
brisk canyon
#

i think i had to take within few months i dont remember exactly but im sure not a year of validity

keen sleet
#

Worst case was 6 months. I won the voucher the same way.

brisk canyon
#

No it was only 2 months for me till Aug 30 2025

#

Got the voucher in June 17 2025 and Validity till Aug 30, i have mail communication as proof

#

i was pretty occupied during that time and couldnt take the exam

keen sleet
#

Ah well too late then. I think we are way past that

#

Maybe if you have had emailed them back then, bit now we're like almost a year later

fierce cobalt
#

Hi I won a full pt1 certification during the love at first breach event, however I only received 1 email saying the team will be contacting me, but more thant one month has passed and I never received more details. I would like to have more info since I don't know when it will expire

keen sleet
fierce cobalt
dusty siren
#

Quick question. I failed the pt1 (pretty miserably lol) so I can retake it again any time until the expiration of a year after I bought it, but I have to wait 2 or 3 (I don't remember) days before I can take it again.

dusty siren
#

Thanks!

opal mauve
#

Guts sal2 is coming before our physical certs xd

burnt pendant
keen sleet
opal mauve
keen sleet
pearl ingot
#

finallly i i passed the pt1

#

🎉

#

can i get the role

ebon creek
lime fulcrumBOT
#

➕ Gave the role PT1 to dash10102

tender flare
#

so when are we getting a pt2?

bleak vessel
clear hound
#

Hey, I passed PT1 (it was pretty challenging 😅), but I still see that I have another attempt available and can start the exam again.

If I retake it and fail, will that affect my current “passed” certification in any way? Or does the original pass stay valid regardless? I just want to re-take the exam because it was such a challenge for me.

vale granite
clear hound
vale granite
lime fulcrumBOT
#

Gave +1 Rep to @clear hound (current: #3703 - 1)

tender flare
burnt pendant
#

We spoke about PT2 before PT1 even launched.

tender flare
#

lol

#

I feel like there needs to be a PT0

#

Just kind of throwing me off with the sec0

burnt pendant
#

Well, SEC0 isn't SAL0.

vital remnant
#

I think the next Red Team cert should be related to Web Security since there isn't one yet?

burnt pendant
#

PT1 has a web app section.

vital remnant
#

Yeah but like a whole cert just to Web, like the CWES from HTB

#

Cause THM has three paths dedicated to Web but no Web cert

dusty siren
silk nexus
#

can we use ai such chatgpt or gemini to advice us during test?

#

and what is scope of test I dont know how can i imagine it, it is some lab, where i should attack machine, and root it or what does it meann? how many machine, or tasks are there, or is there more info about exam like this?

burnt pendant
silk nexus
burnt pendant
keen sleet
orchid flint
#

im doing the pt1 cert and get this error:

Network resetting

The network was recently reset and machines are rebooting. Please wait up to 15 minutes before continuing your investigation. 

While flags repopulate, you can review notes or work on you report.

If this status persists beyond 30 minutes, contact support.

I got before this a similar error.
Another question, is it a problem if the flags changing during the exam. I recognized that a flag changed for the same vuln.

dusty siren
tight anchor
#

Hi

vale granite
#

How many of the pathways should a person complete before attempting this test?

burnt pendant
keen sleet
#

Anybody got any email update on the promised PT1 packages from 1 year ago to the first 100?

cobalt mango
#

anyone has issues with attack box not connecting the the server while taking exam?

fathom stirrup
#

O

vagrant pivotBOT
#

Done!

keen sleet
#

If anyone else has one, please send over.

#

I have this:

#

I remember there was another one on the page itself detailing what the package had.

vagrant pivotBOT
#

:hammer: not_starkid#0 has been banned.

fluid perch
#

If my voucher expires the 21st, can I start the exam that exact date or would I have issues the next day with the lab env?

keen sleet
#

You can, but don't. Most people regret doing this because sometimes they encounter issues and need to contact support.

#

Good practice is to never do an exam last minute.

fluid perch
#

Got it, thanks!

lime parcel
#

It wasn't easy 😁

ebon creek
willow jacinth
#

are we going to have a pt2?

ebon creek
left helm
feral walrus
feral walrus
lime parcel
# feral walrus how long u take?

It took me about 16 hours to complete the entire exam. It would have been faster if I had read the description more carefully.

nocturne rover
#

how long u take to reach from start to Penetration Tester

#

can You tell me?

lime parcel
burnt pendant
rigid gust
#

Idk if I’m allowed to ask this but what do you think about eJPT or PT1 and its social impact ?

keen sleet
#

Social impact?

rigid gust
#

i mean if HR or any person with brain will know what to evaluate

keen sleet
#

Both of these certs have no HR value

rigid gust
#

even for jr lvl ?

keen sleet
#

Yes

#

OSCP is required for juniors

keen sleet
#

Update on PT1 Packages

opal mauve
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #22 - 526)

scenic light
#

.

hollow fjord
#

pt1 is such a drastic jump and there wasnt even any practice sessions in jr pt path

brittle eagle
#

I am having incredible network issues on the webapp part..

hollow fjord
#

me too

#

it wasnt booting up for an hour for me

#

now its just not sending requests

brittle eagle
#

tried resetting the network several times, never helped, when It comes up I cannot even enter it, just fails or timeouts

#

yeah

hollow fjord
#

it genuinly feels like they just want ur money

#

it costs so much and its so slow

#

and such a drastic jump in difficulty

#

i trained for a week after finishing pt1 made notes

Im using obsidian to take notes on endpoints on the webapp and I only found i vuln after 24 hours


brittle eagle
#

yeah, network part was done in like an hour and the webapp is overkill, and it doesn't work again

#

i managed to finally create a user after like an hour

#

still getting timeouts

keen sleet
brittle eagle
#

Thank you, I contacted the support

hollow fjord
#

I am struggling with THE ENTIRE TEST, what rooms could I take if I fail

#

I already did the L0VEATFIRST_BREACH challenges for webapps

brittle eagle
#

I don't know how to feel about the webapp :D think I found 4 possible vulnerabilities but no flags

hollow fjord
hollow fjord
#

pt1 is lowk too hard (imo)

#

whatever

#

thats why you get a free retake

alpine pond
#

Hello guys, I'm a student of the 4th information security course, and I started taking THM courses, but after a few modules I was faced with the fact that I need to buy a course to continue, what do you think? Is it worth it? I'm just starting my journey in this area and I want to go to the end.

red delta
fiery viper
keen sleet
fiery viper
#

Okay thanks. I have pt1 voucher and I have to start prep from zero. I am aiming to attempt the exams in 3 months.

Do you have any suggestions for me? How should I prepare and what should I learn? Is the suggested jr pentester path enough?

keen sleet
near tree
#

Hello, friend. If you are referring to the premium mode of tryhackme, I would advise you to buy it. It is very affordable, and the learning material has very good quality. But if you are referring to the certificates like PT1, SAL1, etc., you should buy them for improving your knowledge but not for HR value as there are better certificates for that.

keen sleet
#

This is an english-only server.

brittle eagle
#

how long does the resource provisioning take sadcooctus it was instant in SAL1 and PT1 first attempt, now I'm waiting for an hour already

keen sleet
brittle eagle
fiery viper
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #21 - 530)

brittle eagle
#

is it some kind of an error when both flags are identical in AD part of PT1? monkaOMEGA

#

I am pretty scared to submit them when they are the same

keen sleet
#

Contact support with video proof and screenshots.

brittle eagle
brittle eagle
#

yeah I guess I won't get the answer before my PT1 timer ends

brittle eagle
#

yep, even though they were identical the second one wasn't correct :D

keen sleet
brittle eagle
feral walrus
brittle eagle
#

Did the exam on 2nd try though, first time I found some vulnerabilites in the webapp that did not award a flag, submitted it with 2/4 flags in the webapp and I failed by few points

feral walrus
brittle eagle
#

It's good when you get to a position where you don't just do SOC L1 work, when the work gets more diverse you learn a lot of new useful stuff

feral walrus
lone wraith
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #20 - 533)

solemn vine
#

Hey guys

#

I'm new here
To the try hack me

cold pike
#

Super happy to share that after failing the PT1 my first try by 19 points, It was reviewed and I have now passed!

can I please have the role?

keen sleet
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #20 - 534)

red delta
cold pike
# red delta well done, any advice for people?

Thank you. My advice is that the web portion requires deeper learning than what is provided by tryhackme in the recommended learning, or at least the web application red teaming path should be a pre req. I would do some portswigger academy labs covering common web vulnerability topics. But for the perimeter network boxes and AD, the recommended learning is more then enough and the boxes and ad environment is really straight forward. The web part IS NOT A CTF. Focus on vulns with real impact to users. Im not sure what else I could say without giving away too much. But do a ton of web practice because thats the part everyone struggles on, including me from my experience. Best of luck to everyone!

lime fulcrumBOT
#

Gave +1 Rep to @red delta (current: #1262 - 5)

red delta
lime fulcrumBOT
#

Gave +1 Rep to @cold pike (current: #2435 - 2)

silk ridge
#

Hello guys

#

I am doing revisions in pt1 path. In the net-sec challenge room, is it normal to give hours to get the password of Eddie and Quinn?

#

I also want to know if I take the exam, do I need to wait hours to just get the passwords?

near tree
silk ridge
#

Ah! I forgot to add port number for ftp 😂

prime halo
#

anyone facing issues - were the machine ip address doesnt appear even after starting the attackbox in excercises ?

fathom stirrup
#

Ho

dire needle
#

I'm currently taking the PT1 exam, but do I need to attach screenshots to my report? I thought they were definitely required, but I can't seem to attach them.

wooden jackal
dire needle
lime fulcrumBOT
#

Gave +1 Rep to @wooden jackal (current: #267 - 41)

ebon creek
vagrant pivotBOT
#

Done!

feral walrus
#

For how long do u guys prepared for PT1 ? And the level of ur experience in cyber security?

red delta
dire needle
# feral walrus For how long do u guys prepared for PT1 ? And the level of ur experience in cybe...

I passed PT1 today.
Starting from scratch, I worked through the recommended study path, which took me about 200 hours.
Since English isn’t my first language, and I struggled with the practice questions in the latter half of the recommended path, it took me this long.

As for my thoughts on the exam, it was an incredibly fun experience. It took me eight hours to earn my first flag, and I was overcome with the feeling that I might not pass. Some topics came up that I was encountering for the first time during the exam, but since the time limit is 48 hours, I was able to look things up as I went along. You get beaten up pretty badly at first, but it gradually becomes more enjoyable.
That said, the Web section is tough. I knew from prior research that the PT1 material alone wouldn’t be enough, so I supplemented my studies with PortSwigger. Even so, it was difficult.
In the end, I secured two flags in the web section. Based on the scoring, I thought I’d fail, but I barely passed with 757 points.

Next, I’m going to take on the CPTS.

red delta
karmic bluff
#

Hello everyone,
I’m currently preparing for a career in Security Operations Centers (SOC) and I would really appreciate your suggestions and guidance. I’ve previously interned with MP Police, which gave me some exposure to security workflows, but I haven’t yet secured an internship with a company.

#

I’m actively learning on TryHackMe and want to understand:

• Is SOC the right roadmap for building a strong cybersecurity career?
• What specific skills should I focus on right now to become job-ready?
• Which tools, technologies, or certifications are most valued in SOC roles?
• What kind of questions are typically asked in SOC interviews, and how can I prepare to clear them?

Any advice, resources, or mentorship would mean a lot. If someone is open to guiding me further, please feel free to DM me.

Thank you in advance for your support!

solemn yew
north burrow
#

This the one im studying forNotLikeThis

unkempt pumice
#

PT1 passed this morning, after 44h > 849/1000

Some errors and I missed one flag on the web part but it was interesting

unkempt pumice
#

Thanks ☺️

Someone had asked me to give some feedback and share a few tips :

I’ve been a DevOps Engineer for several years, so I already had a solid foundation in things like Windows, Active Directory, Linux, and networking concepts. I’m not going to reveal anything crazy, no secrets or anything like that, just state what seems pretty logical :

I mainly followed the rooms provided to prepare for the PT1. I started studying in February and took the exam this month. In hindsight, I probably could’ve taken a bit more time to practice, because there was one vulnerability during the exam that completely went under my radar and I never actually found it. With more training and experience, I probably would’ve spotted it.

What I’d recommend is to really go through the rooms properly and do them intelligently. The use of AI is kind of tolerated, but it should stay a tool to help you understand or guide you , not something that does the rooms or the PT1 for you.

I’d also strongly recommend completing the Junior Penetration Tester and Web Fundamentals paths.

And finally, practice report writing a lot, because it counts heavily toward the final score.

analog charm
#

Hello, everyone! I would like to be humble in sharing my recent conquest in PT 1 certification. After failing on it in the past year and back some steps before trying it retake again I could map what and where to focus my attention. I dedicate this victory to God, my family and all those who desire to achieve the best version of yourself and find and share knowledge. God bless you! Heart 🖤

Moving on to OSCP, KLCP and OSWP now! ✈️

hollow wigeon
#

How do I study for pt1, other than doing the recommended paths and modules?

analog charm
# hollow wigeon How do I study for pt1, other than doing the recommended paths and modules?

Good morning, @hollow wigeon. I highly recommend you follow the recommended learning plan, modules and CTFs suggested on the official site:

https://tryhackme.com/certification/junior-penetration-tester.

https://portswigger.net/web-security/all-materials

https://portswigger.net/training

I finished the recommended learning and I feel that it's enough to deal with the test. But, after two attempts I am quite sure about the further needs to feel more confident to deal with the Web Part.

My two times in this exam were filled with 4~5 hours reserved to the NetSec part followed with more 4~5 hours with AD portion, some nap, bath and carbo/protein reposition (because we are human after all hehe) and the other 30 hours against web part. Man, I highly suggest you and those that have been studying to learn Burp Suite, cUrl and OWASP top 10. The most challenging thing about it is to realize where the flagged vulnerability was configured in the lab. You will find some endpoints with weird configs and maybe putting Web Part to the last part is the best strategy to deal with time and anxiety.

I found 8 assertive flags and used 40 hours in total with this attempt and I'm comfortable to say that time management, reporting during each command and cheat sheets are gold to be successful on exams.

shadow nest
#

Hi there,

I'm currently doing the PT1 exam. Is it normal that the attack box does not have internet access? Luckily I found sharphound.exe on the AttackBox, but who nows which other tools I might need that are not yet on the AttackBox.

Best wishes,
Jonas

keen sleet
shadow nest
shadow nest
#

Hey @vagrant pivot,
I'm writing here because, apparently, even though I am a paying member, I cannot open more than one support ticket at once.

How can it be, that I pay a bunch of money for a PT1-Certification and I can't even work on the task without being kicked out regularly because the website is down (yesterday evening) or the AttackBox crashes. It just happened for at least the fourth time and for the fourth time everything I built and stored on there is gone and whipped away. Not to mention the time I loose each time because all the stuff has to be opened and started. In between, it regularly slows significantly down.

If you can't operate the infrastructure reliably, just say so, so people now the AttackBox is not suitable for serious tasks. But switching to VPN and downloading all the tools to my local machine while the exam clock is ticking is simply not viable. I'm frustrated and this make me angry. The exam by itself is challenging enough and being set back constantly (sorry I have to use such strong words) pisses me off.

shadow nest
#

Heyho,
does anyone know how to get the exam result reviewed by a person? I'm certain that the AI messed up some of the results and this has to be reviewed.

ebon creek
gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

snow beacon
#

Hey guys i need support since i think my environnement don't start correctly, i don't know why but almost all my flag don't return in the web part and now in the network part i can't do nothing, how can i make sure that the environment is properly up ?

keen sleet
topaz coyote
#

What is give me digital forensics road map @ebon creek

ebon creek
shadow nest
lime fulcrumBOT
#

Gave +1 Rep to @gritty lantern (current: #45 - 270)

fluid perch
#

Is someone trying the exam at this time? All networks are on the resetting stage and aren't available.

#

NVM, it appears to be working now

obsidian salmon
#

if i do buy the pt1 exam, does it have any training invloved prior to it? and if so, is it just more tryhackme modules?

ebon creek
obsidian salmon
#

Alrighty, thank you so much 👍

brittle eagle
twin wing
wicked helm
ebon creek
wicked helm
#

kk ty

#

🙏

brittle eagle
ebon creek
vale badge
#

Passed PT1 this past weekend!

left orbit
#

Was doing the Race conditions lab refreshed the page & it disappeared

narrow pasture
#

finished the exam last weekend and u wanna tell me that they revamped the whole exam learning path to a more practical path now lowk cryin

feral walrus
#

Well im very excited with this revamp

ionic sail
fiery viper
#

Asking this from anyone who has done pt1, do you think the revamped jr pentester path is enough to pass the exam?

And what do you think is the difficulty level of the exam for someone who is doing pt1 as their very first cert?

Your input is appreciated, thank you 🙂

red delta
fiery viper
lime fulcrumBOT
#

Gave +1 Rep to @red delta (current: #1117 - 6)

red delta
#

Let us know how it goes <3

fiery viper
#

Thanks, I'll be attempting that in late July or early Aug. Will definitely update here.
Btw, I'm a girl 🙂

red delta
#

lot's of time to study.

fiery viper
regal geyser
#

Attempted my first try here web sec is a bitch lol got a 700 😕

#

Honestly pretty good test though the difficulty is up there definitely understand web sec and and the AD part stumped me for a little there but eventually got it.

feral walrus
cold pike
strong lion
#

can someone please help me in Penetration Testing Frameworks task 9 Question 2

feral walrus
feral walrus
slim birch
#

All tickets collected 🎟️✅

inner stone
#

What's more worth it, PT1 or PJPT?

austere mesa
verbal prairie
red delta
verbal prairie
paper mica
#

I am currently giving my PT1.... I was about to finish AD section, I had access to workstation and was about to get to domain controller
But suddenly my commands were working, so I tried resetting the lab, and restarted my VPN. I then tried re-exploiting the workstation to get a shell, but it is not working.
Every port on workstation is shown filtered now, and above that! I even tried AttackBox (deactivated my openvpn so it does not conflict), but even in Attack Box it does not work!

Any admins can help me with this? Thanks