Home PNPT prep
TCM Security · 58 live drills mapped

PNPT practice,
one technique at a time.

Own the domain, then explain how you did it. The PNPT is an external-to-Domain-Admin engagement that ends with a live debrief — you don't just exploit, you justify. PwnKata drills the path it tests: a web or service foothold, the Active Directory attack chain toward Domain Admin, and the privilege-escalation reps in between, until the methodology is automatic.

Exam 5-day hands-on exam · external recon → AD → Domain Admin · 15-minute live report debrief.
Syllabus map

The PNPT skills, as drillable reps.

Each exam area maps to a set of single-technique drills you can grind until recognition is automatic.

Before exam day

Know you're ready — don't guess.

When the techniques feel automatic, run an Exam Sprint: a timed battery of unseen, blind items weighted to the PNPT blueprint. It returns a readiness report by skill area, so you find your weak spot here instead of in the exam.

  • Blind items — identify the weakness yourself, like the real thing
  • Solved-vs-attempted by skill area, with time outliers flagged
  • A readiness verdict you can actually act on
PNPT sprint readiness On track
External recon & web foothold 86%
Active Directory to Domain Admin 68%
Privilege escalation 44%
Service enumeration 80%
⚠ illustrative — your report is built from your own reps

Start your PNPT reps

Free to start — live isolated targets, a fresh variant every rep.

Start drilling