> For the complete documentation index, see [llms.txt](https://ganesha-hk.gitbook.io/offensive-security-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ganesha-hk.gitbook.io/offensive-security-writeups/my-certifications/pjpt.md).

# PJPT

## Practical Junior Penetration Tester (PJPT)

### A New Milestone in My Penetration Testing Journey 🚀

I’m excited to share that I have successfully earned the **Practical Junior Penetration Tester (PJPT)** certification from **TCM Security**. 🎉

This certification represents an important milestone in my journey toward becoming a penetration tester, but more importantly, it gave me an opportunity to move beyond learning individual vulnerabilities and start thinking about **how a real penetration test is approached from beginning to end**.

Before starting PJPT, I had already spent considerable time learning web application security, Linux, networking, Active Directory, and various offensive security techniques. However, PJPT helped me connect many of those concepts together into a structured penetration-testing methodology.

***

### What I Learned

The PJPT journey strengthened my understanding of several important areas of penetration testing.

#### 🔹 Active Directory

One of the biggest areas of learning for me was **Active Directory penetration testing**.

I worked on understanding concepts such as:

* Active Directory architecture
* Domains, users, groups, and computers
* SMB and Windows networking
* NTLM authentication
* Kerberos fundamentals
* Credential attacks
* Password spraying
* SMB relay concepts
* Windows privilege escalation
* Lateral movement
* Domain enumeration
* Understanding relationships between machines and users

The biggest improvement wasn't simply learning individual attacks.

It was learning **how information gathered during enumeration can lead to the next attack path**.

***

### Internal Network Penetration Testing

PJPT also helped me understand the mindset required for an internal network assessment.

Instead of looking at a machine independently, I started thinking about the network as a connected environment.

A typical workflow became:

```
Reconnaissance
      ↓
Enumeration
      ↓
Initial Access
      ↓
Credential Discovery
      ↓
Privilege Escalation
      ↓
Lateral Movement
      ↓
Domain Enumeration
      ↓
Further Access
      ↓
Evidence Collection
      ↓
Reporting
```

This was one of the most valuable lessons from the certification.

A penetration test isn't just about finding a vulnerability.

It is about understanding **what that vulnerability allows an attacker to do next**.

***

## The SMB Relay Struggle

One of the most memorable parts of my learning journey was **SMB relay**.

Initially, I skipped one of the SMB relay lessons because I couldn't get the attack working properly in my lab.

Instead of simply moving forward, I decided to troubleshoot it.

And that turned into a much bigger challenge than I expected.

I rebuilt my Active Directory lab **more than three times**.

I watched additional tutorials, checked configurations, compared setups, and repeatedly tested the attack until I finally understood what was actually required.

One of the important pieces that helped everything click was understanding the environmental conditions required for the attack, including scenarios where a domain user has **local administrator privileges on multiple machines**.

Once I understood the underlying concept instead of just following commands, the attack finally made sense.

That experience taught me something that I think is more valuable than the attack itself:

> **If something isn't working, don't immediately assume you don't understand the topic. Sometimes the problem is the environment.**

Troubleshooting the lab forced me to understand the attack at a much deeper level.

***

## When I Got Stuck

During the PJPT exam, I reached a point where I was genuinely stuck.

I tried different approaches and even used AI to help me think through the problem, but I wasn't getting the answer I needed.

Eventually, I stopped looking for a shortcut.

I went back to the material I had learned during the **Practical Ethical Hacking (PEH)** course and started reviewing the concepts again.

That revision helped me recognize the direction I needed to take.

This was an important moment for me because it reinforced something I've been learning throughout cybersecurity:

> **Tools can help you, but understanding the fundamentals is what gets you unstuck.**

AI, tools, scripts, and automated scanners are extremely useful.

But when something unexpected happens during a penetration test, you need to be able to reason about the environment yourself.

***

## From Learning Topics to Following a Methodology

Before PJPT, my learning was often divided into individual topics:

```
SQL Injection
XSS
CSRF
SSRF
SMB
Active Directory
Privilege Escalation
Kerberos
Windows
Linux
```

I knew how many individual concepts worked.

PJPT helped me think differently.

Instead of asking:

> "What vulnerability do I know?"

I started asking:

> "What information do I have, what does it tell me, and what should I investigate next?"

That shift in mindset is probably the most important thing I gained from this certification.

***

***

## What PJPT Changed in My Approach

The biggest change wasn't the number of tools I learned.

It was my approach to problems.

Previously, I sometimes approached a target like:

```
Scan → Find Vulnerability → Exploit
```

Now I try to think more like:

```
Understand the Environment
        ↓
Enumerate
        ↓
Build a Mental Model
        ↓
Identify Attack Paths
        ↓
Test Hypotheses
        ↓
Gain Access
        ↓
Escalate
        ↓
Move Laterally
        ↓
Document Everything
```

This mindset is much closer to how I want to approach real penetration tests.

***

## Lessons I Took Away

### 1. Enumeration is Everything

A lot of penetration testing isn't about running exploits.

It's about collecting enough information to recognize an opportunity.

***

### 2. Don't Give Up When Something Doesn't Work

My SMB relay experience is probably the best example of this.

Rebuilding the lab multiple times was frustrating, but it eventually gave me a much stronger understanding of the underlying concept.

***

### 3. Understand the Attack, Don't Memorize Commands

Commands are easy to search for.

Understanding **why the command works** is much more valuable.

If the environment changes, memorized commands may no longer be enough.

Understanding the underlying mechanism allows you to adapt.

***

### 4. AI Is a Tool, Not a Replacement for Fundamentals

AI can help explain concepts, troubleshoot commands, and provide ideas.

But when I got stuck during the exam, I learned that I couldn't depend on it to solve the problem for me.

Going back to the fundamentals was what eventually helped me move forward.

***

### 5. Build Your Own Labs

One of the best decisions I made was rebuilding my Active Directory environment when things weren't working.

Breaking and fixing your own lab teaches you things that simply following a walkthrough doesn't.

***

## PJPT and My Next Step

Earning PJPT is not the end of my learning journey.

It is a checkpoint.

My long-term goal is to work in **penetration testing and offensive security**, with a particular interest in:

* Web application penetration testing
* Internal network penetration testing
* Active Directory security
* Windows environments
* Linux privilege escalation
* Bug bounty
* Red-team techniques

I also want to continue developing my ability to write clear penetration-testing reports and communicate technical findings effectively.

***

## Final Thoughts

PJPT was more than just another certification for me.

It gave me the opportunity to take the concepts I had been studying separately and apply them as part of a complete penetration-testing process.

From rebuilding my Active Directory lab multiple times to getting stuck during the exam and going back to the fundamentals, the journey involved a lot of troubleshooting, mistakes, research, and repetition.

And honestly, those difficult moments were some of the most valuable parts.

The certification is a milestone, but the real achievement for me is developing a better **penetration-testing mindset**.

There is still a lot to learn.

But now I have a stronger foundation to build on.

**One certification down. Many more skills to master. 🚀🔐**

***

### Certification

**Certification:** Practical Junior Penetration Tester (PJPT)\
**Provider:** TCM Security\
**Course:** Practical Ethical Hacking (PEH)\
**Focus:** Internal Network Penetration Testing, Active Directory, Windows, and Practical Penetration Testing

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FUisujtLE0CRW7pnh2VJi%2Fbadge.png?alt=media&amp;token=9998856c-8340-4a92-af88-28bb2a6c3f84" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F2FJbgfBCv5Ha1JPbWGEe%2FPJPT.jpg?alt=media&amp;token=52453997-c693-4ac4-9b8a-a59f0169dcd9" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FIarwZQ0HsR474ltpj1po%2FPEH.jpg?alt=media&amp;token=8979a18e-90d0-4dd1-a2d5-4a6c7ceba580" alt=""><figcaption></figcaption></figure>

***

### What Comes Next?

The next phase of my journey is focused on going deeper into:

```
Active Directory
       +
Windows Privilege Escalation
       +
Internal Pentesting
       +
Web Pentesting
       +
Bug Bounty
       +
Advanced Offensive Security
```

**The goal isn't to collect certifications.**

**The goal is to become a better penetration tester.**


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ganesha-hk.gitbook.io/offensive-security-writeups/my-certifications/pjpt.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
