My PT1 Exam Experience — The Mini OSCP Adventure
What is PT1?
My PT1 Exam Experience — The Mini OSCP Adventure

What is PT1?
The PT1 (Penetration Tester Level 1) exam is a practical, hands-on certification introduced by TryHackMe as a way for beginners to test and prove their penetration testing skills. It’s designed to be an accessible entry point into the world of ethical hacking, giving candidates a realistic but achievable challenge across multiple areas of security.
[embed]
Rather than focusing on theory or multiple-choice questions, PT1 drops you into a live environment and challenges you to exploit vulnerabilities in web applications, network infrastructure, and Active Directory environments. It’s a well-rounded test that introduces newcomers to a variety of attack techniques while still feeling engaging for more experienced learners.
With a total of 48 hours to both complete the lab and write the report, PT1 doesn’t just measure your ability to hack into systems — it also evaluates your documentation and reporting skills, just like in a real penetration test. Many people see it as a “mini OSCP,” making it a great stepping stone before moving on to more advanced and time-intensive certifications.
So what was my experience like ?
If I had to sum up the PT1 exam in one line, I’d say it was an absolute blast… apart from the two days without sleep and the web application section slowly melting my brain.
[embed]
The exam is split into three sections — Web Application, Network Security, and Active Directory. The best part is you don’t have to finish one before starting another. If something is giving you trouble, you can jump into a different section and still rack up points. That takes some of the pressure off and makes it a little more forgiving than the “all or nothing” approach some certifications use
Web Application — The CTF Beast in Disguise
The first section I tackled was the web application challenge, and it immediately felt different from a real-world pentest. This wasn’t about following a structured vulnerability testing process. It was very much a CTF-style puzzle with clever tricks and unusual exploitation paths.
At times, it was frustrating. There were moments where I sat staring at my screen wondering if the answer was even in there. But when things finally clicked, it was an incredibly satisfying feeling — like finding a secret door in a game you’ve been stuck on for hours. That said, it definitely burned through more brainpower than the other sections.
[embed]
Active Directory — The Smooth Ride
The Active Directory section was a completely different vibe — smooth, logical, and extremely fun.
It started with one key target — the “gateway” machine. Getting initial access there took a bit of work, but once you breached that first foothold, everything clicked into place. The rest of the network practically opened up like a treasure map.
AD exploitation here was well-paced and felt like a real engagement — enumeration, privilege escalation, moving between systems — without being overly complicated. It’s the kind of section where you could almost feel yourself grinning while running BloodHound and lining up your next attack.
For me, this was the most enjoyable part of PT1. It struck the perfect balance between challenge and flow.
[embed]
Network Security — The Linux Stumble & Windows Sprint
The network section came with two targets: a Linux machine and a Windows machine.
The Linux box was the trickier of the two. Getting that initial foothold felt like being stuck in a maze — plenty of doors, but only one had the right key. Once I found that entry point, things flowed more naturally, but it was definitely the part that made me stop, think, and rethink my approach.
[embed]
The Windows box, on the other hand, was refreshingly straightforward. It followed a clean exploitation path without unnecessary red herrings. If you’ve done Windows privilege escalation before, you’ll feel right at home.
This section felt balanced overall — one machine to test your patience, one to restore your confidence.
[embed]
The Hidden Fourth Challenge — Sleep Deprivation
The official PT1 timer gives you 48 hours total for both lab time and report writing.
Sounds manageable, right? Well… that depends on whether you value sleep.
I went full hacker-mode and ended up pulling two straight all-nighters. The mix of caffeine, adrenaline, and problem-solving had me bouncing between focus and delirium. At one point, I think I genuinely tried to ssh into my energy drinks.
[embed]
The time limit is fair, though. There’s enough breathing room to finish all sections and still put together a decent report — as long as you pace yourself better than I did.
The Reporting
The reporting stage was more of a guided template than a freeform professional report.
You basically fill in the blanks for findings, evidence, and recommendations. While this is quick and painless, I do think it could be improved — maybe allow code blocks, inline screenshots, and richer formatting to make the evidence look cleaner and more professional.
After hacking for two days straight, though, I wasn’t complaining. This “plug-and-play” style made wrapping up much easier.
CPTS vs PT1 — Which Was Better?
Since I’ve done CPTS before, I couldn’t help but compare the two. CPTS felt far more realistic in terms of simulating an actual corporate pentest. There were no neat sections — you had to follow the entire attack chain from initial access → lateral movement → pivoting → domain compromise. It’s a full network engagement, and you can’t just skip around. If you’re stuck, you’re really stuck. This makes CPTS more intense but also more rewarding for those who thrive in a complete kill-chain scenario.
PT1, on the other hand, is a more relaxed, modular approach. You can choose which section to focus on first, and struggling in one area doesn’t block your progress in another. This makes it less stressful for newer testers or for people who want a broad challenge without the “all eggs in one basket” risk.
In short:
- CPTS → More realistic, continuous-flow network pentest.
- PT1 → Mini OSCP style, modular, and more forgiving.
Personally, I’d say CPTS was the better “real-world simulation,” but PT1 was more fun in terms of variety and flexibility.
Final Thoughts — My Mini OSCP
Overall, PT1 was a solid and well-designed exam.
The mix of skills tested — web, network, and AD — kept it interesting, and the “you can still score even if you get stuck” format made it less mentally punishing than some other certs.
Would I recommend it? Absolutely. Just remember to pace yourself, get some rest, and maybe don’t challenge the web app section at 3 AM unless you enjoy suffering for fun.
For me, PT1 was the Mini OSCP — a smaller but still thrilling taste of a multi-domain hacking exam. And honestly? I’d do it again… after a week of sleep.
메타데이터
- post_id
- 058a2c85d4d5
- slug
- my-pt1-exam-experience-the-mini-oscp-adventure-058a2c85d4d5
- url
- https://medium.com/@kulindukody/my-pt1-exam-experience-the-mini-oscp-adventure-058a2c85d4d5
- canonical_url
- https://medium.com/@kulindukody/my-pt1-exam-experience-the-mini-oscp-adventure-058a2c85d4d5
- author_url
- https://medium.com/@kulindukody
- status
- ok
- fetched_at
- 2026-06-16 19:09:56