Coaching & cert roadmaps
One-to-one guidance and a roadmap built around your background, target role and timeline, so you stop guessing which cert comes next.
See coaching programsPentesting, red teaming, web exploitation, exploit development and AI red teaming.
29 certifications match these filters
| Cert name | Target job title | Level | Prerequisites | Study notes | Recent updates |
|---|---|---|---|---|---|
| CRTA CyberWarFare Labs | Junior Red Team Analyst | Entry | Networking, Linux/Windows basics and introductory web and Active Directory knowledge. | Coming Soon | Entry-level red team cert covering the external-to-internal kill chain: web foothold, pivoting and Active Directory abuse. |
| CEH EC-Council | Ethical Hacker / Junior Penetration Tester | Entry | Two years of infosec experience, or official EC-Council training (which waives the experience requirement). | CEH Notes | v13 (312-50v13) is the current version, with AI woven into all five hacking phases. The optional 6-hour CEH Practical plus CEH earns CEH Master. |
| OSWP OffSec | Wireless Penetration Tester | Entry | Linux command line and networking fundamentals. | OSWP Notes | PEN-210 is included in OffSec's Learn subscriptions. Short proctored practical exam (under 4 hours) on Wi-Fi attacks. |
| eJPT INE Security | Junior Penetration Tester | Entry | None. Networking and Linux basics help. | eJPT Notes | Rebuilt on 31 March 2026: new web-app and recon content, a new Offensive AI course, and a revised practical exam. |
| TryHackMe PT1 TryHackMe | Junior Penetration Tester | Entry | TryHackMe's Jr Penetration Tester path recommended. | THM PT1 Notes | Positioned by TryHackMe as the practical step before OSCP. Business list price includes training and a free retake. |
| HackTheBox CJCA Hack The Box | Junior Security Analyst / Junior Pentester | Entry | Complete the HTB Academy Junior Cybersecurity Associate path. | HackTheBox CJCA Notes | HTB's entry-level certification, covering offensive and defensive fundamentals before CPTS or CDSA. |
| OSCP OffSec | Penetration Tester | Intermediate | No formal prerequisite. Comfortable with Linux/Windows, TCP/IP, web basics and light scripting (Python/Bash). | OSCP Notes | Passing PEN-200 now awards both OSCP (lifetime) and OSCP+ (valid 3 years, renewable via CPE or another OffSec exam). Bonus points are gone and the Active Directory set is scored with partial credit. |
| HackTheBox CPTS Hack The Box | Penetration Tester | Intermediate | Complete the HTB Academy Penetration Tester job-role path (required before the exam voucher can be used). | HackTheBox CPTS Notes | Exam voucher is bundled with HTB Academy's Silver Annual plan. 10-day practical engagement ending in a commercial-grade report. |
| CRTP Altered Security | Active Directory Pentester / Junior Red Teamer | Intermediate | Basic Active Directory concepts, PowerShell and Windows administration. No formal prerequisite. | CRTP Notes | Still the most common first Active Directory attack cert. 24-hour hands-on exam against an AD lab followed by a report. |
| OSWA OffSec | Web Application Penetration Tester | Intermediate | HTTP, HTML/JavaScript basics, Burp Suite familiarity and Linux command line. | OSWA Notes | WEB-200 focuses on black-box web testing (XSS, SQLi, SSTI, SSRF and more) with a 24-hour proctored exam. |
| CompTIA PenTest+ CompTIA | Penetration Tester / Vulnerability Analyst | Intermediate | None required. Network+/Security+ and 3–4 years of hands-on security experience recommended. | COMPTIA Pentest+ Notes | PT0-003 is the current version, adding AI, cloud and attack-surface management topics. DoD 8140 approved. |
| eCPPT INE Security | Penetration Tester | Intermediate | eJPT-level skills; Active Directory and basic exploit development knowledge. | eCPPT Notes | Current v3 format is a hands-on practical exam aligned to INE's Professional Penetration Tester path. |
| TCM PNPT TCM Security | Penetration Tester | Intermediate | Networking, Linux and Active Directory basics. PJPT is a useful stepping stone. | TCM PNPT Notes | 5-day practical engagement (OSINT → external → Active Directory), 2 days for the report, then a live debrief. |
| HackTheBox CWES Hack The Box | Web Application Pentester / Bug Bounty Hunter | Intermediate | Complete the HTB Academy Bug Bounty Hunter path. | HackTheBox CWES Notes | Renamed from CBBH to CWES. Exam voucher is bundled with HTB Academy's Silver Annual plan. |
| CRTO Zero-Point Security | Red Team Operator | Intermediate | OSCP-level skills and Active Directory fundamentals. | Coming Soon | Adversary simulation with Cobalt Strike, from initial access to reporting. The credential does not expire. |
| BSCP PortSwigger | Web Application Pentester | Intermediate | Complete PortSwigger Web Security Academy practitioner-level labs. | Coming Soon | 4-hour practical exam: two web apps, each to be fully compromised using Burp Suite. |
| GPEN GIAC | Penetration Tester | Intermediate | None formal. SANS SEC560 is the aligned course. | Coming Soon | Proctored exam that includes CyberLive hands-on questions. Renewal every 4 years. |
| CARTP Altered Security | Cloud Red Teamer | Intermediate | Active Directory attack basics and working knowledge of Azure and Entra ID. | Coming Soon | Hands-on Azure/Entra ID attack lab with a 24-hour practical exam. |
| CRTE Altered Security | Red Team Operator | Advanced | CRTP-level Active Directory attack skills; comfort with multi-forest trusts and PowerShell tradecraft. | CRTE Notes | 48-hour practical exam across multiple domains and forests, followed by a report. |
| OSEP OffSec | Red Team Operator / Senior Penetration Tester | Advanced | OSCP-level skills plus C#/PowerShell and Active Directory exploitation. | OSEP Notes | 48-hour proctored exam centred on AV/EDR evasion, lateral movement and Active Directory attacks. |
| OSED OffSec | Exploit Developer / Vulnerability Researcher | Advanced | x86 assembly, C, Python and debugging with WinDbg. | OSED Notes | 48-hour exam on Windows user-mode exploit development: DEP/ASLR bypass, ROP chains and custom shellcode. |
| OSAI OffSec | AI Red Teamer / AI Security Engineer | Advanced | OSCP-level offensive skills, Python, and working knowledge of LLM applications, RAG and AI agents. | OSAI Notes | AI-300 launched in 2026. Passing the proctored practical exam against an AI-enabled enterprise environment awards OSAI plus the 3-year OSAI+. |
| HackTheBox CAPE Hack The Box | Active Directory Pentester / Red Teamer | Advanced | Complete the HTB Academy Active Directory Penetration Tester path; CPTS-level skills strongly recommended. | HackTheBox CAPE Notes | Exam voucher is bundled with HTB Academy's Gold Annual plan. Expert-level multi-day AD engagement with a commercial report. |
| TryHackMe PT2 TryHackMe | Penetration Tester | Advanced | PT1 or equivalent hands-on pentest experience across web, AD and cloud. | Coming Soon | Launched 2026: one graded engagement spanning Active Directory, cloud, container breakout and an AI/LLM target. |
| OSWE OffSec | Senior Application Security Engineer / Web Pentester | Advanced | Ability to read PHP, Java, .NET, JavaScript and Python code; OSWA-level web skills. | OSWE Notes | 48-hour exam on white-box source review, chaining auth bypasses into remote code execution. |
| HackTheBox COAE Hack The Box | AI Red Teamer | Expert | Complete the AI Red Teamer job-role path (co-developed with Google); solid Python and ML fundamentals. | HackTheBox COAE Notes | Launched April 2026: a 7-day practical assessment of AI-driven infrastructure plus a commercial-grade report. Available on the Silver Annual plan. |
| CRTL Zero-Point Security | Red Team Lead / Senior Operator | Expert | CRTO-level tradecraft, C programming, Windows internals and EDR evasion. | Coming Soon | Zero-Point Security has joined Fortra, the company behind Cobalt Strike. CRTL remains the advanced evasion-focused follow-on to CRTO. |
| OSEE OffSec | Senior Exploit Developer | Expert | OSED-level exploit development plus Windows kernel internals. | Coming Soon | EXP-401 is delivered as live training only; the exam is a 72-hour practical. |
| HackTheBox CWEE Hack The Box | Senior Web Pentester / AppSec Researcher | Expert | Complete the HTB Academy Senior Web Penetration Tester path. | Coming Soon | Advanced black-box and white-box web exploitation. Voucher bundled with the Gold Annual plan. |
One-to-one guidance and a roadmap built around your background, target role and timeline, so you stop guessing which cert comes next.
See coaching programsMembership with role- and cert-based learning tracks: roadmaps, cheat sheets, assessments, exclusive writeups and member pricing on notes.
Join the learning tracksCheat sheets, command references and exam-day extras for when you already know the material and need it fast and in one place.
Browse prep resources