Case No. 047 2026.04.12 Cyber Certificateใบเซอร์ 6 minutes views

CPTS Certification Review and Guideline

HTB Certified Penetration Testing Specialist

Certificate
CPTS Certification Review and Guideline

Present a certificate : Link

ทักทายกันหน่อย

สวัสดีครับทุกคน บล็อกนี้ผมจะมารีวิว CPTS หรือ Certified Penetration Testing Specialist ของค่าย Hack The Box (HTB) ครับ ตัวนี้เป็นเซอร์สายลงมือเจาะระบบเต็มตัว หลายคนพูดถึงมันในฐานะทางเลือกยุคใหม่ของ OSCP ที่เน้น Active Directory หนักกว่า และมีจุดเด่นตรงที่ต้องส่ง report แบบมืออาชีพด้วย ของผมสอบผ่านรอบแรกเก็บได้ 12 flag ครับ เดี๋ยวจะเล่าให้ฟังตั้งแต่ว่ามันคืออะไร สอบยังไง ไปจนถึง Guideline เตรียมตัว

CPTS · Certified Penetration Testing Specialist

CPTS คืออะไร

CPTS เป็นใบเซอร์ของ Hack The Box ที่ผูกกับเส้นทางเรียน Penetration Tester ใน HTB Academy ครับ เส้นทางนี้มีทั้งหมด 28 โมดูล ครอบคลุมตั้งแต่การเก็บข้อมูล การเจาะเว็บ การทดสอบทั้งจากภายนอกและภายในองค์กร การยกสิทธิ์ทั้งฝั่ง Linux และ Windows การทำ pivoting ไปจนถึงเรื่องที่หนักที่สุดคือ Active Directory ทั้งดุ้น เนื้อหาเยอะและลงลึกมาก มีเครื่องให้ฝึกยิงกว่า 250 เครื่อง

จุดที่ทำให้ CPTS ต่างจากเซอร์ทั่วไปคือ มันไม่ได้วัดแค่ว่าเรายิงเครื่องแตกไหม แต่วัดว่าเราทำงานเป็น pentester ได้จริงหรือเปล่า เพราะต้องส่ง report ระดับที่เอาไปใช้กับลูกค้าได้ด้วย ถ้าเทียบกับ OSCP ผมว่า CPTS เนื้อหา AD ลึกกว่า และตัวคอร์สมีตัวอย่างให้ดูเยอะกว่า แต่ก็แลกมากับปริมาณเนื้อหาที่ต้องอ่านเยอะพอสมควรครับ

รายละเอียดเส้นทาง Penetration Tester : Link รายละเอียดใบเซอร์ CPTS : Link

รูปแบบการสอบ

ข้อสอบ CPTS เป็นแบบลงมือเจาะจริงในสภาพแวดล้อมองค์กรจำลอง สรุปสั้นๆ ได้ประมาณนี้ครับ

  • เป็นการสอบแบบ black-box เริ่มจาก IP ภายนอกแค่ตัวเดียว กับ network range ภายในที่ให้มา พร้อม letter of engagement ไม่มีใบ้ ไม่มี hint
  • สภาพแวดล้อมเป็น Active Directory หลายโดเมนที่มี trust เชื่อมกัน มีเครื่องให้ยึดราวๆ 7 ถึง 8 เครื่อง ทั้ง Linux และ Windows ซึ่งกว่าจะเข้าถึงได้ต้องทำ pivoting ไล่ลึกเข้าไปในเน็ตเวิร์กเอง
  • มี flag ทั้งหมด 14 อัน ต้องเก็บให้ได้อย่างน้อย 12 อันถึงจะผ่าน แต่ flag อย่างเดียวไม่พอ
  • ต้องส่ง report ระดับมืออาชีพด้วย ถ้า report ไม่ผ่าน ต่อให้เก็บ flag ครบก็ตก
  • มีเวลา 10 วันเต็ม สำหรับทั้งเจาะและเขียน report
  • 1 voucher สอบได้ 2 ครั้ง มีอายุ 1 ปี และถ้าตกรอบแรกจะมี feedback ให้ก่อนไปสอบรอบสอง
  • ที่ผมชอบคือ ใบเซอร์ตัวนี้ไม่มีวันหมดอายุ
  • ตัวนี้ไม่ได้เปิดกล้องคุมสอบแบบ OSCP นะครับ เป็นการเข้า lab ทำแล้วส่ง report
TIP

เวลาผลออกจะใช้เวลาราวๆ 20 วันทำการหลังส่ง report ครับ ช่วงนั้นคือช่วงที่ทรมานที่สุด เพราะทำอะไรไม่ได้นอกจากรอ

รายงานคือของโหดตัวจริง

พาร์ทที่ผมอยากเน้นที่สุดคือ report ครับ เพราะนี่แหละคือของจริงที่ CPTS ใช้แยกคนผ่านกับคนตก

หลังเจาะเสร็จ เราต้องเขียน report แบบที่ส่งให้ลูกค้าได้จริง โครงคร่าวๆ ก็จะมี executive summary สำหรับผู้บริหารที่ไม่ใช่สาย tech, ส่วนสรุป findings ที่แยกตามระดับความรุนแรง, การเล่า attack chain ว่าเจาะจากข้างนอกไล่ไปจนถึง Domain Admin ได้ยังไง, ส่วน remediation ที่แบ่งเป็นระยะสั้นกลางยาว และ appendix ที่ต้องมีตารางบันทึกทุกอย่าง ทั้ง flag ที่เก็บได้ เครื่องที่ยึด user ที่ได้มา รวมถึงการเปลี่ยนแปลงที่เราทำไว้ในระบบเพื่อให้ลูกค้าเอาไปกู้คืนได้

ของผมเขียนไป 90 หน้า มี 13 findings ครับ ซึ่งเอาจริงๆ การเขียน report กินเวลาพอๆ กับการเจาะเลย ผมเลยแนะนำเต็มที่ว่าอย่าไปเจาะให้ครบก่อนแล้วค่อยมานั่งเขียนทีเดียว เพราะจะเขียนไม่ทันและลืมรายละเอียด ให้จดและถ่ายหลักฐานไว้ตั้งแต่นาทีแรกที่ลงมือเลยครับ

Guideline เตรียมตัวยังไงให้ผ่าน

มาถึงส่วนที่หลายคนรอ คือแนวทางเตรียมตัวครับ ขอเน้นไว้ก่อนว่าตรงนี้เป็นความรู้และแนวทางที่ควรมี ไม่ใช่การเฉลยข้อสอบ เพราะเนื้อหาในสนามสอบเปิดเผยไม่ได้อยู่แล้ว สิ่งที่ผมทำและอยากแนะนำมีประมาณนี้

  • เรียนเส้นทาง Penetration Tester ให้ครบทั้ง 28 โมดูล ห้ามข้าม แม้แต่โมดูลที่ดูน่าเบื่ออย่างพวก enumeration เพราะข้อสอบดึงมาจากในนี้เกือบทั้งหมด
  • จดโน้ตแบบเข้าใจจริง ไม่ใช่ก็อปคำสั่งมาแปะ ให้จดเป็น methodology ของตัวเองว่าเจอสถานการณ์แบบไหนต้องไล่ตรวจอะไรบ้าง เวลาสอบจริงจะได้ดึงออกมาใช้ได้ทัน
  • ฝึกสนามที่เป็นองค์กรจริงเพิ่ม โดยเฉพาะโมดูล Attacking Enterprise Networks ที่ใกล้เคียงสนามสอบมากที่สุด ส่วน Pro Lab อย่าง Dante กับ Zephyr ก็ช่วยได้เยอะ
  • เก็บเรื่อง Active Directory ให้แน่นที่สุด เพราะ flag และคะแนนส่วนใหญ่อยู่ตรงนี้ พวก Kerberoasting, DCSync, การ abuse พวก ACL และ delegation รวมถึงการยกสิทธิ์ต่างๆ ต้องทำได้คล่อง
  • ฝึกทำ pivoting กับ tunneling ให้ชิน ผมใช้ Ligolo-ng ซึ่งจำเป็นมาก เพราะต้องเจาะผ่านเน็ตเวิร์กหลายชั้น
  • เตรียมเครื่องมือเขียน report ไว้ก่อน ผมใช้ SysReptor แล้วทำ template รอไว้ พอถึงเวลาจริงจะได้ไม่ต้องมานั่งจัดฟอร์แมตตอนใกล้หมดเวลา
  • เขียน report ไปพร้อมกับตอนสอบเลย ไม่ใช่เก็บไว้เขียนทีหลัง
  • อย่าเดา ให้ไล่ตรวจอย่างเป็นระบบทีละอย่าง ข้อสอบค่อนข้างเป็นเส้นตรง ทำภารกิจตรงหน้าให้จบก่อนค่อยไปต่อ อย่าเพิ่งกระโดดข้าม
  • พักบ้าง นอนบ้าง หลายคนรวมถึงผมด้วย ที่ติด flag ยากๆ อยู่นาน แล้วมาคิดออกตอนพักหัวโล่งๆ
  • เผื่อเวลาเขียน report ไว้เยอะๆ และเผื่อเวลาก่อน deadline ด้วย เพราะช่วงท้ายมักมีปัญหาจุกจิกตอน generate PDF
  • จัดการเรื่องพื้นฐานให้เรียบร้อยก่อน ทั้ง snapshot ของ VM ไฟ และเน็ต เพราะสอบยาว 10 วัน อะไรก็เกิดขึ้นได้
NOTE

ผมใช้เวลาเดินเส้นทาง Penetration Tester อยู่หลายเดือนกว่าจะพร้อม แล้วค่อยกดสอบ ส่วนตัวคิดว่าไม่ต้องรีบ ให้พร้อมจริงแล้วค่อยลง เพราะมีตั้ง 2 สิทธิ์ต่อ voucher อยู่แล้ว

สรุป

โดยรวมผมว่า CPTS เป็นเซอร์ที่คุ้มและตอบโจทย์คนที่อยากทำงาน pentester จริงๆ ครับ เพราะมันจำลองงานเจาะระบบองค์กรจริงตั้งแต่ต้นจนจบ ตั้งแต่เจาะเว็บข้างนอก ยกสิทธิ์ ทำ pivoting ไปจนถึงยึด AD ทั้งโดเมน แล้วปิดท้ายด้วยการเขียน report ให้ลูกค้าอ่านรู้เรื่อง

ข้อดีคือมี 2 สิทธิ์สอบต่อ voucher มี feedback ให้ตอนตก และใบเซอร์ไม่มีวันหมดอายุ ถ้าถามว่าเหมาะกับใคร ก็คือคนที่ผ่านพื้นฐานมาแล้วและอยากพิสูจน์ว่าทำงานสาย AD ได้จริง ตัวนี้เหมาะมากครับ

จบแล้วครับสำหรับรีวิว CPTS หวังว่าจะเป็นแนวทางให้คนที่กำลังจะสอบนะครับ ขอบคุณที่อ่านจนจบครับ :)

A quick hello

Hi everyone. In this blog I am reviewing CPTS, the Certified Penetration Testing Specialist from Hack The Box (HTB). This is a fully hands-on offensive cert, and a lot of people talk about it as a modern alternative to OSCP with heavier Active Directory, plus the twist that you have to hand in a professional report. I passed on my first attempt with 12 flags. Let me walk you through what it is, how the exam works, and a full preparation guideline.

CPTS · Certified Penetration Testing Specialist

What is CPTS

CPTS is Hack The Box’s certification tied to the Penetration Tester path in HTB Academy. That path is 28 modules covering information gathering, web attacks, external and internal testing, both Linux and Windows privilege escalation, pivoting, and the heaviest part of all, Active Directory end to end. The content is deep and there is a lot of it, with more than 250 targets to practice on.

What sets CPTS apart is that it does not just measure whether you can pop a box. It measures whether you can actually do the job of a pentester, because you also have to deliver a report a real client could read. Compared to OSCP, I think CPTS goes deeper on AD and the course gives you far more worked examples, at the cost of a genuinely large amount of reading.

Penetration Tester path details : Link CPTS certification details : Link

The exam format

CPTS is a hands-on exam in a simulated corporate environment. Here is the short version.

  • Black-box, starting from a single external IP plus the internal network ranges you are given, with a letter of engagement. No hints.
  • The environment is a multi-domain Active Directory network connected by trusts, with roughly 7 to 8 hosts to compromise, both Linux and Windows, reachable only by pivoting deeper into the network yourself.
  • There are 14 flags total, and you need at least 12 to pass. Flags alone are not enough.
  • You must also submit a professional report. If the report fails, you fail even with every flag.
  • You get a full 10 days for both the hacking and the report.
  • One voucher includes 2 attempts and is valid for 1 year, and if you fail the first attempt you get feedback before the second.
  • My favourite part: the certification never expires.
  • It is not a live-webcam-proctored exam like OSCP. You work in the lab and submit a report.
TIP

Results take around 20 business days after you submit the report. That wait is the most painful part, because there is nothing left to do but sit and wait.

The report is the real beast

The part I most want to stress is the report, because this is what CPTS really uses to separate a pass from a fail.

Once the hacking is done, you write a report that could genuinely go to a client. The rough shape is an executive summary for a non-technical audience, a findings summary bucketed by severity, an attack-chain narrative of how you went from outside the network to Domain Admin, a remediation section split into short, medium, and long term, and appendices with tables tracking everything: the flags you captured, the hosts you compromised, the accounts you obtained, and every change you made so the client can roll it back.

Mine came out to 90 pages with 13 findings. Honestly, writing the report takes about as long as the hacking, so my strong advice is not to hack everything first and then sit down to write it all at the end. You will run out of time and forget details. Document and screenshot from the very first minute.

Guideline: how to prepare and pass

Here is the part a lot of people wait for, the preparation. Let me be clear up front that this is the knowledge and approach you should have, not exam answers, since the exam content is not something you are allowed to reveal anyway. Here is what I did and what I would recommend.

  • Complete the entire 28-module Penetration Tester path and do not skip anything, not even the boring enumeration modules, because the exam draws almost entirely from it.
  • Take notes to actually understand, not copy-paste commands. Build them into your own methodology of what to check when you hit a given situation, so you can pull it out fast under exam pressure.
  • Practice extra enterprise environments, especially the Attacking Enterprise Networks module, which is the closest thing to the real exam, and Pro Labs like Dante and Zephyr help a lot too.
  • Nail Active Directory as hard as you can, because most of the flags and points live there. Kerberoasting, DCSync, abusing ACLs and delegation, and the various privilege escalations all need to be second nature.
  • Get comfortable with pivoting and tunnelling. I used Ligolo-ng, which is essential because you tunnel through several layers of network.
  • Set up your reporting tool ahead of time. I used SysReptor with a template ready to go, so I was not fighting formatting near the deadline.
  • Write the report during the exam, not afterwards.
  • Do not guess. Test systematically, one thing at a time. The exam is fairly linear, so finish the objective in front of you before moving on rather than jumping ahead.
  • Take breaks and sleep. Plenty of people, myself included, got stuck on a hard flag for ages and only cracked it after stepping away with a clear head.
  • Budget generous time for the report and leave a safety margin before the deadline, because the final stretch often brings fiddly PDF-generation problems.
  • Sort out the basics first: VM snapshots, power, and internet. It is a 10-day exam, and anything can happen.
NOTE

I spent several months working through the Penetration Tester path before I felt ready, then booked the exam. Personally I would not rush it, get genuinely ready and then sit it, since you have 2 attempts per voucher anyway.

Wrapping up

Overall I think CPTS is well worth it and a great fit for anyone who actually wants to work as a pentester, because it simulates a real corporate engagement from start to finish: external web exploitation, privilege escalation, pivoting, full-domain AD compromise, and then writing a report a client can actually read.

The upsides are 2 attempts per voucher, feedback if you fail, and a certification that never expires. If you ask me who it suits, it is people who already have the fundamentals and want to prove they can really do AD-heavy offensive work. For that, this one is a great fit.

That is the CPTS review. I hope it gives some direction to anyone about to sit it. Thanks for reading.

⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣤⣤⣤⣤⣤⣤⣤⣤⣀⣀
⠀⠀⠀⠀⠀⠀⠀⢀⣤⣶⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣤⡀
⠀⠀⠀⠀⠀⣠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣄
⠀⠀⠀⢠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠛⠻⣿⣿⣿⣿⣿⣿⣿⣷⣄
⠀⠀⣰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⡿⠂
⠀⣸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⣤⣴⣿⣿⣿⣿⣿⡿⠛⠁
⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠁
⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠋⠀⢀⣀
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠋⠁⠀⠀⠀⣴⣿⣿⣿⣦
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣀⠀⠀⠀⠀⢿⣿⣿⣿⡟⠀Ar3mus @ CPTS Certification Review and Guideline
⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣄⠀⠉⠉⠁
⠸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⣄⡀
⠀⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣄⡀
⠀⠀⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⡄
⠀⠀⠀⠙⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋
⠀⠀⠀⠀⠀⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋⠁
⠀⠀⠀⠀⠀⠀⠀⠉⠻⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠉
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠙⠛⠛⠻⠿⠿⠟⠛⠛⠋⠉
CPTS Certification Review and Guideline
https://ar3mus.pages.dev/posts/certificate/4/
Author
Ar3mus
Published at
2026-04-12

Related Cases

2026.08.22 KLCP Certification Review and Guideline Cyber Certificateใบเซอร์ 2026.04.15 Road to OSCP · Review and Exam Tips Cyber Certificateใบเซอร์ 2024.11.11 eJPT Certification Review and Guideline Cyber Certificateใบเซอร์
L's ThemeHideki Taniuchi