Case No. 054 2026.08.27 Cyber Certificateใบเซอร์ 7 minutes views

CAPE Certification Review and Guideline

รีวิวและแนวทางสอบ CAPE ของ Hack The Box เซอร์ Active Directory ระดับ Expert ตั้งแต่ path ไปจนถึงการเขียน report My HTB CAPE review and exam guide · Hack The Box's expert-level, all Active Directory 10-day exam, from the job-role path through to writing the report.

Certificate
CAPE Certification Review and Guideline

Present a certificate : Link Verified on Credly : Link

ทักทายกันหน่อย

สวัสดีครับทุกคน บล็อกนี้ผมจะมารีวิว CAPE หรือ Certified Active Directory Pentesting Expert ของค่าย Hack The Box (HTB) ครับ ตัวนี้เป็นเซอร์ระดับ expert ที่โฟกัส Active Directory ล้วน ๆ ถือเป็นบทสรุปของ path สาย AD ทั้งเส้น และเป็นตัวที่ยากที่สุดเท่าที่ผมเคยสอบมา ของผมสอบผ่านรอบแรก เก็บครบทั้ง 10 flag ครับ เดี๋ยวจะเล่าให้ฟังตั้งแต่ว่ามันคืออะไร สอบยังไง ไปจนถึง Guideline เตรียมตัว

CAPE Certification Review and Guideline · exam passed

CAPE คืออะไร

CAPE เป็นใบเซอร์ระดับ expert ของ Hack The Box ที่ผูกกับ path ชื่อ Active Directory Penetration Tester ใน HTB Academy ครับ path นี้มี 15 โมดูล รวม 253 section อยู่ระดับ Hard เนื้อหาทั้งเส้นเป็นเรื่อง AD ล้วน ตั้งแต่ enumeration, LDAP, PowerView, BloodHound, Kerberos Attacks, DACL Attacks, NTLM Relay, ADCS Attacks, Trust Attacks ไปจนถึง lateral movement และการโจมตี MSSQL, Exchange, SCCM

จุดที่ทำให้ CAPE ต่างจากเซอร์ตัวอื่นคือ มันไม่ได้วัดว่าเรายิงเครื่องแตกไหม แต่วัดว่าเราไล่ attack path ที่ซับซ้อนใน AD จริงได้หรือเปล่า และร้อยหลายช่องโหว่เข้าด้วยกันจนล้มทั้ง forest ได้ไหม ถ้าเทียบกับ CPTS ผมว่า CPTS วัดความเป็น pentester รอบด้าน ส่วน CAPE คือการลงลึก AD อย่างเดียวแต่ลึกกว่ามาก HTB เองก็แนะนำว่าควรมีพื้นฐาน AD แน่น และผ่าน CPTS มาก่อนจะช่วยได้เยอะครับ

รายละเอียด path Active Directory Penetration Tester : Link รายละเอียดใบเซอร์ CAPE : Link

รูปแบบการสอบ

ข้อสอบ CAPE เป็นแบบลงมือเจาะจริงในสภาพแวดล้อม AD ขององค์กรจำลอง สรุปสั้น ๆ ได้ประมาณนี้ครับ

  • เป็นการสอบแบบ assumed breach เริ่มจากจุดที่อยู่บนเน็ตเวิร์กแล้ว ไม่มี credential ของโดเมนมาให้ ให้แต่ network range ไม่มี hint
  • สภาพแวดล้อมเป็น AD หลายโดเมนข้าม forest ที่ fully-patched ปิดช่องระดับ protocol มาแน่นหนา งานทั้งหมดคือการหา misconfiguration แล้วร้อยมันเข้าด้วยกัน ไม่ใช่การยิง exploit ตรง ๆ
  • ต้องเก็บ flag บนเครื่องเป้าหมายให้ครบ ของผมมี 10 เครื่อง เก็บได้ 10 จาก 10
  • ต้องส่ง report เป็น PDF ไม่เกิน 20MB ด้วย flag อย่างเดียวไม่พอ ถ้า report ไม่ผ่านก็ตก
  • มีเวลา 10 วันเต็ม สำหรับทั้งเจาะและเขียน report
  • 1 voucher สอบได้ 2 ครั้ง ตกรอบแรกมี feedback ให้ก่อนไปสอบรอบสอง
  • เป็นการสอบแบบ proctor-free ไม่ต้องเปิดกล้องคุมสอบ เข้า lab ทำแล้วส่ง report
  • ใบเซอร์ไม่มีวันหมดอายุ
TIP

ตัวสนามสอบ hardened กว่าที่คิดเยอะครับ หลายเทคนิคที่เคยใช้ได้สบาย ๆ ในสนามฝึก จะโดนปิดตายในนี้ ต้องเปลี่ยนวิธีคิดจาก “มีช่องไหน” เป็น “ที่เหลือที่ยังเปิดอยู่คืออะไร”

รายงานคือของโหดตัวจริง

พาร์ทที่ผมอยากเน้นที่สุดคือ report ครับ เพราะนี่แหละคือของจริงที่ CAPE ใช้แยกคนผ่านกับคนตก

หลังเจาะเสร็จ เราต้องเขียน report แบบที่ส่งให้ลูกค้าได้จริง โครงคร่าว ๆ ก็จะมี executive summary สำหรับผู้บริหารที่ไม่ใช่สาย tech, ส่วนสรุป findings ที่แยกตามระดับความรุนแรง, การเล่า attack chain ว่าไล่จากจุดเริ่มไปจนคุมทั้ง forest ได้ยังไง, ส่วน remediation ที่แบ่งเป็นระยะสั้นกลางยาว และ appendix ที่ต้องมีตารางบันทึกทุกอย่าง ทั้ง flag ที่เก็บได้ เครื่องที่ยึด user ที่ได้มา รวมถึงการเปลี่ยนแปลงที่เราทำไว้ในระบบเพื่อให้ลูกค้าเอาไปกู้คืนได้

ของผมเขียนไป 60 หน้า มี 11 findings ครับ การเขียน report กินเวลาพอ ๆ กับการเจาะเลย ผมเลยแนะนำเต็มที่ว่าอย่าไปเจาะให้ครบก่อนแล้วค่อยมานั่งเขียนทีเดียว เพราะจะเขียนไม่ทันและลืมรายละเอียด ให้จดและถ่ายหลักฐานไว้ตั้งแต่นาทีแรกที่ลงมือเลยครับ อีกอย่างที่ CAPE เน้นคือ ทุกการเปลี่ยนแปลงที่เราทำในโดเมน ต้อง revert กลับให้หมดและจดไว้ในส่วน cleanup ตรงนี้กรรมการดูจริง

Guideline เตรียมตัวยังไงให้ผ่าน

มาถึงส่วนที่หลายคนรอ คือแนวทางเตรียมตัวครับ ขอเน้นไว้ก่อนว่าตรงนี้เป็นความรู้และแนวทางที่ควรมี ไม่ใช่การเฉลยข้อสอบ เพราะเนื้อหาในสนามสอบเปิดเผยไม่ได้อยู่แล้ว ทุกข้อด้านล่างเป็นเทคนิค AD สาธารณะที่มีสอนทั้งใน path และตามบล็อกความปลอดภัยทั่วไป สิ่งที่ผมทำและอยากแนะนำมีประมาณนี้

  • เดิน path Active Directory Penetration Tester ให้ครบทั้ง 15 โมดูล อย่าข้าม โดยเฉพาะพวก DACL Attacks, Kerberos Attacks, NTLM Relay, ADCS Attacks และ Trust Attacks เพราะข้อสอบดึงแนวคิดมาจากตรงนี้เกือบหมด
  • BloodHound คือแผนที่ของเรา แต่ต้องรู้ข้อจำกัดของมันด้วย มันเดินแค่ Domain naming context ส่วนที่มันไม่เดินอย่าง Configuration partition คือจุดบอด และ write ที่อันตรายที่สุดบางอันก็ซ่อนอยู่ตรงที่กราฟไม่ส่อง ให้ไล่ ACL เองเพิ่มนอกเหนือจากที่มันชี้ด้วย
  • delegation ต้องแม่นทั้งสามแบบ unconstrained, constrained และ RBCD รวมถึง protocol transition ผ่าน S4U2Self กับ S4U2Proxy จุดที่คนมองข้ามคือ SPN ปลายทางของ delegation ไม่จำเป็นต้องอยู่บนเครื่องที่เราคุมเต็ม ถ้าเราเขียน servicePrincipalName ได้ เราเปลี่ยนได้ว่า ticket จะถูกเข้ารหัสด้วย key ของใคร และอย่าลืมว่า built-in Administrator มักโดนตั้ง NOT_DELEGATED เอาไว้ ให้มองหาบัญชีสิทธิ์สูงตัวที่ delegate ได้แทน
  • AD CS ต้องไล่เคส ESC ให้ครบ โดยเฉพาะเคสที่ผูกกับ UPN หรือ template ที่ไม่ฝัง SID security extension จุดพวกนี้พลิกเกมได้จากบัญชีสิทธิ์ต่ำ
  • Shadow Credentials คือการเขียน msDS-KeyCredentialLink ต่อด้วย PKINIT ต่อด้วย DCSync เป็น chain ที่เริ่มจาก WriteDACL ตัวเดียวก็จบโดเมนได้ ฝึกให้คล่อง
  • coercion อย่าง PetitPotam หรือ PrinterBug คู่กับ unconstrained delegation ใช้ดึง TGT ของเครื่องเป้าหมายมาได้ ต้องรู้จังหวะว่าใช้ตอนไหน
  • เก็บของให้หมดทุกเครื่องที่ยึดได้ ไม่ใช่แค่ DC เพราะ credential ซ่อนอยู่บน member server เยอะ ทั้ง DPAPI blob และ credential ของ scheduled task ที่รันด้วย SYSTEM หลายทีบัญชีสำคัญที่พาเราไปต่อ โผล่มาจากเครื่องธรรมดา ๆ นี่แหละ
  • อ่าน trust ให้ขาด ทิศทางและ attribute ของ trust เป็นตัวบอกว่า Domain Admin ที่ได้จากอีกฝั่งจะ authenticate ข้ามมาได้ไหม ถ้าเป็น trust ทางเดียวขาเข้า เราต้องยึด forest นั้นจากข้างในด้วยบัญชีของมันเอง ไม่ใช่แบกตั๋วข้ามมา
  • forest ที่ hardened ก็ล้มได้โดยไม่ต้องแตะ NTLM ไม่ต้องมี AD CS และไม่ต้อง crack รหัสแข็ง ๆ เลย ถ้าการป้องกันระดับ protocol ถูกเปิดหมด คำตอบมักย้อนกลับมาที่ ACL, delegation และ Group Policy ตรงนี้ misconfiguration ชนะ patch level เสมอ
  • pivoting หลายชั้นคือของบังคับ ผมใช้ Ligolo-ng เป็นหลัก และเตรียม fallback ที่นิ่งกว่าอย่าง netsh portproxy ไว้ด้วย เผื่อ tunnel หลุด เครื่อง DC ที่ dual-homed คือสะพานข้าม segment
  • เตรียมเครื่องมือเขียน report ไว้ก่อน ผมใช้ SysReptor แล้วทำ template รอไว้ พอถึงเวลาจริงจะได้ไม่ต้องมานั่งจัดฟอร์แมตตอนใกล้หมดเวลา
  • เขียน report ไปพร้อมกับตอนสอบเลย ถ่ายหลักฐานทุกขั้น และจดทุกการเปลี่ยนแปลงในระบบไว้ให้ครบ เพื่อ revert และเขียนส่วน cleanup
  • พักบ้าง นอนบ้าง flag ยาก ๆ ผมคิดออกตอนลุกไปพักหัวโล่ง ๆ ทุกที
NOTE

เครื่องมือที่ผมใช้ในสนามหลัก ๆ คือ NetExec, Impacket, BloodHound-CE, bloodyAD, Certipy, Responder, PetitPotam, minikerberos, Ligolo-ng, Rubeus, pypykatz, Evil-WinRM และ hashcat ส่วน report ใช้ SysReptor ครับ ไม่ต้องใช้ครบทุกตัว แต่ให้รู้ว่าตัวไหนทำอะไรและหยิบใช้ได้ทัน

ของสะสมปิดท้าย

นอกจากใบเซอร์ดิจิทัลกับ badge ใน Credly แล้ว HTB ยังมีชุด physical certification package ขายแยกด้วยครับ เป็นกล่องพร้อมแผ่น certificate ตัวจริง ผมสั่งมาเก็บไว้เป็นที่ระลึกของด่านที่หินที่สุดด่านนึงที่เคยผ่านมา ใครสอบผ่านแล้วอยากได้ของจริงมาตั้งโต๊ะ สั่งได้ที่ร้านของ HTB เลย

CAPE Certification Review and Guideline · physical certification package order

สั่งชุด CAPE Certification Package : Link

สรุป

โดยรวมผมว่า CAPE เป็นเซอร์ที่โหดและคุ้มสำหรับคนที่อยากเอาดีทางสาย Active Directory จริง ๆ ครับ เพราะมันไม่ปล่อยให้เรายิง exploit ตรง ๆ แล้วจบ แต่บังคับให้เราคิดแบบคนที่เข้าใจว่า AD ทำงานยังไง แล้วหา misconfiguration เล็ก ๆ มาร้อยกันจนล้มทั้ง forest ที่ปิดช่องมาแน่นแล้ว

ข้อดีคือมี 2 สิทธิ์สอบต่อ voucher มี feedback ให้ตอนตก และใบเซอร์ไม่มีวันหมดอายุ ถ้าถามว่าเหมาะกับใคร ก็คือคนที่ผ่าน CPTS หรือมีพื้นฐาน AD แน่นแล้ว และอยากพิสูจน์ว่าเล่นงาน AD ระดับองค์กรที่ hardened ได้จริง ตัวนี้เหมาะมากครับ

จบแล้วครับสำหรับรีวิว CAPE หวังว่าจะเป็นแนวทางให้คนที่กำลังจะสอบนะครับ ขอบคุณที่อ่านจนจบครับ :)

A quick hello

Hi everyone. In this blog I am reviewing CAPE, the Certified Active Directory Pentesting Expert from Hack The Box (HTB). This is an expert-level cert focused purely on Active Directory, the capstone of the whole AD path, and the hardest exam I have sat so far. I passed on my first attempt with all 10 flags. Let me walk you through what it is, how the exam works, and a full preparation guideline.

CAPE Certification Review and Guideline · exam passed

What is CAPE

CAPE is Hack The Box’s expert-level certification tied to the Active Directory Penetration Tester path in HTB Academy. That path is 15 modules and 253 sections at Hard difficulty, and it is all Active Directory: enumeration, LDAP, PowerView, BloodHound, Kerberos attacks, DACL attacks, NTLM relay, ADCS attacks, trust attacks, lateral movement, and attacking MSSQL, Exchange, and SCCM.

What sets CAPE apart is that it does not measure whether you can pop a box. It measures whether you can trace a complex AD attack path and chain many misconfigurations together until an entire forest falls. Compared to CPTS, I would say CPTS measures all-round pentesting while CAPE is AD only, but far deeper. HTB itself recommends a solid AD foundation, and having CPTS behind you helps a lot.

Active Directory Penetration Tester path details : Link CAPE certification details : Link

The exam format

CAPE is a hands-on exam in a simulated corporate Active Directory environment. Here is the short version.

  • Assumed breach. You start already on the network but with no domain credentials, given the network ranges, no hints.
  • The environment is a multi-domain, cross-forest AD that is fully patched and hardened at the protocol level. The whole job is finding misconfigurations and chaining them, not firing off a direct exploit.
  • You capture a flag on each objective host. Mine had 10 hosts, and I took 10 out of 10.
  • You must also submit a report as a PDF under 20MB. Flags alone are not enough; if the report fails, you fail.
  • You get a full 10 days for both the hacking and the report.
  • One voucher includes 2 attempts, and if you fail the first attempt you get feedback before the second.
  • It is proctor-free. No webcam, you work in the lab and submit a report.
  • The certification never expires.
TIP

The exam is far more hardened than you expect. Plenty of techniques that work easily in the labs are shut off here. You have to switch your mindset from “where is the hole” to “what is left that is still open”.

The report is the real beast

The part I most want to stress is the report, because this is what CAPE really uses to separate a pass from a fail.

Once the hacking is done, you write a report that could genuinely go to a client. The rough shape is an executive summary for a non-technical audience, a findings summary bucketed by severity, an attack-chain narrative of how you went from the initial foothold to full control of the forest, a remediation section split into short, medium, and long term, and appendices with tables tracking everything: the flags you captured, the hosts you compromised, the accounts you obtained, and every change you made so the client can roll it back.

Mine came out to 60 pages with 11 findings. Writing the report takes about as long as the hacking, so my strong advice is not to hack everything first and then sit down to write it all at the end. You will run out of time and forget details. Document and screenshot from the very first minute. One more thing CAPE stresses: every change you make in the domain has to be reverted and logged in a cleanup section. The graders actually check.

Guideline: how to prepare and pass

Here is the part a lot of people wait for, the preparation. Let me be clear up front that this is the knowledge and approach you should have, not exam answers, since the exam content is not something you are allowed to reveal anyway. Everything below is public AD tradecraft, taught both in the path and across the usual security blogs. Here is what I did and what I would recommend.

  • Complete the entire 15-module Active Directory Penetration Tester path and do not skip anything, especially DACL Attacks, Kerberos Attacks, NTLM Relay, ADCS Attacks, and Trust Attacks, because the exam draws almost entirely from these ideas.
  • BloodHound is your map, but know its limits. It only walks the Domain naming context, so the parts it does not walk, like the Configuration partition, are a blind spot, and some of the nastiest write primitives hide exactly where the graph does not look. Enumerate ACLs yourself beyond what it points at.
  • Know delegation cold in all three forms, unconstrained, constrained, and RBCD, plus protocol transition through S4U2Self and S4U2Proxy. The thing people miss is that a delegation-target SPN does not have to sit on a machine you fully own. If you can write servicePrincipalName, you change whose key the ticket is encrypted with. And remember the built-in Administrator is often set NOT_DELEGATED, so look for the privileged account that is delegatable instead.
  • Work through the AD CS ESC cases, especially the ones that hinge on the UPN or on a template that does not embed the SID security extension. These can flip the game from a low-privileged account.
  • Shadow Credentials, writing msDS-KeyCredentialLink then PKINIT then DCSync, is a chain that can end the domain from a single WriteDACL. Make it second nature.
  • Coercion like PetitPotam or PrinterBug paired with unconstrained delegation lets you capture a target machine’s TGT. Know when to reach for it.
  • Loot every box you own, not just the DCs, because credentials hide all over member servers, both DPAPI blobs and scheduled-task credentials that run as SYSTEM. Often the account that carries you forward turns up on some ordinary box.
  • Read the trust carefully. Its direction and attributes decide whether a Domain Admin from one side can even authenticate across. A one-way, inbound-only trust means you take that forest from the inside with its own accounts, not by carrying a ticket across.
  • A hardened forest can still fall without touching NTLM, without AD CS, and without cracking a single strong secret. When the protocol-level defences are all on, the answer usually comes back to ACLs, delegation, and Group Policy. Misconfiguration beats patch level every time.
  • Multi-layer pivoting is mandatory. I used Ligolo-ng as my main tool and kept a steadier fallback, netsh portproxy, ready for when the tunnel drops. Dual-homed DCs are your bridges between segments.
  • Set up your reporting tool ahead of time. I used SysReptor with a template ready to go, so I was not fighting formatting near the deadline.
  • Write the report during the exam, screenshot every step, and log every change you make so you can revert it and write the cleanup section.
  • Take breaks and sleep. I cracked every hard flag after stepping away with a clear head.
NOTE

My main toolset in the lab was NetExec, Impacket, BloodHound-CE, bloodyAD, Certipy, Responder, PetitPotam, minikerberos, Ligolo-ng, Rubeus, pypykatz, Evil-WinRM, and hashcat, with SysReptor for the report. You do not need every one of them, but know what each does so you can reach for the right one in time.

One last collectible

Beyond the digital cert and the Credly badge, HTB also sells a physical certification package. It is a box with a real printed certificate inside, and I ordered one to keep as a memento of one of the toughest challenges I have cleared. If you have passed and want the real thing on your desk, you can order it from the HTB store.

CAPE Certification Review and Guideline · physical certification package order

Order the CAPE Certification Package : Link

Wrapping up

Overall I think CAPE is brutal and well worth it for anyone who genuinely wants to specialise in Active Directory, because it never lets you fire a direct exploit and call it done. It forces you to think like someone who understands how AD works, then find small misconfigurations and chain them until a fully hardened forest falls.

The upsides are 2 attempts per voucher, feedback if you fail, and a certification that never expires. If you ask me who it suits, it is people who already have CPTS or a solid AD foundation and want to prove they can take on hardened, enterprise-grade AD for real. For that, this one is a great fit.

That is the CAPE review. I hope it gives some direction to anyone about to sit it. Thanks for reading.

⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣤⣤⣤⣤⣤⣤⣤⣤⣀⣀
⠀⠀⠀⠀⠀⠀⠀⢀⣤⣶⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣤⡀
⠀⠀⠀⠀⠀⣠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣄
⠀⠀⠀⢠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠛⠻⣿⣿⣿⣿⣿⣿⣿⣷⣄
⠀⠀⣰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⡿⠂
⠀⣸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⣤⣴⣿⣿⣿⣿⣿⡿⠛⠁
⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠁
⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠋⠀⢀⣀
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠋⠁⠀⠀⠀⣴⣿⣿⣿⣦
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣀⠀⠀⠀⠀⢿⣿⣿⣿⡟⠀Ar3mus @ CAPE Certification Review and Guideline
⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣄⠀⠉⠉⠁
⠸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⣄⡀
⠀⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣄⡀
⠀⠀⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⡄
⠀⠀⠀⠙⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋
⠀⠀⠀⠀⠀⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋⠁
⠀⠀⠀⠀⠀⠀⠀⠉⠻⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠉
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠙⠛⠛⠻⠿⠿⠟⠛⠛⠋⠉
CAPE Certification Review and Guideline
https://ar3mus.pages.dev/posts/certificate/5/
Author
Ar3mus
Published on
2026-08-27

Related Casesแฟ้มที่เกี่ยวข้อง

2026.08.22 KLCP Certification Review and Guideline Cyber Certificateใบเซอร์ 2026.04.15 Road to OSCP · Review and Exam Tips Cyber Certificateใบเซอร์ 2026.04.12 CPTS Certification Review and Guideline Cyber Certificateใบเซอร์
L's Theme Hideki Taniuchi