Skip to main content

PT2 Training Content

Topics covered and frequently asked questions about the PT2.

Written by BigFawn

This certification has been designed by industry experts to validate the hands-on, job-ready skills required to take a modern penetration testing engagement end to end. It focuses on practical exploitation across the full modern attack surface - from web, AI/LLM, and containers through to cloud and Active Directory - aligned to real-world engagement workflows.

A Guide to Advanced Penetration Testing Skills

Modern Infrastructure Attacks (Section 1 - 5 machines, 6 flags)

Five Linux targets across the modern half of the estate. Two parallel entry points open the section - a modern web application and a live LLM target - and the rest of the section only opens up once the candidate breaks out of a container and pivots into an internal network unreachable from the VPN. Behind it sit a hardened internal host (two flags: user foothold and root) and a cloud environment with misconfigured IAM. Covers web application exploitation, AI/LLM exploitation, advanced container bypass and pivoting, local Linux privilege escalation, and cloud misconfiguration and IAM privilege escalation.


Active Directory Attacks (Section 2 - 5 machines, 5 flags)

Five Windows targets forming a full relay-to-forest-root chain across two domains, plus an external trust, reachable the moment the candidate connects and competing with Section 1 for the full 72 hours. Covers NTLM relay and Active Directory Certificate Services abuse, delegation abuse, child domain controller privilege escalation, forest root privilege escalation, and inter-forest trust exploitation (an optional capstone).


Professional reporting & remediation

For every flag, submit the flag value together with an attack description and practical remediation advice. Within each flag: 70% flag capture, 20% attack description, 10% remediation. Written components are graded against a published rubric; reporting is mandatory and worth 30% overall, so flags alone cannot reach the pass mark.


Tooling & workflow fluency

10 machines in a single network instance reached over VPN. Attack from the TryHackMe AttackBox or your own VPN-connected machine with your usual toolkit. No paid tool licence is required to sit the exam. Both sections are open from the first minute, with no prescribed order - candidates choose their own entry point and switch surface as often as they like.


Frequently Asked Questions

What is PT2?

Penetration Tester Level 2 (PT2) is TryHackMe's advanced penetration testing certification. Over 72 hours you compromise 10 machines across two attack surfaces that are live at the same time: modern infrastructure (web, AI and LLM, containers, privilege escalation, cloud) and Active Directory. Every finding is scored on the flag you capture, your description of the attack, and your remediation advice.

Who is PT2 designed for?

Working penetration testers with a year or more of engagement experience, PT1 and WEB1 holders stepping up from an entry credential, and single-surface specialists who need evidence on the surfaces outside their speciality.

Is PT2 entry-level?

No. It is an advanced certification that assumes you can already exploit modern web applications, work in Linux and Windows, attack Active Directory, and pivot through a network you cannot reach directly. PT1 and WEB1 are the natural route in.

How is PT2 different from other advanced penetration testing certifications?

Three things. It is the first penetration testing certification with a graded AI and LLM section in the exam, alongside cloud and a two-domain forest. Two attack surfaces run at once for the full 72 hours rather than one engagement worked in sequence. And the report carries 30% of the mark finding by finding, rather than being submitted and reviewed once.

What does the exam format look like?

72 hours, fully hands-on, non-proctored, covering both the practical work and the reporting. Ten machines in a single network instance across two sections, worth 1000 points in total, pass at 740 (74%). Each flag splits 70% capture, 20% attack description, 10% remediation.

Do I need to buy any extra tools?

No. You can work from the TryHackMe AttackBox or your own VPN-connected machine with your usual toolkit. No paid tool licence is required to sit the exam.

Is there a retake policy?

Yes. One free retake is included, on a fresh instance with fresh flags. Further retakes can be purchased separately.

Does PT2 expire?

The credential is valid for 3 years.

How does PT2 relate to PT1 and WEB1?

PT1 proves broad penetration testing skill and WEB1 proves web depth. PT2 is the advanced step above both: more of the attack surface, no prescribed route, and reporting weighted into the score. You do not need PT1 or WEB1 to sit PT2, but they are the natural preparation if you are already on the path.

How much does PT2 cost?

Pricing is geo-tiered, with a discount for TryHackMe subscribers, and includes one free retake.

How should I prepare?

Work through the Penetration Tester Level 2 path and its PT2 prep module, then top up on the specific surfaces: Attacking LLMs and Chaining Vulnerabilities, Container Security, and Hacking Active Directory.


Still got more questions?

You can reach out to [email protected] or ask in our Discord server or Subreddit for further assistance.


TryHackMe

Did this answer your question?