eCPPTv3 Review
Almost a year ago, I took the INE’s “eCPPTv3” exam, and here is my honest reviewWhy eCPPT?A year ago 2026-7-18 09:22:38 Author: infosecwriteups.com(查看原文) 阅读量:9 收藏

Said-Abbosxon Nabijonov | 0trc

Almost a year ago, I took the INE’s “eCPPTv3” exam, and here is my honest review

Why eCPPT?
A year ago (May 29) I’ve bought the bundle which included 3 months of premium subscription and 2 exam attempts, thankfully a single attempt was enough for me. Back then I wasn’t really familiar with HackTheBox, so I chose eCPPT. Now, comparing the eCPPT and CPTS exams and paths, I’d advise you to choose CPTS instead.

Get Said-Abbosxon Nabijonov | 0trc’s stories in your inbox

Join Medium for free to get updates from this writer.

Remember me for faster sign in

Path:
The path is enough to pass the exam I believe, and there is even some extra material included in the path, like the C2 module. By the way, if you have finished eJPT/eWPT, some modules (very few) might be repeated in the eCPPTv3 path. Then, there are some modules that you don’t get in the exam, e.g. the macros development part. One thing I liked a lot about the path was that most of the material is videos, and labs/skill assessments are included as well, as I am both visual and practical learner I just loved most of the path.

  • Tip: All of the techniques you will encounter in the exam were explained in the course itself, nothing out of it — whether it’s priv.esc, brute-force, or lateral movement.
Preview

Preparation:
Unlike HTB, here you can start the exam any time you want, you are not required to finish the path 100% before you start the exam, which I believe is actually a huge advantage (not always though). Before you start the exam, I’d advise you to finish the following modules and be comfortable with solving the labs and CTF challenges at the end of them:

  • PowerShell for Pentesters
  • Web Application Penetration Testing
  • Network Penetration Testing
  • Privilege Escalation (get really comfortable with this one)
  • Active Directory Penetration Testing

Then, one more hint I’d give is to get extremely comfortable with brute-forcing and lateral-movement. Be patient, and don’t break under pressure — the exam is only 24 hours and expect brute forces take anywhere from seconds to 2 hours, like for real, don’t rush — sometimes you might wait 30 minutes for your brute-force to finish, and since there is such limited time, it can get heavy mentally — be ready for it, don’t panic.

Exam:
This exam was no joke — brute-force, lateral movement, AD systems, privilege escalation, web, and it keeps testing you until you get to the passing point. Since I was taking this exam a year ago, there was a problem with WinRM, which I fixed using this reddit post:
https://www.reddit.com/r/eLearnSecurity/comments/1hpsfo2/ecppt_exam_evilwinrm_workaround/. Furthermore, make sure you have organized notes on techniques and commands, tools, etc. that you covered in the course, especially from the AD, LM, PowerShell, and PrivEsc modules. One huge thing the eCPPTv3 lacks is the report — it’s “competitors” — OSCP, CPTS both require you to write a professional grade report, whereas in eCPPTv3 the report was for some reason removed.

One word of advise:
If you are wondering should you take eCPPT over CPTS, I would not advise you to take CPTS over eCPPT. Why? Because I believe that CPTS’ path is more modern when it comes to exploitation, and more hands-on, and, I believe that it’s harder than eCPPT as well, and finally CPTS costs a bit less and one huge W for HTB is that they’ve got a student subscription, which, unfortunately INE does not — but remember that CPTS and eCPPT exams differ a bit, in eCPPT all you got is 24 hours of intentse hacking with no report, while in CPTS it’s 10 days.

eCPPTv3 Certified

文章来源: https://infosecwriteups.com/ecpptv3-review-522cf02bf996?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh