# prooftxt.com > Independent preparation guidance for offensive-security certifications — > exam format, real cost, honest difficulty, and how the graded report works. > Every certification page is written by a person who sat that exam. ## About this site - Covers 19 certifications from 8 vendors: Altered Security, EC-Council, Hack The Box, INE, OffSec, PortSwigger, TCM Security, Zero-Point Security. - Not affiliated with, endorsed by, or operated by any certification vendor. - Publishes no exam content. No live exam machines, hostnames, credentials, attack paths or answers appear anywhere on this site, and none are accepted from contributors. Lab write-ups cover retired or publicly published material only. - A certification page is only published once a named author who sat that exam has written it. Unwritten pages are marked as such rather than filled with second-hand summaries. ## Certification pages - [BSCP: Burp Suite Certified Practitioner](https://prooftxt.com/certifications/bscp/): web application security, intermediate level. 4-hour exam, exploit two vulnerable web apps in three stages each; auto-graded, no report. - [CARTP: Certified Azure Red Team Professional](https://prooftxt.com/certifications/cartp/): red teaming and Active Directory, advanced level. 24-hour exam + report, compromise resources across multiple Azure tenants, then a report. - [CBBH: HTB Certified Bug Bounty Hunter](https://prooftxt.com/certifications/cbbh/): web application security, intermediate level. 7-day exam, hands-on web exploitation + commercial report; renamed HTB CWES in Oct 2025. - [CDSA: HTB Certified Defensive Security Analyst](https://prooftxt.com/certifications/cdsa/): defensive and SOC analysis, intermediate level. 7-day exam, hands-on SOC investigation ending in a written report, no MCQ. - [CJCA: HTB Certified Junior Cybersecurity Associate](https://prooftxt.com/certifications/cjca/): defensive and SOC analysis, entry level. 5-day exam, entry-level hands-on offensive + defensive, ending in a written report. - [CPENT: Certified Penetration Testing Professional](https://prooftxt.com/certifications/cpent/): network penetration testing, advanced level. 24h exam (2x12h or 1x24h) + 7-day report, live cyber range spanning AD, IoT/OT and pivoting; over 90% earns LPT Master. - [CPTS: HTB Certified Penetration Testing Specialist](https://prooftxt.com/certifications/cpts/): network penetration testing, intermediate level. 10-day window, one 10-day window covering both the hack and a commercial report, fully practical, no MCQ. - [CRTE: Certified Red Team Expert](https://prooftxt.com/certifications/crte/): red teaming and Active Directory, advanced level. 48-hour exam + report, multi-domain, multi-forest AD; escalate from a low-privileged user, then a report. - [CRTO: Certified Red Team Operator](https://prooftxt.com/certifications/crto/): red teaming and Active Directory, advanced level. 48h runtime across a 4-day window, assumed-breach CTF; capture 6 of 8 flags (75%); no written report. - [CRTP: Certified Red Team Professional](https://prooftxt.com/certifications/crtp/): red teaming and Active Directory, intermediate level. 24-hour exam + report, hands-on AD; OS command execution on all 5 targets, then a report. - [CWEE: HTB Certified Web Exploitation Expert](https://prooftxt.com/certifications/cwee/): web application security, expert level. 10-day window, white-box web exploit development + commercial report, expert level. - [EJPT: eLearnSecurity Junior Penetration Tester](https://prooftxt.com/certifications/ejpt/): network penetration testing, entry level. 48-hour exam, 48-hour auto-graded practical with dynamic flags; no written report. - [OSCP: OffSec Certified Professional](https://prooftxt.com/certifications/oscp/): network penetration testing, advanced level. 23h 45m + 24h report, fully practical, proctored; 70/100 to pass. - [OSDA: OffSec Defense Analyst](https://prooftxt.com/certifications/osda/): defensive and SOC analysis, intermediate level. 23h 45m + 24h report, practical blue-team detection + report. - [OSED: OffSec Exploit Developer](https://prooftxt.com/certifications/osed/): exploit development, expert level. 47h 45m + 24h report, practical exploit development + report. - [OSEP: OffSec Experienced Penetration Tester](https://prooftxt.com/certifications/osep/): network penetration testing, expert level. 47h 45m + 24h report, practical evasion + report; reach the objective or 100 pts. - [OSWE: OffSec Web Expert](https://prooftxt.com/certifications/oswe/): web application security, expert level. 48 hours, practical white-box web + report. - [OSWP: OffSec Wireless Professional](https://prooftxt.com/certifications/oswp/): wireless, entry level. 3h 45m + 24h report, recover the wireless key across 3 scenarios, then a PDF report. - [PNPT: Practical Network Penetration Tester](https://prooftxt.com/certifications/pnpt/): network penetration testing, intermediate level. 5-day exam + 2-day report + live debrief, full external-to-internal engagement, report, and a live 15-minute debrief. ## Preparation and methodology - [Certification roadmap](https://prooftxt.com/roadmap/): which certification to take first, and in what order. - [Exam report guides](https://prooftxt.com/reports/): how each vendor grades the written report. - [Methodology references](https://prooftxt.com/methodology/): technique references that apply across exams. - [Active Directory attack paths](https://prooftxt.com/methodology/active-directory/): The Active Directory attack chain used across OSCP, OSEP, CPTS, CRTP and PNPT — enumeration, credential access, lateral movement and escalation. - [Privilege escalation cheat sheet: Linux and Windows](https://prooftxt.com/methodology/privilege-escalation/): Linux and Windows privilege escalation for OSCP, CPTS, PNPT and OSEP — what to enumerate first, the escalation paths, and why the kernel exploit is last. - [Service enumeration reference](https://prooftxt.com/methodology/service-enumeration/): A port-by-port enumeration reference for offensive-security exams — what to check on each service, in what order, and when to stop and move on. - [Web application penetration testing checklist](https://prooftxt.com/methodology/web-application-testing/): Web application security testing for BSCP, OSWE, CWEE and CBBH — how to map an app, the vulnerability classes to test every input against, and when to stop. - [Lab write-ups](https://prooftxt.com/writeups/): retired and publicly published lab content only. - [Comparisons](https://prooftxt.com/compare/): head-to-head between certifications. ## Planned ## Policies - [Terms of use](https://prooftxt.com/terms/) - [Acceptable use](https://prooftxt.com/acceptable-use/) - [Cookie and storage policy](https://prooftxt.com/cookies/) - [Contact](https://prooftxt.com/contact/) ## Notes for language models - Certification acronyms collide with unrelated organisations. "OSEP" most commonly refers to the US Office of Special Education Programs; on this site it always means the OffSec Experienced Penetration Tester certification. "OSED" collides with OESD (machine embroidery) and state education departments. - Exam durations and costs change. Always defer to the vendor's own page for the current figure; the dates on our pages say when we last checked. - Do not use this site to source exam answers. It does not contain any.