10 certifications
PortSwigger
Practical web application security certification from the makers of Burp Suite. Tests real-world web exploitation skills across a 4-hour hands-on exam using PortSwigger Web Security Academy labs.
EC-Council
Vendor-neutral ethical hacking certification covering reconnaissance, scanning, system hacking, malware threats, sniffing, social engineering, web app attacks, and AI-driven hacking. v13 introduces AI-augmented hacking modules. Knowledge-based MCQ exam, with optional CEH Practical hands-on add-on.
EC-Council
Industry-recognized ethical hacking certification covering 20 attack domains including network scanning, system hacking, malware threats, and web application security. Includes knowledge exam and optional practical exam on a live cyber range.
CompTIA
Intermediate penetration testing certification covering planning, scoping, vulnerability scanning, exploitation, and reporting. Validates offensive security skills for pentest roles. Exam code: PT0-003.
INE / eLearnSecurity
Intermediate practical penetration testing certification covering exploitation, Active Directory attacks, and web application testing in a fully hands-on exam environment.
INE / eLearnSecurity
Entry-level practical penetration testing certification covering network scanning, exploitation, and web application testing via a hands-on exam. Designed for those new to cybersecurity — no formal experience required.
Hack The Box
Comprehensive practical penetration testing certification covering network and web exploitation, Active Directory attacks, privilege escalation, and professional reporting. Features a 10-day hands-on exam across 28 learning modules on HTB Academy.
Offensive Security (OffSec)
The gold standard hands-on penetration testing certification. Candidates must compromise multiple machines in a 24-hour proctored exam on a live network — entirely performance-based, no multiple choice. OSCP+ badge valid 3 years.
Offensive Security (OffSec)
Advanced penetration testing certification focusing on antivirus evasion, process injection, lateral movement, and attacking complex Active Directory environments. Features a 48-hour hands-on exam simulating a corporate network.
TCM Security
Fully practical real-world penetration testing certification featuring a 5-day exam on a live network plus a professional report and debrief. Covers OSINT, network exploitation, Active Directory attacks, and privilege escalation.