
CPTC: Great Lakes Regional
At a glance
Competition: CPTC 11, Collegiate Penetration Testing Competition, Great Lakes Regional
Team: CyberHawks, Illinois Tech
Host: Baldwin Wallace University, Berea, Ohio
Result: 🥉 3rd place
Year: 2025
What CPTC Is
CPTC is a competition where student teams act as a professional security consulting firm hired by a client, rather than just attacking a target for points. You’re given a realistic environment to assess, and the deliverables that matter most are the professional ones: a written penetration test report of prioritized findings with clear business risk and remediation, and a client-facing debrief presentation where you explain what you found to people who aren’t necessarily technical.
The competition also runs injects throughout the event: time-boxed tasks and curveballs that mimic the interruptions and shifting priorities of a real engagement. It exercises both the technical work and the professional judgment and communication that go with it.
My Role
Going into the competition, I owned the credential access and lateral movement portion of the engagement. That’s the phase of a test where, after gaining a foothold, you try to recover credentials and move between systems inside the environment.
I was also responsible for writing the executive summary and the technical summary of our report. These are two of the most important parts of the deliverable. The executive summary has to communicate risk to a non-technical client, and the technical summary has to hold up to a technical reader.
Where I am with credential access and lateral movement: I’m actively developing this area. I’m comfortable with the overall workflow and the concepts behind the tooling, and I’m still deepening my command of some of the individual tools. The competition was where I got my first real, close-up experience applying it under pressure.
Preparation
Before the regional, our club completed an intensive 8-week training program, held every Saturday from 12:00 PM to 6:00 PM in the Smart Tech Lab. Having access to a real lab environment made a huge difference. It gave us serious, hands-on penetration testing reps instead of just theory.
For my area specifically, preparation meant getting comfortable with the credential access and lateral movement workflow and the tooling that goes with it. Some of the tools I trained with:
- BloodHound, for mapping Active Directory relationships and attack paths
- NetExec, for enumeration and authentication across a network
- Impacket, for a range of authentication and remote-execution techniques
- Rubeus and mimikatz, for working with Windows and Kerberos credential material
- Evil-WinRM, for authenticated remote access
Not all of this preparation turned into a headline finding during the competition, but it gave me the hands-on practice I needed to contribute when the engagement got difficult.
The Work We Did
The work was intense and time-boxed. The first stretch of the day went to finding and validating the critical vulnerabilities, and the rest of it went to turning everything we’d found into the written report and the client debrief. That split is a real part of the experience. The technical work is only half of it, and the writing is what the client actually walks away with.
Across the engagement, we assessed the client’s internal network and documented findings spanning their web applications, operational and control systems, and Active Directory environment. For my part of it, the AD path was the hard one. We found and documented weaknesses on that side, but it didn’t fully land the way some of the other findings did, and the stronger footholds in our report came from other parts of the environment. Working that contrast in real time was one of the most useful things I took away.
One thing our team never did was break character. From start to finish we behaved like an actual security consulting firm: methodical, professional, and client-focused, right through the client-facing debrief.
The work we produced reflects that. Our report laid out findings ranging from critical to low, each paired with a clear explanation of business impact and practical remediation, along with the attack paths we identified and a network topology of the environment. It was written up so that both leadership and technical readers could actually use it. That quality is what I’m proud of.
Challenges I Faced
- A tough environment. Escalation didn’t come easily, especially on the Active Directory side that I owned.
- Working at real depth. Finding vulnerabilities and thinking like an attacker in a live, time-pressured setting pushed me well past anything a lab exercise had asked of me.
- Still leveling up the tooling. I was applying tools I’m still growing into, under competition pressure.
- Injects. On top of the core assessment, the injects meant constantly re-prioritizing and switching context.
How We Responded
When something wasn’t landing for one person, the rest of us jumped in. We crossed lanes constantly, shared every discovery as it happened, and re-attacked blockers as a group instead of staying boxed into our assigned roles. We kept communication tight and made sure all of that technical effort actually flowed into the deliverables CPTC scores: a clear, well-organized report and a confident client debrief. When the injects came in, we absorbed them without losing the thread of the main assessment.
What I Learned
- A much clearer, close-up understanding of how vulnerabilities are actually found, and where my own strengths and gaps are.
- That in a hard engagement, teamwork and communication carry as much weight as raw technical skill. The result came from the team pulling in the same direction, not from any one person cracking everything alone.
- How to write for two audiences at once: turning technical findings into an executive summary a client can act on, and a technical summary that holds up to scrutiny.
Results
We placed 3rd at the CPTC 11 Great Lakes Regional, out of ten competing universities. I was proud of the result. It was a huge accomplishment and a strong reflection of our CyberHawks’ growth, discipline, teamwork, and commitment.
| Place | Team |
|---|---|
| 🥇 1st | University of Florida |
| 🥈 2nd | Rochester Institute of Technology |
| 🥉 3rd | Illinois Institute of Technology |
Our result was also covered in Illinois Tech’s official news: CyberHawks crack the code in pen testing competition.

The CyberHawks receiving 3rd place at the CPTC 11 Great Lakes Regional.
Closing Thought
This competition was eye-opening. It pushed me outside my usual defensive perspective and gave me a much better appreciation for what happens on the other side of the security problem. I left with a clearer idea of where I want to grow next.
A huge thank you to my teammates, Mohamed Trigui, Benjamin De Pater, Lucas Ferguson, Natorion Johnson, and Kacper Stasik, for the work we put into this together. And thank you to our coach, John Ford, for the training that got us ready, and to Professor Jeremy Hajek for the lab access that made the experience possible.
