- What the Certified PowerShell Hacker Credential Actually Is
- Clearing Up the Acronym: CPSH vs. Other Credentials
- Exam Format at a Glance
- The Eight Preparation Topics in Detail
- Who Should Pursue It and Who Hires for These Skills
- Suggested Background Knowledge
- Buying the Exam: Mechanics and Open Questions
- Three-Year Validity and the Renewal Picture
- Sequencing Your Preparation Around the Curriculum
- Frequently Asked Questions
- C)PSH here means Certified Powershell Hacker, awarded by Mile2 and focused on offensive and defensive PowerShell in Windows and Active Directory environments.
- Mile2's course outline specifies 100 multiple-choice questions, about two hours, and a 70% minimum passing grade.
- The outline lists eight preparation topics, from PowerShell basics through Kerberos, privilege escalation, persistence, and defending against PowerShell...
- Certification is valid for three years; renewal sources differ, so confirm your route with Mile2 before relying on any single description.
What the Certified PowerShell Hacker Credential Actually Is
The Certified Powershell Hacker credential, styled "Certified PowerShell Hacker" in Mile2's course materials, is a vendor certification from Mile2 that validates your understanding of how PowerShell is used in modern Windows environments, both by attackers and by the defenders trying to stop them. If you have ever wondered what a C)PSH is, the short answer is this: it is a specialist, post-fundamentals certification aimed at people who already understand penetration testing concepts and want to work at the scripting and Active Directory layer.
PowerShell sits at an unusual intersection. It is a legitimate administrative tool installed on virtually every modern Windows system, which makes it enormously valuable to administrators and, for the same reasons, to adversaries. A candidate preparing for this credential needs to think in both directions: how a script can enumerate a domain, escalate privileges, and move laterally, and how a defender can detect, constrain, and log that same activity.
If you want a quick orientation on the terminology before going deeper, our short explainers on what C)PSH is and what C)PSH stands for cover the basics. This article goes further into format, curriculum, and practical decisions.
Clearing Up the Acronym: CPSH vs. Other Credentials
Several unrelated credentials in the industry share the same letters. For this site and this article, C)PSH refers only to Mile2's Certified Powershell Hacker. When you research exam details, fees, or career outcomes, make sure the source you are reading is actually about the Mile2 credential. Details belonging to a different certification with a similar acronym will mislead you on cost, format, and renewal.
Because the parenthesis in the name is awkward to type, many people search using the punctuation-free alias CPSH. The two refer to the same Mile2 credential here. For more on the naming question, see our pieces on the meaning of C)PSH and what C)PSH means.
Exam Format at a Glance
Mile2's current linked course outline for Certified PowerShell Hacker specifies the following exam parameters. The outline itself is undated, so check Mile2's course page for any revision before you schedule.
| Attribute | What Mile2's Outline Specifies |
|---|---|
| Question count | 100 questions |
| Question style | Multiple choice |
| Time allowed | Approximately two hours |
| Minimum passing grade | 70% |
| Delivery | Online, through Mile2's learning management system and your Mile2.com account |
| Attempts included with purchase | Two (per Mile2's FAQ for exam purchases) |
The 70% threshold means you need at least 70 of 100 questions correct if each question counts equally. For a deeper look at how scoring thresholds play out in practice, read our guide to the C)PSH passing score.
What about proctoring and open-book rules?
This is an area where Mile2's published material is not perfectly consistent. The FAQ states that standard exams are available online on demand without a live-proctor appointment. Meanwhile, Mile2's general Policies and Procedures document describes randomized, open-book online examinations and webcam or screen-sharing proctoring in its general certification procedures, while other sections say only some exams require proctors. Mile2 also names certain proctoring exceptions for other credentials, and those are not this one.
The practical takeaway: do not assume the exam is open-book, and do not assume it is unproctored. Follow the instructions shown in your own C)PSH account and booking flow, and prepare as though you must know the material cold. Our overview of scheduling and exam windows explains how to approach booking with this uncertainty in mind.
The Eight Preparation Topics in Detail
Mile2's Detailed Outline lists eight curriculum headings. These are preparation topics, not a verified weighted exam blueprint, so do not assume each carries equal weight or that the list is an exhaustive map of every question. They are, however, the best published guide to what to study. For a topic-by-topic walkthrough, see our complete guide to the C)PSH content areas.
Domain 1: Introduction to PowerShell
The foundation. You need real fluency with the language before any offensive or defensive concept makes sense.
- Cmdlets, the pipeline, and object-based output
- Variables, functions, modules, and scripting constructs
- Execution policy and how scripts are loaded and run
- Remoting concepts and how PowerShell communicates across systems
Domain 2: Introduction to Active Directory and Kerberos
Almost every later domain assumes you understand how a Windows domain is structured and how authentication flows through it.
- Domains, forests, trusts, organizational units, and group policy
- Users, groups, service accounts, and delegation
- The Kerberos ticket exchange and why its design creates both security and attack surface
Domain 3: Pen Testing Methodology Revisited
Mile2's overview uses a different title for this module, but the detailed heading is "Pen Testing Methodology Revisited." It frames the engagement workflow through a PowerShell lens.
- How standard penetration-testing phases map onto PowerShell-driven work
- Scoping, authorization, and staying within rules of engagement
- Where scripting fits at each phase of an assessment
Domain 4: Information Gathering and Enumeration
Understanding what an environment reveals about itself to an authenticated or unauthenticated user.
- Enumerating domain objects, accounts, groups, and computers
- Identifying relationships and trust paths worth investigating
- Recognizing which native tooling produces telltale logs
Domain 5: Privilege Escalation
How a low-privileged foothold becomes something more powerful, and which misconfigurations make that possible.
- Common local and domain-level escalation weaknesses
- Credential exposure and misconfigured permissions
- How escalation techniques appear from a defender's perspective
Domain 6: Lateral Movements and Abusing Trust
Moving between systems and exploiting the trust relationships that administrators create for convenience.
- Remote execution mechanisms and their authentication requirements
- Trust relationships between accounts, systems, and domains
- Why legitimate administrative pathways are hard to distinguish from abuse
Domain 7: Persistence and Bypassing Defenses
How access is maintained over time and how defensive controls can be evaded, studied so that you can recognize and counter it.
- Persistence mechanisms and where they hide
- Defensive controls and their known limitations
- Conceptual awareness of evasion, kept within authorized, isolated training environments
Domain 8: Defending Against PowerShell Attacks
The payoff domain for blue teams and a differentiator for the credential overall.
- Logging, monitoring, and detection strategies for script-based activity
- Hardening and constraining PowerShell in production environments
- Translating what you learned offensively into concrete defensive controls
Key Takeaway
Do not treat Domain 8 as an afterthought. A credential built around PowerShell attacks inevitably asks whether you can also defend against them, and defensive knowledge often anchors the most practical scenario questions.
Who Should Pursue It and Who Hires for These Skills
The skills behind this credential map to several job families. Penetration testers and red team members use PowerShell to automate enumeration and assess Active Directory weaknesses. Security analysts and incident responders need to recognize malicious script activity in logs. Windows and Active Directory administrators benefit from understanding how their own environments get attacked. Defensive engineers building detection and hardening programs find Domain 8 directly applicable.
Employers that run Windows-heavy infrastructure, security consultancies, managed security providers, and internal security teams all value people who understand PowerShell tradecraft. Whether the certification itself moves your compensation is a separate question, and we address it candidly in our salary analysis and the broader worth-it breakdown. We do not quote specific earnings here because reliable credential-specific figures are scarce. You can also browse our overview of C)PSH jobs to see how the skills translate into roles.
Suggested Background Knowledge
Mile2's materials suggest preparation that includes the C)PEH and C)PTE certifications or equivalent knowledge, along with penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. You are not formally required to hold any earlier Mile2 credential to buy the exam, and purchasing or completing a Mile2 course is likewise not required. Our requirements guide walks through eligibility in more detail.
Mile2's training offering
Mile2 pairs the credential with a four-day course that carries 32 course CEUs and includes seven training labs. Those figures describe the training, not the exam. They do not indicate how long the exam lasts, they do not represent a separate practical assessment, and they should not be read as a verified renewal-hour requirement. If you want a self-directed route instead, see our notes on C)PSH training options.
Buying the Exam: Mechanics and Open Questions
Mile2 offers a C)PSH Exam Combo that includes exam access, a preparation guide, and quiz or simulator preparation. A separate exam-only fee and a current bundle price were not verified in the listing we reviewed, and earlier promotional amounts should not be treated as today's fees. Always confirm the live price on Mile2's product page at checkout. Our cost breakdown explains how to think about total spend without relying on stale numbers.
- Create or sign in to your Mile2.com account.
- Review the current C)PSH course outline and exam listing for any updates.
- Choose between the exam combo and any exam-only option that is currently listed.
- Follow the booking and access instructions specific to C)PSH in your account.
- Remember that the purchase includes two attempts, so plan your first attempt as a genuine try rather than a throwaway.
Three-Year Validity and the Renewal Picture
Certification is valid for three years. Renewal is where Mile2's published sources diverge, and it is worth being precise about the disagreement rather than flattening it into one tidy rule.
| Source | What It Describes |
|---|---|
| Dedicated renewal pages | Two alternative routes: a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment; or an exam route using the latest existing certification exam or an eligible qualifying exam |
| Course outline | Describes 20 CEUs annually plus passing the current exam |
| Policies and Procedures (May 2026) | Describes CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period |
| FAQ | Lists a USD 200 U.S.-region renewal fee |
Because these descriptions differ, do not combine them into a single unqualified rule. The dedicated renewal pages present the CEU and exam routes as alternatives, which is the most direct reading, but confirm your exact obligations with Mile2 well before your expiry date. Keeping records of professional activity from the start protects you whichever route applies.
Sequencing Your Preparation Around the Curriculum
You do not need an elaborate system. What matters is ordering the eight topics so that each builds on the last. Because later domains assume earlier fluency, front-load the foundations. The sample plan below assumes you already have general penetration-testing familiarity; stretch it if you do not. For a fuller roadmap, see our C)PSH study guide, and when you want to gauge readiness, try the practice questions on the main practice test site.
Language foundations
- Domain 1: write small scripts daily in an isolated lab
- Practice the pipeline, modules, and remoting concepts until they feel natural
Identity infrastructure
- Domain 2: draw the Kerberos exchange from memory
- Map domain, forest, and trust structures
Methodology and discovery
- Domains 3 and 4: connect engagement phases to enumeration activity
- Note which actions generate logs a defender would see
Offense in sequence
- Domains 5 and 6: escalation and lateral movement, studied conceptually or in authorized labs only
Persistence and defense
- Domains 7 and 8: pair every offensive technique with its detection and mitigation
- Finish with timed practice sets under a two-hour limit
The reason Domain 8 gets the final slot is that defensive knowledge is easiest to retain once you understand what you are defending against. Revisit it twice. Also, since the exam is multiple choice, practice reading answer options carefully: in a technical field, two options often look plausible and only one fits the exact scenario. Our cheat sheet is useful for a final-days review, and our assessment of exam difficulty helps you calibrate how much time to budget.
Frequently Asked Questions
On this site it stands for Certified Powershell Hacker, a Mile2 certification. Other credentials in the industry share the acronym, so confirm that any source you read is about the Mile2 certification. You can also search for it as CPSH. See our related explainer for more.
Mile2's current course outline specifies 100 multiple-choice questions, roughly two hours, and a minimum passing grade of 70%. Because the outline is undated, check Mile2's course page for updates before you test.
No. Purchasing or completing a Mile2 course is not required to purchase the exam, and prior certifications are suggested rather than mandatory. Mile2 recommends C)PEH and C)PTE or equivalent knowledge, plus penetration-testing fundamentals, Active Directory, scripting, and programming.
Mile2's published material is inconsistent. The FAQ describes standard exams as available online on demand without a live-proctor appointment, while the general policies document describes open-book online exams and webcam or screen-sharing proctoring in certain procedures. Follow the instructions in your own C)PSH booking flow rather than assuming either rule.
It is valid for three years. Renewal sources differ: the dedicated pages describe a 60-CEU route and an alternative exam route, while other documents describe different CEU and exam combinations. Confirm your specific route with Mile2 before your expiry date.