OSCP
The OSCP (Offensive Security Certified Professional) is the most recognized pentesting certification in the industry. Its 24-hour practical exam (“try harder”) has made it the reference standard for demonstrating you can actually compromise systems, not just answer a test.
What it covers (PEN-200 course)
Section titled “What it covers (PEN-200 course)”- pentest methodology, enumeration, exploitation (web and services)- Active Directory (very relevant in the current exam, see the Windows & AD area)- Linux and Windows privilege escalation (linux-privesc/win-privesc)- pivoting/port forwarding, client-side, buffer overflow (reduced in recent versions)- basic scripting and use of public exploits (adapting them)The exam
Section titled “The exam”- 24 practical hours + 24h for the professional REPORT (the report SCORES)- independent machines + an Active Directory set (full chain)- 70/100 points to pass; tool restrictions (Metasploit limited)- demonstrates real process: enumerate, exploit, escalate, documentHow to prepare
Section titled “How to prepare”- the official material (PEN-200) + the included labs- HTB (TJnull's OSCP-like machine list) and PG Practice (Proving Grounds)- practice AD thoroughly (ad-*); Linux/Windows escalation; take notes and a report template- simulate the exam: a timed 24h with a reportKeys to passing
Section titled “Keys to passing”- ENUMERATE exhaustively (see ctf-metodologia): most blocks are from this- time management: don't obsess over one machine; rotate- document WHILE you progress (screenshots, commands) -> the report is part of the grade- rest during the 24h; fatigue makes you miss obvious stepsProfessional value
Section titled “Professional value”- requirement or big plus in junior/mid PENTESTER job ads- demonstrates real practical capability (not just theory) -> highly valued- a base to specialize later (OSWE web, OSEP evasion, CRTO red team)Blue Team / career
Section titled “Blue Team / career”- The OSCP validates real practical capability; preparing it teaches methodology transferable to the job.
- Enumeration + time management + reporting are the three keys to the exam.
- Practicing AD and escalation (ad-*, *-privesc) is essential in the current version.
- Complement with a portfolio; after OSCP, specialize (OSWE/OSEP/CRTO).
Tips and common mistakes
Section titled “Tips and common mistakes”- Manage the 24 h: set time caps per box and avoid rabbit holes.
- Document while you exploit (screenshots, commands); write the report in parallel, not at the end.
- Prepare AD thoroughly (mandatory, high-point block) and master manual enumeration without autopwn.
- Common mistake: relying on restricted automated tools; drill the manual method.
Testing checklist
Section titled “Testing checklist”- Solid fundamentals (networks, Linux/Windows, scripting)
- PEN-200 material + labs completed
- Practice on HTB (TJnull list) and PG Practice
- Active Directory thoroughly (ad-*)
- Linux and Windows escalation (linux-privesc/Windows Privilege Escalation)
- Report template and documentation practice
- Timed 24h simulated exam