Skip to content

OSCP

The OSCP (Offensive Security Certified Professional) is the most recognized pentesting certification in the industry. Its 24-hour practical exam (“try harder”) has made it the reference standard for demonstrating you can actually compromise systems, not just answer a test.

- pentest methodology, enumeration, exploitation (web and services)
- Active Directory (very relevant in the current exam, see the Windows & AD area)
- Linux and Windows privilege escalation (linux-privesc/win-privesc)
- pivoting/port forwarding, client-side, buffer overflow (reduced in recent versions)
- basic scripting and use of public exploits (adapting them)
- 24 practical hours + 24h for the professional REPORT (the report SCORES)
- independent machines + an Active Directory set (full chain)
- 70/100 points to pass; tool restrictions (Metasploit limited)
- demonstrates real process: enumerate, exploit, escalate, document
- the official material (PEN-200) + the included labs
- HTB (TJnull's OSCP-like machine list) and PG Practice (Proving Grounds)
- practice AD thoroughly (ad-*); Linux/Windows escalation; take notes and a report template
- simulate the exam: a timed 24h with a report
- ENUMERATE exhaustively (see ctf-metodologia): most blocks are from this
- time management: don't obsess over one machine; rotate
- document WHILE you progress (screenshots, commands) -> the report is part of the grade
- rest during the 24h; fatigue makes you miss obvious steps
- requirement or big plus in junior/mid PENTESTER job ads
- demonstrates real practical capability (not just theory) -> highly valued
- a base to specialize later (OSWE web, OSEP evasion, CRTO red team)
  • The OSCP validates real practical capability; preparing it teaches methodology transferable to the job.
  • Enumeration + time management + reporting are the three keys to the exam.
  • Practicing AD and escalation (ad-*, *-privesc) is essential in the current version.
  • Complement with a portfolio; after OSCP, specialize (OSWE/OSEP/CRTO).
  • Manage the 24 h: set time caps per box and avoid rabbit holes.
  • Document while you exploit (screenshots, commands); write the report in parallel, not at the end.
  • Prepare AD thoroughly (mandatory, high-point block) and master manual enumeration without autopwn.
  • Common mistake: relying on restricted automated tools; drill the manual method.
  • Solid fundamentals (networks, Linux/Windows, scripting)
  • PEN-200 material + labs completed
  • Practice on HTB (TJnull list) and PG Practice
  • Active Directory thoroughly (ad-*)
  • Linux and Windows escalation (linux-privesc/Windows Privilege Escalation)
  • Report template and documentation practice
  • Timed 24h simulated exam