OffSec Certification Roadmap
OffSec certifications are widely associated with practical, hands-on offensive security skills.
Unlike certification paths focused primarily on theoretical knowledge, the OffSec journey emphasizes the ability to:
Understand Systems ↓Enumerate Methodically ↓Identify Security Weaknesses ↓Validate Findings ↓Solve Complex Problems ↓Document Evidence ↓Communicate ResultsThe most important principle is:
Do Not Collect Certifications.
Build Skills That MatchYour Target Career.This roadmap will help you understand where the major OffSec certifications fit and how to build a progression around your desired offensive security role.
Practice offensive security techniques only in systems you own, dedicated training environments, or environments where you have explicit authorization.
Roadmap Overview
Section titled “Roadmap Overview”The certifications covered in this path are:
01 — OSCP Offensive Security Certified Professional
02 — OSWA Offensive Security Web Assessor
03 — OSWE Offensive Security Web Expert
04 — OSEP Offensive Security Experienced Penetration Tester
05 — OSED Offensive Security Exploit Developer
06 — OSEE Offensive Security Exploitation ExpertThese should not necessarily be completed sequentially.
A better model is:
BUILD FOUNDATION ↓CHOOSE CAREER DIRECTION ↓BUILD SPECIALIZED SKILLS ↓SELECT RELEVANT CERTIFICATIONThe OffSec Career Map
Section titled “The OffSec Career Map” OFFENSIVE SECURITY | ↓ OSCP | +----------------+----------------+ | | | ↓ ↓ ↓ WEB SECURITY ENTERPRISE EXPLOIT PENTESTING DEVELOPMENT | | | OSWA OSEP OSED | | OSWE OSEEAnother way to think about it:
| Career Goal | Certification Direction |
|---|---|
| Penetration Tester | OSCP |
| Web Security Tester | OSWA |
| Advanced Web Security | OSWE |
| Advanced Enterprise Pentesting | OSEP |
| Red Team / Adversary Simulation | OSCP → OSEP |
| Exploit Development | OSED |
| Advanced Exploitation Research | OSEE |
Certification names, associated training, prerequisites, exam formats, and program requirements can evolve. Always verify current details with OffSec before registering.
Stage 00 — Before OffSec Certifications
Section titled “Stage 00 — Before OffSec Certifications”Before beginning the certification path, build technical foundations.
You should understand:
Networking
Linux
Windows
Web Technologies
Security Fundamentals
Scripting
Virtualization
Command-Line AdministrationNetworking Foundation
Section titled “Networking Foundation”Understand:
TCP/IP
TCP
UDP
DNS
HTTP/HTTPS
SSH
SMB
LDAP
Kerberos
RDP
Routing
NAT
Firewalls
Network SegmentationYou should be able to reason through:
HOST ↓IP ↓PORT ↓PROTOCOL ↓SERVICE ↓APPLICATIONLinux Foundation
Section titled “Linux Foundation”Be comfortable with:
Filesystem
Users
Groups
Permissions
Processes
Services
Networking
SSH
Logs
Cron
Shell Environment
SudoUseful administrative commands include:
pwdlscdcatgrepfindpsssipchmodchownsudosystemctljournalctlWindows Foundation
Section titled “Windows Foundation”Understand:
Users
Groups
NTFS Permissions
Processes
Services
Registry
Scheduled Tasks
PowerShell
Windows Networking
Remote Administration
Event LogsYou should also understand the basics of:
Active Directory
Domains
Domain Controllers
Kerberos
NTLM
Group PolicyWeb Foundation
Section titled “Web Foundation”Understand:
HTTP Requests
HTTP Responses
Headers
Cookies
Sessions
Authentication
Authorization
HTML
JavaScript Basics
APIs
JSONScripting Foundation
Section titled “Scripting Foundation”Develop basic capability with:
Python
Bash
PowerShellYou do not need to be an expert programmer.
You should be able to:
Read Code
Modify Simple Scripts
Understand Logic
Process Data
Automate Repetitive Tasks
Troubleshoot ErrorsCertification 01 — OSCP
Section titled “Certification 01 — OSCP”Offensive Security Certified Professional
Section titled “Offensive Security Certified Professional”OSCP is the central certification in the OffSec penetration-testing path.
Think of OSCP as developing the ability to move from:
CYBERSECURITY KNOWLEDGE ↓PRACTICAL PENETRATION TESTINGIt is particularly relevant for learners targeting:
Penetration Tester
Security Consultant
Offensive Security Engineer
Red Team Junior Roles
Vulnerability Assessment RolesOSCP Skill Areas
Section titled “OSCP Skill Areas”Build practical competency in areas such as:
Reconnaissance
Service Enumeration
Vulnerability Analysis
Web Assessment
Linux Assessment
Windows Assessment
Privilege Escalation
Active Directory
Network Analysis
Documentation
ReportingOSCP Methodology
Section titled “OSCP Methodology”Develop a consistent workflow:
SCOPE ↓DISCOVERY ↓ENUMERATION ↓ANALYSIS ↓VALIDATION ↓CONTROLLED EXPLOITATION ↓PRIVILEGE ASSESSMENT ↓EVIDENCE ↓REPORTINGThe Enumeration Habit
Section titled “The Enumeration Habit”One of the most valuable habits is:
ENUMERATE ↓FORM HYPOTHESIS ↓VALIDATE ↓RE-ENUMERATEWhen you get stuck, do not immediately assume you need another tool.
Ask:
Did I Fully Enumerate the Service?
Did I Miss an Application?
Did I Ignore a Permission?
Did I Miss a Credential?
Did I Misunderstand the Technology?
Did I Make an Incorrect Assumption?OSCP Preparation Milestone
Section titled “OSCP Preparation Milestone”Before attempting advanced timed practice, you should be comfortable performing authorized assessments of:
Linux Host +Windows Host +Web Application +Active Directory Environmentwithout depending completely on walkthroughs.
Recommended OSCP Lab Progression
Section titled “Recommended OSCP Lab Progression”Guided Labs ↓Easy Standalone Systems ↓Intermediate Systems ↓Privilege Escalation Labs ↓Active Directory Labs ↓Multi-System Environments ↓Timed Practice ↓Full SimulationsWho Should Prioritize OSCP?
Section titled “Who Should Prioritize OSCP?”Prioritize OSCP if your goal is:
General Penetration Testing
Infrastructure Pentesting
Internal Pentesting
Enterprise Security Consulting
Offensive Security Engineering
Red Team FoundationsCertification 02 — OSWA
Section titled “Certification 02 — OSWA”Offensive Security Web Assessor
Section titled “Offensive Security Web Assessor”OSWA focuses on web application security.
It is particularly relevant for professionals targeting:
Web Penetration Testing
Application Security
Product Security
Security ConsultingThe transition is:
GENERAL SECURITY ↓WEB TECHNOLOGIES ↓WEB SECURITY TESTINGBefore OSWA
Section titled “Before OSWA”Understand:
HTTP
HTTPS
Cookies
Sessions
Authentication
Authorization
HTML
JavaScript Basics
APIs
Databases
Web Servers
Application ArchitectureOSWA Skill Development
Section titled “OSWA Skill Development”Develop competency around:
Application Mapping
Input Analysis
Authentication Testing
Authorization Testing
Session Security
Injection Concepts
File Handling
Web Configuration
API Security
Application LogicWeb Testing Mental Model
Section titled “Web Testing Mental Model”Use:
APPLICATION ↓FUNCTION ↓REQUEST ↓USER-CONTROLLED INPUT ↓SERVER PROCESSING ↓SECURITY DECISION ↓RESPONSEThen ask:
Can Input Be Manipulated?
Is Authentication Enforced?
Is Authorization Enforced?
Can Users Cross Trust Boundaries?
Does the Server Trust User-Controlled Data?
Can Application Logic Be Abused?Who Should Prioritize OSWA?
Section titled “Who Should Prioritize OSWA?”Consider OSWA if your target role is:
Junior Web Penetration Tester
Application Security Analyst
Product Security Analyst
Web Security ConsultantOSWA to OSWE Progression
Section titled “OSWA to OSWE Progression”Think:
WEB FUNDAMENTALS ↓OSWA ↓REAL APPLICATION EXPERIENCE ↓CODE ANALYSIS ↓ADVANCED WEB SECURITY ↓OSWECertification 03 — OSWE
Section titled “Certification 03 — OSWE”Offensive Security Web Expert
Section titled “Offensive Security Web Expert”OSWE represents a deeper web application security specialization.
The progression moves beyond basic vulnerability identification toward understanding how applications behave internally.
Think:
REQUEST ↓APPLICATION LOGIC ↓SOURCE CODE ↓DATA FLOW ↓SECURITY CONTROL ↓VULNERABILITYOSWE Preparation Areas
Section titled “OSWE Preparation Areas”Develop stronger knowledge of:
Programming
Source-Code Analysis
Web Architecture
Authentication Logic
Authorization Logic
Data Flow
Application Frameworks
Database Interaction
API Architecture
Vulnerability ChainingCode Reading Becomes Important
Section titled “Code Reading Becomes Important”At this level, you should increasingly be able to examine code and ask:
Where Does Input Enter?
Where Does the Data Go?
Is It Validated?
Is It Encoded?
Which Security Check Runs?
Can the Check Be Bypassed?
Which Sensitive Operation Follows?OSWE Mindset
Section titled “OSWE Mindset”Beginner web testing may look like:
INPUT ↓PAYLOAD ↓RESPONSEAdvanced web assessment becomes:
APPLICATION ARCHITECTURE ↓SOURCE CODE ↓DATA FLOW ↓TRUST BOUNDARY ↓SECURITY CONTROL ↓LOGIC WEAKNESS ↓IMPACTWho Should Prioritize OSWE?
Section titled “Who Should Prioritize OSWE?”OSWE is especially relevant for:
Senior Web Penetration Tester
Application Security Engineer
Product Security Engineer
Security Researcher
Application Security ConsultantWeb Security Career Path
Section titled “Web Security Career Path”HTTP FUNDAMENTALS ↓WEB APPLICATION SECURITY ↓OSWA ↓MANUAL WEB TESTING ↓PROGRAMMING ↓SOURCE-CODE REVIEW ↓OSWE ↓ADVANCED APPSEC / PRODUCT SECURITYCertification 04 — OSEP
Section titled “Certification 04 — OSEP”Offensive Security Experienced Penetration Tester
Section titled “Offensive Security Experienced Penetration Tester”OSEP moves deeper into advanced enterprise offensive security.
This path becomes particularly relevant when environments include:
Multiple Windows Systems
Active Directory
Enterprise Identity
Network Segmentation
Administrative Infrastructure
Security Monitoring
Endpoint ControlsOSEP Career Direction
Section titled “OSEP Career Direction”OSEP is particularly aligned with:
Senior Penetration Testing
Enterprise Pentesting
Red Teaming
Adversary Simulation
Advanced Offensive Security ConsultingBefore OSEP
Section titled “Before OSEP”Build strong competency in:
Windows
Active Directory
PowerShell
Networking
Enterprise Authentication
Privilege Relationships
Linux
Penetration Testing MethodologyOSCP-level methodology provides an important foundation.
Enterprise Attack-Path Thinking
Section titled “Enterprise Attack-Path Thinking”At this stage, stop thinking only in terms of:
ONE HOST ↓ONE VULNERABILITYStart thinking:
IDENTITY ↓WORKSTATION ↓CREDENTIAL ↓SERVER ↓TRUST ↓PRIVILEGED IDENTITY ↓BUSINESS SYSTEMOSEP Skill Development
Section titled “OSEP Skill Development”Focus on understanding:
Enterprise Reconnaissance
Active Directory Relationships
Authentication
Network Segmentation
Privilege Relationships
Application Control Concepts
Endpoint Security Controls
Enterprise Attack Paths
Operational Security
Evidence CollectionUnderstanding Defenses Matters
Section titled “Understanding Defenses Matters”Advanced offensive professionals should understand controls such as:
EDR
Antivirus
Application Control
Network Segmentation
MFA
SIEM
Logging
Identity ProtectionThe professional objective is not simply:
AVOID DETECTIONIt is to understand whether authorized adversary behaviors can achieve the engagement objective and what defenders can learn from the exercise.
Who Should Prioritize OSEP?
Section titled “Who Should Prioritize OSEP?”OSEP is particularly useful for learners targeting:
Senior Penetration Tester
Red Team Operator
Adversary Simulation Engineer
Offensive Security Consultant
Enterprise Security TesterEnterprise Career Progression
Section titled “Enterprise Career Progression”NETWORKING ↓WINDOWS ↓ACTIVE DIRECTORY ↓OSCP ↓ENTERPRISE PENTESTING ↓ADVANCED AD ↓DEFENSIVE CONTROL AWARENESS ↓OSEP ↓RED TEAM / ADVERSARY SIMULATIONCertification 05 — OSED
Section titled “Certification 05 — OSED”Offensive Security Exploit Developer
Section titled “Offensive Security Exploit Developer”OSED represents a significant specialization away from general penetration testing.
The focus shifts toward lower-level software security and exploit development.
This requires stronger knowledge of:
Programming
Assembly
Computer Architecture
Memory
Debugging
Operating System Internals
Software VulnerabilitiesOSED Mental Model
Section titled “OSED Mental Model”Think:
PROGRAM ↓INPUT ↓MEMORY ↓CPU ↓PROGRAM STATE ↓VULNERABILITY ↓CONTROLLED RESEARCHBefore OSED
Section titled “Before OSED”Build knowledge in:
C / C++
Assembly
CPU Registers
Stack
Heap
Memory Addressing
Debugging
Windows Internals
Software Vulnerability ConceptsUnderstand the Stack
Section titled “Understand the Stack”Conceptually:
HIGH MEMORY+--------------------+| || STACK || |+--------------------+| || HEAP || |+--------------------+| || PROGRAM DATA || |+--------------------+| || PROGRAM CODE || |+--------------------+LOW MEMORYYou should eventually understand how:
Program Input ↓Memory Operations ↓Unexpected Program State ↓Security Impactcan occur.
Debugging Skills
Section titled “Debugging Skills”Become comfortable conceptually with:
Breakpoints
Registers
Memory
Stack Frames
Instructions
Program Flow
Exceptions
Crash AnalysisWho Should Prioritize OSED?
Section titled “Who Should Prioritize OSED?”OSED is particularly relevant for:
Exploit Developer
Vulnerability Researcher
Security Researcher
Low-Level Security Engineer
Advanced Offensive Security EngineerOSED Career Progression
Section titled “OSED Career Progression”PROGRAMMING ↓C / C++ ↓ASSEMBLY ↓COMPUTER ARCHITECTURE ↓DEBUGGING ↓WINDOWS INTERNALS ↓VULNERABILITY RESEARCH ↓OSEDCertification 06 — OSEE
Section titled “Certification 06 — OSEE”Offensive Security Exploitation Expert
Section titled “Offensive Security Exploitation Expert”OSEE sits in a highly advanced exploitation and security-research direction.
This is not normally the starting point for an offensive security learner.
The progression is closer to:
SECURITY FUNDAMENTALS ↓PROGRAMMING ↓OPERATING SYSTEM INTERNALS ↓ASSEMBLY ↓DEBUGGING ↓EXPLOIT DEVELOPMENT ↓VULNERABILITY RESEARCH ↓ADVANCED EXPLOITATION ↓OSEEOSEE Skill Direction
Section titled “OSEE Skill Direction”Professionals moving toward this level typically need deep knowledge of areas such as:
Operating System Internals
Memory Management
Advanced Debugging
Reverse Engineering
Exploit Development
Vulnerability Research
Software Security
Modern Exploit MitigationsOSEE Mindset
Section titled “OSEE Mindset”At this level, the question increasingly becomes:
WHY DID THE SOFTWARE FAIL?followed by:
HOW DOES THE OPERATING SYSTEMHANDLE THE FAILURE?and:
WHICH SECURITY MITIGATIONSAFFECT THE RESULT?Who Should Consider OSEE?
Section titled “Who Should Consider OSEE?”It is most relevant for highly specialized roles such as:
Senior Vulnerability Researcher
Exploit Researcher
Advanced Security Researcher
Exploit Development SpecialistDo You Need Every OffSec Certification?
Section titled “Do You Need Every OffSec Certification?”No.
For most professionals:
OSCP+ROLE-SPECIFIC SPECIALIZATIONis a much better strategy than attempting every certification.
Path 01 — Penetration Tester
Section titled “Path 01 — Penetration Tester”Recommended progression:
Networking ↓Linux ↓Windows ↓Web Fundamentals ↓Active Directory ↓OSCP ↓Professional Pentesting ExperiencePath 02 — Web Penetration Tester
Section titled “Path 02 — Web Penetration Tester”Recommended progression:
Web Development Fundamentals ↓HTTP ↓Web Security ↓OSWA ↓Programming ↓Source-Code Analysis ↓OSWEPath 03 — Red Team Operator
Section titled “Path 03 — Red Team Operator”Recommended progression:
Networking ↓Windows ↓Active Directory ↓OSCP ↓Enterprise Pentesting ↓Defensive Security Awareness ↓OSEP ↓Red Team OperationsPath 04 — Application Security Engineer
Section titled “Path 04 — Application Security Engineer”Recommended progression:
Programming ↓Web Development ↓Web Security ↓OSWA ↓Secure Coding ↓Code Review ↓OSWE ↓Application Security EngineeringPath 05 — Exploit Developer
Section titled “Path 05 — Exploit Developer”Recommended progression:
Programming ↓C / C++ ↓Assembly ↓Computer Architecture ↓Debugging ↓Operating System Internals ↓OSED ↓Advanced Vulnerability ResearchPath 06 — Vulnerability Researcher
Section titled “Path 06 — Vulnerability Researcher”Recommended progression:
Programming ↓Reverse Engineering ↓Operating System Internals ↓Debugging ↓Exploit Development ↓OSED ↓Advanced Research ↓OSEEHow to Choose Your First Certification
Section titled “How to Choose Your First Certification”Ask yourself:
What Job Do I Want?If the answer is:
Penetration Tester
Section titled “Penetration Tester”Start toward:
OSCPWeb Security Tester
Section titled “Web Security Tester”Consider:
OSWAApplication Security Specialist
Section titled “Application Security Specialist”Build toward:
OSWA ↓OSWEAdvanced Enterprise Pentester
Section titled “Advanced Enterprise Pentester”Build toward:
OSCP ↓OSEPExploit Developer
Section titled “Exploit Developer”Build toward:
OSEDAdvanced Exploitation Researcher
Section titled “Advanced Exploitation Researcher”Build deep foundations toward:
OSED ↓OSEESkill-Based Certification Strategy
Section titled “Skill-Based Certification Strategy”Use:
LEARN ↓LAB ↓REPEAT ↓BUILD PROJECT ↓ASSESS YOURSELF ↓CERTIFICATIONAvoid:
BUY COURSE ↓MEMORIZE ↓PASS EXAM ↓FORGETBuild Skills Before Exam Preparation
Section titled “Build Skills Before Exam Preparation”For each certification, divide your preparation into three stages.
Stage 1 — Foundation
Section titled “Stage 1 — Foundation”Understand the technologies.
Stage 2 — Practical Skill
Section titled “Stage 2 — Practical Skill”Practice repeatedly.
Stage 3 — Exam Preparation
Section titled “Stage 3 — Exam Preparation”Develop:
Time Management
Documentation
Methodology
Troubleshooting
Independent Problem SolvingRecommended Learning Ratio
Section titled “Recommended Learning Ratio”For practical offensive security certifications:
20% READING +60% HANDS-ON PRACTICE +20% NOTES + REPORTINGThe exact ratio can vary, but hands-on repetition should remain central.
The Three-Pass Lab Method
Section titled “The Three-Pass Lab Method”Pass 01 — Guided
Section titled “Pass 01 — Guided”Follow the lesson.
Understand each step.Pass 02 — Notes Only
Section titled “Pass 02 — Notes Only”Repeat using your own notes.Pass 03 — Independent
Section titled “Pass 03 — Independent”Start from scratch.
Use no walkthrough.
Solve independently.The third pass is where confidence develops.
Build a Personal Knowledge Base
Section titled “Build a Personal Knowledge Base”Maintain structured notes for:
Networking
Linux
Windows
Web
Active Directory
Enumeration
Privilege Escalation
Applications
Troubleshooting
ReportingFor each technology document:
What Is It?
How Does It Work?
How Do I Identify It?
How Do I Assess It?
What Common Weaknesses Exist?
What Evidence Should I Capture?
How Is It Remediated?Build Methodology Checklists
Section titled “Build Methodology Checklists”Example:
TARGET ↓DISCOVERY ↓SERVICE ENUMERATION ↓APPLICATION ENUMERATION ↓IDENTITY ENUMERATION ↓PERMISSION ANALYSIS ↓VULNERABILITY ANALYSIS ↓VALIDATION ↓PRIVILEGE ANALYSIS ↓EVIDENCE ↓REPORTAvoid Tool Dependency
Section titled “Avoid Tool Dependency”Do not build your learning around:
Tool A
Tool B
Tool CBuild it around:
PROTOCOL
TECHNOLOGY
ENUMERATION
SECURITY CONTROL
WEAKNESS
IMPACTTools will change.
Fundamentals remain.
Certification Preparation Mistake 01
Section titled “Certification Preparation Mistake 01”Avoid:
Watching Hundreds of HoursWithout PracticingReplace it with:
LEARN ↓PRACTICE ↓FAIL ↓TROUBLESHOOT ↓REPEATCertification Preparation Mistake 02
Section titled “Certification Preparation Mistake 02”Avoid:
Following Walkthroughs ForeverWalkthroughs can teach.
Dependency on walkthroughs prevents independent problem solving.
Certification Preparation Mistake 03
Section titled “Certification Preparation Mistake 03”Avoid:
Memorizing ExploitsInstead understand:
Technology ↓Configuration ↓Weakness ↓Security ConsequenceCertification Preparation Mistake 04
Section titled “Certification Preparation Mistake 04”Avoid ignoring reporting.
Practice writing:
Finding
Evidence
Impact
Remediationfrom the beginning.
Certification Preparation Mistake 05
Section titled “Certification Preparation Mistake 05”Do not compare your timeline with another learner.
Someone may have:
10 Years Linux Experiencewhile another person is learning:
Linux for the First TimeThe appropriate preparation period will be different.
When Are You Ready?
Section titled “When Are You Ready?”Do not measure readiness only by:
Number of Machines CompletedInstead ask:
Can I Enumerate Without a Checklist?
Can I Explain Why I Run Each Test?
Can I Troubleshoot When Something Fails?
Can I Recognize When My Assumption Is Wrong?
Can I Work Without a Walkthrough?
Can I Keep Accurate Notes?
Can I Produce a Professional Report?Certification vs Job Readiness
Section titled “Certification vs Job Readiness”Remember:
CERTIFICATION ≠AUTOMATIC JOB READINESSA stronger equation is:
CERTIFICATION +FOUNDATIONAL KNOWLEDGE +LAB EXPERIENCE +PROJECTS +REPORTING +COMMUNICATION =STRONGER JOB READINESSPortfolio Strategy
Section titled “Portfolio Strategy”For every major certification stage, create a portfolio project.
OSCP Direction
Section titled “OSCP Direction”Build:
Enterprise Penetration Testing ReportOSWA Direction
Section titled “OSWA Direction”Build:
Web Application Security AssessmentOSWE Direction
Section titled “OSWE Direction”Build:
Secure Code Review / AdvancedApplication AssessmentOSEP Direction
Section titled “OSEP Direction”Build:
Enterprise Attack-Path AssessmentOSED Direction
Section titled “OSED Direction”Build:
Controlled Vulnerability ResearchProjectKeep projects limited to authorized lab environments and sanitized evidence.
Career Mapping
Section titled “Career Mapping”| Certification | Primary Skill Direction | Typical Career Alignment |
|---|---|---|
| OSCP | Penetration Testing | Penetration Tester |
| OSWA | Web Security | Web Security Tester |
| OSWE | Advanced Web Security | AppSec / Web Pentester |
| OSEP | Enterprise Offensive Security | Senior Pentester / Red Team |
| OSED | Exploit Development | Security Research |
| OSEE | Advanced Exploitation | Advanced Security Research |
Beginner Roadmap
Section titled “Beginner Roadmap”If you are new to cybersecurity:
IT FUNDAMENTALS ↓NETWORKING ↓LINUX ↓WINDOWS ↓CYBERSECURITY ↓WEB ↓ACTIVE DIRECTORY ↓PENTESTING FUNDAMENTALS ↓OSCP PREPARATIONDo not rush directly into advanced certification material.
Intermediate Roadmap
Section titled “Intermediate Roadmap”If you already understand systems and security:
PENTESTING METHODOLOGY ↓LINUX + WINDOWS LABS ↓WEB LABS ↓ACTIVE DIRECTORY LABS ↓PRIVILEGE ESCALATION ↓ENTERPRISE LABS ↓OSCP ↓SPECIALIZATIONAdvanced Roadmap
Section titled “Advanced Roadmap”After building professional penetration-testing experience:
OSCP | +----------------+----------------+ | | | ↓ ↓ ↓ OSWE OSEP OSED | | | ↓ ↓ ↓ APPSEC RED TEAM RESEARCH | ↓ OSEEJob-Ready Milestone 01 — OSCP Direction
Section titled “Job-Ready Milestone 01 — OSCP Direction”You should be able to perform:
Network Enumeration
Linux Assessment
Windows Assessment
Web Enumeration
Privilege Analysis
Active Directory Assessment
Evidence Collection
Technical ReportingJob-Ready Milestone 02 — Web Direction
Section titled “Job-Ready Milestone 02 — Web Direction”You should be able to:
Map Applications
Analyze HTTP
Understand Sessions
Test Authentication
Test Authorization
Analyze Input
Understand Application Logic
Document FindingsJob-Ready Milestone 03 — Enterprise Direction
Section titled “Job-Ready Milestone 03 — Enterprise Direction”You should understand:
Windows Enterprise Architecture
Active Directory
Identity Relationships
Network Segmentation
Administrative Infrastructure
Security Monitoring
Attack PathsJob-Ready Milestone 04 — Research Direction
Section titled “Job-Ready Milestone 04 — Research Direction”You should understand:
Programming
Assembly
Memory
Debugging
Operating System Internals
Software Vulnerabilities
Exploit MitigationsOffSec Certification Readiness Checklist
Section titled “OffSec Certification Readiness Checklist”Foundations
Section titled “Foundations”- Networking fundamentals
- Linux administration
- Windows administration
- Security fundamentals
- Web fundamentals
- Basic scripting
Penetration Testing
Section titled “Penetration Testing”- Understand scope and authorization
- Perform reconnaissance
- Perform systematic enumeration
- Analyze vulnerabilities
- Validate findings
- Assess Linux privilege
- Assess Windows privilege
- Understand Active Directory
- Collect evidence
- Write reports
Web Security
Section titled “Web Security”- Understand HTTP deeply
- Understand authentication
- Understand authorization
- Understand sessions
- Understand APIs
- Perform manual web testing
- Understand application logic
Enterprise Security
Section titled “Enterprise Security”- Understand Windows environments
- Understand Active Directory
- Understand Kerberos
- Understand NTLM
- Understand enterprise identity
- Understand segmentation
- Understand defensive controls
Exploit Development
Section titled “Exploit Development”- Understand programming
- Understand C/C++
- Understand assembly
- Understand memory
- Understand debugging
- Understand OS internals
- Understand exploit mitigations
Professional Skills
Section titled “Professional Skills”- Maintain structured notes
- Troubleshoot independently
- Collect appropriate evidence
- Explain technical risk
- Recommend remediation
- Write professional reports
30 OffSec Roadmap Interview Questions
Section titled “30 OffSec Roadmap Interview Questions”- What is OffSec?
- What type of skills do OffSec certifications emphasize?
- What is OSCP?
- Who should consider OSCP?
- What foundations should you build before OSCP?
- Why is enumeration important?
- Why is reporting important in penetration testing?
- What is OSWA?
- Who should consider OSWA?
- What web fundamentals should you understand before web security testing?
- What is OSWE?
- How does advanced web testing differ from basic web testing?
- Why is source-code analysis valuable in application security?
- What is OSEP?
- Who should consider OSEP?
- Why is Active Directory important for enterprise penetration testing?
- Why should offensive professionals understand defensive controls?
- What is OSED?
- Who should consider exploit development?
- Why is assembly useful in vulnerability research?
- Why is debugging important?
- What is OSEE?
- Who is the advanced exploitation path intended for?
- Do penetration testers need every OffSec certification?
- How should certifications be selected?
- What is the three-pass lab method?
- Why should walkthrough dependency be avoided?
- What makes a strong offensive security portfolio?
- What is the difference between certification readiness and job readiness?
- How would you choose between OSWE, OSEP, and OSED?
Final OffSec Certification Map
Section titled “Final OffSec Certification Map”Remember:
START ↓ BUILD FUNDAMENTALS ↓ PENETRATION TESTING ↓ OSCP | +-------------+-------------+ | | | ↓ ↓ ↓ WEB ENTERPRISE EXPLOIT SECURITY OFFENSIVE DEVELOPMENT | SECURITY | ↓ ↓ ↓ OSWA OSEP OSED | | ↓ ↓ OSWE OSEEChoose according to your destination:
PENETRATION TESTER ↓ OSCPWEB / APPLICATION SECURITY ↓ OSWA ↓ OSWEENTERPRISE PENTEST / RED TEAM ↓ OSCP ↓ OSEPEXPLOIT DEVELOPMENT / RESEARCH ↓ OSED ↓ OSEEThe most important lesson is:
CERTIFICATIONS VALIDATEA PORTION OF YOUR SKILLS.
THEY DO NOT REPLACETHE PROCESS OF BUILDING THEM.Build:
FOUNDATION +PRACTICE +METHODOLOGY +PROJECTS +REPORTING +PROFESSIONAL EXPERIENCEand use certification as a milestone along that journey.
What’s Next?
Section titled “What’s Next?”➡️ 01 — OSCP
Next, you will focus specifically on the Offensive Security Certified Professional (OSCP) path and build a structured preparation strategy around:
OSCP Career Value ↓Prerequisite Skills ↓Networking ↓Linux ↓Windows ↓Web Security ↓Enumeration ↓Privilege Escalation ↓Active Directory ↓Practical Labs ↓Note-Taking ↓Reporting ↓Independent Practice ↓Exam Readiness ↓Job ReadinessThe goal will not simply be to prepare for a certification.
The goal will be to develop the practical penetration-testing methodology expected from an offensive security professional.