Skip to content

OffSec Certification Roadmap

OffSec certifications are widely associated with practical, hands-on offensive security skills.

Unlike certification paths focused primarily on theoretical knowledge, the OffSec journey emphasizes the ability to:

Understand Systems
Enumerate Methodically
Identify Security Weaknesses
Validate Findings
Solve Complex Problems
Document Evidence
Communicate Results

The most important principle is:

Do Not Collect Certifications.
Build Skills That Match
Your Target Career.

This roadmap will help you understand where the major OffSec certifications fit and how to build a progression around your desired offensive security role.

Practice offensive security techniques only in systems you own, dedicated training environments, or environments where you have explicit authorization.

The certifications covered in this path are:

01 — OSCP
Offensive Security Certified Professional
02 — OSWA
Offensive Security Web Assessor
03 — OSWE
Offensive Security Web Expert
04 — OSEP
Offensive Security Experienced
Penetration Tester
05 — OSED
Offensive Security Exploit Developer
06 — OSEE
Offensive Security Exploitation Expert

These should not necessarily be completed sequentially.

A better model is:

BUILD FOUNDATION
CHOOSE CAREER DIRECTION
BUILD SPECIALIZED SKILLS
SELECT RELEVANT CERTIFICATION
OFFENSIVE SECURITY
|
OSCP
|
+----------------+----------------+
| | |
↓ ↓ ↓
WEB SECURITY ENTERPRISE EXPLOIT
PENTESTING DEVELOPMENT
| | |
OSWA OSEP OSED
| |
OSWE OSEE

Another way to think about it:

Career Goal Certification Direction
Penetration Tester OSCP
Web Security Tester OSWA
Advanced Web Security OSWE
Advanced Enterprise Pentesting OSEP
Red Team / Adversary Simulation OSCP → OSEP
Exploit Development OSED
Advanced Exploitation Research OSEE

Certification names, associated training, prerequisites, exam formats, and program requirements can evolve. Always verify current details with OffSec before registering.

Before beginning the certification path, build technical foundations.

You should understand:

Networking
Linux
Windows
Web Technologies
Security Fundamentals
Scripting
Virtualization
Command-Line Administration

Understand:

TCP/IP
TCP
UDP
DNS
HTTP/HTTPS
SSH
SMB
LDAP
Kerberos
RDP
Routing
NAT
Firewalls
Network Segmentation

You should be able to reason through:

HOST
IP
PORT
PROTOCOL
SERVICE
APPLICATION

Be comfortable with:

Filesystem
Users
Groups
Permissions
Processes
Services
Networking
SSH
Logs
Cron
Shell Environment
Sudo

Useful administrative commands include:

Terminal window
pwd
ls
cd
cat
grep
find
ps
ss
ip
chmod
chown
sudo
systemctl
journalctl

Understand:

Users
Groups
NTFS Permissions
Processes
Services
Registry
Scheduled Tasks
PowerShell
Windows Networking
Remote Administration
Event Logs

You should also understand the basics of:

Active Directory
Domains
Domain Controllers
Kerberos
NTLM
Group Policy

Understand:

HTTP Requests
HTTP Responses
Headers
Cookies
Sessions
Authentication
Authorization
HTML
JavaScript Basics
APIs
JSON

Develop basic capability with:

Python
Bash
PowerShell

You do not need to be an expert programmer.

You should be able to:

Read Code
Modify Simple Scripts
Understand Logic
Process Data
Automate Repetitive Tasks
Troubleshoot Errors

OSCP is the central certification in the OffSec penetration-testing path.

Think of OSCP as developing the ability to move from:

CYBERSECURITY KNOWLEDGE
PRACTICAL PENETRATION TESTING

It is particularly relevant for learners targeting:

Penetration Tester
Security Consultant
Offensive Security Engineer
Red Team Junior Roles
Vulnerability Assessment Roles

Build practical competency in areas such as:

Reconnaissance
Service Enumeration
Vulnerability Analysis
Web Assessment
Linux Assessment
Windows Assessment
Privilege Escalation
Active Directory
Network Analysis
Documentation
Reporting

Develop a consistent workflow:

SCOPE
DISCOVERY
ENUMERATION
ANALYSIS
VALIDATION
CONTROLLED EXPLOITATION
PRIVILEGE ASSESSMENT
EVIDENCE
REPORTING

One of the most valuable habits is:

ENUMERATE
FORM HYPOTHESIS
VALIDATE
RE-ENUMERATE

When you get stuck, do not immediately assume you need another tool.

Ask:

Did I Fully Enumerate the Service?
Did I Miss an Application?
Did I Ignore a Permission?
Did I Miss a Credential?
Did I Misunderstand the Technology?
Did I Make an Incorrect Assumption?

Before attempting advanced timed practice, you should be comfortable performing authorized assessments of:

Linux Host
+
Windows Host
+
Web Application
+
Active Directory Environment

without depending completely on walkthroughs.

Guided Labs
Easy Standalone Systems
Intermediate Systems
Privilege Escalation Labs
Active Directory Labs
Multi-System Environments
Timed Practice
Full Simulations

Prioritize OSCP if your goal is:

General Penetration Testing
Infrastructure Pentesting
Internal Pentesting
Enterprise Security Consulting
Offensive Security Engineering
Red Team Foundations

OSWA focuses on web application security.

It is particularly relevant for professionals targeting:

Web Penetration Testing
Application Security
Product Security
Security Consulting

The transition is:

GENERAL SECURITY
WEB TECHNOLOGIES
WEB SECURITY TESTING

Understand:

HTTP
HTTPS
Cookies
Sessions
Authentication
Authorization
HTML
JavaScript Basics
APIs
Databases
Web Servers
Application Architecture

Develop competency around:

Application Mapping
Input Analysis
Authentication Testing
Authorization Testing
Session Security
Injection Concepts
File Handling
Web Configuration
API Security
Application Logic

Use:

APPLICATION
FUNCTION
REQUEST
USER-CONTROLLED INPUT
SERVER PROCESSING
SECURITY DECISION
RESPONSE

Then ask:

Can Input Be Manipulated?
Is Authentication Enforced?
Is Authorization Enforced?
Can Users Cross Trust Boundaries?
Does the Server Trust User-Controlled Data?
Can Application Logic Be Abused?

Consider OSWA if your target role is:

Junior Web Penetration Tester
Application Security Analyst
Product Security Analyst
Web Security Consultant

Think:

WEB FUNDAMENTALS
OSWA
REAL APPLICATION EXPERIENCE
CODE ANALYSIS
ADVANCED WEB SECURITY
OSWE

OSWE represents a deeper web application security specialization.

The progression moves beyond basic vulnerability identification toward understanding how applications behave internally.

Think:

REQUEST
APPLICATION LOGIC
SOURCE CODE
DATA FLOW
SECURITY CONTROL
VULNERABILITY

Develop stronger knowledge of:

Programming
Source-Code Analysis
Web Architecture
Authentication Logic
Authorization Logic
Data Flow
Application Frameworks
Database Interaction
API Architecture
Vulnerability Chaining

At this level, you should increasingly be able to examine code and ask:

Where Does Input Enter?
Where Does the Data Go?
Is It Validated?
Is It Encoded?
Which Security Check Runs?
Can the Check Be Bypassed?
Which Sensitive Operation Follows?

Beginner web testing may look like:

INPUT
PAYLOAD
RESPONSE

Advanced web assessment becomes:

APPLICATION ARCHITECTURE
SOURCE CODE
DATA FLOW
TRUST BOUNDARY
SECURITY CONTROL
LOGIC WEAKNESS
IMPACT

OSWE is especially relevant for:

Senior Web Penetration Tester
Application Security Engineer
Product Security Engineer
Security Researcher
Application Security Consultant
HTTP FUNDAMENTALS
WEB APPLICATION SECURITY
OSWA
MANUAL WEB TESTING
PROGRAMMING
SOURCE-CODE REVIEW
OSWE
ADVANCED APPSEC / PRODUCT SECURITY

Offensive Security Experienced Penetration Tester

Section titled “Offensive Security Experienced Penetration Tester”

OSEP moves deeper into advanced enterprise offensive security.

This path becomes particularly relevant when environments include:

Multiple Windows Systems
Active Directory
Enterprise Identity
Network Segmentation
Administrative Infrastructure
Security Monitoring
Endpoint Controls

OSEP is particularly aligned with:

Senior Penetration Testing
Enterprise Pentesting
Red Teaming
Adversary Simulation
Advanced Offensive Security Consulting

Build strong competency in:

Windows
Active Directory
PowerShell
Networking
Enterprise Authentication
Privilege Relationships
Linux
Penetration Testing Methodology

OSCP-level methodology provides an important foundation.

At this stage, stop thinking only in terms of:

ONE HOST
ONE VULNERABILITY

Start thinking:

IDENTITY
WORKSTATION
CREDENTIAL
SERVER
TRUST
PRIVILEGED IDENTITY
BUSINESS SYSTEM

Focus on understanding:

Enterprise Reconnaissance
Active Directory Relationships
Authentication
Network Segmentation
Privilege Relationships
Application Control Concepts
Endpoint Security Controls
Enterprise Attack Paths
Operational Security
Evidence Collection

Advanced offensive professionals should understand controls such as:

EDR
Antivirus
Application Control
Network Segmentation
MFA
SIEM
Logging
Identity Protection

The professional objective is not simply:

AVOID DETECTION

It is to understand whether authorized adversary behaviors can achieve the engagement objective and what defenders can learn from the exercise.

OSEP is particularly useful for learners targeting:

Senior Penetration Tester
Red Team Operator
Adversary Simulation Engineer
Offensive Security Consultant
Enterprise Security Tester
NETWORKING
WINDOWS
ACTIVE DIRECTORY
OSCP
ENTERPRISE PENTESTING
ADVANCED AD
DEFENSIVE CONTROL AWARENESS
OSEP
RED TEAM / ADVERSARY SIMULATION

OSED represents a significant specialization away from general penetration testing.

The focus shifts toward lower-level software security and exploit development.

This requires stronger knowledge of:

Programming
Assembly
Computer Architecture
Memory
Debugging
Operating System Internals
Software Vulnerabilities

Think:

PROGRAM
INPUT
MEMORY
CPU
PROGRAM STATE
VULNERABILITY
CONTROLLED RESEARCH

Build knowledge in:

C / C++
Assembly
CPU Registers
Stack
Heap
Memory Addressing
Debugging
Windows Internals
Software Vulnerability Concepts

Conceptually:

HIGH MEMORY
+--------------------+
| |
| STACK |
| |
+--------------------+
| |
| HEAP |
| |
+--------------------+
| |
| PROGRAM DATA |
| |
+--------------------+
| |
| PROGRAM CODE |
| |
+--------------------+
LOW MEMORY

You should eventually understand how:

Program Input
Memory Operations
Unexpected Program State
Security Impact

can occur.

Become comfortable conceptually with:

Breakpoints
Registers
Memory
Stack Frames
Instructions
Program Flow
Exceptions
Crash Analysis

OSED is particularly relevant for:

Exploit Developer
Vulnerability Researcher
Security Researcher
Low-Level Security Engineer
Advanced Offensive Security Engineer
PROGRAMMING
C / C++
ASSEMBLY
COMPUTER ARCHITECTURE
DEBUGGING
WINDOWS INTERNALS
VULNERABILITY RESEARCH
OSED

OSEE sits in a highly advanced exploitation and security-research direction.

This is not normally the starting point for an offensive security learner.

The progression is closer to:

SECURITY FUNDAMENTALS
PROGRAMMING
OPERATING SYSTEM INTERNALS
ASSEMBLY
DEBUGGING
EXPLOIT DEVELOPMENT
VULNERABILITY RESEARCH
ADVANCED EXPLOITATION
OSEE

Professionals moving toward this level typically need deep knowledge of areas such as:

Operating System Internals
Memory Management
Advanced Debugging
Reverse Engineering
Exploit Development
Vulnerability Research
Software Security
Modern Exploit Mitigations

At this level, the question increasingly becomes:

WHY DID THE SOFTWARE FAIL?

followed by:

HOW DOES THE OPERATING SYSTEM
HANDLE THE FAILURE?

and:

WHICH SECURITY MITIGATIONS
AFFECT THE RESULT?

It is most relevant for highly specialized roles such as:

Senior Vulnerability Researcher
Exploit Researcher
Advanced Security Researcher
Exploit Development Specialist

No.

For most professionals:

OSCP
+
ROLE-SPECIFIC SPECIALIZATION

is a much better strategy than attempting every certification.

Recommended progression:

Networking
Linux
Windows
Web Fundamentals
Active Directory
OSCP
Professional Pentesting Experience

Recommended progression:

Web Development Fundamentals
HTTP
Web Security
OSWA
Programming
Source-Code Analysis
OSWE

Recommended progression:

Networking
Windows
Active Directory
OSCP
Enterprise Pentesting
Defensive Security Awareness
OSEP
Red Team Operations

Recommended progression:

Programming
Web Development
Web Security
OSWA
Secure Coding
Code Review
OSWE
Application Security Engineering

Recommended progression:

Programming
C / C++
Assembly
Computer Architecture
Debugging
Operating System Internals
OSED
Advanced Vulnerability Research

Recommended progression:

Programming
Reverse Engineering
Operating System Internals
Debugging
Exploit Development
OSED
Advanced Research
OSEE

Ask yourself:

What Job Do I Want?

If the answer is:

Start toward:

OSCP

Consider:

OSWA

Build toward:

OSWA
OSWE

Build toward:

OSCP
OSEP

Build toward:

OSED

Build deep foundations toward:

OSED
OSEE

Use:

LEARN
LAB
REPEAT
BUILD PROJECT
ASSESS YOURSELF
CERTIFICATION

Avoid:

BUY COURSE
MEMORIZE
PASS EXAM
FORGET

For each certification, divide your preparation into three stages.

Understand the technologies.

Practice repeatedly.

Develop:

Time Management
Documentation
Methodology
Troubleshooting
Independent Problem Solving

For practical offensive security certifications:

20% READING
+
60% HANDS-ON PRACTICE
+
20% NOTES + REPORTING

The exact ratio can vary, but hands-on repetition should remain central.

Follow the lesson.
Understand each step.
Repeat using your own notes.
Start from scratch.
Use no walkthrough.
Solve independently.

The third pass is where confidence develops.

Maintain structured notes for:

Networking
Linux
Windows
Web
Active Directory
Enumeration
Privilege Escalation
Applications
Troubleshooting
Reporting

For each technology document:

What Is It?
How Does It Work?
How Do I Identify It?
How Do I Assess It?
What Common Weaknesses Exist?
What Evidence Should I Capture?
How Is It Remediated?

Example:

TARGET
DISCOVERY
SERVICE ENUMERATION
APPLICATION ENUMERATION
IDENTITY ENUMERATION
PERMISSION ANALYSIS
VULNERABILITY ANALYSIS
VALIDATION
PRIVILEGE ANALYSIS
EVIDENCE
REPORT

Do not build your learning around:

Tool A
Tool B
Tool C

Build it around:

PROTOCOL
TECHNOLOGY
ENUMERATION
SECURITY CONTROL
WEAKNESS
IMPACT

Tools will change.

Fundamentals remain.

Avoid:

Watching Hundreds of Hours
Without Practicing

Replace it with:

LEARN
PRACTICE
FAIL
TROUBLESHOOT
REPEAT

Avoid:

Following Walkthroughs Forever

Walkthroughs can teach.

Dependency on walkthroughs prevents independent problem solving.

Avoid:

Memorizing Exploits

Instead understand:

Technology
Configuration
Weakness
Security Consequence

Avoid ignoring reporting.

Practice writing:

Finding
Evidence
Impact
Remediation

from the beginning.

Do not compare your timeline with another learner.

Someone may have:

10 Years Linux Experience

while another person is learning:

Linux for the First Time

The appropriate preparation period will be different.

Do not measure readiness only by:

Number of Machines Completed

Instead ask:

Can I Enumerate Without a Checklist?
Can I Explain Why I Run Each Test?
Can I Troubleshoot When Something Fails?
Can I Recognize When My Assumption Is Wrong?
Can I Work Without a Walkthrough?
Can I Keep Accurate Notes?
Can I Produce a Professional Report?

Remember:

CERTIFICATION
AUTOMATIC JOB READINESS

A stronger equation is:

CERTIFICATION
+
FOUNDATIONAL KNOWLEDGE
+
LAB EXPERIENCE
+
PROJECTS
+
REPORTING
+
COMMUNICATION
=
STRONGER JOB READINESS

For every major certification stage, create a portfolio project.

Build:

Enterprise Penetration Testing Report

Build:

Web Application Security Assessment

Build:

Secure Code Review / Advanced
Application Assessment

Build:

Enterprise Attack-Path Assessment

Build:

Controlled Vulnerability Research
Project

Keep projects limited to authorized lab environments and sanitized evidence.

Certification Primary Skill Direction Typical Career Alignment
OSCP Penetration Testing Penetration Tester
OSWA Web Security Web Security Tester
OSWE Advanced Web Security AppSec / Web Pentester
OSEP Enterprise Offensive Security Senior Pentester / Red Team
OSED Exploit Development Security Research
OSEE Advanced Exploitation Advanced Security Research

If you are new to cybersecurity:

IT FUNDAMENTALS
NETWORKING
LINUX
WINDOWS
CYBERSECURITY
WEB
ACTIVE DIRECTORY
PENTESTING FUNDAMENTALS
OSCP PREPARATION

Do not rush directly into advanced certification material.

If you already understand systems and security:

PENTESTING METHODOLOGY
LINUX + WINDOWS LABS
WEB LABS
ACTIVE DIRECTORY LABS
PRIVILEGE ESCALATION
ENTERPRISE LABS
OSCP
SPECIALIZATION

After building professional penetration-testing experience:

OSCP
|
+----------------+----------------+
| | |
↓ ↓ ↓
OSWE OSEP OSED
| | |
↓ ↓ ↓
APPSEC RED TEAM RESEARCH
|
OSEE

You should be able to perform:

Network Enumeration
Linux Assessment
Windows Assessment
Web Enumeration
Privilege Analysis
Active Directory Assessment
Evidence Collection
Technical Reporting

You should be able to:

Map Applications
Analyze HTTP
Understand Sessions
Test Authentication
Test Authorization
Analyze Input
Understand Application Logic
Document Findings

Job-Ready Milestone 03 — Enterprise Direction

Section titled “Job-Ready Milestone 03 — Enterprise Direction”

You should understand:

Windows Enterprise Architecture
Active Directory
Identity Relationships
Network Segmentation
Administrative Infrastructure
Security Monitoring
Attack Paths

Job-Ready Milestone 04 — Research Direction

Section titled “Job-Ready Milestone 04 — Research Direction”

You should understand:

Programming
Assembly
Memory
Debugging
Operating System Internals
Software Vulnerabilities
Exploit Mitigations
  • Networking fundamentals
  • Linux administration
  • Windows administration
  • Security fundamentals
  • Web fundamentals
  • Basic scripting
  • Understand scope and authorization
  • Perform reconnaissance
  • Perform systematic enumeration
  • Analyze vulnerabilities
  • Validate findings
  • Assess Linux privilege
  • Assess Windows privilege
  • Understand Active Directory
  • Collect evidence
  • Write reports
  • Understand HTTP deeply
  • Understand authentication
  • Understand authorization
  • Understand sessions
  • Understand APIs
  • Perform manual web testing
  • Understand application logic
  • Understand Windows environments
  • Understand Active Directory
  • Understand Kerberos
  • Understand NTLM
  • Understand enterprise identity
  • Understand segmentation
  • Understand defensive controls
  • Understand programming
  • Understand C/C++
  • Understand assembly
  • Understand memory
  • Understand debugging
  • Understand OS internals
  • Understand exploit mitigations
  • Maintain structured notes
  • Troubleshoot independently
  • Collect appropriate evidence
  • Explain technical risk
  • Recommend remediation
  • Write professional reports
  1. What is OffSec?
  2. What type of skills do OffSec certifications emphasize?
  3. What is OSCP?
  4. Who should consider OSCP?
  5. What foundations should you build before OSCP?
  6. Why is enumeration important?
  7. Why is reporting important in penetration testing?
  8. What is OSWA?
  9. Who should consider OSWA?
  10. What web fundamentals should you understand before web security testing?
  11. What is OSWE?
  12. How does advanced web testing differ from basic web testing?
  13. Why is source-code analysis valuable in application security?
  14. What is OSEP?
  15. Who should consider OSEP?
  16. Why is Active Directory important for enterprise penetration testing?
  17. Why should offensive professionals understand defensive controls?
  18. What is OSED?
  19. Who should consider exploit development?
  20. Why is assembly useful in vulnerability research?
  21. Why is debugging important?
  22. What is OSEE?
  23. Who is the advanced exploitation path intended for?
  24. Do penetration testers need every OffSec certification?
  25. How should certifications be selected?
  26. What is the three-pass lab method?
  27. Why should walkthrough dependency be avoided?
  28. What makes a strong offensive security portfolio?
  29. What is the difference between certification readiness and job readiness?
  30. How would you choose between OSWE, OSEP, and OSED?

Remember:

START
BUILD FUNDAMENTALS
PENETRATION TESTING
OSCP
|
+-------------+-------------+
| | |
↓ ↓ ↓
WEB ENTERPRISE EXPLOIT
SECURITY OFFENSIVE DEVELOPMENT
| SECURITY |
↓ ↓ ↓
OSWA OSEP OSED
| |
↓ ↓
OSWE OSEE

Choose according to your destination:

PENETRATION TESTER
OSCP
WEB / APPLICATION SECURITY
OSWA
OSWE
ENTERPRISE PENTEST / RED TEAM
OSCP
OSEP
EXPLOIT DEVELOPMENT / RESEARCH
OSED
OSEE

The most important lesson is:

CERTIFICATIONS VALIDATE
A PORTION OF YOUR SKILLS.
THEY DO NOT REPLACE
THE PROCESS OF BUILDING THEM.

Build:

FOUNDATION
+
PRACTICE
+
METHODOLOGY
+
PROJECTS
+
REPORTING
+
PROFESSIONAL EXPERIENCE

and use certification as a milestone along that journey.

➡️ 01 — OSCP

Next, you will focus specifically on the Offensive Security Certified Professional (OSCP) path and build a structured preparation strategy around:

OSCP Career Value
Prerequisite Skills
Networking
Linux
Windows
Web Security
Enumeration
Privilege Escalation
Active Directory
Practical Labs
Note-Taking
Reporting
Independent Practice
Exam Readiness
Job Readiness

The goal will not simply be to prepare for a certification.

The goal will be to develop the practical penetration-testing methodology expected from an offensive security professional.