Skip to content

01 — OSCP

The Offensive Security Certified Professional (OSCP) is a practical offensive security certification focused on penetration-testing methodology, technical problem solving, enumeration, exploitation concepts, privilege escalation, Active Directory, documentation, and reporting.

For aspiring penetration testers, OSCP should be viewed as more than an exam.

It represents a transition from:

I Understand Cybersecurity Concepts

to:

I Can Methodically Assess
an Authorized Environment
and Document the Security Risk

The real objective of your preparation should therefore be:

FUNDAMENTALS
METHODOLOGY
PRACTICE
INDEPENDENT PROBLEM SOLVING
DOCUMENTATION
PROFESSIONAL PENTESTING SKILLS

Perform penetration-testing activities only against systems you own, dedicated training environments, or systems where you have explicit authorization.

Certification: OSCP
Primary Domain: Penetration Testing
Skill Level: Intermediate Practical Offensive Security
Primary Career Direction: Penetration Testing and Offensive Security
Recommended Approach: Hands-on practice combined with strong fundamentals and systematic methodology

Relevant career roles include:

Junior Penetration Tester
Penetration Tester
Security Consultant
Offensive Security Engineer
Vulnerability Assessment Consultant
Red Team Operator — Foundation

Your preparation should develop the ability to:

Understand the Target
Discover Services
Enumerate Thoroughly
Analyze Weaknesses
Validate Safely
Assess Privilege
Understand Attack Paths
Collect Evidence
Document Findings
Produce a Professional Report

Think of OSCP as a strong practical milestone between foundational cybersecurity knowledge and professional penetration testing.

IT FUNDAMENTALS
NETWORKING
LINUX + WINDOWS
SECURITY FUNDAMENTALS
WEB TECHNOLOGIES
PENTESTING FUNDAMENTALS
OSCP
PENETRATION TESTER
SENIOR PENTESTER
SPECIALIZATION

Possible specializations after building strong practical experience include:

Web Application Security
Enterprise Penetration Testing
Red Teaming
Cloud Penetration Testing
Application Security
Exploit Development

01 — Understand the Professional Pentesting Mindset

Section titled “01 — Understand the Professional Pentesting Mindset”

A beginner often thinks:

Find Vulnerability
Run Exploit
Get Access

A professional penetration tester thinks:

Understand Scope
Understand Environment
Enumerate
Form Hypothesis
Validate
Understand Impact
Collect Evidence
Recommend Remediation

That difference is critical.

02 — Learn the Penetration Testing Lifecycle

Section titled “02 — Learn the Penetration Testing Lifecycle”

Develop a repeatable workflow.

AUTHORIZATION
SCOPE
RECONNAISSANCE
DISCOVERY
ENUMERATION
VULNERABILITY ANALYSIS
CONTROLLED VALIDATION
PRIVILEGE ASSESSMENT
IMPACT ANALYSIS
EVIDENCE
CLEANUP
REPORTING

Do not skip directly from:

IP ADDRESS

to:

EXPLOIT

The work between those two stages is where much of the real skill exists.

Before touching a target, establish:

What Can I Test?
What Cannot I Test?
When Can I Test?
Which Techniques Are Permitted?
Which Activities Are Restricted?
Who Do I Contact if Something Goes Wrong?

Professional penetration testing requires:

Authorization
+
Scope
+
Rules of Engagement

Networking is foundational for OSCP preparation.

You should understand:

TCP/IP
IPv4
Subnetting
Routing
TCP
UDP
ICMP
DNS
HTTP
HTTPS
SSH
SMB
LDAP
Kerberos
RDP
NAT
VPN
Firewalls
Network Segmentation
TARGET
IP ADDRESS
PORT
PROTOCOL
SERVICE
APPLICATION
SECURITY CONTROL
Port Common Service Why It Matters
21 FTP File transfer
22 SSH Remote administration
25 SMTP Email
53 DNS Name resolution
80 HTTP Web
88 Kerberos Domain authentication
135 RPC Windows services
139 NetBIOS Legacy Windows networking
389 LDAP Directory services
443 HTTPS Encrypted web
445 SMB Windows file/service access
636 LDAPS Encrypted LDAP
3389 RDP Windows remote desktop

Do not only memorize ports.

For every service ask:

What Does It Do?
How Does It Authenticate?
What Information Does It Expose?
Which Configuration Controls It?
What Permissions Exist?
What Security Weaknesses Commonly Affect It?

Linux knowledge is essential.

Become comfortable with:

Filesystem
Users
Groups
Permissions
Processes
Services
Networking
Packages
SSH
Logs
Cron
Environment Variables
Shells
Sudo

Useful commands include:

Terminal window
whoami
id
hostname
pwd
ls
cat
grep
find
ps
ss
ip
sudo
systemctl
journalctl

When entering an authorized Linux lab system, ask:

WHO AM I?
WHAT SYSTEM IS THIS?
WHAT GROUPS DO I BELONG TO?
WHAT IS RUNNING?
WHAT FILES CAN I ACCESS?
WHAT PRIVILEGE DO I HAVE?

Learn:

User
Group
Other
Read
Write
Execute
Ownership
SUID/SGID Concepts
Sudo

Understand why:

PERMISSION
+
FILE
+
PROCESS
+
IDENTITY

can create a security boundary.

Windows is equally important.

Understand:

Users
Groups
NTFS Permissions
Processes
Services
Registry
Scheduled Tasks
PowerShell
Windows Firewall
Networking
Event Logs
Remote Administration

Useful commands include:

Terminal window
whoami
hostname
Get-ComputerInfo
Get-Process
Get-Service
Get-LocalUser
Get-LocalGroup
Get-LocalGroupMember Administrators
Get-ScheduledTask
Get-NetTCPConnection
IDENTITY
GROUPS
PRIVILEGES
SERVICES
TASKS
APPLICATIONS
FILESYSTEM
CONFIGURATION

You do not need advanced software-development skills before beginning OSCP preparation.

You should be comfortable reading and modifying:

Python
Bash
PowerShell

Understand:

Variables
Conditions
Loops
Functions
Files
Strings
Arguments
HTTP Requests
JSON
Error Handling

The objective is:

Understand What the Script Does
Understand What Input It Takes
Understand What It Changes
Troubleshoot It Safely

Never execute unfamiliar code simply because it appears in a walkthrough.

Before assessing web applications, understand:

HTTP
HTTPS
Request Methods
Status Codes
Headers
Cookies
Sessions
Authentication
Authorization
HTML
JavaScript Basics
APIs
JSON
Databases
CLIENT
HTTP REQUEST
WEB SERVER
APPLICATION
DATABASE / API
HTTP RESPONSE

Understand the structure:

METHOD
PATH
HEADERS
COOKIES
PARAMETERS
BODY

Example conceptually:

Client
Request
Application
Security Decision
Response

Ask:

What Can the User Control?
What Does the Server Trust?
Where Is Authentication Checked?
Where Is Authorization Checked?

Develop familiarity with areas such as:

Authentication Weaknesses
Authorization Weaknesses
Input Validation
Injection
Cross-Site Scripting
File Upload Security
Path Traversal
Server-Side Request Forgery
Session Security
API Security
Security Misconfiguration

Use OWASP concepts to organize your learning.

Do not depend completely on automated scanners.

Learn how to inspect:

Requests
Responses
Parameters
Headers
Cookies
Sessions
Tokens
Application Workflow

A strong workflow is:

MAP APPLICATION
IDENTIFY INPUT
UNDERSTAND EXPECTED BEHAVIOR
IDENTIFY SECURITY DECISION
TEST ASSUMPTION
DOCUMENT RESULT

Enumeration is one of the most important OSCP skills.

Think:

DISCOVERY
SERVICE
VERSION
CONFIGURATION
APPLICATION
IDENTITY
PERMISSIONS
POTENTIAL WEAKNESS

The question is not:

Which Exploit Should I Try?

The better question is:

What Have I Learned About
This Service?

14 — Build a Service Enumeration Checklist

Section titled “14 — Build a Service Enumeration Checklist”

For each discovered service record:

IP Address:
Port:
Protocol:
Service:
Version:
Authentication:
Accessible Resources:
Observed Configuration:
Potential Security Concerns:
Next Validation Step:

This prevents random testing.

A vulnerability scanner can identify potential weaknesses.

It does not automatically prove:

Exploitability
Business Impact
Actual Exposure

Use:

DETECTION
RESEARCH
ENVIRONMENT VALIDATION
CONTROLLED TEST
IMPACT ANALYSIS

When you discover a technology, research:

Product
Version
Configuration
Known Security Issues
Vendor Advisories
Required Preconditions
Affected Versions
Available Mitigations

Avoid:

Copy Random Exploit
Run Immediately

Prefer:

READ
UNDERSTAND
VERIFY
TEST SAFELY

Before using proof-of-concept code in an authorized lab, determine:

What Does It Do?
Which Target Does It Contact?
Which Parameters Must Change?
Does It Modify the Target?
Could It Crash the Service?
Does It Download Anything?
Does It Require Elevated Privilege?

18 — Learn Linux Privilege Escalation Methodology

Section titled “18 — Learn Linux Privilege Escalation Methodology”

After obtaining authorized low-privilege access, begin systematic enumeration.

CURRENT USER
GROUPS
SUDO
FILES
PROCESSES
SERVICES
SCHEDULED JOBS
CREDENTIAL EXPOSURE
CONFIGURATION

Use:

Terminal window
whoami
id

Understand:

User
UID
Groups
Effective Privilege

In an authorized lab:

Terminal window
sudo -l

Ask:

Which Commands Are Allowed?
Under Which Identity?
Are Restrictions Applied?
Is the Permission Required?

The important skill is understanding the privilege relationship.

Look conceptually for:

Sensitive Files Writable by
Unprivileged Users
Privileged Scripts with Weak Permissions
Application Configuration Exposure
Credential Files
Unnecessary Group Write Access

Understand:

Which Processes Run?
Which Identity Runs Them?
Which Files Do They Use?
Which Configuration Controls Them?
Which Network Services Do They Expose?

Understand:

Cron Jobs
Scheduled Scripts
Automated Maintenance
Backup Jobs

Ask:

What Runs?
When?
As Whom?
From Which File?
Who Can Modify It?

Do not think:

Run Enumeration Script
Pick Highlighted Result
Get Root

Think:

ENUMERATE
UNDERSTAND
IDENTIFY TRUST
IDENTIFY WEAK PERMISSION
VALIDATE

25 — Learn Windows Privilege Escalation Methodology

Section titled “25 — Learn Windows Privilege Escalation Methodology”

Use the same systematic approach.

CURRENT USER
GROUPS
PRIVILEGES
SERVICES
SCHEDULED TASKS
FILESYSTEM
REGISTRY
APPLICATIONS
CREDENTIAL EXPOSURE

Start with:

Terminal window
whoami
whoami /groups
whoami /priv

Understand:

Current User
Group Membership
Available Privileges
Administrative Context

Use:

Terminal window
Get-Service

For interesting services investigate:

Service Identity
Executable
Configuration
Permissions
Startup Behavior
Business Purpose

Use:

Terminal window
Get-ScheduledTask

Ask:

What Runs?
Who Runs It?
When Does It Run?
Where Is the Executable?
Who Can Modify the Referenced Content?

Inventory:

Installed Applications
Custom Applications
Administrative Tools
Legacy Software

Understand:

Version
Configuration
Permissions
Execution Context
Business Purpose

30 — Learn Active Directory Fundamentals

Section titled “30 — Learn Active Directory Fundamentals”

Active Directory is a major enterprise skill area.

Understand:

Forest
Domain
Domain Controller
Organizational Unit
User
Group
Computer
Group Policy
Trust
LDAP
Kerberos
NTLM
DNS
FOREST
|
+-- DOMAIN
|
+-- Domain Controllers
|
+-- Users
|
+-- Groups
|
+-- Computers
|
+-- OUs
|
+-- GPOs

Learn normal authentication before studying attacks.

Conceptually:

USER
AUTHENTICATION
DOMAIN CONTROLLER
IDENTITY VALIDATION
RESOURCE ACCESS

Understand the roles of:

Kerberos
NTLM
LDAP
DNS

At a high level:

USER
AUTHENTICATION SERVICE
TICKET-GRANTING TICKET
SERVICE REQUEST
SERVICE TICKET
RESOURCE

You should understand:

Identity
Tickets
Services
Trust
Authorization

before learning attack techniques.

Groups often determine enterprise access.

Think:

USER
GROUP
PRIVILEGE
RESOURCE

Review concepts such as:

Domain Groups
Administrative Groups
Nested Membership
Delegation
Service Accounts

Enterprise compromise is often not caused by one critical vulnerability.

It can result from:

SMALL WEAKNESS
+
EXCESSIVE ACCESS
+
CREDENTIAL EXPOSURE
+
WEAK SEGMENTATION

creating:

ATTACK PATH

Example conceptually:

LOW-PRIVILEGE USER
WORKSTATION ACCESS
EXCESSIVE PERMISSION
SERVER ACCESS
PRIVILEGED RELATIONSHIP
HIGHER BUSINESS IMPACT

Build a mental inventory:

DOMAIN
USERS
GROUPS
COMPUTERS
SESSIONS
SERVICES
POLICIES
TRUST RELATIONSHIPS
PRIVILEGE PATHS

Learn the differences between:

Password
Password Hash
Authentication Token
Kerberos Ticket
SSH Key
API Credential
Certificate

For each credential type ask:

Where Is It Stored?
Who Can Access It?
How Is It Protected?
How Long Is It Valid?
What Can It Access?

Enterprise environments are rarely flat.

You may encounter:

USER NETWORK
|
+-- SERVER NETWORK
|
+-- MANAGEMENT NETWORK
|
+-- APPLICATION NETWORK
|
+-- DIRECTORY SERVICES

Understand:

Routing
Reachability
Firewall Rules
Trust Boundaries

Pivoting allows an authorized assessment to evaluate reachable systems through another controlled system.

Think:

TESTING SYSTEM
AUTHORIZED HOST A
INTERNAL NETWORK
AUTHORIZED HOST B

The core skills behind pivoting are:

Routing
Ports
Interfaces
Network Reachability
Segmentation

Do not treat pivoting as merely memorizing tunneling commands.

Lateral movement is about moving between authorized systems or identity contexts while evaluating enterprise attack paths.

Common legitimate enterprise technologies involved in remote administration include:

RDP
SMB
SSH
PowerShell Remoting
Administrative Platforms

The security question is:

Can Weak Credentials,
Excessive Privilege,
or Poor Segmentation
Turn Legitimate Administration
into an Attack Path?

40 — Build a Repeatable Host Methodology

Section titled “40 — Build a Repeatable Host Methodology”

For every authorized target:

01 Identify Host
02 Identify Open Services
03 Enumerate Every Service
04 Identify Applications
05 Identify Authentication
06 Identify Accessible Resources
07 Research Technology
08 Form Hypotheses
09 Validate Safely
10 Document Evidence
11 Re-Enumerate

When stuck:

DO NOT PANIC
DO NOT RANDOMLY ATTACK
RETURN TO ENUMERATION

Ask:

Which Port Did I Ignore?
Which Web Directory Did I Miss?
Which Application Function Did I Skip?
Which Credential Did I Not Test
Where Authorized?
Which Permission Did I Overlook?
Which Service Needs Deeper Research?

Create notes from the first minute of an assessment.

Example:

Target:
192.0.2.10
Operating System:
Unknown
Services:
22 SSH
80 HTTP
Web:
Application identified
Authentication:
Observed
Potential Findings:
Pending validation
Evidence:
Captured
Next Actions:
Deeper service enumeration
TARGET
|
+-- Discovery
|
+-- Services
|
+-- Web
|
+-- Credentials
|
+-- Access
|
+-- Privilege
|
+-- Evidence
|
+-- Findings
|
+-- Cleanup

Do not wait until the end.

Capture:

Target
Timestamp
Relevant Command
Relevant Output
Screenshot
Security Context
Result

Your evidence should prove the finding without unnecessarily collecting sensitive data.

A penetration-testing report typically contains:

Executive Summary
Scope
Methodology
Technical Findings
Evidence
Risk
Business Impact
Recommendations
Conclusion
Finding ID:
Title:
Severity:
Affected Asset:
Description:
Evidence:
Technical Impact:
Business Impact:
Recommendation:
Validation:
Finding ID:
PT-001
Title:
Excessive Administrative Privilege
Severity:
High
Observation:
An account intended for standard operations
has administrative access beyond its
documented business requirement.
Security Risk:
Compromise of the identity could allow an
attacker to perform privileged actions.
Recommendation:
Remove unnecessary administrative access
and apply least privilege with periodic
access reviews.

44 — Practice Writing Executive Summaries

Section titled “44 — Practice Writing Executive Summaries”

Executives generally need:

What Was Tested?
What Was Found?
What Is the Risk?
What Should Be Fixed First?

Avoid filling the executive summary with:

Commands
Payloads
Raw Tool Output
Technical Noise

Your practice should progress from simple systems to complete environments.

FOUNDATION LABS
SINGLE-HOST LABS
PRIVILEGE LABS
WEB LABS
WINDOWS + LINUX LABS
ACTIVE DIRECTORY LABS
MULTI-SYSTEM LABS
TIMED SIMULATIONS

Use the learning material.

Understand:

Why?
What?
How?

Repeat the lab using your own notes.

Start again without the guide.

If you cannot reproduce the workflow, return to the weak area.

Create:

Mistake:
What Happened:
Why I Missed It:
Correct Approach:
How I Will Recognize It Next Time:

Common entries may include:

Did Not Enumerate All Services
Ignored Application Function
Assumed Credentials Were Invalid Everywhere
Missed Permission
Did Not Re-Enumerate After Access
Poor Notes
Spent Too Long on One Hypothesis

48 — Build a Personal Enumeration Playbook

Section titled “48 — Build a Personal Enumeration Playbook”

Organize by technology.

FTP
SSH
DNS
HTTP
HTTPS
SMB
LDAP
Kerberos
RDP
Databases
Linux
Windows
Active Directory

For each service document:

Purpose
Identification
Enumeration Questions
Authentication
Common Misconfigurations
Evidence
Remediation

A checklist should support your thinking.

It should not replace it.

Bad:

Command 1
Command 2
Command 3
Nothing Worked
Give Up

Better:

What Am I Trying to Learn?
Which Protocol Provides That Information?
Which Test Can Answer the Question?
What Did the Result Tell Me?

Automation is valuable.

But periodically perform manual enumeration so you understand what automation is doing.

The progression should be:

MANUAL
UNDERSTAND
AUTOMATE
VALIDATE AUTOMATION

not:

AUTOMATE
TRUST EVERYTHING

Timed practical assessments require discipline.

Create checkpoints such as:

Initial Discovery
Service Enumeration
Primary Hypotheses
Re-Enumeration
Documentation Check
Evidence Check

If one path consumes excessive time without producing new evidence:

STOP
REVIEW
RE-ENUMERATE
CHANGE HYPOTHESIS

Instead of:

Try Everything

use:

Observation:
Web application exposes upload functionality.
Hypothesis:
Server-side validation may be insufficient.
Validation:
Test safely within the authorized lab.
Result:
Document whether the hypothesis was
supported or rejected.

This is closer to professional security testing.

A common preparation problem is spending too long on one path.

Ask:

Am I Learning New Information?
Do I Have Evidence Supporting This Path?
Have I Fully Enumerated Other Services?
Am I Repeating the Same Failed Test?

If not:

MOVE
ENUMERATE SOMETHING ELSE
RETURN LATER

When something fails, determine:

Is the Target Reachable?
Is the Port Reachable?
Is the Service Running?
Is Authentication Required?
Is My Syntax Correct?
Is My Assumption Correct?
Is a Security Control Interfering?

Troubleshooting is an offensive security skill.

When you use a command or script, understand:

Command
Options
Target
Expected Result
Potential Impact

If you cannot explain what it does, research it first.

Example:

OSCP-Practice
|
+-- 01-Targets
|
+-- 02-Enumeration
|
+-- 03-Web
|
+-- 04-Linux
|
+-- 05-Windows
|
+-- 06-Active-Directory
|
+-- 07-Evidence
|
+-- 08-Reports
|
+-- 09-Mistakes
|
+-- 10-Playbooks

Track any artifacts created during authorized testing.

Maintain:

Artifact
Target
Purpose
Created
Removed
Verified

Cleanup is part of professional assessment methodology.

Do not publish sensitive lab solutions or material you are not permitted to redistribute.

Instead create original authorized projects demonstrating your methodology.

Document:

System Discovery
Service Enumeration
Linux Enumeration
Privilege Analysis
Findings
Remediation

Document:

Windows Enumeration
Users
Groups
Services
Applications
Privilege Analysis
Security Findings

Document:

Application Mapping
Authentication
Authorization
Input Security
Findings
Remediation

Project 04 — Active Directory Assessment

Section titled “Project 04 — Active Directory Assessment”

Document:

Domain Architecture
Users
Groups
Computers
Authentication
Privilege Relationships
Attack Paths
Findings

Combine:

NETWORK
+
LINUX
+
WINDOWS
+
WEB
+
ACTIVE DIRECTORY
+
REPORTING

59 — Build Exam Readiness Through Competency

Section titled “59 — Build Exam Readiness Through Competency”

Avoid measuring readiness solely by:

Hours Watched
Notes Written
Machines Completed

Measure:

Can I Start from an Unknown Target?
Can I Enumerate Methodically?
Can I Explain Every Test?
Can I Troubleshoot?
Can I Work Without a Walkthrough?
Can I Maintain Evidence?
Can I Produce a Clear Report?

You should understand:

Networking
Linux
Windows
HTTP
Security Fundamentals

Given an authorized host, you can systematically determine:

Open Services
Applications
Authentication
Accessible Resources
Potential Weaknesses

OSCP Readiness Level 03 — Initial Access Analysis

Section titled “OSCP Readiness Level 03 — Initial Access Analysis”

You can:

Research Technologies
Understand Vulnerability Preconditions
Modify Lab Configuration Safely
Validate a Hypothesis
Troubleshoot Failure

OSCP Readiness Level 04 — Privilege Assessment

Section titled “OSCP Readiness Level 04 — Privilege Assessment”

Given authorized low-privilege lab access, you can systematically assess:

Linux Privilege
Windows Privilege
Permissions
Services
Scheduled Activity
Configuration
Credential Exposure

OSCP Readiness Level 05 — Active Directory

Section titled “OSCP Readiness Level 05 — Active Directory”

You understand:

Domain Architecture
Users
Groups
Computers
Kerberos
NTLM
LDAP
Group Policy
Privilege Relationships
Attack Paths

You can produce:

Scope
Methodology
Evidence
Findings
Impact
Remediation
Executive Summary

OSCP Readiness Level 07 — Independent Assessment

Section titled “OSCP Readiness Level 07 — Independent Assessment”

You can complete an unfamiliar authorized lab using:

Your Methodology
Your Notes
Your Research
Your Reasoning

rather than relying on:

Step-by-Step Walkthrough

Use this as a flexible framework rather than a guarantee.

Focus on:

Networking
Linux
Windows
HTTP
Scripting

Focus on:

Service Discovery
Service Enumeration
Web Enumeration
Vulnerability Research

Focus on:

Linux Assessment
Windows Assessment
Privilege Escalation Methodology
Troubleshooting

Focus on:

HTTP
Authentication
Authorization
Input Security
Application Logic
Manual Testing

Focus on:

Domain Architecture
Kerberos
NTLM
LDAP
Users
Groups
Computers
Privilege Relationships

Practice:

Multi-System Enumeration
Attack-Path Analysis
Evidence Collection
Reporting

Perform:

Timed Practice
Independent Enumeration
Independent Troubleshooting
Evidence Capture
Report Writing
Weak-Area Review

Example:

30 Minutes
Concept Review
90 Minutes
Hands-On Lab
30 Minutes
Notes
30 Minutes
Repeat Weak Area

Adjust this according to your schedule.

Consistency matters more than one unusually long study session.

At the end of each week ask:

What Did I Learn?
What Can I Reproduce?
Where Did I Need a Walkthrough?
What Did I Miss During Enumeration?
What Should I Repeat Next Week?

For any practical timed assessment, focus on:

CALM
METHOD
ENUMERATION
EVIDENCE
TIME MANAGEMENT
REPORTING

Avoid:

PANIC
RANDOM TESTING
POOR NOTES
LOST EVIDENCE

Do not think:

I Will Recreate Everything Later

Instead:

ACTION
RESULT
EVIDENCE
NOTE

Avoid:

Starting Without Networking Fundamentals
Ignoring Linux Administration
Ignoring Windows Administration
Weak Active Directory Knowledge
Depending Entirely on Automated Tools
Using Walkthroughs Too Quickly
Memorizing Commands Without Understanding
Running Unknown Scripts Blindly
Poor Enumeration
Failure to Re-Enumerate
Ignoring Web Fundamentals
Ignoring Reporting
Poor Note-Taking
Spending Too Long on One Hypothesis
Not Practicing Under Time Constraints
Collecting Machines Instead of Building Skills

Use:

01 Stop Random Testing
02 Review Scope
03 Review Existing Notes
04 Recheck Open Services
05 Enumerate Each Service Again
06 Review Application Functionality
07 Review Credentials and Permissions
08 Verify Assumptions
09 Research the Technology
10 Form a New Hypothesis

The key question is:

What Information Am I Missing?

Passing a certification and becoming an effective penetration tester are related but different goals.

Certification preparation develops:

Technical Skills
Methodology
Problem Solving
Time Management
Reporting

Professional pentesting additionally requires:

Client Communication
Scope Management
Risk Assessment
Change Awareness
Business Context
Evidence Handling
Remediation Guidance
Team Collaboration

Once you have developed strong general penetration-testing skills, decide where to specialize.

OSCP
|
+----------------+----------------+
| | |
↓ ↓ ↓
WEB ENTERPRISE CLOUD
SECURITY OFFENSIVE SECURITY
| | |
↓ ↓ ↓
OSWA / OSWE OSEP CLOUD PENTEST

Another path is:

OSCP
LOW-LEVEL PROGRAMMING
ASSEMBLY
DEBUGGING
OSED
VULNERABILITY RESEARCH

A possible progression is:

Cybersecurity Learner
Junior Penetration Tester
Penetration Tester
Senior Penetration Tester
Offensive Security Consultant
Red Team Operator
Offensive Security Lead

What is the most important phase of penetration testing?

There is no single universal phase, but authorization and scope come first operationally, while thorough enumeration is one of the most important technical habits.

Why is enumeration important?

Because it transforms a target from:

Unknown System

into:

Known Services
+
Known Applications
+
Known Identities
+
Known Permissions
+
Testable Hypotheses

What do you do when automated scanning finds a vulnerability?

Validate:

Technology
Version
Configuration
Preconditions
Exposure
Security Controls
Actual Impact

before reporting it as confirmed.

What do you do after obtaining authorized access to a system?

Re-enumerate from the new security context.

NEW ACCESS
NEW INFORMATION
NEW PERMISSIONS
NEW ATTACK PATHS

What is privilege escalation?

Privilege escalation is the movement from one authorization level to a higher level because of a weakness, excessive permission, or insecure configuration.

  1. What is OSCP?
  2. What skills does OSCP emphasize?
  3. Why is networking important?
  4. What is reconnaissance?
  5. What is enumeration?
  6. What is vulnerability analysis?
  7. Why should scanner results be validated?
  8. What is controlled exploitation?
  9. What is privilege escalation?
  10. What is lateral movement?
  11. What is an attack path?
  12. What is TCP?
  13. What is UDP?
  14. What is DNS?
  15. What is SMB?
  16. What is LDAP?
  17. What is Kerberos?
  18. What is NTLM?
  19. Why is Linux important for penetration testing?
  20. Why is Windows important?
  21. What is sudo?
  22. Why should services be reviewed during privilege assessment?
  23. Why should scheduled tasks be reviewed?
  24. What is HTTP?
  25. What is the difference between authentication and authorization?
  26. Why is manual web testing important?
  27. What is Active Directory?
  28. What is a domain controller?
  29. Why are AD groups security sensitive?
  30. What is network segmentation?
  31. What is pivoting conceptually?
  32. Why should credentials be treated carefully?
  33. Why should proof-of-concept code be reviewed before use?
  34. Why is note-taking important?
  35. What evidence should a penetration tester collect?
  36. Why is cleanup important?
  37. What should a penetration-testing finding contain?
  38. Why should remediation guidance be included?
  39. What should you do when you are stuck?
  40. What makes someone job-ready for penetration testing?
  • Understand TCP/IP
  • Understand common protocols
  • Understand ports and services
  • Understand DNS
  • Understand routing
  • Understand segmentation
  • Navigate Linux confidently
  • Understand users and groups
  • Understand permissions
  • Understand processes
  • Understand services
  • Understand scheduled activity
  • Understand Linux networking
  • Understand users and groups
  • Understand privileges
  • Understand NTFS permissions
  • Understand processes
  • Understand services
  • Understand scheduled tasks
  • Understand PowerShell
  • Understand HTTP
  • Understand requests and responses
  • Understand cookies
  • Understand sessions
  • Understand authentication
  • Understand authorization
  • Understand APIs
  • Understand common web weaknesses
  • Enumerate every discovered service
  • Research technologies
  • Identify authentication
  • Identify accessible resources
  • Build hypotheses
  • Re-enumerate after new access
  • Assess Linux privilege systematically
  • Assess Windows privilege systematically
  • Review permissions
  • Review services
  • Review scheduled activity
  • Review configuration
  • Review credential exposure safely
  • Understand forests
  • Understand domains
  • Understand domain controllers
  • Understand users
  • Understand groups
  • Understand computers
  • Understand Kerberos
  • Understand NTLM
  • Understand LDAP
  • Understand Group Policy
  • Understand attack-path concepts
  • Maintain structured notes
  • Collect evidence continuously
  • Troubleshoot independently
  • Manage time
  • Write technical findings
  • Explain business impact
  • Recommend remediation
  • Produce a professional report

Remember:

AUTHORIZED TARGET
DISCOVER
ENUMERATE
UNDERSTAND
FORM HYPOTHESIS
VALIDATE
GAIN NEW CONTEXT
RE-ENUMERATE
ASSESS PRIVILEGE
UNDERSTAND IMPACT
CAPTURE EVIDENCE
CLEAN UP
REPORT

The OSCP mindset is not:

Which Exploit Gets Me Access?

It is:

What Does the Evidence Tell Me
About This Environment,
and What Should I Investigate Next?

The strongest preparation combines:

FUNDAMENTALS
+
ENUMERATION
+
PRACTICE
+
PERSISTENCE
+
PROBLEM SOLVING
+
DOCUMENTATION
+
REPORTING

➡️ 02 — OSWA

Next, you will move from general penetration testing into dedicated web application security.

You will build skills around:

Web Architecture
HTTP
Application Mapping
Requests and Responses
Authentication
Authorization
Sessions
Input Handling
Application Logic
API Security
Manual Web Testing
Evidence
Reporting

The goal is to begin thinking like a Web Application Penetration Tester, rather than simply applying generic vulnerability scanners to web applications.