01 — OSCP
The Offensive Security Certified Professional (OSCP) is a practical offensive security certification focused on penetration-testing methodology, technical problem solving, enumeration, exploitation concepts, privilege escalation, Active Directory, documentation, and reporting.
For aspiring penetration testers, OSCP should be viewed as more than an exam.
It represents a transition from:
I Understand Cybersecurity Conceptsto:
I Can Methodically Assessan Authorized Environmentand Document the Security RiskThe real objective of your preparation should therefore be:
FUNDAMENTALS ↓METHODOLOGY ↓PRACTICE ↓INDEPENDENT PROBLEM SOLVING ↓DOCUMENTATION ↓PROFESSIONAL PENTESTING SKILLSPerform penetration-testing activities only against systems you own, dedicated training environments, or systems where you have explicit authorization.
Certification Information
Section titled “Certification Information”Certification: OSCP
Primary Domain: Penetration Testing
Skill Level: Intermediate Practical Offensive Security
Primary Career Direction: Penetration Testing and Offensive Security
Recommended Approach: Hands-on practice combined with strong fundamentals and systematic methodology
Relevant career roles include:
Junior Penetration Tester
Penetration Tester
Security Consultant
Offensive Security Engineer
Vulnerability Assessment Consultant
Red Team Operator — FoundationWhat OSCP Should Validate
Section titled “What OSCP Should Validate”Your preparation should develop the ability to:
Understand the Target ↓Discover Services ↓Enumerate Thoroughly ↓Analyze Weaknesses ↓Validate Safely ↓Assess Privilege ↓Understand Attack Paths ↓Collect Evidence ↓Document Findings ↓Produce a Professional ReportOSCP Career Position
Section titled “OSCP Career Position”Think of OSCP as a strong practical milestone between foundational cybersecurity knowledge and professional penetration testing.
IT FUNDAMENTALS ↓NETWORKING ↓LINUX + WINDOWS ↓SECURITY FUNDAMENTALS ↓WEB TECHNOLOGIES ↓PENTESTING FUNDAMENTALS ↓OSCP ↓PENETRATION TESTER ↓SENIOR PENTESTER ↓SPECIALIZATIONPossible specializations after building strong practical experience include:
Web Application Security
Enterprise Penetration Testing
Red Teaming
Cloud Penetration Testing
Application Security
Exploit Development01 — Understand the Professional Pentesting Mindset
Section titled “01 — Understand the Professional Pentesting Mindset”A beginner often thinks:
Find Vulnerability ↓Run Exploit ↓Get AccessA professional penetration tester thinks:
Understand Scope ↓Understand Environment ↓Enumerate ↓Form Hypothesis ↓Validate ↓Understand Impact ↓Collect Evidence ↓Recommend RemediationThat difference is critical.
02 — Learn the Penetration Testing Lifecycle
Section titled “02 — Learn the Penetration Testing Lifecycle”Develop a repeatable workflow.
AUTHORIZATION ↓SCOPE ↓RECONNAISSANCE ↓DISCOVERY ↓ENUMERATION ↓VULNERABILITY ANALYSIS ↓CONTROLLED VALIDATION ↓PRIVILEGE ASSESSMENT ↓IMPACT ANALYSIS ↓EVIDENCE ↓CLEANUP ↓REPORTINGDo not skip directly from:
IP ADDRESSto:
EXPLOITThe work between those two stages is where much of the real skill exists.
03 — Authorization Comes First
Section titled “03 — Authorization Comes First”Before touching a target, establish:
What Can I Test?
What Cannot I Test?
When Can I Test?
Which Techniques Are Permitted?
Which Activities Are Restricted?
Who Do I Contact if Something Goes Wrong?Professional penetration testing requires:
Authorization +Scope +Rules of Engagement04 — Build Networking Fundamentals
Section titled “04 — Build Networking Fundamentals”Networking is foundational for OSCP preparation.
You should understand:
TCP/IP
IPv4
Subnetting
Routing
TCP
UDP
ICMP
DNS
HTTP
HTTPS
SSH
SMB
LDAP
Kerberos
RDP
NAT
VPN
Firewalls
Network SegmentationNetwork Mental Model
Section titled “Network Mental Model”TARGET ↓IP ADDRESS ↓PORT ↓PROTOCOL ↓SERVICE ↓APPLICATION ↓SECURITY CONTROLCommon Services
Section titled “Common Services”| Port | Common Service | Why It Matters |
|---|---|---|
| 21 | FTP | File transfer |
| 22 | SSH | Remote administration |
| 25 | SMTP | |
| 53 | DNS | Name resolution |
| 80 | HTTP | Web |
| 88 | Kerberos | Domain authentication |
| 135 | RPC | Windows services |
| 139 | NetBIOS | Legacy Windows networking |
| 389 | LDAP | Directory services |
| 443 | HTTPS | Encrypted web |
| 445 | SMB | Windows file/service access |
| 636 | LDAPS | Encrypted LDAP |
| 3389 | RDP | Windows remote desktop |
Do not only memorize ports.
For every service ask:
What Does It Do?
How Does It Authenticate?
What Information Does It Expose?
Which Configuration Controls It?
What Permissions Exist?
What Security Weaknesses Commonly Affect It?05 — Learn Linux Administration
Section titled “05 — Learn Linux Administration”Linux knowledge is essential.
Become comfortable with:
Filesystem
Users
Groups
Permissions
Processes
Services
Networking
Packages
SSH
Logs
Cron
Environment Variables
Shells
SudoUseful commands include:
whoamiidhostnamepwdlscatgrepfindpsssipsudosystemctljournalctlLinux Assessment Mental Model
Section titled “Linux Assessment Mental Model”When entering an authorized Linux lab system, ask:
WHO AM I? ↓WHAT SYSTEM IS THIS? ↓WHAT GROUPS DO I BELONG TO? ↓WHAT IS RUNNING? ↓WHAT FILES CAN I ACCESS? ↓WHAT PRIVILEGE DO I HAVE?06 — Understand Linux Permissions
Section titled “06 — Understand Linux Permissions”Learn:
User
Group
Other
Read
Write
Execute
Ownership
SUID/SGID Concepts
SudoUnderstand why:
PERMISSION +FILE +PROCESS +IDENTITYcan create a security boundary.
07 — Learn Windows Administration
Section titled “07 — Learn Windows Administration”Windows is equally important.
Understand:
Users
Groups
NTFS Permissions
Processes
Services
Registry
Scheduled Tasks
PowerShell
Windows Firewall
Networking
Event Logs
Remote AdministrationUseful commands include:
whoamihostnameGet-ComputerInfoGet-ProcessGet-ServiceGet-LocalUserGet-LocalGroupGet-LocalGroupMember AdministratorsGet-ScheduledTaskGet-NetTCPConnectionWindows Assessment Mental Model
Section titled “Windows Assessment Mental Model”IDENTITY ↓GROUPS ↓PRIVILEGES ↓SERVICES ↓TASKS ↓APPLICATIONS ↓FILESYSTEM ↓CONFIGURATION08 — Learn Basic Scripting
Section titled “08 — Learn Basic Scripting”You do not need advanced software-development skills before beginning OSCP preparation.
You should be comfortable reading and modifying:
Python
Bash
PowerShellUnderstand:
Variables
Conditions
Loops
Functions
Files
Strings
Arguments
HTTP Requests
JSON
Error HandlingThe objective is:
Understand What the Script Does ↓Understand What Input It Takes ↓Understand What It Changes ↓Troubleshoot It SafelyNever execute unfamiliar code simply because it appears in a walkthrough.
09 — Understand Web Technologies
Section titled “09 — Understand Web Technologies”Before assessing web applications, understand:
HTTP
HTTPS
Request Methods
Status Codes
Headers
Cookies
Sessions
Authentication
Authorization
HTML
JavaScript Basics
APIs
JSON
DatabasesWeb Architecture
Section titled “Web Architecture”CLIENT ↓HTTP REQUEST ↓WEB SERVER ↓APPLICATION ↓DATABASE / API ↓HTTP RESPONSE10 — Learn HTTP Requests
Section titled “10 — Learn HTTP Requests”Understand the structure:
METHOD
PATH
HEADERS
COOKIES
PARAMETERS
BODYExample conceptually:
Client ↓Request ↓Application ↓Security Decision ↓ResponseAsk:
What Can the User Control?
What Does the Server Trust?
Where Is Authentication Checked?
Where Is Authorization Checked?11 — Learn Web Application Security
Section titled “11 — Learn Web Application Security”Develop familiarity with areas such as:
Authentication Weaknesses
Authorization Weaknesses
Input Validation
Injection
Cross-Site Scripting
File Upload Security
Path Traversal
Server-Side Request Forgery
Session Security
API Security
Security MisconfigurationUse OWASP concepts to organize your learning.
12 — Learn Manual Web Testing
Section titled “12 — Learn Manual Web Testing”Do not depend completely on automated scanners.
Learn how to inspect:
Requests
Responses
Parameters
Headers
Cookies
Sessions
Tokens
Application WorkflowA strong workflow is:
MAP APPLICATION ↓IDENTIFY INPUT ↓UNDERSTAND EXPECTED BEHAVIOR ↓IDENTIFY SECURITY DECISION ↓TEST ASSUMPTION ↓DOCUMENT RESULT13 — Master Enumeration
Section titled “13 — Master Enumeration”Enumeration is one of the most important OSCP skills.
Think:
DISCOVERY ↓SERVICE ↓VERSION ↓CONFIGURATION ↓APPLICATION ↓IDENTITY ↓PERMISSIONS ↓POTENTIAL WEAKNESSThe question is not:
Which Exploit Should I Try?The better question is:
What Have I Learned AboutThis Service?14 — Build a Service Enumeration Checklist
Section titled “14 — Build a Service Enumeration Checklist”For each discovered service record:
IP Address:
Port:
Protocol:
Service:
Version:
Authentication:
Accessible Resources:
Observed Configuration:
Potential Security Concerns:
Next Validation Step:This prevents random testing.
15 — Learn Vulnerability Analysis
Section titled “15 — Learn Vulnerability Analysis”A vulnerability scanner can identify potential weaknesses.
It does not automatically prove:
Exploitability
Business Impact
Actual ExposureUse:
DETECTION ↓RESEARCH ↓ENVIRONMENT VALIDATION ↓CONTROLLED TEST ↓IMPACT ANALYSIS16 — Learn to Research Vulnerabilities
Section titled “16 — Learn to Research Vulnerabilities”When you discover a technology, research:
Product
Version
Configuration
Known Security Issues
Vendor Advisories
Required Preconditions
Affected Versions
Available MitigationsAvoid:
Copy Random Exploit ↓Run ImmediatelyPrefer:
READ ↓UNDERSTAND ↓VERIFY ↓TEST SAFELY17 — Understand Exploit Code Before Use
Section titled “17 — Understand Exploit Code Before Use”Before using proof-of-concept code in an authorized lab, determine:
What Does It Do?
Which Target Does It Contact?
Which Parameters Must Change?
Does It Modify the Target?
Could It Crash the Service?
Does It Download Anything?
Does It Require Elevated Privilege?18 — Learn Linux Privilege Escalation Methodology
Section titled “18 — Learn Linux Privilege Escalation Methodology”After obtaining authorized low-privilege access, begin systematic enumeration.
CURRENT USER ↓GROUPS ↓SUDO ↓FILES ↓PROCESSES ↓SERVICES ↓SCHEDULED JOBS ↓CREDENTIAL EXPOSURE ↓CONFIGURATION19 — Start with Identity
Section titled “19 — Start with Identity”Use:
whoamiidUnderstand:
User
UID
Groups
Effective Privilege20 — Review Sudo Rights
Section titled “20 — Review Sudo Rights”In an authorized lab:
sudo -lAsk:
Which Commands Are Allowed?
Under Which Identity?
Are Restrictions Applied?
Is the Permission Required?The important skill is understanding the privilege relationship.
21 — Review Filesystem Permissions
Section titled “21 — Review Filesystem Permissions”Look conceptually for:
Sensitive Files Writable byUnprivileged Users
Privileged Scripts with Weak Permissions
Application Configuration Exposure
Credential Files
Unnecessary Group Write Access22 — Review Processes and Services
Section titled “22 — Review Processes and Services”Understand:
Which Processes Run?
Which Identity Runs Them?
Which Files Do They Use?
Which Configuration Controls Them?
Which Network Services Do They Expose?23 — Review Scheduled Activity
Section titled “23 — Review Scheduled Activity”Understand:
Cron Jobs
Scheduled Scripts
Automated Maintenance
Backup JobsAsk:
What Runs?
When?
As Whom?
From Which File?
Who Can Modify It?24 — Linux Privilege Escalation Mindset
Section titled “24 — Linux Privilege Escalation Mindset”Do not think:
Run Enumeration Script ↓Pick Highlighted Result ↓Get RootThink:
ENUMERATE ↓UNDERSTAND ↓IDENTIFY TRUST ↓IDENTIFY WEAK PERMISSION ↓VALIDATE25 — Learn Windows Privilege Escalation Methodology
Section titled “25 — Learn Windows Privilege Escalation Methodology”Use the same systematic approach.
CURRENT USER ↓GROUPS ↓PRIVILEGES ↓SERVICES ↓SCHEDULED TASKS ↓FILESYSTEM ↓REGISTRY ↓APPLICATIONS ↓CREDENTIAL EXPOSURE26 — Review Windows Identity
Section titled “26 — Review Windows Identity”Start with:
whoamiwhoami /groupswhoami /privUnderstand:
Current User
Group Membership
Available Privileges
Administrative Context27 — Review Services
Section titled “27 — Review Services”Use:
Get-ServiceFor interesting services investigate:
Service Identity
Executable
Configuration
Permissions
Startup Behavior
Business Purpose28 — Review Scheduled Tasks
Section titled “28 — Review Scheduled Tasks”Use:
Get-ScheduledTaskAsk:
What Runs?
Who Runs It?
When Does It Run?
Where Is the Executable?
Who Can Modify the Referenced Content?29 — Review Windows Applications
Section titled “29 — Review Windows Applications”Inventory:
Installed Applications
Custom Applications
Administrative Tools
Legacy SoftwareUnderstand:
Version
Configuration
Permissions
Execution Context
Business Purpose30 — Learn Active Directory Fundamentals
Section titled “30 — Learn Active Directory Fundamentals”Active Directory is a major enterprise skill area.
Understand:
Forest
Domain
Domain Controller
Organizational Unit
User
Group
Computer
Group Policy
Trust
LDAP
Kerberos
NTLM
DNSActive Directory Architecture
Section titled “Active Directory Architecture”FOREST | +-- DOMAIN | +-- Domain Controllers | +-- Users | +-- Groups | +-- Computers | +-- OUs | +-- GPOs31 — Understand Domain Authentication
Section titled “31 — Understand Domain Authentication”Learn normal authentication before studying attacks.
Conceptually:
USER ↓AUTHENTICATION ↓DOMAIN CONTROLLER ↓IDENTITY VALIDATION ↓RESOURCE ACCESSUnderstand the roles of:
Kerberos
NTLM
LDAP
DNS32 — Understand Kerberos
Section titled “32 — Understand Kerberos”At a high level:
USER ↓AUTHENTICATION SERVICE ↓TICKET-GRANTING TICKET ↓SERVICE REQUEST ↓SERVICE TICKET ↓RESOURCEYou should understand:
Identity
Tickets
Services
Trust
Authorizationbefore learning attack techniques.
33 — Understand Active Directory Groups
Section titled “33 — Understand Active Directory Groups”Groups often determine enterprise access.
Think:
USER ↓GROUP ↓PRIVILEGE ↓RESOURCEReview concepts such as:
Domain Groups
Administrative Groups
Nested Membership
Delegation
Service Accounts34 — Learn Attack-Path Thinking
Section titled “34 — Learn Attack-Path Thinking”Enterprise compromise is often not caused by one critical vulnerability.
It can result from:
SMALL WEAKNESS +EXCESSIVE ACCESS +CREDENTIAL EXPOSURE +WEAK SEGMENTATIONcreating:
ATTACK PATHExample conceptually:
LOW-PRIVILEGE USER ↓WORKSTATION ACCESS ↓EXCESSIVE PERMISSION ↓SERVER ACCESS ↓PRIVILEGED RELATIONSHIP ↓HIGHER BUSINESS IMPACT35 — Learn Active Directory Enumeration
Section titled “35 — Learn Active Directory Enumeration”Build a mental inventory:
DOMAIN ↓USERS ↓GROUPS ↓COMPUTERS ↓SESSIONS ↓SERVICES ↓POLICIES ↓TRUST RELATIONSHIPS ↓PRIVILEGE PATHS36 — Understand Credential Security
Section titled “36 — Understand Credential Security”Learn the differences between:
Password
Password Hash
Authentication Token
Kerberos Ticket
SSH Key
API Credential
CertificateFor each credential type ask:
Where Is It Stored?
Who Can Access It?
How Is It Protected?
How Long Is It Valid?
What Can It Access?37 — Learn Network Segmentation
Section titled “37 — Learn Network Segmentation”Enterprise environments are rarely flat.
You may encounter:
USER NETWORK | +-- SERVER NETWORK | +-- MANAGEMENT NETWORK | +-- APPLICATION NETWORK | +-- DIRECTORY SERVICESUnderstand:
Routing
Reachability
Firewall Rules
Trust Boundaries38 — Understand Pivoting Conceptually
Section titled “38 — Understand Pivoting Conceptually”Pivoting allows an authorized assessment to evaluate reachable systems through another controlled system.
Think:
TESTING SYSTEM ↓AUTHORIZED HOST A ↓INTERNAL NETWORK ↓AUTHORIZED HOST BThe core skills behind pivoting are:
Routing
Ports
Interfaces
Network Reachability
SegmentationDo not treat pivoting as merely memorizing tunneling commands.
39 — Understand Lateral Movement
Section titled “39 — Understand Lateral Movement”Lateral movement is about moving between authorized systems or identity contexts while evaluating enterprise attack paths.
Common legitimate enterprise technologies involved in remote administration include:
RDP
SMB
SSH
PowerShell Remoting
Administrative PlatformsThe security question is:
Can Weak Credentials,Excessive Privilege,or Poor SegmentationTurn Legitimate Administrationinto an Attack Path?40 — Build a Repeatable Host Methodology
Section titled “40 — Build a Repeatable Host Methodology”For every authorized target:
01 Identify Host
02 Identify Open Services
03 Enumerate Every Service
04 Identify Applications
05 Identify Authentication
06 Identify Accessible Resources
07 Research Technology
08 Form Hypotheses
09 Validate Safely
10 Document Evidence
11 Re-EnumerateThe Re-Enumeration Rule
Section titled “The Re-Enumeration Rule”When stuck:
DO NOT PANIC ↓DO NOT RANDOMLY ATTACK ↓RETURN TO ENUMERATIONAsk:
Which Port Did I Ignore?
Which Web Directory Did I Miss?
Which Application Function Did I Skip?
Which Credential Did I Not TestWhere Authorized?
Which Permission Did I Overlook?
Which Service Needs Deeper Research?41 — Develop a Note-Taking System
Section titled “41 — Develop a Note-Taking System”Create notes from the first minute of an assessment.
Example:
Target:192.0.2.10
Operating System:Unknown
Services:22 SSH80 HTTP
Web:Application identified
Authentication:Observed
Potential Findings:Pending validation
Evidence:Captured
Next Actions:Deeper service enumerationRecommended Notes Structure
Section titled “Recommended Notes Structure”TARGET|+-- Discovery|+-- Services|+-- Web|+-- Credentials|+-- Access|+-- Privilege|+-- Evidence|+-- Findings|+-- Cleanup42 — Capture Evidence as You Work
Section titled “42 — Capture Evidence as You Work”Do not wait until the end.
Capture:
Target
Timestamp
Relevant Command
Relevant Output
Screenshot
Security Context
ResultYour evidence should prove the finding without unnecessarily collecting sensitive data.
43 — Learn Professional Reporting
Section titled “43 — Learn Professional Reporting”A penetration-testing report typically contains:
Executive Summary
Scope
Methodology
Technical Findings
Evidence
Risk
Business Impact
Recommendations
ConclusionFinding Template
Section titled “Finding Template”Finding ID:
Title:
Severity:
Affected Asset:
Description:
Evidence:
Technical Impact:
Business Impact:
Recommendation:
Validation:Example Finding
Section titled “Example Finding”Finding ID:PT-001
Title:Excessive Administrative Privilege
Severity:High
Observation:An account intended for standard operationshas administrative access beyond itsdocumented business requirement.
Security Risk:Compromise of the identity could allow anattacker to perform privileged actions.
Recommendation:Remove unnecessary administrative accessand apply least privilege with periodicaccess reviews.44 — Practice Writing Executive Summaries
Section titled “44 — Practice Writing Executive Summaries”Executives generally need:
What Was Tested?
What Was Found?
What Is the Risk?
What Should Be Fixed First?Avoid filling the executive summary with:
Commands
Payloads
Raw Tool Output
Technical Noise45 — Build Your Lab Strategy
Section titled “45 — Build Your Lab Strategy”Your practice should progress from simple systems to complete environments.
FOUNDATION LABS ↓SINGLE-HOST LABS ↓PRIVILEGE LABS ↓WEB LABS ↓WINDOWS + LINUX LABS ↓ACTIVE DIRECTORY LABS ↓MULTI-SYSTEM LABS ↓TIMED SIMULATIONS46 — Use the Three-Pass Lab Method
Section titled “46 — Use the Three-Pass Lab Method”Pass 01 — Guided
Section titled “Pass 01 — Guided”Use the learning material.
Understand:
Why?
What?
How?Pass 02 — Notes Only
Section titled “Pass 02 — Notes Only”Repeat the lab using your own notes.
Pass 03 — Independent
Section titled “Pass 03 — Independent”Start again without the guide.
If you cannot reproduce the workflow, return to the weak area.
47 — Maintain a Mistake Log
Section titled “47 — Maintain a Mistake Log”Create:
Mistake:
What Happened:
Why I Missed It:
Correct Approach:
How I Will Recognize It Next Time:Common entries may include:
Did Not Enumerate All Services
Ignored Application Function
Assumed Credentials Were Invalid Everywhere
Missed Permission
Did Not Re-Enumerate After Access
Poor Notes
Spent Too Long on One Hypothesis48 — Build a Personal Enumeration Playbook
Section titled “48 — Build a Personal Enumeration Playbook”Organize by technology.
FTP
SSH
DNS
HTTP
HTTPS
SMB
LDAP
Kerberos
RDP
Databases
Linux
Windows
Active DirectoryFor each service document:
Purpose
Identification
Enumeration Questions
Authentication
Common Misconfigurations
Evidence
Remediation49 — Avoid Checklist Dependency
Section titled “49 — Avoid Checklist Dependency”A checklist should support your thinking.
It should not replace it.
Bad:
Command 1Command 2Command 3Nothing WorkedGive UpBetter:
What Am I Trying to Learn?
Which Protocol Provides That Information?
Which Test Can Answer the Question?
What Did the Result Tell Me?50 — Practice Without Automation
Section titled “50 — Practice Without Automation”Automation is valuable.
But periodically perform manual enumeration so you understand what automation is doing.
The progression should be:
MANUAL ↓UNDERSTAND ↓AUTOMATE ↓VALIDATE AUTOMATIONnot:
AUTOMATE ↓TRUST EVERYTHING51 — Learn to Manage Time
Section titled “51 — Learn to Manage Time”Timed practical assessments require discipline.
Create checkpoints such as:
Initial Discovery
Service Enumeration
Primary Hypotheses
Re-Enumeration
Documentation Check
Evidence CheckIf one path consumes excessive time without producing new evidence:
STOP ↓REVIEW ↓RE-ENUMERATE ↓CHANGE HYPOTHESIS52 — Use Hypothesis-Driven Testing
Section titled “52 — Use Hypothesis-Driven Testing”Instead of:
Try Everythinguse:
Observation:Web application exposes upload functionality.
Hypothesis:Server-side validation may be insufficient.
Validation:Test safely within the authorized lab.
Result:Document whether the hypothesis wassupported or rejected.This is closer to professional security testing.
53 — Know When to Move On
Section titled “53 — Know When to Move On”A common preparation problem is spending too long on one path.
Ask:
Am I Learning New Information?
Do I Have Evidence Supporting This Path?
Have I Fully Enumerated Other Services?
Am I Repeating the Same Failed Test?If not:
MOVE ↓ENUMERATE SOMETHING ELSE ↓RETURN LATER54 — Practice Troubleshooting
Section titled “54 — Practice Troubleshooting”When something fails, determine:
Is the Target Reachable?
Is the Port Reachable?
Is the Service Running?
Is Authentication Required?
Is My Syntax Correct?
Is My Assumption Correct?
Is a Security Control Interfering?Troubleshooting is an offensive security skill.
55 — Do Not Depend on Copy-Paste
Section titled “55 — Do Not Depend on Copy-Paste”When you use a command or script, understand:
Command
Options
Target
Expected Result
Potential ImpactIf you cannot explain what it does, research it first.
56 — Build a Clean Lab Workspace
Section titled “56 — Build a Clean Lab Workspace”Example:
OSCP-Practice|+-- 01-Targets|+-- 02-Enumeration|+-- 03-Web|+-- 04-Linux|+-- 05-Windows|+-- 06-Active-Directory|+-- 07-Evidence|+-- 08-Reports|+-- 09-Mistakes|+-- 10-Playbooks57 — Practice Cleanup
Section titled “57 — Practice Cleanup”Track any artifacts created during authorized testing.
Maintain:
Artifact
Target
Purpose
Created
Removed
VerifiedCleanup is part of professional assessment methodology.
58 — Build OSCP Portfolio Projects
Section titled “58 — Build OSCP Portfolio Projects”Do not publish sensitive lab solutions or material you are not permitted to redistribute.
Instead create original authorized projects demonstrating your methodology.
Project 01 — Linux Assessment
Section titled “Project 01 — Linux Assessment”Document:
System Discovery
Service Enumeration
Linux Enumeration
Privilege Analysis
Findings
RemediationProject 02 — Windows Assessment
Section titled “Project 02 — Windows Assessment”Document:
Windows Enumeration
Users
Groups
Services
Applications
Privilege Analysis
Security FindingsProject 03 — Web Security Assessment
Section titled “Project 03 — Web Security Assessment”Document:
Application Mapping
Authentication
Authorization
Input Security
Findings
RemediationProject 04 — Active Directory Assessment
Section titled “Project 04 — Active Directory Assessment”Document:
Domain Architecture
Users
Groups
Computers
Authentication
Privilege Relationships
Attack Paths
FindingsProject 05 — Enterprise Pentest
Section titled “Project 05 — Enterprise Pentest”Combine:
NETWORK +LINUX +WINDOWS +WEB +ACTIVE DIRECTORY +REPORTING59 — Build Exam Readiness Through Competency
Section titled “59 — Build Exam Readiness Through Competency”Avoid measuring readiness solely by:
Hours Watched
Notes Written
Machines CompletedMeasure:
Can I Start from an Unknown Target?
Can I Enumerate Methodically?
Can I Explain Every Test?
Can I Troubleshoot?
Can I Work Without a Walkthrough?
Can I Maintain Evidence?
Can I Produce a Clear Report?OSCP Readiness Level 01 — Foundation
Section titled “OSCP Readiness Level 01 — Foundation”You should understand:
Networking
Linux
Windows
HTTP
Security FundamentalsOSCP Readiness Level 02 — Enumeration
Section titled “OSCP Readiness Level 02 — Enumeration”Given an authorized host, you can systematically determine:
Open Services
Applications
Authentication
Accessible Resources
Potential WeaknessesOSCP Readiness Level 03 — Initial Access Analysis
Section titled “OSCP Readiness Level 03 — Initial Access Analysis”You can:
Research Technologies
Understand Vulnerability Preconditions
Modify Lab Configuration Safely
Validate a Hypothesis
Troubleshoot FailureOSCP Readiness Level 04 — Privilege Assessment
Section titled “OSCP Readiness Level 04 — Privilege Assessment”Given authorized low-privilege lab access, you can systematically assess:
Linux Privilege
Windows Privilege
Permissions
Services
Scheduled Activity
Configuration
Credential ExposureOSCP Readiness Level 05 — Active Directory
Section titled “OSCP Readiness Level 05 — Active Directory”You understand:
Domain Architecture
Users
Groups
Computers
Kerberos
NTLM
LDAP
Group Policy
Privilege Relationships
Attack PathsOSCP Readiness Level 06 — Reporting
Section titled “OSCP Readiness Level 06 — Reporting”You can produce:
Scope
Methodology
Evidence
Findings
Impact
Remediation
Executive SummaryOSCP Readiness Level 07 — Independent Assessment
Section titled “OSCP Readiness Level 07 — Independent Assessment”You can complete an unfamiliar authorized lab using:
Your Methodology
Your Notes
Your Research
Your Reasoningrather than relying on:
Step-by-Step Walkthrough12-Week OSCP Preparation Framework
Section titled “12-Week OSCP Preparation Framework”Use this as a flexible framework rather than a guarantee.
Weeks 1–2 — Foundations
Section titled “Weeks 1–2 — Foundations”Focus on:
Networking
Linux
Windows
HTTP
ScriptingWeeks 3–4 — Enumeration
Section titled “Weeks 3–4 — Enumeration”Focus on:
Service Discovery
Service Enumeration
Web Enumeration
Vulnerability ResearchWeeks 5–6 — Linux + Windows
Section titled “Weeks 5–6 — Linux + Windows”Focus on:
Linux Assessment
Windows Assessment
Privilege Escalation Methodology
TroubleshootingWeeks 7–8 — Web Security
Section titled “Weeks 7–8 — Web Security”Focus on:
HTTP
Authentication
Authorization
Input Security
Application Logic
Manual TestingWeeks 9–10 — Active Directory
Section titled “Weeks 9–10 — Active Directory”Focus on:
Domain Architecture
Kerberos
NTLM
LDAP
Users
Groups
Computers
Privilege RelationshipsWeek 11 — Enterprise Labs
Section titled “Week 11 — Enterprise Labs”Practice:
Multi-System Enumeration
Attack-Path Analysis
Evidence Collection
ReportingWeek 12 — Simulation
Section titled “Week 12 — Simulation”Perform:
Timed Practice
Independent Enumeration
Independent Troubleshooting
Evidence Capture
Report Writing
Weak-Area ReviewDaily Study Structure
Section titled “Daily Study Structure”Example:
30 MinutesConcept Review
90 MinutesHands-On Lab
30 MinutesNotes
30 MinutesRepeat Weak AreaAdjust this according to your schedule.
Consistency matters more than one unusually long study session.
Weekly Review
Section titled “Weekly Review”At the end of each week ask:
What Did I Learn?
What Can I Reproduce?
Where Did I Need a Walkthrough?
What Did I Miss During Enumeration?
What Should I Repeat Next Week?Exam-Day Mindset
Section titled “Exam-Day Mindset”For any practical timed assessment, focus on:
CALM ↓METHOD ↓ENUMERATION ↓EVIDENCE ↓TIME MANAGEMENT ↓REPORTINGAvoid:
PANIC ↓RANDOM TESTING ↓POOR NOTES ↓LOST EVIDENCEMaintain Evidence Continuously
Section titled “Maintain Evidence Continuously”Do not think:
I Will Recreate Everything LaterInstead:
ACTION ↓RESULT ↓EVIDENCE ↓NOTECommon OSCP Preparation Mistakes
Section titled “Common OSCP Preparation Mistakes”Avoid:
Starting Without Networking Fundamentals
Ignoring Linux Administration
Ignoring Windows Administration
Weak Active Directory Knowledge
Depending Entirely on Automated Tools
Using Walkthroughs Too Quickly
Memorizing Commands Without Understanding
Running Unknown Scripts Blindly
Poor Enumeration
Failure to Re-Enumerate
Ignoring Web Fundamentals
Ignoring Reporting
Poor Note-Taking
Spending Too Long on One Hypothesis
Not Practicing Under Time Constraints
Collecting Machines Instead of Building SkillsWhat to Do When You Are Stuck
Section titled “What to Do When You Are Stuck”Use:
01 Stop Random Testing
02 Review Scope
03 Review Existing Notes
04 Recheck Open Services
05 Enumerate Each Service Again
06 Review Application Functionality
07 Review Credentials and Permissions
08 Verify Assumptions
09 Research the Technology
10 Form a New HypothesisThe key question is:
What Information Am I Missing?OSCP vs Job Readiness
Section titled “OSCP vs Job Readiness”Passing a certification and becoming an effective penetration tester are related but different goals.
Certification preparation develops:
Technical Skills
Methodology
Problem Solving
Time Management
ReportingProfessional pentesting additionally requires:
Client Communication
Scope Management
Risk Assessment
Change Awareness
Business Context
Evidence Handling
Remediation Guidance
Team CollaborationAfter OSCP
Section titled “After OSCP”Once you have developed strong general penetration-testing skills, decide where to specialize.
OSCP | +----------------+----------------+ | | | ↓ ↓ ↓ WEB ENTERPRISE CLOUD SECURITY OFFENSIVE SECURITY | | | ↓ ↓ ↓ OSWA / OSWE OSEP CLOUD PENTESTAnother path is:
OSCP ↓LOW-LEVEL PROGRAMMING ↓ASSEMBLY ↓DEBUGGING ↓OSED ↓VULNERABILITY RESEARCHCareer Progression
Section titled “Career Progression”A possible progression is:
Cybersecurity Learner ↓Junior Penetration Tester ↓Penetration Tester ↓Senior Penetration Tester ↓Offensive Security Consultant ↓Red Team Operator ↓Offensive Security LeadOSCP Interview Questions
Section titled “OSCP Interview Questions”Question 01
Section titled “Question 01”What is the most important phase of penetration testing?
There is no single universal phase, but authorization and scope come first operationally, while thorough enumeration is one of the most important technical habits.
Question 02
Section titled “Question 02”Why is enumeration important?
Because it transforms a target from:
Unknown Systeminto:
Known Services+Known Applications+Known Identities+Known Permissions+Testable HypothesesQuestion 03
Section titled “Question 03”What do you do when automated scanning finds a vulnerability?
Validate:
Technology
Version
Configuration
Preconditions
Exposure
Security Controls
Actual Impactbefore reporting it as confirmed.
Question 04
Section titled “Question 04”What do you do after obtaining authorized access to a system?
Re-enumerate from the new security context.
NEW ACCESS ↓NEW INFORMATION ↓NEW PERMISSIONS ↓NEW ATTACK PATHSQuestion 05
Section titled “Question 05”What is privilege escalation?
Privilege escalation is the movement from one authorization level to a higher level because of a weakness, excessive permission, or insecure configuration.
40 OSCP Interview and Review Questions
Section titled “40 OSCP Interview and Review Questions”- What is OSCP?
- What skills does OSCP emphasize?
- Why is networking important?
- What is reconnaissance?
- What is enumeration?
- What is vulnerability analysis?
- Why should scanner results be validated?
- What is controlled exploitation?
- What is privilege escalation?
- What is lateral movement?
- What is an attack path?
- What is TCP?
- What is UDP?
- What is DNS?
- What is SMB?
- What is LDAP?
- What is Kerberos?
- What is NTLM?
- Why is Linux important for penetration testing?
- Why is Windows important?
- What is
sudo? - Why should services be reviewed during privilege assessment?
- Why should scheduled tasks be reviewed?
- What is HTTP?
- What is the difference between authentication and authorization?
- Why is manual web testing important?
- What is Active Directory?
- What is a domain controller?
- Why are AD groups security sensitive?
- What is network segmentation?
- What is pivoting conceptually?
- Why should credentials be treated carefully?
- Why should proof-of-concept code be reviewed before use?
- Why is note-taking important?
- What evidence should a penetration tester collect?
- Why is cleanup important?
- What should a penetration-testing finding contain?
- Why should remediation guidance be included?
- What should you do when you are stuck?
- What makes someone job-ready for penetration testing?
OSCP Readiness Checklist
Section titled “OSCP Readiness Checklist”Networking
Section titled “Networking”- Understand TCP/IP
- Understand common protocols
- Understand ports and services
- Understand DNS
- Understand routing
- Understand segmentation
- Navigate Linux confidently
- Understand users and groups
- Understand permissions
- Understand processes
- Understand services
- Understand scheduled activity
- Understand Linux networking
Windows
Section titled “Windows”- Understand users and groups
- Understand privileges
- Understand NTFS permissions
- Understand processes
- Understand services
- Understand scheduled tasks
- Understand PowerShell
- Understand HTTP
- Understand requests and responses
- Understand cookies
- Understand sessions
- Understand authentication
- Understand authorization
- Understand APIs
- Understand common web weaknesses
Enumeration
Section titled “Enumeration”- Enumerate every discovered service
- Research technologies
- Identify authentication
- Identify accessible resources
- Build hypotheses
- Re-enumerate after new access
Privilege Assessment
Section titled “Privilege Assessment”- Assess Linux privilege systematically
- Assess Windows privilege systematically
- Review permissions
- Review services
- Review scheduled activity
- Review configuration
- Review credential exposure safely
Active Directory
Section titled “Active Directory”- Understand forests
- Understand domains
- Understand domain controllers
- Understand users
- Understand groups
- Understand computers
- Understand Kerberos
- Understand NTLM
- Understand LDAP
- Understand Group Policy
- Understand attack-path concepts
Professional Skills
Section titled “Professional Skills”- Maintain structured notes
- Collect evidence continuously
- Troubleshoot independently
- Manage time
- Write technical findings
- Explain business impact
- Recommend remediation
- Produce a professional report
Final OSCP Mental Model
Section titled “Final OSCP Mental Model”Remember:
AUTHORIZED TARGET ↓DISCOVER ↓ENUMERATE ↓UNDERSTAND ↓FORM HYPOTHESIS ↓VALIDATE ↓GAIN NEW CONTEXT ↓RE-ENUMERATE ↓ASSESS PRIVILEGE ↓UNDERSTAND IMPACT ↓CAPTURE EVIDENCE ↓CLEAN UP ↓REPORTThe OSCP mindset is not:
Which Exploit Gets Me Access?It is:
What Does the Evidence Tell MeAbout This Environment,and What Should I Investigate Next?The strongest preparation combines:
FUNDAMENTALS +ENUMERATION +PRACTICE +PERSISTENCE +PROBLEM SOLVING +DOCUMENTATION +REPORTINGWhat’s Next?
Section titled “What’s Next?”➡️ 02 — OSWA
Next, you will move from general penetration testing into dedicated web application security.
You will build skills around:
Web Architecture ↓HTTP ↓Application Mapping ↓Requests and Responses ↓Authentication ↓Authorization ↓Sessions ↓Input Handling ↓Application Logic ↓API Security ↓Manual Web Testing ↓Evidence ↓ReportingThe goal is to begin thinking like a Web Application Penetration Tester, rather than simply applying generic vulnerability scanners to web applications.