Skip to content

04 — OSEP

The Offensive Security Experienced Penetration Tester (OSEP) path moves beyond individual-host penetration testing into the assessment of complex enterprise environments.

At this stage, the objective is no longer simply:

Find a Vulnerability
Gain Access

Instead, you learn to think in terms of:

ENTERPRISE ENVIRONMENT
IDENTITIES
SYSTEMS
TRUST RELATIONSHIPS
SECURITY CONTROLS
ATTACK PATHS
BUSINESS IMPACT

OSEP-oriented skills are particularly relevant for:

Senior Penetration Tester
Enterprise Penetration Tester
Red Team Operator
Offensive Security Engineer
Security Consultant
Adversary Simulation Specialist

Perform enterprise offensive-security activities only inside systems you own, purpose-built labs, or environments where you have explicit authorization and clearly defined rules of engagement.

Certification: OSEP
Primary Domain: Advanced Enterprise Penetration Testing
Skill Level: Advanced
Career Direction: Enterprise Pentesting and Red Team Operations
Core Transition: Host exploitation → Enterprise attack-path analysis
Recommended Foundation: Strong OSCP-level networking, Windows, Linux, Active Directory, scripting, enumeration, privilege analysis, and reporting skills

Your preparation should develop competency around:

Enterprise Architecture
Windows Security
Active Directory
Identity Relationships
Authentication
Authorization
Privilege Relationships
Network Segmentation
Endpoint Security Controls
Application Control
Operational Security
Attack-Path Analysis
Adversary Simulation
Evidence Collection
Remediation
Professional Reporting

A practical progression is:

NETWORKING
LINUX + WINDOWS
PENTESTING FUNDAMENTALS
OSCP
ENTERPRISE SECURITY
ACTIVE DIRECTORY
DEFENSE AWARENESS
OSEP
RED TEAMING
SENIOR OFFENSIVE SECURITY

01 — Understand the Enterprise Pentesting Mindset

Section titled “01 — Understand the Enterprise Pentesting Mindset”

A single-host assessment may look like:

TARGET
SERVICE
WEAKNESS
ACCESS
PRIVILEGE

Enterprise assessments add another dimension:

IDENTITY
WORKSTATION
SERVER
APPLICATION
DOMAIN
TRUST
SENSITIVE ASSET

The security question becomes:

How Can Multiple
Individually Limited Weaknesses
Combine Into a Meaningful
Enterprise Attack Path?

An attack path represents relationships between:

Identity
Privilege
System
Credential
Application
Network
Trust

Example:

STANDARD USER
WORKSTATION
EXCESSIVE LOCAL PRIVILEGE
SERVER ACCESS
PRIVILEGED IDENTITY EXPOSURE
SENSITIVE RESOURCE

The important skill is understanding why each transition is possible.

03 — Build an Enterprise Architecture Model

Section titled “03 — Build an Enterprise Architecture Model”

Before testing, map the environment.

A simplified enterprise may look like:

INTERNET
|
FIREWALL
|
DMZ
|
+---------+---------+
| |
WEB TIER VPN / ACCESS
|
APP TIER
|
DATABASE
INTERNAL NETWORK
|
+-- User Workstations
|
+-- Application Servers
|
+-- File Servers
|
+-- Domain Controllers
|
+-- Management Systems
|
+-- Security Systems

Enterprise networks commonly contain zones such as:

Internet
DMZ
User Network
Server Network
Management Network
Database Network
Security Network
Backup Network
Cloud Network

For each zone determine:

Who Can Reach It?
From Where?
Using Which Protocol?
Under Which Identity?
What Security Controls Exist?

A trust boundary separates different security contexts.

Examples:

Internet → DMZ
DMZ → Internal Network
User Network → Server Network
Workstation → Domain Controller
Standard User → Administrator
On-Premises → Cloud

Attack-path analysis frequently begins by asking:

Can This Trust Boundary
Be Crossed in a Way
the Organization Did Not Intend?

Document:

Asset Role Zone Identity Context Criticality
WS01 Workstation User Standard User Medium
APP01 Application Server Service Identity High
DC01 Domain Controller Management Domain Services Critical
DB01 Database Data Service Identity Critical

Enterprise security is increasingly identity-driven.

Inventory:

Standard Users
Administrators
Service Accounts
Application Identities
Domain Accounts
Local Accounts
Machine Accounts
Emergency Accounts
Third-Party Identities

Create:

Identity System Privilege Purpose Expected?
UserA WS01 Standard Daily work Yes
AdminA SRV01 Admin Server management Yes
ServiceA APP01 Service Application Yes
UserB SRV02 Admin Unknown Review

This can expose:

Privilege Creep
Unnecessary Administration
Weak Separation
Unexpected Trust

09 — Understand Windows Enterprise Security

Section titled “09 — Understand Windows Enterprise Security”

OSEP preparation requires strong Windows knowledge.

Understand:

Local Users
Domain Users
Groups
Privileges
Services
Scheduled Tasks
Registry
NTFS Permissions
Windows Firewall
PowerShell
Event Logging
Remote Administration
IDENTITY
TOKEN
GROUPS + PRIVILEGES
ACCESS CHECK
RESOURCE

After authentication, Windows creates a security context containing information such as:

User Identity
Group Membership
Privileges
Integrity Context

Conceptually:

USER
AUTHENTICATION
ACCESS TOKEN
RESOURCE ACCESS

Understanding this model helps explain why group membership and privilege assignments matter.

Local administrator rights are highly security-sensitive.

Assess:

Who Has Local Admin?
Why?
On Which Systems?
How Is Membership Managed?
Are Rights Temporary?
Are They Reviewed?

Privilege creep occurs when identities accumulate access over time.

USER
PROJECT A ACCESS
PROJECT B ACCESS
TEMP ADMIN
ROLE CHANGE
OLD ACCESS NEVER REMOVED

Eventually:

EXCESSIVE PRIVILEGE

can create enterprise attack paths.

13 — Understand Active Directory Architecture

Section titled “13 — Understand Active Directory Architecture”

You should be comfortable with:

Forest
Domain
Domain Controller
Organizational Unit
Users
Groups
Computers
Group Policy
Trusts
DNS
LDAP
Kerberos
NTLM
FOREST
|
+-- DOMAIN
|
+-- Domain Controllers
|
+-- Users
|
+-- Groups
|
+-- Computers
|
+-- OUs
|
+-- GPOs

Domain controllers provide critical services such as:

Authentication
Directory Services
Kerberos
Group Policy Distribution
Identity Management

They should therefore be treated as:

CRITICAL SECURITY ASSETS

At a high level:

USER
AUTHENTICATION
TICKET-GRANTING TICKET
SERVICE REQUEST
SERVICE TICKET
RESOURCE

Your goal should be to understand:

Identity
Tickets
Service Accounts
Trust
Authorization

rather than merely memorizing attack terminology.

NTLM remains relevant in many Windows environments because of:

Legacy Systems
Compatibility Requirements
Application Dependencies

From a security-assessment perspective, determine:

Where Is It Used?
Why Is It Required?
Can Usage Be Reduced?
What Monitoring Exists?

LDAP provides directory access.

Conceptually:

CLIENT
DIRECTORY QUERY
DOMAIN CONTROLLER
DIRECTORY OBJECTS

Directory information can include:

Users
Groups
Computers
Organizational Units
Service Information

Active Directory relies heavily on DNS.

Conceptually:

CLIENT
DNS
DOMAIN SERVICE LOCATION
DOMAIN CONTROLLER

DNS problems can therefore become:

Authentication Problems
Service Discovery Problems
Operational Problems

Enterprise access frequently follows:

USER
GROUP
ROLE
RESOURCE

Review:

Direct Membership
Nested Membership
Administrative Groups
Application Groups
Delegated Groups

Nested groups can make effective access difficult to see.

USER
GROUP A
GROUP B
PRIVILEGED GROUP
SENSITIVE RESOURCE

The user may have significant privilege without appearing directly in the final group.

Organizations delegate administrative responsibility so every task does not require the highest privilege.

Examples include:

Password Reset
User Administration
Computer Administration
OU Management
Application Administration

Poor delegation can create unintended privilege paths.

Group Policy can control:

Security Settings
Firewall
Scripts
User Rights
Application Configuration
System Configuration

Conceptually:

DOMAIN
OU
GPO
COMPUTER / USER

Review:

Who Can Create GPOs?
Who Can Edit Them?
Where Are They Linked?
Which Systems Receive Them?
Can Delegated Users Modify Sensitive Policy?

A configuration-management mechanism can become a privilege path if its permissions are weak.

Service accounts support:

Applications
Databases
Scheduled Tasks
Services
Automation

Review:

Purpose
Privilege
Credential Management
Interactive Login
Rotation
Ownership
Lifecycle

Where supported, organizations should consider mechanisms such as:

Managed Service Accounts
Group Managed Service Accounts
Platform-Managed Identities
Workload Federation

instead of unnecessary long-lived manually managed credentials.

Credentials may be exposed through:

Configuration
Scripts
Deployment Files
Backups
User Behavior
Administrative Processes
Application Secrets

The assessment question is:

What Credential Exists?
What Can It Access?
Why Is It Exposed?
How Should It Be Protected?

27 — Treat Credentials as Sensitive Evidence

Section titled “27 — Treat Credentials as Sensitive Evidence”

Never unnecessarily reproduce secrets in reports.

Prefer:

Credential Type
Affected Asset
Privilege
Exposure Location
Redacted Evidence

instead of publishing complete credentials.

28 — Understand Administrative Separation

Section titled “28 — Understand Administrative Separation”

A mature environment may separate:

Standard User Identity
Workstation Admin Identity
Server Admin Identity
Domain Administration Identity

Conceptually:

DAILY USER
PRIVILEGED ADMIN

This reduces the chance that compromise of one identity automatically exposes every privilege tier.

29 — Understand Privileged Access Workstations

Section titled “29 — Understand Privileged Access Workstations”

Highly privileged administrative activity may be restricted to specially managed systems.

Conceptually:

ADMINISTRATOR
SECURED ADMIN WORKSTATION
PRIVILEGED RESOURCE

rather than:

ADMINISTRATOR
EVERYDAY WORKSTATION
PRIVILEGED RESOURCE

Segmentation limits:

Reachability
Lateral Movement
Administrative Exposure
Attack Surface
USER NETWORK
|
X
|
SERVER NETWORK
|
X
|
MANAGEMENT NETWORK

The X represents controlled boundaries rather than unrestricted connectivity.

For each boundary ask:

Source?
Destination?
Protocol?
Port?
Identity?
Business Requirement?
Security Control?

32 — Understand Lateral Movement Conceptually

Section titled “32 — Understand Lateral Movement Conceptually”

Lateral movement refers to movement between systems or security contexts after initial access.

Conceptually:

HOST A
AUTHORIZED RELATIONSHIP
HOST B

Common legitimate administrative technologies involved in enterprise environments include:

RDP
SMB
SSH
PowerShell Remoting
Management Platforms

Security problems arise when these relationships are exposed through:

Weak Credentials
Excessive Privilege
Poor Segmentation
Weak Administrative Separation

A pivot allows an assessment to evaluate another authorized network segment through an already controlled lab system.

TESTING SYSTEM
LAB HOST A
INTERNAL LAB NETWORK
LAB HOST B

The foundational knowledge is:

Routing
Interfaces
Ports
Reachability
Segmentation

34 — Build a Network Reachability Matrix

Section titled “34 — Build a Network Reachability Matrix”
Source Destination Service Expected Observed
User Zone Web Tier HTTPS Yes Yes
User Zone Database Database Port No Review
Web Tier Database Database Port Yes Yes
User Zone DC Admin Service Restricted Review

This turns segmentation into measurable evidence.

35 — Understand Endpoint Security Controls

Section titled “35 — Understand Endpoint Security Controls”

Modern enterprise environments may use:

Antivirus
EDR
Host Firewall
Application Control
Attack Surface Reduction
Device Compliance
Central Logging

OSEP preparation should include understanding what these controls are designed to prevent and detect.

Do not treat endpoint security merely as:

Something to Bypass

Understand:

What Does It Detect?
Which Telemetry Does It Collect?
Which Behavior Is Restricted?
How Would the SOC Investigate It?

Antivirus commonly evaluates:

Files
Signatures
Known Threats
Potentially Suspicious Content

Modern endpoint protection may add additional behavioral and cloud-based analysis.

Endpoint Detection and Response may collect telemetry around:

Processes
Parent-Child Relationships
Network Connections
Files
Registry
User Activity
Security Events

Conceptually:

ENDPOINT
TELEMETRY
DETECTION
SECURITY PLATFORM
SOC ANALYST

Application control restricts what software can execute.

Possible approaches include:

Allowlisting
Publisher Rules
Path Rules
Hash Rules
Managed Installer Trust

From an assessment perspective, determine:

What Is Allowed?
What Is Blocked?
Why?
Which Systems Are Covered?
Are Exceptions Controlled?

PowerShell is an important Windows administration platform.

Organizations may apply controls around:

Script Logging
Module Logging
Transcription
Application Control
Endpoint Monitoring
Language Restrictions

OSEP-level knowledge should include both:

Administrative Utility

and:

Defensive Visibility

During an enterprise assessment, think about what defenders may observe.

AUTHENTICATION
LOGON EVENT
PROCESS START
PROCESS TELEMETRY
NETWORK CONNECTION
NETWORK TELEMETRY
PRIVILEGE CHANGE
DIRECTORY / AUDIT EVENT

For each simulated activity ask:

Which Log Would Record This?
Which Security Product Might Detect It?
What Alert Could Be Generated?
What Evidence Would the SOC See?

This improves both offensive and defensive understanding.

Operational security means controlling how an authorized assessment is conducted so it does not create unnecessary risk.

Consider:

Scope
Timing
Noise
Artifacts
Sensitive Data
Persistence
Cleanup
Communication

Before testing, define:

Authorized Targets
Excluded Targets
Permitted Techniques
Restricted Techniques
Testing Window
Escalation Contacts
Emergency Stop Procedure
Data Handling
Reporting Requirements

A technique that is acceptable in a dedicated lab may be inappropriate in production.

Always consider:

Could This Crash a Service?
Could This Lock an Account?
Could This Corrupt Data?
Could This Trigger Business Disruption?
Could This Affect Other Tenants?

Professional assessments should seek:

MINIMUM ACTION
SUFFICIENT EVIDENCE
CONFIRMED RISK

not:

MAXIMUM POSSIBLE DAMAGE

Adversary simulation tests whether an organization can:

Prevent
Detect
Investigate
Contain

realistic attacker behavior under controlled conditions.

A penetration test often asks:

What Security Weaknesses Exist?

A red-team-style exercise may ask:

Can a Realistic Attack Path
Reach a Defined Objective,
and Can the Organization
Detect and Respond to It?

Examples:

Evaluate Administrative Separation
Evaluate Network Segmentation
Evaluate Identity Controls
Evaluate Detection Coverage
Evaluate Privileged Access Governance

Avoid vague objectives such as:

Hack Everything

Crown jewels are high-value business assets.

Examples:

Identity Infrastructure
Critical Databases
Production Management Systems
Sensitive Intellectual Property
Backup Infrastructure
Security Management Systems

If the objective is:

CRITICAL APPLICATION

ask:

Who Administers It?
Which Identities Can Access It?
Which Systems Can Reach It?
Which Authentication Is Required?
Which Trust Relationships Exist?

This creates a potential attack-path map.

Conceptually:

USER A
|
v
WORKSTATION
|
v
GROUP B
|
v
SERVER C
|
v
SERVICE IDENTITY
|
v
SENSITIVE APPLICATION

Every edge should represent a real, validated relationship.

For every transition record:

Source:
Destination:
Required Identity:
Required Privilege:
Required Network Access:
Required Configuration:
Observed Control:
Security Concern:

Do not conclude:

A Can Reach B
Therefore
A Can Compromise B

Validate:

Authentication
Authorization
Configuration
Privilege
Control Effectiveness

55 — Understand Privilege Escalation in Context

Section titled “55 — Understand Privilege Escalation in Context”

Privilege escalation is not limited to:

User → SYSTEM

Enterprise privilege escalation may also involve:

User
Application Administrator
Server Administrator
Identity Administrator
Service Account
Sensitive Database

56 — Understand Vertical and Horizontal Movement

Section titled “56 — Understand Vertical and Horizontal Movement”
LOW PRIVILEGE
HIGHER PRIVILEGE
SYSTEM A
SYSTEM B

Enterprise attack paths often combine both.

A secure environment should define:

Who Administers Workstations?
Who Administers Servers?
Who Administers Domain Controllers?
From Which Devices?
Using Which Accounts?

Uncontrolled overlap increases risk.

A simplified privilege model may separate:

TIER 0
Identity Infrastructure
TIER 1
Servers and Applications
TIER 2
User Workstations

The goal is to prevent lower-trust systems from becoming stepping stones toward highly privileged environments.

Ask:

Where Do Privileged Accounts Log In?
Do Domain-Level Admins Use Workstations?
Do Server Admins Browse the Internet?
Are Admin Sessions Isolated?
Are Privileged Sessions Monitored?

Credential security includes:

Unique Passwords
Rotation
MFA
Managed Credentials
Limited Privilege
Secure Storage
Restricted Logon
Monitoring

61 — Understand Local Administrator Password Management

Section titled “61 — Understand Local Administrator Password Management”

Organizations should avoid unmanaged reuse of local administrator credentials.

Modern environments can use centralized mechanisms for:

Unique Credentials
Rotation
Controlled Retrieval
Auditing

Service accounts may become high-value because they often have:

Long Lifetimes
Application Access
Server Access
Database Access
Automation Privilege

Review:

Can Interactive Login Be Disabled?
Can Privilege Be Reduced?
Can Managed Identity Be Used?
Is Credential Rotation Automated?

Directory objects have permissions.

Conceptually:

IDENTITY
DIRECTORY PERMISSION
OBJECT

Review whether delegated identities can perform sensitive operations beyond their intended role.

Object ownership can be security-sensitive because owners may have capabilities affecting object permissions.

Assess ownership of:

Groups
Service Accounts
Policies
Administrative Objects
Applications

Enterprises may contain:

Domain Trusts
Forest Trusts
Application Trusts
Cloud Federation
Third-Party Trust

Trust should always be evaluated from both directions.

A trusted environment may have:

Different Security Controls
Different Administrators
Different Patch Levels
Different Monitoring

Therefore:

TRUST RELATIONSHIP
+
WEAKER ENVIRONMENT

can increase enterprise risk.

Modern organizations may connect:

On-Premises Active Directory
Identity Synchronization
Cloud Identity Platform
SaaS / Cloud Resources

This creates new relationships between:

On-Prem Identity
Cloud Identity
Applications
Devices
Administrative Roles

Ask:

Can On-Premises Privilege
Influence Cloud Access?
Can Cloud Privilege
Influence On-Premises Systems?
Which Synchronization Components
Are Highly Privileged?

Enterprise offensive security increasingly intersects with:

Microsoft Azure
AWS
Google Cloud
SaaS
Cloud Identity
Cloud Management

OSEP foundations therefore benefit from understanding hybrid architecture.

During assessments, sensitive information may be encountered.

Define procedures for:

Collection
Storage
Encryption
Access
Retention
Deletion

Prefer:

Enough Evidence
to Demonstrate Risk

rather than:

Copy Every Available File

72 — Build an Enterprise Enumeration Workflow

Section titled “72 — Build an Enterprise Enumeration Workflow”

Use:

01 Understand Scope
02 Map Network
03 Identify Systems
04 Identify Services
05 Map Identities
06 Map Groups
07 Map Privileges
08 Map Trust
09 Map Segmentation
10 Map Security Controls
11 Identify Potential Paths
12 Validate Paths
13 Assess Impact
14 Collect Evidence
15 Cleanup
16 Report

73 — Re-Enumerate After Every Context Change

Section titled “73 — Re-Enumerate After Every Context Change”

Whenever you gain a new authorized security context:

NEW IDENTITY
RE-ENUMERATE

Whenever you reach a new network:

NEW NETWORK
RE-ENUMERATE

Whenever privilege changes:

NEW PRIVILEGE
RE-ENUMERATE

74 — Build an Identity Relationship Matrix

Section titled “74 — Build an Identity Relationship Matrix”
Identity Groups Systems Privilege Sensitive Access
UserA Employees WS01 Standard No
AdminA Server Admins SRV01 Admin Yes
ServiceA App Services APP01 Service Database
Control Coverage Purpose Validation
MFA Admins Authentication Review
EDR Endpoints Detection Review
Firewall Servers Segmentation Review
App Control Admin Systems Execution Control Review
SIEM Enterprise Monitoring Review

Use:

ID Finding Asset Severity Attack Path
ENT-001 Excessive Admin Access SRV01 High AP-01
ENT-002 Weak Segmentation DB01 High AP-02
ENT-003 Stale Privileged Account AD High AP-03
Attack Path ID:
Objective:
Starting Context:
Systems Involved:
Identities Involved:
Trust Relationships:
Security Controls:
Weaknesses:
Validated Impact:
Evidence:
Recommended Remediation:

A choke point is a control whose improvement can break multiple attack paths.

Examples may include:

Privileged Access Governance
Network Segmentation
Administrative Separation
MFA
Service Account Governance
Endpoint Hardening

This makes remediation more strategic.

Instead of reporting:

Finding A
Finding B
Finding C

show when appropriate:

Finding A
+
Finding B
+
Finding C
Enterprise Attack Path

Technical statement:

Excessive Administrative Group Membership

Business-oriented statement:

Compromise of a standard operational
identity could provide a path toward
administrative access to systems supporting
a critical business application.

Use:

Finding ID:
Title:
Severity:
Affected Assets:
Affected Identities:
Description:
Attack-Path Relationship:
Evidence:
Technical Impact:
Business Impact:
Recommendation:
Validation Method:

Example Finding — Administrative Separation

Section titled “Example Finding — Administrative Separation”
Finding ID:
ENT-001
Title:
Privileged Administrative Accounts Used
on Lower-Trust Workstations
Severity:
High
Observation:
Highly privileged identities are permitted
to authenticate to general-purpose user
workstations.
Risk:
Compromise of a lower-trust workstation may
increase the likelihood of privileged
credential or session exposure.
Recommendation:
Implement administrative tiering and
restrict privileged identities to approved
administrative systems.
Finding ID:
ENT-002
Title:
User Network Has Unnecessary Access to
Sensitive Server Services
Severity:
High
Observation:
General user systems can directly reach
administrative or sensitive services in a
higher-trust server zone without a
documented business requirement.
Risk:
Compromise of a workstation may provide a
direct network path toward critical
systems.
Recommendation:
Restrict network access using
deny-by-default segmentation and explicitly
allow only documented business flows.
Finding ID:
ENT-003
Title:
Service Identity Holds Excessive Privilege
Severity:
High
Observation:
An application service identity has
privileges significantly beyond those
required for its documented function.
Risk:
Compromise of the application or service
identity may provide access to additional
enterprise systems or sensitive data.
Recommendation:
Reduce privileges to the minimum required,
restrict interactive use, and migrate to
managed credential mechanisms where
supported.

Example:

STANDARD USER
|
v
WORKSTATION
|
| Excessive Privilege
v
APPLICATION SERVER
|
| Service Identity
v
DATABASE
|
| Sensitive Access
v
BUSINESS DATA

This is often easier for stakeholders to understand than isolated technical findings.

Executives need:

What Was Tested?
What Was the Objective?
What Attack Paths Were Identified?
Which Business Assets Were Exposed?
Which Controls Failed?
What Should Be Fixed First?

Prioritize:

IMMEDIATE
Critical exposure
SHORT TERM
Privilege and configuration
MEDIUM TERM
Architecture and segmentation
LONG TERM
Identity and security maturity

Enterprise offensive-security reports can also recommend:

Authentication Monitoring
Privileged Group Monitoring
Endpoint Telemetry
Network Monitoring
Service Account Monitoring
Directory Change Monitoring

A mature red/purple-team workflow may involve:

OFFENSIVE TEAM
SIMULATED ACTIVITY
DEFENSIVE TELEMETRY
SOC ANALYSIS
DETECTION IMPROVEMENT

Purple teaming connects:

OFFENSIVE KNOWLEDGE
+
DEFENSIVE KNOWLEDGE

to improve:

Prevention
Detection
Investigation
Response

A dedicated authorized lab might contain:

ATTACKER / TEST SYSTEM
|
v
LAB FIREWALL
|
+-- Windows Workstation
|
+-- Member Server
|
+-- Domain Controller
|
+-- Application Server
|
+-- Linux Server

Keep it isolated from production.

Use:

Dedicated Virtual Network
Snapshots
Test Accounts
Synthetic Data
Documented Scope
Rollback Plan

Avoid using:

Production Credentials
Real Customer Data
Corporate Production Systems

for uncontrolled experimentation.

90 — Lab Project 01: Enterprise Discovery

Section titled “90 — Lab Project 01: Enterprise Discovery”

Create an inventory of an authorized enterprise lab.

Document:

Hosts
Services
Operating Systems
Zones
Users
Groups
Trust Boundaries

Create:

Enterprise Asset Map

91 — Lab Project 02: Identity Relationship Assessment

Section titled “91 — Lab Project 02: Identity Relationship Assessment”

Map:

Users
Groups
Administrative Rights
Service Accounts
Privileged Identities

Identify unnecessary relationships.

Identity Privilege Matrix

92 — Lab Project 03: Segmentation Assessment

Section titled “92 — Lab Project 03: Segmentation Assessment”

Compare expected and actual connectivity between:

User Zone
Server Zone
Management Zone
Network Reachability Matrix

93 — Lab Project 04: Active Directory Security Review

Section titled “93 — Lab Project 04: Active Directory Security Review”

Review:

Privileged Groups
Delegation
GPO Permissions
Service Accounts
Administrative Separation
Stale Identities
AD Security Findings Register

94 — Lab Project 05: Attack-Path Analysis

Section titled “94 — Lab Project 05: Attack-Path Analysis”

Build:

Starting Identity
System Relationship
Privilege Relationship
Sensitive Asset

Validate each relationship safely.

Enterprise Attack-Path Report

95 — Lab Project 06: Detection Validation

Section titled “95 — Lab Project 06: Detection Validation”

Coordinate simulated activity with lab monitoring.

Observe:

Windows Logs
Endpoint Telemetry
Authentication Events
Directory Events
Network Events
Activity → Telemetry → Detection Matrix

96 — Lab Project 07: Enterprise Security Assessment

Section titled “96 — Lab Project 07: Enterprise Security Assessment”

Combine:

NETWORK
+
IDENTITY
+
WINDOWS
+
ACTIVE DIRECTORY
+
SEGMENTATION
+
SECURITY CONTROLS
+
ATTACK PATHS
+
REPORTING

Produce a professional assessment report.

Focus on:

Networking
Windows
PowerShell
Active Directory
Linux
Scripting

You should already have strong fundamentals before moving deeper.

Focus on:

Enterprise Enumeration
Identity Mapping
Privilege Mapping
Trust Analysis
Segmentation

Focus on:

Windows Security
Endpoint Controls
Application Control
Logging
Defender Awareness

Focus on:

Attack Paths
Administrative Separation
Hybrid Environments
Service Accounts
Privilege Relationships

Focus on:

Adversary Simulation
Evidence
Detection Validation
Reporting
Remediation

Use this as a flexible learning structure rather than an exam guarantee.

Focus on:

Windows Architecture
Users
Groups
Privileges
Services
PowerShell
Logging

Focus on:

Domains
Users
Groups
Computers
Kerberos
NTLM
LDAP
DNS
Group Policy

Focus on:

Service Accounts
Delegation
Privileged Access
Administrative Separation
Credential Governance

Weeks 7–8 — Network and Endpoint Security

Section titled “Weeks 7–8 — Network and Endpoint Security”

Focus on:

Segmentation
Firewalling
Endpoint Security
Application Control
Monitoring

Focus on:

Identity Relationships
Privilege Relationships
Trust Relationships
Enterprise Attack Paths

Perform:

Discovery
Identity Mapping
Control Assessment
Attack-Path Analysis
Evidence Collection

Complete:

Timed Assessment
Attack-Path Documentation
Security Findings
Executive Summary
Remediation Roadmap

Example:

30 Minutes
Concept Review
90 Minutes
Hands-On Lab
30 Minutes
Attack-Path Notes
30 Minutes
Defensive Analysis

You understand:

Users
Groups
Privileges
Processes
Services
PowerShell
Remote Administration
Logging

OSEP Readiness Level 02 — Active Directory

Section titled “OSEP Readiness Level 02 — Active Directory”

You understand:

Forest
Domain
Domain Controllers
Users
Groups
Computers
Kerberos
NTLM
LDAP
DNS
GPO

OSEP Readiness Level 03 — Enterprise Identity

Section titled “OSEP Readiness Level 03 — Enterprise Identity”

You can assess:

Administrative Accounts
Service Accounts
Group Membership
Delegation
Privilege Relationships
Administrative Separation

OSEP Readiness Level 04 — Network Architecture

Section titled “OSEP Readiness Level 04 — Network Architecture”

You can map:

Zones
Routes
Services
Trust Boundaries
Segmentation
Management Paths

OSEP Readiness Level 05 — Security Controls

Section titled “OSEP Readiness Level 05 — Security Controls”

You understand the purpose and visibility of:

Endpoint Protection
EDR
Firewalling
Application Control
PowerShell Logging
Central Monitoring

You can take:

IDENTITIES
+
SYSTEMS
+
PRIVILEGES
+
NETWORK ACCESS
+
TRUST

and construct validated:

ATTACK PATHS

OSEP Readiness Level 07 — Defender Awareness

Section titled “OSEP Readiness Level 07 — Defender Awareness”

For simulated activity you can explain:

What Happened?
What Telemetry Should Exist?
What Could Detect It?
How Should Defenders Investigate?

You can communicate:

Individual Findings
Attack Paths
Business Impact
Control Gaps
Remediation Priorities

OSEP Readiness Level 09 — Independent Assessment

Section titled “OSEP Readiness Level 09 — Independent Assessment”

You can receive an unfamiliar authorized enterprise lab and systematically:

MAP
ENUMERATE
UNDERSTAND
MODEL
VALIDATE
DOCUMENT
REPORT

without relying on a walkthrough.

Avoid:

Weak Windows Fundamentals
Weak Active Directory Fundamentals
Thinking Only About Individual Hosts
Ignoring Identity Relationships
Ignoring Network Segmentation
Ignoring Service Accounts
Ignoring Administrative Separation
Treating EDR Only as an Obstacle
Ignoring Defender Telemetry
Ignoring Business Impact
Poor Evidence Collection
Poor Cleanup
Ignoring Reporting
Depending Entirely on Automated Tools
Building Attack Paths Without Validating Each Step

Think:

OSCP
=
Practical Penetration Testing Foundation

OSEP expands toward:

COMPLEX ENTERPRISE ENVIRONMENTS
+
IDENTITY
+
ACTIVE DIRECTORY
+
DEFENSE AWARENESS
+
ATTACK PATHS
OSWE
=
Advanced Application Security
OSEP
=
Advanced Enterprise Offensive Security

A professional may pursue either direction based on specialization.

OSEP-oriented skills provide a strong technical foundation for red-team work, but professional red teaming also requires:

Engagement Planning
Operational Security
Threat Intelligence
Detection Awareness
Communication
Risk Management
Stakeholder Coordination

OSEP-oriented skills support roles such as:

Senior Penetration Tester
Enterprise Penetration Tester
Offensive Security Engineer
Red Team Operator
Security Consultant
Purple Team Engineer
Adversary Simulation Specialist

What is an enterprise attack path?

An enterprise attack path is a sequence of validated relationships involving identities, systems, privileges, network access, or trust that can allow compromise to progress toward a more sensitive asset.

Why is Active Directory important in enterprise security?

Because it frequently provides centralized:

Identity
Authentication
Authorization
Policy
Administration

for large portions of the enterprise.

Why is administrative separation important?

It limits the ability of compromise in a lower-trust environment to expose highly privileged administrative identities.

Why is network segmentation important?

Segmentation reduces unnecessary connectivity and can prevent one compromised system from directly reaching higher-value assets.

Why should offensive security engineers understand EDR?

Because understanding defensive telemetry allows them to assess whether security controls provide effective visibility and helps organizations improve detection and response.

  1. What is OSEP?
  2. How does OSEP differ from OSCP?
  3. What is enterprise penetration testing?
  4. What is an attack path?
  5. What is a trust boundary?
  6. What is Active Directory?
  7. What is a forest?
  8. What is a domain?
  9. What is a domain controller?
  10. What is Kerberos?
  11. What is NTLM?
  12. What is LDAP?
  13. Why is DNS important to Active Directory?
  14. What is Group Policy?
  15. Why are GPO permissions security-sensitive?
  16. What is delegation?
  17. What is privilege creep?
  18. Why are nested groups security-sensitive?
  19. What is a service account?
  20. Why should service-account privileges be minimized?
  21. What is administrative separation?
  22. What is privilege tiering?
  23. What is network segmentation?
  24. What is lateral movement conceptually?
  25. What is pivoting conceptually?
  26. What is an EDR?
  27. What is application control?
  28. Why is PowerShell logging useful?
  29. What is operational security?
  30. What are rules of engagement?
  31. What is adversary simulation?
  32. How does a penetration test differ from a red-team exercise?
  33. What are crown jewels?
  34. What is a network reachability matrix?
  35. What is an identity privilege matrix?
  36. Why should every attack-path transition be validated?
  37. What is purple teaming?
  38. Why should reports include business impact?
  39. What is a remediation choke point?
  40. What skills make someone job-ready for enterprise offensive security?
  • Understand Windows users
  • Understand groups
  • Understand privileges
  • Understand access tokens
  • Understand services
  • Understand PowerShell
  • Understand remote administration
  • Understand Windows logging
  • Understand forests
  • Understand domains
  • Understand domain controllers
  • Understand users
  • Understand groups
  • Understand computers
  • Understand Kerberos
  • Understand NTLM
  • Understand LDAP
  • Understand DNS
  • Understand GPOs
  • Understand delegation
  • Understand trusts
  • Map privileged users
  • Map administrative groups
  • Review nested membership
  • Review service accounts
  • Review delegated privilege
  • Review administrative separation
  • Review credential governance
  • Map network zones
  • Understand routing
  • Understand segmentation
  • Build reachability matrices
  • Identify management paths
  • Identify trust boundaries
  • Understand antivirus
  • Understand EDR
  • Understand host firewalls
  • Understand application control
  • Understand endpoint telemetry
  • Understand PowerShell visibility
  • Map identities
  • Map systems
  • Map privilege
  • Map network access
  • Map trust
  • Validate every relationship
  • Identify crown-jewel exposure
  • Identify remediation choke points
  • Confirm authorization
  • Understand scope
  • Follow rules of engagement
  • Minimize production risk
  • Protect sensitive evidence
  • Track artifacts
  • Perform cleanup
  • Communicate significant events
  • Document technical findings
  • Document attack paths
  • Explain business impact
  • Provide evidence
  • Recommend remediation
  • Prioritize fixes
  • Include detection opportunities
  • Produce executive summaries

Remember:

AUTHORIZED ENTERPRISE
UNDERSTAND ARCHITECTURE
MAP NETWORK
MAP IDENTITIES
MAP PRIVILEGES
MAP TRUST
MAP SECURITY CONTROLS
IDENTIFY ATTACK PATH
VALIDATE EACH RELATIONSHIP
ASSESS BUSINESS IMPACT
UNDERSTAND DEFENDER VISIBILITY
CAPTURE EVIDENCE
CLEAN UP
REPORT
RECOMMEND CONTROL IMPROVEMENTS

The OSEP mindset is not:

How Many Systems
Can I Compromise?

It is:

Which Enterprise Trust Relationships
Create Meaningful Security Risk,
How Can Those Relationships Be
Validated Safely,
and Which Controls Would Break
the Attack Path?

The strongest enterprise offensive-security professionals combine:

WINDOWS
+
ACTIVE DIRECTORY
+
NETWORKING
+
IDENTITY SECURITY
+
PRIVILEGE ANALYSIS
+
SEGMENTATION
+
DEFENSE AWARENESS
+
ATTACK-PATH THINKING
+
OPERATIONAL DISCIPLINE
+
REPORTING

➡️ 05 — OSED

Next, you will move from enterprise offensive security into advanced exploit development and low-level security research.

The next stage will focus on:

Computer Architecture
Memory Fundamentals
C / C++
Assembly Language
Registers
Stack and Heap
Debugging
Binary Analysis
Memory Corruption
Exploit Mitigations
Vulnerability Research
Exploit Development

The major transition will be:

OSEP
=
Understand Enterprise
Attack Paths

toward:

OSED
=
Understand Vulnerabilities
at the Binary and
Memory Level