04 — OSEP
The Offensive Security Experienced Penetration Tester (OSEP) path moves beyond individual-host penetration testing into the assessment of complex enterprise environments.
At this stage, the objective is no longer simply:
Find a Vulnerability ↓Gain AccessInstead, you learn to think in terms of:
ENTERPRISE ENVIRONMENT ↓IDENTITIES ↓SYSTEMS ↓TRUST RELATIONSHIPS ↓SECURITY CONTROLS ↓ATTACK PATHS ↓BUSINESS IMPACTOSEP-oriented skills are particularly relevant for:
Senior Penetration Tester
Enterprise Penetration Tester
Red Team Operator
Offensive Security Engineer
Security Consultant
Adversary Simulation SpecialistPerform enterprise offensive-security activities only inside systems you own, purpose-built labs, or environments where you have explicit authorization and clearly defined rules of engagement.
Certification Information
Section titled “Certification Information”Certification: OSEP
Primary Domain: Advanced Enterprise Penetration Testing
Skill Level: Advanced
Career Direction: Enterprise Pentesting and Red Team Operations
Core Transition: Host exploitation → Enterprise attack-path analysis
Recommended Foundation: Strong OSCP-level networking, Windows, Linux, Active Directory, scripting, enumeration, privilege analysis, and reporting skills
What OSEP Should Build
Section titled “What OSEP Should Build”Your preparation should develop competency around:
Enterprise Architecture
Windows Security
Active Directory
Identity Relationships
Authentication
Authorization
Privilege Relationships
Network Segmentation
Endpoint Security Controls
Application Control
Operational Security
Attack-Path Analysis
Adversary Simulation
Evidence Collection
Remediation
Professional ReportingOSEP Career Position
Section titled “OSEP Career Position”A practical progression is:
NETWORKING ↓LINUX + WINDOWS ↓PENTESTING FUNDAMENTALS ↓OSCP ↓ENTERPRISE SECURITY ↓ACTIVE DIRECTORY ↓DEFENSE AWARENESS ↓OSEP ↓RED TEAMING ↓SENIOR OFFENSIVE SECURITY01 — Understand the Enterprise Pentesting Mindset
Section titled “01 — Understand the Enterprise Pentesting Mindset”A single-host assessment may look like:
TARGET ↓SERVICE ↓WEAKNESS ↓ACCESS ↓PRIVILEGEEnterprise assessments add another dimension:
IDENTITY ↓WORKSTATION ↓SERVER ↓APPLICATION ↓DOMAIN ↓TRUST ↓SENSITIVE ASSETThe security question becomes:
How Can MultipleIndividually Limited WeaknessesCombine Into a MeaningfulEnterprise Attack Path?02 — Think in Attack Paths
Section titled “02 — Think in Attack Paths”An attack path represents relationships between:
Identity
Privilege
System
Credential
Application
Network
TrustExample:
STANDARD USER ↓WORKSTATION ↓EXCESSIVE LOCAL PRIVILEGE ↓SERVER ACCESS ↓PRIVILEGED IDENTITY EXPOSURE ↓SENSITIVE RESOURCEThe important skill is understanding why each transition is possible.
03 — Build an Enterprise Architecture Model
Section titled “03 — Build an Enterprise Architecture Model”Before testing, map the environment.
A simplified enterprise may look like:
INTERNET | FIREWALL | DMZ | +---------+---------+ | | WEB TIER VPN / ACCESS | APP TIER | DATABASE
INTERNAL NETWORK | +-- User Workstations | +-- Application Servers | +-- File Servers | +-- Domain Controllers | +-- Management Systems | +-- Security Systems04 — Identify Security Zones
Section titled “04 — Identify Security Zones”Enterprise networks commonly contain zones such as:
Internet
DMZ
User Network
Server Network
Management Network
Database Network
Security Network
Backup Network
Cloud NetworkFor each zone determine:
Who Can Reach It?
From Where?
Using Which Protocol?
Under Which Identity?
What Security Controls Exist?05 — Understand Trust Boundaries
Section titled “05 — Understand Trust Boundaries”A trust boundary separates different security contexts.
Examples:
Internet → DMZ
DMZ → Internal Network
User Network → Server Network
Workstation → Domain Controller
Standard User → Administrator
On-Premises → CloudAttack-path analysis frequently begins by asking:
Can This Trust BoundaryBe Crossed in a Waythe Organization Did Not Intend?06 — Build an Asset Inventory
Section titled “06 — Build an Asset Inventory”Document:
| Asset | Role | Zone | Identity Context | Criticality |
|---|---|---|---|---|
| WS01 | Workstation | User | Standard User | Medium |
| APP01 | Application | Server | Service Identity | High |
| DC01 | Domain Controller | Management | Domain Services | Critical |
| DB01 | Database | Data | Service Identity | Critical |
07 — Build an Identity Inventory
Section titled “07 — Build an Identity Inventory”Enterprise security is increasingly identity-driven.
Inventory:
Standard Users
Administrators
Service Accounts
Application Identities
Domain Accounts
Local Accounts
Machine Accounts
Emergency Accounts
Third-Party Identities08 — Build a Privilege Matrix
Section titled “08 — Build a Privilege Matrix”Create:
| Identity | System | Privilege | Purpose | Expected? |
|---|---|---|---|---|
| UserA | WS01 | Standard | Daily work | Yes |
| AdminA | SRV01 | Admin | Server management | Yes |
| ServiceA | APP01 | Service | Application | Yes |
| UserB | SRV02 | Admin | Unknown | Review |
This can expose:
Privilege Creep
Unnecessary Administration
Weak Separation
Unexpected Trust09 — Understand Windows Enterprise Security
Section titled “09 — Understand Windows Enterprise Security”OSEP preparation requires strong Windows knowledge.
Understand:
Local Users
Domain Users
Groups
Privileges
Services
Scheduled Tasks
Registry
NTFS Permissions
Windows Firewall
PowerShell
Event Logging
Remote AdministrationWindows Security Model
Section titled “Windows Security Model”IDENTITY ↓TOKEN ↓GROUPS + PRIVILEGES ↓ACCESS CHECK ↓RESOURCE10 — Understand Access Tokens
Section titled “10 — Understand Access Tokens”After authentication, Windows creates a security context containing information such as:
User Identity
Group Membership
Privileges
Integrity ContextConceptually:
USER ↓AUTHENTICATION ↓ACCESS TOKEN ↓RESOURCE ACCESSUnderstanding this model helps explain why group membership and privilege assignments matter.
11 — Review Local Administrative Access
Section titled “11 — Review Local Administrative Access”Local administrator rights are highly security-sensitive.
Assess:
Who Has Local Admin?
Why?
On Which Systems?
How Is Membership Managed?
Are Rights Temporary?
Are They Reviewed?12 — Understand Privilege Creep
Section titled “12 — Understand Privilege Creep”Privilege creep occurs when identities accumulate access over time.
USER ↓PROJECT A ACCESS ↓PROJECT B ACCESS ↓TEMP ADMIN ↓ROLE CHANGE ↓OLD ACCESS NEVER REMOVEDEventually:
EXCESSIVE PRIVILEGEcan create enterprise attack paths.
13 — Understand Active Directory Architecture
Section titled “13 — Understand Active Directory Architecture”You should be comfortable with:
Forest
Domain
Domain Controller
Organizational Unit
Users
Groups
Computers
Group Policy
Trusts
DNS
LDAP
Kerberos
NTLMAD Architecture
Section titled “AD Architecture”FOREST | +-- DOMAIN | +-- Domain Controllers | +-- Users | +-- Groups | +-- Computers | +-- OUs | +-- GPOs14 — Understand Domain Controllers
Section titled “14 — Understand Domain Controllers”Domain controllers provide critical services such as:
Authentication
Directory Services
Kerberos
Group Policy Distribution
Identity ManagementThey should therefore be treated as:
CRITICAL SECURITY ASSETS15 — Understand Kerberos
Section titled “15 — Understand Kerberos”At a high level:
USER ↓AUTHENTICATION ↓TICKET-GRANTING TICKET ↓SERVICE REQUEST ↓SERVICE TICKET ↓RESOURCEYour goal should be to understand:
Identity
Tickets
Service Accounts
Trust
Authorizationrather than merely memorizing attack terminology.
16 — Understand NTLM
Section titled “16 — Understand NTLM”NTLM remains relevant in many Windows environments because of:
Legacy Systems
Compatibility Requirements
Application DependenciesFrom a security-assessment perspective, determine:
Where Is It Used?
Why Is It Required?
Can Usage Be Reduced?
What Monitoring Exists?17 — Understand LDAP
Section titled “17 — Understand LDAP”LDAP provides directory access.
Conceptually:
CLIENT ↓DIRECTORY QUERY ↓DOMAIN CONTROLLER ↓DIRECTORY OBJECTSDirectory information can include:
Users
Groups
Computers
Organizational Units
Service Information18 — Understand DNS Dependency
Section titled “18 — Understand DNS Dependency”Active Directory relies heavily on DNS.
Conceptually:
CLIENT ↓DNS ↓DOMAIN SERVICE LOCATION ↓DOMAIN CONTROLLERDNS problems can therefore become:
Authentication Problems
Service Discovery Problems
Operational Problems19 — Understand Group-Based Privilege
Section titled “19 — Understand Group-Based Privilege”Enterprise access frequently follows:
USER ↓GROUP ↓ROLE ↓RESOURCEReview:
Direct Membership
Nested Membership
Administrative Groups
Application Groups
Delegated Groups20 — Understand Nested Group Risk
Section titled “20 — Understand Nested Group Risk”Nested groups can make effective access difficult to see.
USER ↓GROUP A ↓GROUP B ↓PRIVILEGED GROUP ↓SENSITIVE RESOURCEThe user may have significant privilege without appearing directly in the final group.
21 — Understand Delegation
Section titled “21 — Understand Delegation”Organizations delegate administrative responsibility so every task does not require the highest privilege.
Examples include:
Password Reset
User Administration
Computer Administration
OU Management
Application AdministrationPoor delegation can create unintended privilege paths.
22 — Understand Group Policy
Section titled “22 — Understand Group Policy”Group Policy can control:
Security Settings
Firewall
Scripts
User Rights
Application Configuration
System ConfigurationConceptually:
DOMAIN ↓OU ↓GPO ↓COMPUTER / USER23 — Assess GPO Security
Section titled “23 — Assess GPO Security”Review:
Who Can Create GPOs?
Who Can Edit Them?
Where Are They Linked?
Which Systems Receive Them?
Can Delegated Users Modify Sensitive Policy?A configuration-management mechanism can become a privilege path if its permissions are weak.
24 — Understand Service Accounts
Section titled “24 — Understand Service Accounts”Service accounts support:
Applications
Databases
Scheduled Tasks
Services
AutomationReview:
Purpose
Privilege
Credential Management
Interactive Login
Rotation
Ownership
Lifecycle25 — Prefer Managed Identity Patterns
Section titled “25 — Prefer Managed Identity Patterns”Where supported, organizations should consider mechanisms such as:
Managed Service Accounts
Group Managed Service Accounts
Platform-Managed Identities
Workload Federationinstead of unnecessary long-lived manually managed credentials.
26 — Understand Credential Exposure
Section titled “26 — Understand Credential Exposure”Credentials may be exposed through:
Configuration
Scripts
Deployment Files
Backups
User Behavior
Administrative Processes
Application SecretsThe assessment question is:
What Credential Exists?
What Can It Access?
Why Is It Exposed?
How Should It Be Protected?27 — Treat Credentials as Sensitive Evidence
Section titled “27 — Treat Credentials as Sensitive Evidence”Never unnecessarily reproduce secrets in reports.
Prefer:
Credential Type
Affected Asset
Privilege
Exposure Location
Redacted Evidenceinstead of publishing complete credentials.
28 — Understand Administrative Separation
Section titled “28 — Understand Administrative Separation”A mature environment may separate:
Standard User Identity
Workstation Admin Identity
Server Admin Identity
Domain Administration IdentityConceptually:
DAILY USER ≠PRIVILEGED ADMINThis reduces the chance that compromise of one identity automatically exposes every privilege tier.
29 — Understand Privileged Access Workstations
Section titled “29 — Understand Privileged Access Workstations”Highly privileged administrative activity may be restricted to specially managed systems.
Conceptually:
ADMINISTRATOR ↓SECURED ADMIN WORKSTATION ↓PRIVILEGED RESOURCErather than:
ADMINISTRATOR ↓EVERYDAY WORKSTATION ↓PRIVILEGED RESOURCE30 — Understand Network Segmentation
Section titled “30 — Understand Network Segmentation”Segmentation limits:
Reachability
Lateral Movement
Administrative Exposure
Attack SurfaceSegmentation Model
Section titled “Segmentation Model”USER NETWORK | X |SERVER NETWORK | X |MANAGEMENT NETWORKThe X represents controlled boundaries rather than unrestricted connectivity.
31 — Evaluate Segmentation
Section titled “31 — Evaluate Segmentation”For each boundary ask:
Source?
Destination?
Protocol?
Port?
Identity?
Business Requirement?
Security Control?32 — Understand Lateral Movement Conceptually
Section titled “32 — Understand Lateral Movement Conceptually”Lateral movement refers to movement between systems or security contexts after initial access.
Conceptually:
HOST A ↓AUTHORIZED RELATIONSHIP ↓HOST BCommon legitimate administrative technologies involved in enterprise environments include:
RDP
SMB
SSH
PowerShell Remoting
Management PlatformsSecurity problems arise when these relationships are exposed through:
Weak Credentials
Excessive Privilege
Poor Segmentation
Weak Administrative Separation33 — Understand Pivoting
Section titled “33 — Understand Pivoting”A pivot allows an assessment to evaluate another authorized network segment through an already controlled lab system.
TESTING SYSTEM ↓LAB HOST A ↓INTERNAL LAB NETWORK ↓LAB HOST BThe foundational knowledge is:
Routing
Interfaces
Ports
Reachability
Segmentation34 — Build a Network Reachability Matrix
Section titled “34 — Build a Network Reachability Matrix”| Source | Destination | Service | Expected | Observed |
|---|---|---|---|---|
| User Zone | Web Tier | HTTPS | Yes | Yes |
| User Zone | Database | Database Port | No | Review |
| Web Tier | Database | Database Port | Yes | Yes |
| User Zone | DC | Admin Service | Restricted | Review |
This turns segmentation into measurable evidence.
35 — Understand Endpoint Security Controls
Section titled “35 — Understand Endpoint Security Controls”Modern enterprise environments may use:
Antivirus
EDR
Host Firewall
Application Control
Attack Surface Reduction
Device Compliance
Central LoggingOSEP preparation should include understanding what these controls are designed to prevent and detect.
36 — Think Like a Security Engineer
Section titled “36 — Think Like a Security Engineer”Do not treat endpoint security merely as:
Something to BypassUnderstand:
What Does It Detect?
Which Telemetry Does It Collect?
Which Behavior Is Restricted?
How Would the SOC Investigate It?37 — Understand Antivirus
Section titled “37 — Understand Antivirus”Antivirus commonly evaluates:
Files
Signatures
Known Threats
Potentially Suspicious ContentModern endpoint protection may add additional behavioral and cloud-based analysis.
38 — Understand EDR
Section titled “38 — Understand EDR”Endpoint Detection and Response may collect telemetry around:
Processes
Parent-Child Relationships
Network Connections
Files
Registry
User Activity
Security EventsConceptually:
ENDPOINT ↓TELEMETRY ↓DETECTION ↓SECURITY PLATFORM ↓SOC ANALYST39 — Understand Application Control
Section titled “39 — Understand Application Control”Application control restricts what software can execute.
Possible approaches include:
Allowlisting
Publisher Rules
Path Rules
Hash Rules
Managed Installer TrustFrom an assessment perspective, determine:
What Is Allowed?
What Is Blocked?
Why?
Which Systems Are Covered?
Are Exceptions Controlled?40 — Understand PowerShell Security
Section titled “40 — Understand PowerShell Security”PowerShell is an important Windows administration platform.
Organizations may apply controls around:
Script Logging
Module Logging
Transcription
Application Control
Endpoint Monitoring
Language RestrictionsOSEP-level knowledge should include both:
Administrative Utilityand:
Defensive Visibility41 — Understand Security Telemetry
Section titled “41 — Understand Security Telemetry”During an enterprise assessment, think about what defenders may observe.
AUTHENTICATION ↓LOGON EVENT
PROCESS START ↓PROCESS TELEMETRY
NETWORK CONNECTION ↓NETWORK TELEMETRY
PRIVILEGE CHANGE ↓DIRECTORY / AUDIT EVENT42 — Build Defender Awareness
Section titled “42 — Build Defender Awareness”For each simulated activity ask:
Which Log Would Record This?
Which Security Product Might Detect It?
What Alert Could Be Generated?
What Evidence Would the SOC See?This improves both offensive and defensive understanding.
43 — Understand Operational Security
Section titled “43 — Understand Operational Security”Operational security means controlling how an authorized assessment is conducted so it does not create unnecessary risk.
Consider:
Scope
Timing
Noise
Artifacts
Sensitive Data
Persistence
Cleanup
Communication44 — Rules of Engagement
Section titled “44 — Rules of Engagement”Before testing, define:
Authorized Targets
Excluded Targets
Permitted Techniques
Restricted Techniques
Testing Window
Escalation Contacts
Emergency Stop Procedure
Data Handling
Reporting Requirements45 — Understand Production Risk
Section titled “45 — Understand Production Risk”A technique that is acceptable in a dedicated lab may be inappropriate in production.
Always consider:
Could This Crash a Service?
Could This Lock an Account?
Could This Corrupt Data?
Could This Trigger Business Disruption?
Could This Affect Other Tenants?46 — Use Controlled Validation
Section titled “46 — Use Controlled Validation”Professional assessments should seek:
MINIMUM ACTION ↓SUFFICIENT EVIDENCE ↓CONFIRMED RISKnot:
MAXIMUM POSSIBLE DAMAGE47 — Understand Adversary Simulation
Section titled “47 — Understand Adversary Simulation”Adversary simulation tests whether an organization can:
Prevent
Detect
Investigate
Containrealistic attacker behavior under controlled conditions.
48 — Pentest vs Red Team
Section titled “48 — Pentest vs Red Team”A penetration test often asks:
What Security Weaknesses Exist?A red-team-style exercise may ask:
Can a Realistic Attack PathReach a Defined Objective,and Can the OrganizationDetect and Respond to It?49 — Define Exercise Objectives
Section titled “49 — Define Exercise Objectives”Examples:
Evaluate Administrative Separation
Evaluate Network Segmentation
Evaluate Identity Controls
Evaluate Detection Coverage
Evaluate Privileged Access GovernanceAvoid vague objectives such as:
Hack Everything50 — Define Crown Jewels
Section titled “50 — Define Crown Jewels”Crown jewels are high-value business assets.
Examples:
Identity Infrastructure
Critical Databases
Production Management Systems
Sensitive Intellectual Property
Backup Infrastructure
Security Management Systems51 — Work Backward from the Objective
Section titled “51 — Work Backward from the Objective”If the objective is:
CRITICAL APPLICATIONask:
Who Administers It?
Which Identities Can Access It?
Which Systems Can Reach It?
Which Authentication Is Required?
Which Trust Relationships Exist?This creates a potential attack-path map.
52 — Build an Attack-Path Graph
Section titled “52 — Build an Attack-Path Graph”Conceptually:
USER A | vWORKSTATION | vGROUP B | vSERVER C | vSERVICE IDENTITY | vSENSITIVE APPLICATIONEvery edge should represent a real, validated relationship.
53 — Document Attack-Path Preconditions
Section titled “53 — Document Attack-Path Preconditions”For every transition record:
Source:
Destination:
Required Identity:
Required Privilege:
Required Network Access:
Required Configuration:
Observed Control:
Security Concern:54 — Avoid Attack-Path Assumptions
Section titled “54 — Avoid Attack-Path Assumptions”Do not conclude:
A Can Reach BThereforeA Can Compromise BValidate:
Authentication
Authorization
Configuration
Privilege
Control Effectiveness55 — Understand Privilege Escalation in Context
Section titled “55 — Understand Privilege Escalation in Context”Privilege escalation is not limited to:
User → SYSTEMEnterprise privilege escalation may also involve:
User ↓Application AdministratorServer Administrator ↓Identity AdministratorService Account ↓Sensitive Database56 — Understand Vertical and Horizontal Movement
Section titled “56 — Understand Vertical and Horizontal Movement”Vertical
Section titled “Vertical”LOW PRIVILEGE ↓HIGHER PRIVILEGEHorizontal
Section titled “Horizontal”SYSTEM A ↓SYSTEM BEnterprise attack paths often combine both.
57 — Understand Administrative Paths
Section titled “57 — Understand Administrative Paths”A secure environment should define:
Who Administers Workstations?
Who Administers Servers?
Who Administers Domain Controllers?
From Which Devices?
Using Which Accounts?Uncontrolled overlap increases risk.
58 — Understand Tiering Concepts
Section titled “58 — Understand Tiering Concepts”A simplified privilege model may separate:
TIER 0Identity Infrastructure
TIER 1Servers and Applications
TIER 2User WorkstationsThe goal is to prevent lower-trust systems from becoming stepping stones toward highly privileged environments.
59 — Evaluate Administrative Logons
Section titled “59 — Evaluate Administrative Logons”Ask:
Where Do Privileged Accounts Log In?
Do Domain-Level Admins Use Workstations?
Do Server Admins Browse the Internet?
Are Admin Sessions Isolated?
Are Privileged Sessions Monitored?60 — Understand Credential Hygiene
Section titled “60 — Understand Credential Hygiene”Credential security includes:
Unique Passwords
Rotation
MFA
Managed Credentials
Limited Privilege
Secure Storage
Restricted Logon
Monitoring61 — Understand Local Administrator Password Management
Section titled “61 — Understand Local Administrator Password Management”Organizations should avoid unmanaged reuse of local administrator credentials.
Modern environments can use centralized mechanisms for:
Unique Credentials
Rotation
Controlled Retrieval
Auditing62 — Understand Service Account Risk
Section titled “62 — Understand Service Account Risk”Service accounts may become high-value because they often have:
Long Lifetimes
Application Access
Server Access
Database Access
Automation PrivilegeReview:
Can Interactive Login Be Disabled?
Can Privilege Be Reduced?
Can Managed Identity Be Used?
Is Credential Rotation Automated?63 — Understand Active Directory ACLs
Section titled “63 — Understand Active Directory ACLs”Directory objects have permissions.
Conceptually:
IDENTITY ↓DIRECTORY PERMISSION ↓OBJECTReview whether delegated identities can perform sensitive operations beyond their intended role.
64 — Understand Ownership
Section titled “64 — Understand Ownership”Object ownership can be security-sensitive because owners may have capabilities affecting object permissions.
Assess ownership of:
Groups
Service Accounts
Policies
Administrative Objects
Applications65 — Understand Trust Relationships
Section titled “65 — Understand Trust Relationships”Enterprises may contain:
Domain Trusts
Forest Trusts
Application Trusts
Cloud Federation
Third-Party TrustTrust should always be evaluated from both directions.
66 — Trust Does Not Mean Equal Security
Section titled “66 — Trust Does Not Mean Equal Security”A trusted environment may have:
Different Security Controls
Different Administrators
Different Patch Levels
Different MonitoringTherefore:
TRUST RELATIONSHIP +WEAKER ENVIRONMENTcan increase enterprise risk.
67 — Understand Hybrid Identity
Section titled “67 — Understand Hybrid Identity”Modern organizations may connect:
On-Premises Active Directory ↓Identity Synchronization ↓Cloud Identity Platform ↓SaaS / Cloud ResourcesThis creates new relationships between:
On-Prem Identity
Cloud Identity
Applications
Devices
Administrative Roles68 — Hybrid Attack-Path Thinking
Section titled “68 — Hybrid Attack-Path Thinking”Ask:
Can On-Premises PrivilegeInfluence Cloud Access?
Can Cloud PrivilegeInfluence On-Premises Systems?
Which Synchronization ComponentsAre Highly Privileged?69 — Understand Cloud Integration
Section titled “69 — Understand Cloud Integration”Enterprise offensive security increasingly intersects with:
Microsoft Azure
AWS
Google Cloud
SaaS
Cloud Identity
Cloud ManagementOSEP foundations therefore benefit from understanding hybrid architecture.
70 — Understand Data Protection
Section titled “70 — Understand Data Protection”During assessments, sensitive information may be encountered.
Define procedures for:
Collection
Storage
Encryption
Access
Retention
Deletion71 — Minimize Sensitive Data Collection
Section titled “71 — Minimize Sensitive Data Collection”Prefer:
Enough Evidenceto Demonstrate Riskrather than:
Copy Every Available File72 — Build an Enterprise Enumeration Workflow
Section titled “72 — Build an Enterprise Enumeration Workflow”Use:
01 Understand Scope
02 Map Network
03 Identify Systems
04 Identify Services
05 Map Identities
06 Map Groups
07 Map Privileges
08 Map Trust
09 Map Segmentation
10 Map Security Controls
11 Identify Potential Paths
12 Validate Paths
13 Assess Impact
14 Collect Evidence
15 Cleanup
16 Report73 — Re-Enumerate After Every Context Change
Section titled “73 — Re-Enumerate After Every Context Change”Whenever you gain a new authorized security context:
NEW IDENTITY ↓RE-ENUMERATEWhenever you reach a new network:
NEW NETWORK ↓RE-ENUMERATEWhenever privilege changes:
NEW PRIVILEGE ↓RE-ENUMERATE74 — Build an Identity Relationship Matrix
Section titled “74 — Build an Identity Relationship Matrix”| Identity | Groups | Systems | Privilege | Sensitive Access |
|---|---|---|---|---|
| UserA | Employees | WS01 | Standard | No |
| AdminA | Server Admins | SRV01 | Admin | Yes |
| ServiceA | App Services | APP01 | Service | Database |
75 — Build a Security-Control Matrix
Section titled “75 — Build a Security-Control Matrix”| Control | Coverage | Purpose | Validation |
|---|---|---|---|
| MFA | Admins | Authentication | Review |
| EDR | Endpoints | Detection | Review |
| Firewall | Servers | Segmentation | Review |
| App Control | Admin Systems | Execution Control | Review |
| SIEM | Enterprise | Monitoring | Review |
76 — Build a Findings Register
Section titled “76 — Build a Findings Register”Use:
| ID | Finding | Asset | Severity | Attack Path |
|---|---|---|---|---|
| ENT-001 | Excessive Admin Access | SRV01 | High | AP-01 |
| ENT-002 | Weak Segmentation | DB01 | High | AP-02 |
| ENT-003 | Stale Privileged Account | AD | High | AP-03 |
77 — Build an Attack-Path Register
Section titled “77 — Build an Attack-Path Register”Attack Path ID:
Objective:
Starting Context:
Systems Involved:
Identities Involved:
Trust Relationships:
Security Controls:
Weaknesses:
Validated Impact:
Evidence:
Recommended Remediation:78 — Prioritize Choke Points
Section titled “78 — Prioritize Choke Points”A choke point is a control whose improvement can break multiple attack paths.
Examples may include:
Privileged Access Governance
Network Segmentation
Administrative Separation
MFA
Service Account Governance
Endpoint HardeningThis makes remediation more strategic.
79 — Think Beyond Individual Findings
Section titled “79 — Think Beyond Individual Findings”Instead of reporting:
Finding A
Finding B
Finding Cshow when appropriate:
Finding A +Finding B +Finding C ↓Enterprise Attack Path80 — Explain Business Impact
Section titled “80 — Explain Business Impact”Technical statement:
Excessive Administrative Group MembershipBusiness-oriented statement:
Compromise of a standard operationalidentity could provide a path towardadministrative access to systems supportinga critical business application.81 — Write Enterprise Findings
Section titled “81 — Write Enterprise Findings”Use:
Finding ID:
Title:
Severity:
Affected Assets:
Affected Identities:
Description:
Attack-Path Relationship:
Evidence:
Technical Impact:
Business Impact:
Recommendation:
Validation Method:Example Finding — Administrative Separation
Section titled “Example Finding — Administrative Separation”Finding ID:ENT-001
Title:Privileged Administrative Accounts Usedon Lower-Trust Workstations
Severity:High
Observation:Highly privileged identities are permittedto authenticate to general-purpose userworkstations.
Risk:Compromise of a lower-trust workstation mayincrease the likelihood of privilegedcredential or session exposure.
Recommendation:Implement administrative tiering andrestrict privileged identities to approvedadministrative systems.Example Finding — Segmentation
Section titled “Example Finding — Segmentation”Finding ID:ENT-002
Title:User Network Has Unnecessary Access toSensitive Server Services
Severity:High
Observation:General user systems can directly reachadministrative or sensitive services in ahigher-trust server zone without adocumented business requirement.
Risk:Compromise of a workstation may provide adirect network path toward criticalsystems.
Recommendation:Restrict network access usingdeny-by-default segmentation and explicitlyallow only documented business flows.Example Finding — Service Account
Section titled “Example Finding — Service Account”Finding ID:ENT-003
Title:Service Identity Holds Excessive Privilege
Severity:High
Observation:An application service identity hasprivileges significantly beyond thoserequired for its documented function.
Risk:Compromise of the application or serviceidentity may provide access to additionalenterprise systems or sensitive data.
Recommendation:Reduce privileges to the minimum required,restrict interactive use, and migrate tomanaged credential mechanisms wheresupported.82 — Create an Attack-Path Diagram
Section titled “82 — Create an Attack-Path Diagram”Example:
STANDARD USER | vWORKSTATION | | Excessive Privilege vAPPLICATION SERVER | | Service Identity vDATABASE | | Sensitive Access vBUSINESS DATAThis is often easier for stakeholders to understand than isolated technical findings.
83 — Write an Executive Summary
Section titled “83 — Write an Executive Summary”Executives need:
What Was Tested?
What Was the Objective?
What Attack Paths Were Identified?
Which Business Assets Were Exposed?
Which Controls Failed?
What Should Be Fixed First?84 — Build a Remediation Roadmap
Section titled “84 — Build a Remediation Roadmap”Prioritize:
IMMEDIATECritical exposure
SHORT TERMPrivilege and configuration
MEDIUM TERMArchitecture and segmentation
LONG TERMIdentity and security maturity85 — Include Detection Recommendations
Section titled “85 — Include Detection Recommendations”Enterprise offensive-security reports can also recommend:
Authentication Monitoring
Privileged Group Monitoring
Endpoint Telemetry
Network Monitoring
Service Account Monitoring
Directory Change Monitoring86 — Collaborate with Defenders
Section titled “86 — Collaborate with Defenders”A mature red/purple-team workflow may involve:
OFFENSIVE TEAM ↓SIMULATED ACTIVITY ↓DEFENSIVE TELEMETRY ↓SOC ANALYSIS ↓DETECTION IMPROVEMENT87 — Understand Purple Teaming
Section titled “87 — Understand Purple Teaming”Purple teaming connects:
OFFENSIVE KNOWLEDGE +DEFENSIVE KNOWLEDGEto improve:
Prevention
Detection
Investigation
Response88 — Build an OSEP Lab Environment
Section titled “88 — Build an OSEP Lab Environment”A dedicated authorized lab might contain:
ATTACKER / TEST SYSTEM | vLAB FIREWALL | +-- Windows Workstation | +-- Member Server | +-- Domain Controller | +-- Application Server | +-- Linux ServerKeep it isolated from production.
89 — Lab Safety
Section titled “89 — Lab Safety”Use:
Dedicated Virtual Network
Snapshots
Test Accounts
Synthetic Data
Documented Scope
Rollback PlanAvoid using:
Production Credentials
Real Customer Data
Corporate Production Systemsfor uncontrolled experimentation.
90 — Lab Project 01: Enterprise Discovery
Section titled “90 — Lab Project 01: Enterprise Discovery”Mission
Section titled “Mission”Create an inventory of an authorized enterprise lab.
Document:
Hosts
Services
Operating Systems
Zones
Users
Groups
Trust BoundariesDeliverable
Section titled “Deliverable”Create:
Enterprise Asset Map91 — Lab Project 02: Identity Relationship Assessment
Section titled “91 — Lab Project 02: Identity Relationship Assessment”Mission
Section titled “Mission”Map:
Users
Groups
Administrative Rights
Service Accounts
Privileged IdentitiesIdentify unnecessary relationships.
Deliverable
Section titled “Deliverable”Identity Privilege Matrix92 — Lab Project 03: Segmentation Assessment
Section titled “92 — Lab Project 03: Segmentation Assessment”Mission
Section titled “Mission”Compare expected and actual connectivity between:
User Zone
Server Zone
Management ZoneDeliverable
Section titled “Deliverable”Network Reachability Matrix93 — Lab Project 04: Active Directory Security Review
Section titled “93 — Lab Project 04: Active Directory Security Review”Review:
Privileged Groups
Delegation
GPO Permissions
Service Accounts
Administrative Separation
Stale IdentitiesDeliverable
Section titled “Deliverable”AD Security Findings Register94 — Lab Project 05: Attack-Path Analysis
Section titled “94 — Lab Project 05: Attack-Path Analysis”Build:
Starting Identity ↓System Relationship ↓Privilege Relationship ↓Sensitive AssetValidate each relationship safely.
Deliverable
Section titled “Deliverable”Enterprise Attack-Path Report95 — Lab Project 06: Detection Validation
Section titled “95 — Lab Project 06: Detection Validation”Coordinate simulated activity with lab monitoring.
Observe:
Windows Logs
Endpoint Telemetry
Authentication Events
Directory Events
Network EventsDeliverable
Section titled “Deliverable”Activity → Telemetry → Detection Matrix96 — Lab Project 07: Enterprise Security Assessment
Section titled “96 — Lab Project 07: Enterprise Security Assessment”Combine:
NETWORK +IDENTITY +WINDOWS +ACTIVE DIRECTORY +SEGMENTATION +SECURITY CONTROLS +ATTACK PATHS +REPORTINGProduce a professional assessment report.
97 — OSEP Preparation Phase 01
Section titled “97 — OSEP Preparation Phase 01”Focus on:
Networking
Windows
PowerShell
Active Directory
Linux
ScriptingYou should already have strong fundamentals before moving deeper.
98 — OSEP Preparation Phase 02
Section titled “98 — OSEP Preparation Phase 02”Focus on:
Enterprise Enumeration
Identity Mapping
Privilege Mapping
Trust Analysis
Segmentation99 — OSEP Preparation Phase 03
Section titled “99 — OSEP Preparation Phase 03”Focus on:
Windows Security
Endpoint Controls
Application Control
Logging
Defender Awareness100 — OSEP Preparation Phase 04
Section titled “100 — OSEP Preparation Phase 04”Focus on:
Attack Paths
Administrative Separation
Hybrid Environments
Service Accounts
Privilege Relationships101 — OSEP Preparation Phase 05
Section titled “101 — OSEP Preparation Phase 05”Focus on:
Adversary Simulation
Evidence
Detection Validation
Reporting
Remediation12-Week OSEP Preparation Framework
Section titled “12-Week OSEP Preparation Framework”Use this as a flexible learning structure rather than an exam guarantee.
Weeks 1–2 — Windows and PowerShell
Section titled “Weeks 1–2 — Windows and PowerShell”Focus on:
Windows Architecture
Users
Groups
Privileges
Services
PowerShell
LoggingWeeks 3–4 — Active Directory
Section titled “Weeks 3–4 — Active Directory”Focus on:
Domains
Users
Groups
Computers
Kerberos
NTLM
LDAP
DNS
Group PolicyWeeks 5–6 — Enterprise Identity
Section titled “Weeks 5–6 — Enterprise Identity”Focus on:
Service Accounts
Delegation
Privileged Access
Administrative Separation
Credential GovernanceWeeks 7–8 — Network and Endpoint Security
Section titled “Weeks 7–8 — Network and Endpoint Security”Focus on:
Segmentation
Firewalling
Endpoint Security
Application Control
MonitoringWeeks 9–10 — Attack-Path Analysis
Section titled “Weeks 9–10 — Attack-Path Analysis”Focus on:
Identity Relationships
Privilege Relationships
Trust Relationships
Enterprise Attack PathsWeek 11 — Full Enterprise Lab
Section titled “Week 11 — Full Enterprise Lab”Perform:
Discovery
Identity Mapping
Control Assessment
Attack-Path Analysis
Evidence CollectionWeek 12 — Simulation and Reporting
Section titled “Week 12 — Simulation and Reporting”Complete:
Timed Assessment
Attack-Path Documentation
Security Findings
Executive Summary
Remediation RoadmapDaily Practice Model
Section titled “Daily Practice Model”Example:
30 MinutesConcept Review
90 MinutesHands-On Lab
30 MinutesAttack-Path Notes
30 MinutesDefensive AnalysisOSEP Readiness Level 01 — Windows
Section titled “OSEP Readiness Level 01 — Windows”You understand:
Users
Groups
Privileges
Processes
Services
PowerShell
Remote Administration
LoggingOSEP Readiness Level 02 — Active Directory
Section titled “OSEP Readiness Level 02 — Active Directory”You understand:
Forest
Domain
Domain Controllers
Users
Groups
Computers
Kerberos
NTLM
LDAP
DNS
GPOOSEP Readiness Level 03 — Enterprise Identity
Section titled “OSEP Readiness Level 03 — Enterprise Identity”You can assess:
Administrative Accounts
Service Accounts
Group Membership
Delegation
Privilege Relationships
Administrative SeparationOSEP Readiness Level 04 — Network Architecture
Section titled “OSEP Readiness Level 04 — Network Architecture”You can map:
Zones
Routes
Services
Trust Boundaries
Segmentation
Management PathsOSEP Readiness Level 05 — Security Controls
Section titled “OSEP Readiness Level 05 — Security Controls”You understand the purpose and visibility of:
Endpoint Protection
EDR
Firewalling
Application Control
PowerShell Logging
Central MonitoringOSEP Readiness Level 06 — Attack Paths
Section titled “OSEP Readiness Level 06 — Attack Paths”You can take:
IDENTITIES +SYSTEMS +PRIVILEGES +NETWORK ACCESS +TRUSTand construct validated:
ATTACK PATHSOSEP Readiness Level 07 — Defender Awareness
Section titled “OSEP Readiness Level 07 — Defender Awareness”For simulated activity you can explain:
What Happened?
What Telemetry Should Exist?
What Could Detect It?
How Should Defenders Investigate?OSEP Readiness Level 08 — Reporting
Section titled “OSEP Readiness Level 08 — Reporting”You can communicate:
Individual Findings
Attack Paths
Business Impact
Control Gaps
Remediation PrioritiesOSEP Readiness Level 09 — Independent Assessment
Section titled “OSEP Readiness Level 09 — Independent Assessment”You can receive an unfamiliar authorized enterprise lab and systematically:
MAP ↓ENUMERATE ↓UNDERSTAND ↓MODEL ↓VALIDATE ↓DOCUMENT ↓REPORTwithout relying on a walkthrough.
Common OSEP Preparation Mistakes
Section titled “Common OSEP Preparation Mistakes”Avoid:
Weak Windows Fundamentals
Weak Active Directory Fundamentals
Thinking Only About Individual Hosts
Ignoring Identity Relationships
Ignoring Network Segmentation
Ignoring Service Accounts
Ignoring Administrative Separation
Treating EDR Only as an Obstacle
Ignoring Defender Telemetry
Ignoring Business Impact
Poor Evidence Collection
Poor Cleanup
Ignoring Reporting
Depending Entirely on Automated Tools
Building Attack Paths Without Validating Each StepOSEP vs OSCP
Section titled “OSEP vs OSCP”Think:
OSCP=Practical Penetration Testing FoundationOSEP expands toward:
COMPLEX ENTERPRISE ENVIRONMENTS +IDENTITY +ACTIVE DIRECTORY +DEFENSE AWARENESS +ATTACK PATHSOSEP vs OSWE
Section titled “OSEP vs OSWE”OSWE=Advanced Application SecurityOSEP=Advanced Enterprise Offensive SecurityA professional may pursue either direction based on specialization.
OSEP vs Red Teaming
Section titled “OSEP vs Red Teaming”OSEP-oriented skills provide a strong technical foundation for red-team work, but professional red teaming also requires:
Engagement Planning
Operational Security
Threat Intelligence
Detection Awareness
Communication
Risk Management
Stakeholder CoordinationCareer Connection
Section titled “Career Connection”OSEP-oriented skills support roles such as:
Senior Penetration Tester
Enterprise Penetration Tester
Offensive Security Engineer
Red Team Operator
Security Consultant
Purple Team Engineer
Adversary Simulation SpecialistInterview Question 01
Section titled “Interview Question 01”What is an enterprise attack path?
An enterprise attack path is a sequence of validated relationships involving identities, systems, privileges, network access, or trust that can allow compromise to progress toward a more sensitive asset.
Interview Question 02
Section titled “Interview Question 02”Why is Active Directory important in enterprise security?
Because it frequently provides centralized:
Identity
Authentication
Authorization
Policy
Administrationfor large portions of the enterprise.
Interview Question 03
Section titled “Interview Question 03”Why is administrative separation important?
It limits the ability of compromise in a lower-trust environment to expose highly privileged administrative identities.
Interview Question 04
Section titled “Interview Question 04”Why is network segmentation important?
Segmentation reduces unnecessary connectivity and can prevent one compromised system from directly reaching higher-value assets.
Interview Question 05
Section titled “Interview Question 05”Why should offensive security engineers understand EDR?
Because understanding defensive telemetry allows them to assess whether security controls provide effective visibility and helps organizations improve detection and response.
40 OSEP Interview and Review Questions
Section titled “40 OSEP Interview and Review Questions”- What is OSEP?
- How does OSEP differ from OSCP?
- What is enterprise penetration testing?
- What is an attack path?
- What is a trust boundary?
- What is Active Directory?
- What is a forest?
- What is a domain?
- What is a domain controller?
- What is Kerberos?
- What is NTLM?
- What is LDAP?
- Why is DNS important to Active Directory?
- What is Group Policy?
- Why are GPO permissions security-sensitive?
- What is delegation?
- What is privilege creep?
- Why are nested groups security-sensitive?
- What is a service account?
- Why should service-account privileges be minimized?
- What is administrative separation?
- What is privilege tiering?
- What is network segmentation?
- What is lateral movement conceptually?
- What is pivoting conceptually?
- What is an EDR?
- What is application control?
- Why is PowerShell logging useful?
- What is operational security?
- What are rules of engagement?
- What is adversary simulation?
- How does a penetration test differ from a red-team exercise?
- What are crown jewels?
- What is a network reachability matrix?
- What is an identity privilege matrix?
- Why should every attack-path transition be validated?
- What is purple teaming?
- Why should reports include business impact?
- What is a remediation choke point?
- What skills make someone job-ready for enterprise offensive security?
OSEP Readiness Checklist
Section titled “OSEP Readiness Checklist”Windows
Section titled “Windows”- Understand Windows users
- Understand groups
- Understand privileges
- Understand access tokens
- Understand services
- Understand PowerShell
- Understand remote administration
- Understand Windows logging
Active Directory
Section titled “Active Directory”- Understand forests
- Understand domains
- Understand domain controllers
- Understand users
- Understand groups
- Understand computers
- Understand Kerberos
- Understand NTLM
- Understand LDAP
- Understand DNS
- Understand GPOs
- Understand delegation
- Understand trusts
Enterprise Identity
Section titled “Enterprise Identity”- Map privileged users
- Map administrative groups
- Review nested membership
- Review service accounts
- Review delegated privilege
- Review administrative separation
- Review credential governance
Network Security
Section titled “Network Security”- Map network zones
- Understand routing
- Understand segmentation
- Build reachability matrices
- Identify management paths
- Identify trust boundaries
Endpoint Security
Section titled “Endpoint Security”- Understand antivirus
- Understand EDR
- Understand host firewalls
- Understand application control
- Understand endpoint telemetry
- Understand PowerShell visibility
Attack-Path Analysis
Section titled “Attack-Path Analysis”- Map identities
- Map systems
- Map privilege
- Map network access
- Map trust
- Validate every relationship
- Identify crown-jewel exposure
- Identify remediation choke points
Professional Operations
Section titled “Professional Operations”- Confirm authorization
- Understand scope
- Follow rules of engagement
- Minimize production risk
- Protect sensitive evidence
- Track artifacts
- Perform cleanup
- Communicate significant events
Reporting
Section titled “Reporting”- Document technical findings
- Document attack paths
- Explain business impact
- Provide evidence
- Recommend remediation
- Prioritize fixes
- Include detection opportunities
- Produce executive summaries
Final OSEP Mental Model
Section titled “Final OSEP Mental Model”Remember:
AUTHORIZED ENTERPRISE ↓UNDERSTAND ARCHITECTURE ↓MAP NETWORK ↓MAP IDENTITIES ↓MAP PRIVILEGES ↓MAP TRUST ↓MAP SECURITY CONTROLS ↓IDENTIFY ATTACK PATH ↓VALIDATE EACH RELATIONSHIP ↓ASSESS BUSINESS IMPACT ↓UNDERSTAND DEFENDER VISIBILITY ↓CAPTURE EVIDENCE ↓CLEAN UP ↓REPORT ↓RECOMMEND CONTROL IMPROVEMENTSThe OSEP mindset is not:
How Many SystemsCan I Compromise?It is:
Which Enterprise Trust RelationshipsCreate Meaningful Security Risk,How Can Those Relationships BeValidated Safely,and Which Controls Would Breakthe Attack Path?The strongest enterprise offensive-security professionals combine:
WINDOWS +ACTIVE DIRECTORY +NETWORKING +IDENTITY SECURITY +PRIVILEGE ANALYSIS +SEGMENTATION +DEFENSE AWARENESS +ATTACK-PATH THINKING +OPERATIONAL DISCIPLINE +REPORTINGWhat’s Next?
Section titled “What’s Next?”➡️ 05 — OSED
Next, you will move from enterprise offensive security into advanced exploit development and low-level security research.
The next stage will focus on:
Computer Architecture ↓Memory Fundamentals ↓C / C++ ↓Assembly Language ↓Registers ↓Stack and Heap ↓Debugging ↓Binary Analysis ↓Memory Corruption ↓Exploit Mitigations ↓Vulnerability Research ↓Exploit DevelopmentThe major transition will be:
OSEP=Understand EnterpriseAttack Pathstoward:
OSED=Understand Vulnerabilitiesat the Binary andMemory Level