1 Quick Overview
The OSCP is the most respected penetration testing certification in the industry. Unlike multiple-choice exams, you spend 24 hours hacking into actual machines and then write a professional pentest report.
It's hard. It's expensive. It will make you question your life choices at 3am. But it's worth it-employers actively seek OSCP holders, and it genuinely makes you a better pentester.
2025 Updates: The OSCP+ now requires completing the Active Directory set (40 points) to pass-no more skipping AD! Bonus points have been eliminated, and certifications are valid for 3 years. Start with eJPT or PNPT if you're not ready.
The Good
- ✓ Gold standard-instantly recognized by employers
- ✓ Proves you can actually hack, not just pass tests
- ✓ Huge community support and resources
- ✓ Forces proper methodology and documentation
- ✓ Opens doors to senior pentest roles
The Tough
- ✗ Expensive-Learn One subscription at $2,749/year
- ✗ 3-6 months of serious study required
- ✗ Brutal 24-hour exam is mentally exhausting
- ✗ ~60% fail rate on first attempt
- ✗ Report writing adds another 24 hours
💡 Bottom Line: If you want to be a pentester, get your OSCP+. If you're just collecting certs, save your money.
2 What is OSCP+?
The OffSec Certified Professional (OSCP+) is the industry's most respected hands-on penetration testing certification. It's earned through the PEN-200 course: "Penetration Testing with Kali Linux." The "+" signifies OffSec's 2024 updated curriculum with enhanced Active Directory coverage and modern attack techniques.
What makes OSCP+ special is the practical exam format. You don't memorize answers-you demonstrate skills by actually compromising machines in a controlled environment. The certification validates that you can:
The course includes 90+ days of lab access (depending on package), extensive course materials, and the certification exam attempt.
3 Exam Details
23h 45min
Hacking Time
24 hours
Report Writing
70 Points
To Pass
Exam Structure (2024 Format)
Active Directory Set
40 pointsFull AD chain: 2 clients + 1 DC. All or nothing.
Standalone Machine 1
20 points10 pts user + 10 pts root
Standalone Machine 2
20 points10 pts user + 10 pts root
Standalone Machine 3
20 points10 pts user + 10 pts root
🎁 Bonus Points (Up to 10)
Complete 80% of PEN-200 course exercises AND 30 lab machines with documented writeups = 10 bonus points. This can save your exam!
Ways to Pass (70+ points)
✓ Safest Path
AD set (40) + 2 standalones (40) = 80 pts
✓ With Bonus
AD set (40) + 1 standalone (20) + bonus (10) = 70
⚠️ Risky Path
3 standalones (60) + bonus (10) = 70 pts
✗ Not Enough
AD (40) + user flags (30) = 70 (need root!)
4 Prerequisites
OffSec has no official prerequisites, but you'll struggle without these foundations. Be honest with yourself.
Navigation, permissions, piping, bash scripting basics
TCP/IP, ports, protocols, subnetting, firewalls
Python or Bash-enough to modify exploits
HTTP, requests, basic SQLi/XSS concepts
CMD/PowerShell, services, Active Directory concepts
20-30 boxes on TryHackMe/HackTheBox
🤔 Am I Ready?
If you can answer YES to these, you're ready to start:
- I can navigate Linux without googling every command
- I understand what an IP address and port number mean
- I can read and modify basic Python/Bash scripts
- I've completed at least 10-20 beginner CTF boxes
5 Recommended Study Path
Pre-Course Prep
2-4 weeks- • Complete TryHackMe "Offensive Pentesting" path
- • Watch IppSec videos to understand methodology
- • Get comfortable with Kali Linux
- • Do 10-15 easy HackTheBox machines
Course Materials
4-6 weeks- • Read ALL the PDF-don't skim it
- • Watch ALL the videos
- • Complete 80%+ exercises for bonus points
- • Take detailed notes you can reference later
Lab Grinding
6-10 weeks- • Root 40+ machines in the PEN-200 labs
- • Document 30+ machines for bonus points
- • Focus on AD labs-critical for exam
- • Supplement with Proving Grounds Practice
Exam Prep
1-2 weeks- • Review your notes and cheatsheets
- • Do practice exams (mock exams exist)
- • Prepare your report template
- • Rest well the week before-you'll need it
Total: 3-6 months
Depending on prior experience and study time available
6 Notes & Cheatsheets
CyberCert Reviews Cheatsheets
Free, comprehensive cheatsheets created by our community of certified professionals.
OSCP Essentials
-
Scanning & Enumeration
Nmap, Masscan, service enumeration
-
HTTP & Web Attacks
Directory busting, SQLi, LFI, RCE
-
SMB Enumeration
Shares, users, null sessions
-
Linux Privilege Escalation
SUID, sudo, cron, capabilities, kernel
-
Windows Privilege Escalation
Services, tokens, UAC, potato attacks
-
Active Directory AttacksMANDATORY
Kerberoasting, AS-REP, DCSync, lateral movement
📋 Quick Reference: Enumeration Starter
nmap -sC -sV -oA initial $IP
# Full port scan
nmap -p- --min-rate 1000 -oA allports $IP
# Web directory enumeration
gobuster dir -u http://$IP -w /usr/share/wordlists/dirb/common.txt
# SMB enumeration
smbclient -L //$IP -N
7 Recommended Resources
Practice Platforms
-
Proving GroundsEssential
OffSec's own practice-closest to exam
-
HackTheBoxGreat
Retired boxes: Shocker, Lame, Optimum, etc.
-
TryHackMeGood Start
Offensive Pentesting path
-
VulnHubOptional
Free downloadable VMs
Videos & Guides
-
IppSec (YouTube)Must Watch
Best HTB walkthroughs, learn methodology
-
TCM SecurityGreat
Privilege escalation courses
-
HackTricksEssential
Free online reference wiki
-
PayloadsAllTheThingsBookmark It
GitHub payload reference
8 Exam Day Tips
Before the Exam
During the Exam
Time Management Strategy
Hours 1-6
AD set focus
Hours 6-12
Standalone #1 & #2
Hours 12-18
Sleep + #3
Hours 18-24
Cleanup & verify
Advanced Strategies (Community Insights)
Build a Comprehensive Checklist
Create a reference document containing:
- • Advanced nmap/autorecon commands you've refined
- • Service-specific tools (feroxbuster for HTTP, smbmap for SMB, snmpbulkwalk)
- • Data staging methods (Python uploadserver, impacket-smbserver)
- • Every privesc technique and tool you've used in labs
Machine Rotation Strategy
Don't tunnel vision. If stuck for 30+ minutes, rotate to another machine. Many successful candidates report returning to a machine fresh and solving it quickly. A fresh perspective often reveals what you missed.
AD Partial Credit System
AD machines award points separately: 10 + 10 + 20 = 40 points. You don't need to complete the entire chain-partial credit creates multiple passing paths. Focus on what you can get rather than all-or-nothing thinking.
The Golden Rule: Enumerate to Death
Most exam failures come from user error, not difficulty. Before assuming you're stuck, run enumeration again. Check every port, every service, every potential attack vector. Comprehensive reconnaissance prevents wasted hours on red herrings.
Lab Priority Order
Focus on OSCP Challenge Labs (A, B, C) before external resources like HackTheBox. These directly mirror exam difficulty and reveal methodology gaps. For HTB, stick to "Easy" machines on TJ Null's PWK list-they align closest with exam difficulty.
Essential Tools Quick Reference
Pivoting & AD
- • Ligolo-ng - AD environment pivoting
- • BloodHound - AD attack path visualization
- • LDAPDomainDump - Quick AD enumeration
- • Impacket tools - psexec, wmiexec, secretsdump
Shell Access
- • evil-winrm - Windows shell with upload/download
- • powercat - Upgrade from plain nc on Windows
- • Kerberoasting/ASREPRoasting - Credential attacks
- • LinPEAS/WinPEAS - Privilege escalation discovery
9 Community Discussions
Real experiences from thousands of OSCP candidates. We aggregate discussions from the best security communities-no fake reviews here.
50k+ members sharing experiences & tips
Official community with study groups
Mastodon for security pros
Live pass announcements & tips
Common Themes from the Community
Share your OSCP+ journey and help others
Join Our Discord Community →Community Mentors
These OSCP+ holders volunteer their time to help others on their journey. They're not paid-they just love giving back to the community.
10 Current Deals 🔥
Learn One Annual Subscription
365-day access to PEN-200 + all Learn One courses + 2 exam attempts
Includes: OSCP+, plus access to 9+ other courses
OffSec Subscription Plans (2026)
| Plan | Courses | Exam Attempts | Price/Year |
|---|---|---|---|
| Learn Fundamentals | Intro courses | - | $799 |
| Learn One ⭐ | PEN-200 + 9 courses | 2 | $2,749 |
| Learn Unlimited | All OffSec courses | Unlimited | $5,499 |
| Exam Retake Only | - | 1 | $249 |
| 90-Day Bundle 🎯 | PEN-200 only | 1 | $1,499* |
🎯 90-Day Course + Cert Bundle
90 days of lab access + 1 exam attempt. Best for focused study.
* Affiliate disclosure: We may earn a commission at no extra cost to you.
12 FAQ
Is OSCP+ worth it in 2026?
Yes, if you want to work in penetration testing. It's still the most recognized practical pentesting cert and is often listed as a requirement or preference in job postings. However, if you're just starting out, consider eJPT or Security+ first.
How long should I study before attempting the exam?
Most successful candidates study 3-6 months. If you have prior CTF experience, you might be ready sooner. If you're completely new to pentesting, budget 6+ months. The key metric is machines rooted-aim for 50+ before your first attempt.
Can I use Metasploit on the exam?
Yes, but only on ONE machine. Choose wisely. Most people save it for a standalone machine if they're stuck. For AD, you'll want manual techniques anyway.
What if I fail? How much is a retake?
Exam retakes are $249. There's a cooldown period: 6 weeks after first fail, 8 weeks after second, 12 weeks after third. Many people fail their first attempt-it's not the end of the world. Learn from it.
Does OSCP+ expire?
OSCP+ is valid for 3 years. To maintain it, you need to earn CPE credits through continuing education, or retake the exam. The OffSec platform tracks your CPE progress.