Index
[!WARNING] Educational & authorized use only. Offensive techniques are explained conceptually for understanding, methodology, and defense — no weaponized step-by-step playbooks or exploit code. Use them only against systems you own or are explicitly authorized in writing to test. See the CEH hub's legal & ethics.
[!NOTE] Unofficial & no fabrication. Not affiliated with or endorsed by OffSec. Exam specifics are from OffSec's PEN-200 page and OSCP+ exam guide; volatile items (price, exact structure, CPE/validity) should be re-checked there. Compiled 2026-06-21.
📋 At a glance¶
| Item | Detail |
|---|---|
| Provider / course | OffSec · PEN-200 (Penetration Testing with Kali Linux) |
| Exam | 24-hour proctored hands-on + ~24-hour report window |
| Scoring | 100 points, 70 to pass · AD set (3 machines) = 40 · 3 standalone = 60 · no bonus (since 1 Nov 2024) |
| OSCP vs OSCP+ | OSCP doesn't expire; OSCP+ (current AD-inclusive exam) expires 3 years, maintained via CPE (verify) |
| Style | Fully hands-on — "Try Harder" |
Full details: exam structure.
📦 What's inside¶
| Section | Contents |
|---|---|
| Overview | What is OSCP · Exam structure |
| Skill areas | The PEN-200 practical skills (not official "domains") |
| Exam prep | Study plan — methodology, practice, the report |
The skill areas¶
| # | Skill | Page |
|---|---|---|
| 1 | Enumeration & information gathering | 01-enumeration-and-information-gathering.md |
| 2 | Web application attacks | 02-web-application-attacks.md |
| 3 | Password & client-side attacks | 03-password-and-client-side-attacks.md |
| 4 | Privilege escalation (Linux & Windows) | 04-privilege-escalation.md |
| 5 | Active Directory attacks | 05-active-directory-attacks.md |
| 6 | Pivoting & tunneling | 06-pivoting-and-tunneling.md |
🧭 Where it fits¶
OSCP is the hands-on depth milestone on the offensive track:
- After the breadth of CEH / PenTest+ and often the practical PNPT.
- Defender's mirror → the AD-attack and privilege-escalation focus is exactly what the attack → defense matrix and WALLIX / PAM hub defend against — strong attacker context for PAM practitioners.
🔗 Quick links¶
OSCP, OSCP+, OffSec and PEN-200 are trademarks of OffSec, used here for identification and educational purposes only.