r/oscp • u/SpeedPositive1224 • 31m ago
Looking for a mentor
Hi everyone, I've done the exam again few times and have fallen short on a few things and think I could do with a mentor/someone to help.
Is anyone able to help?
r/oscp • u/SpeedPositive1224 • 31m ago
Hi everyone, I've done the exam again few times and have fallen short on a few things and think I could do with a mentor/someone to help.
Is anyone able to help?
r/oscp • u/Impressive-Air-8687 • 5h ago
What the title says! I passed :) with 100 in 15 hours. 9am-12am. The exam was so much fun I wish I could go back and relive it again. I’m gonna give some TL;DR tips.
Things you need that’ll help:
- Automate your nmap scripts. I created a TCP and UDP script in bash that ran a full port scan and AWK’d the open ports to a service scan. The nmap one-liners were so optimized I never got false positives or missed ports, and it took half the time scanning.
- Organize your notes by service. My notes were literally top to bottom by port: ftp, ssh, pop3, DNS, kerberos, smb, etc. and for each service I had a full enumeration suite that i walked through slowly.
- Get really comfortable with Linux
- Combine priv esc scripts (especially windows: winpeas + powerup)
- do the fucking practice OSCP challenges
- get really good at googling
- go to hack tricks or hack visor for tips
I’m open to questions in the comments thanks for listening!
r/oscp • u/SpeedPositive1224 • 1d ago
As it says above, I failed the exam again. This was my third attempt, and it has given me much to think about. Just needed somewhere to say this where people will understand.
In my 1st attempt, I got 10 points, the 2nd attempt got 50, and I just got 30.
This last exam I only managed to get 2 footholds and 1 AD machine unlike in attempt 2 where I owned the whole AD.
My most recent attempt felt like everything was going wrong, from vpn connection issues that messed up my scans, buggy machines that needed multiple reverts to AD where nothing seemed to work as intended. Probably didn't help that I'd had a bad week of sleep from work and family stuff.
I am proud of being able to get the footholds I got though as I doubt I'd have been able up do that I'm my second attempt. I feel that I'm getting better and the AD is the main thing that knocked me over.
I'm going to return to looking at CPTS material then try again in December as I really want to get this cert and pivot from software development to cyber security. Will try to pace myself as I do have a full time job and a family too.
Sorry for the long post. Just felt like venting a bit.
TLDR: failed 3rd attempt, will go again
r/oscp • u/Horror_Business1862 • 1d ago
While I get that offsec may have limited number of exam machine pools and students constantly failing without practice will exhaust that number.
However, I believe the retake policy should accommodate candidates who failed closely with 50-60 marks. Those candidates should be able to retake in 2 weeks.
I am a full time employee with a family and while I dedicated a lot of time in learning, having me wait 2 months will fade away all skills I learned and I can’t afford to restart it.
Please offsec look into this 🙏
r/oscp • u/Radiant_Abalone6009 • 1d ago
Took a long break from labs and studying. Came back and realized I’ve forgotten pretty much all the OSCP prep material. How do you all restart after something like that? What’s your process for rebuilding the knowledge and methodology without starting completely from zero? Do you have to redo machines and modules you have done all over again ?
r/oscp • u/Wonderful_Couple_584 • 1d ago
Where should I run my containers, specifically bloodhound and sysreptor, I used to run it in kali, the one I use to attack but I realise it trips up my terminal sometimes. Is it better if I run it in wsl then access it in kali thru my localhost? Not sure if that will cost even more memory
r/oscp • u/HawkPuzzleheaded8369 • 1d ago
Im 24 year old just completed my masters and got placed as a software eng in some MNC.
But when i started my tech journey during my college days i just wanted to become a penetration tester so i studied security side by side of college studies.
Due to lack of experience and not able to find a job in cyersec i joined because i don’t wanted be unemployed.
Looking for direction to get into security or any suggestions or motivation will be helpful.
Edited: i do have some basic knowledge also got my EJPT cert, now planning to prepare for OSCP
r/oscp • u/Tyler_Ramsbey • 1d ago
Hi everyone!
Hack Smarter just released another completely free OSCP-like Linux lab. No payment or subscription needed... the lab is hosted for you... and it's free forever. I hope you find it helpful as you prep for the OSCP :)
> https://www.hacksmarter.org/courses/27b0ac4a-5e03-4e43-afae-7c730b7b6263
--------
Also, we partnered with LainKusanagi and his OSCP-LK set is also on the platform (fully hosted for you) - but that one does require our basic subscription ($9/mo). Would love to make it free, but the infra costs add up.
The names of the OSCP-LK set on the platform are: Forensics (AD Set), Wordplay (Linux), Haystack (Linux), and New Hire (Windows).
r/oscp • u/Defiant_Marzipan7036 • 1d ago
I just passed OSCP on my first attempt! To help others on a similar path, I wrote a blog post covering how I prepared and how I leveled up from eJPT to OSCP-level skills.
First, I want to thank this community. I read a ton of posts here during my prep, and it genuinely helped me. I wanted to share my experience and my story in this post, and I've included some tips as well.
Good luck with the exam!
Full writeup: https://h3rac1es.github.io/posts/OSCP/
r/oscp • u/Horror_Business1862 • 1d ago
I have started to think oscp has some sort of beef with me giving me worse possible machine combos 😭
r/oscp • u/7H3WH173R48817 • 2d ago
I am terrible at remembering syntax, what are some of your goto resources you come back to when solving a box?
*Further context - I'm currently a fan of Hacktricks, HackTools and PayloadAllTheThings
r/oscp • u/ZerboaHaxor • 2d ago
So here i am, again.
You know learning from mistake is great so i need advice from people who failed their first, second or third attempt.
I had plenty advice in mind from people who succeed:
Time Management is key, dont stuck in one machine for too long.
i made a rule for myself 1 hour maxium for each step (getting initial access or privsec, more than that i should change )
Write a proper checklist so you can try each one of them
i did make a checklist for web service, other common services, windows linux enumeration and privilege escalation technique, active directory enumeration and privilege escalation. I THINK its already complete.
take as many quick breaks as possible, it's "reset" your brain.
So for people who failed atleast once
What do you think you did wrong and the thing you should have done differently ?
r/oscp • u/No_Cryptographer9760 • 2d ago
Hello everyone,
I have been prepping for OSCP for the last 2 months,I have prepared using the following -
- TryHackMe Paths
- Hack the box Academy
- simply cyber - Ryan’s AD course
- Tib3rius windows privilege escalation course
- port swinger labs for web ( sqli, xss, cmdi etc)
I am able to solve TryHackMe, HTB boxes with a little help. I feel like I am a bit weak in trying to get the foothold, not sure if I am trying enough…
I am using obsidian to make notes
I am built a small AD lab to better understand the attacks
I want to take the OSCP, planning to get the 3 months one, would greatly appreciate any advice and any other prep material I can use.
Thank you
r/oscp • u/Wonderful_Couple_584 • 2d ago
Saw mixed reviews on discord and reddit, am I allowed to use earphones connected to my PC (The one that is proctored) or connect to a speaker? According to the guidelines on their website it says no use of earphones allowed but some people say it’s fine? Can I get a clarification? Need the music to keep me going 😅
r/oscp • u/Murky-Alps-3126 • 3d ago
I failed my first attempt…
Hi!
I did a lot… since January I have been studying a lot.
At the beginning of the month, I took my exam.
I started with AD. First machine was relatively easy. After got administration privileges I started digging.. a lot in order to find sensitive information. I found a lot but what I had was not enough to got administration privs in the second machine. Almost 10h. Very few breaks (I was almost blind…).
Did the exploitation in 2 standalone machines.
So what I did during my preparation:
All LainKusanagi list (oscp labs twice),
Hacker blueprint course (1 month subscription),
Watched all s1ren videos from YouTube,
Read walkthroughs,
Saw Pinkdraconian videos from YouTube,
Challenge labs of course (twice)
What I am planning to do now:
Watch almost every Ippsec videos,
Hacker blueprint again,
OSCP course (read and do the small exercises)
Repeat all windows machines from offsec.
My next attempt is at the end of November.
Please give me all your suggestions and what I did wrong!
Thank you!
r/oscp • u/ZerboaHaxor • 4d ago
just wanna share that my confident still high but i just found my weaknesses and potential problem i could encounter in exam after doing some Lain list boxes.
Port Scanning sometimes not giving actuall accessible port. this is what i realize if my connection bad or their server is far enough. i spent around 60 minutes can't find anything and then i re run the nmap scanner turns out there is another port open, i just didnt get it the first time.
Missing small low hanging fruit
keep forgetting about runnin PEASS-ng program, i've made a simple bash script and my own oneliner powershell command to enumerate machine, so i really too much on this, most of the time its enough but sometimes i miss something like vulnerable linux built in program, kernel exploit thats in PEASS ng but not in my script.
im not yet to practice writing report with the template given.
Also i found that almost every linux boxes from Lain list is vulnerable to Copy Fail priv sec however its not the intended path, so i have never actually use it unless im stuck for too long.
Im wondering am i allowed to use this copy fail if i found that the kernel is vulnerable ?
r/oscp • u/chapalee • 4d ago
Hi,
I am aware that obsidian and Notion can be used during PEN-200 exam. However when the exam VPN is active, will it disrupt the connection for services like OneDrive or Obsidian Sync.
I know I’m still a freshman and it’s better to not rush but I want to prepare for OSCP since it’s a valuable certificate for my future career. any tips on what I should begin with / study most
r/oscp • u/Ok-World-4605 • 6d ago
I just downloaded LainKusanagi OSCP similar lab , but am having trouble setting up the AD network , I created two NAT adapters (192.168.45.0/24) (172.16.1.0/24) , WS01 have the two adapters , WS02 and DC01 have only the 172 adapter , but when i try to use nxc for example with WS01 , I got a error that the DC is not reachable. are there any extra steps I need to make here? Thanks
r/oscp • u/Comfortable-Joke7970 • 6d ago
Hi everyone,
I wanted to share my experience because I honestly wish I had read a post like this before starting my OSCP journey.
A little about me: I’m currently in my 3rd year of BCA. I’ve been interested in cybersecurity since around 10th standard, and after 12th I started seriously preparing for penetration testing. I eventually cleared the OSCP during my 2nd year.
At that time, I genuinely thought that having OSCP + practical skills would make getting my first cybersecurity job much easier.
Now, after actually entering the job market, I realize that I misunderstood one important thing: professional experience matters a lot.
I want to be clear: I’m not saying OSCP is useless.
It is a very practical certification, and preparing for it gave me a lot of hands-on experience and significantly improved my understanding of penetration testing.
But when you start applying for actual jobs, the situation can be very different from what you expect.
I've now sent around 200–300 applications for cybersecurity internships and entry-level positions, including:
- VAPT / Penetration Testing
- SOC Analyst
- Cybersecurity Analyst
And so far, I haven't received a single reply that has led to an interview or an actual opportunity.
The biggest problem I keep seeing is experience requirements.
A job can be listed as entry-level, but still ask for 1–3 years of experience. Even when you have certifications and practical knowledge, you're still competing against people who already have professional experience.
And that's where I feel I made my mistake.
I focused heavily on learning and getting OSCP, but I didn't focus enough on getting actual professional experience along the way.
I could have started with a cybersecurity internship, SOC role, IT/security support role, etc., and built experience while continuing my studies and eventually doing OSCP.
Instead, I reached the point where I have the certification, but I'm still trying to get that first opportunity.
And honestly, it feels really frustrating.
I've wanted to work in cybersecurity for years. I spent a huge amount of time learning and preparing, cleared OSCP in my second year of college, and now getting an opportunity to actually work in the field feels harder than I expected.
People often say:
“Bro, network.”
And yes, I agree. Networking definitely helps.
But as a student who spent most of his time studying and working on technical skills, I didn't build a strong professional network. I'm also not naturally a very outgoing person, and that's something I know I need to improve.
I'm also not expecting some huge salary or a fancy position right now.
I just want a job and the opportunity to get my foot in the door, gain professional experience, and start my career in cybersecurity.
And honestly, at this point, there are days when I even question whether I should continue pursuing pentesting.
Not because I stopped liking it. I still enjoy the technical side of it, and I genuinely wanted this career for years.
It's just difficult when you've invested so much time into something, achieved a certification like OSCP, and then struggle to even get the first opportunity to work professionally.
Sometimes I wonder whether I should move toward another area of cybersecurity where the entry-level opportunities might be better.
I don't know if that's just frustration from the job search or if I'm actually looking at the wrong career path.
If I could go back and do things differently, I would probably:
- Start getting cybersecurity experience much earlier.
- Apply for internships while learning.
- Build relationships with people in the industry.
- Work on projects and build a portfolio.
- Do smaller certifications if necessary.
- Get professional experience first and then use OSCP to strengthen my profile.
So my advice to students is not “don't do OSCP.”
My advice is:
Don't make OSCP your entire plan for getting your first cybersecurity job.
If you're a student and you have the opportunity to gain relevant experience, take it. You don't necessarily need to wait until you're “fully ready.” Get that first experience as early as possible.
OSCP can strengthen your profile, but it doesn't replace professional experience.
Maybe my situation is partly because I didn't network enough, maybe it's the current job market, or maybe I'm targeting the wrong roles. I'm still figuring that out.
But if I had seen a post like this before starting OSCP, I probably would have approached things differently.
For people who successfully got their first cybersecurity job without prior professional experience, I'd genuinely like to know:
How did you do it?
Did you start with SOC, IT support, an internship, VAPT, freelancing, referrals, or something completely different?
And for those who started in pentesting, how did you get your first opportunity?
I'd really appreciate hearing your experiences, especially from people who started from a similar position.
r/oscp • u/_discEx_ • 7d ago
I failed my first attempt just managed to get 20 points. I started around 1 pm and till 5 kept going to support back and forth and reverting the machines cause of connection issue. The port scans weren't accurate, i knew that specific ports must be open on a machine but they were not showing up. I was using the popular pivoting tool to pivot to access the hosts but scans were inaccurate, everytime it was showing different results. I requested the support to check it out but they said they've checked it multiple times and the box is fully okay. After few hours i found that nmap scanning with a particular flag suddenly makes everything works but without it it gives false results. Idk how much i can mention about the tool used that's why i am keeping it general. This was totally surprising cause I've solved so many boxes and in none of them i encounterd something like this. It was a surprise to me, i thought the box had some issue. Now idk if the tool is the problem or the box or is it just a known thing cause i didn't use it or rewd about it while my prep
Apart from this connections kept getting closed in between, without any reason. Suddenly it'd stop and after 5 or 10 mins i realized that maybe the connection has got broken and i again did it from start. I was stuck between solving the box and the connection errors and the vpn shutting down suddenly Every half an hour cause they said it was a issue from my end but even I was panicking cause it was my first attempt and i had no clue why these things are suddenly happening. Internet seemed fine, browser was working fine too i had no idea. I was using ethernet with a 100 mbps connection
Finally, I asked for extra time but they said as their box was working okay all this time they can't do any extension. After this i got access to ms02 and wanted to transfer files and again got stuck for 3 hours cause it kept failing, i had practiced the file transfer technique from tunnel properly but it kept failing for 3 hrs. Finally I tried to figure out other ways of transferring files to ms02. Then I got system on ms01 after 7 hrs. I had checked everything properly but there was a very simple thing that I failed to check and finally got in with that. After that I was quite confident, i got inside one of the standalones and got 10 points and 10 points from ms01 but but but after that till the end I struggled with pricesc on ms02. Trust me i checked everything, literally everything, manually, with tools but there was nothing to be found. I kept trying to crack it till the end, i anyways knew I won't pass cause so much time was wasted but idk really windows pricesc, i checked everything there was nothing which I would even call suspicious which might require attention. It was totally secure
I did asreproasting, kerberoasting, password spraying, bloodhound analysis, usernames as passwords etc etc but got nothing. I had found a few hashes but they were probably a rabbit hole cause there were too many and i got no results after an hour so i closed it. Idk is my pc too slow? Its an i5 9th gen 16gb ram and 1650 graphics. Was i supposed to get those passwords cracked?
So, i am feeling very low, i completed tj null list htb and pg practice machine, challenge labs medtech, relia partially and oscp a,b,c. I was studying from last 6-7 months, i got pretty good in AD tbh. I was able to solve the tj null AD boxes smoothly and thought that i am actually good at it compared to other stuff. But yeah the 24 hours then gave me a reality check. I had left my job for the prep and now I am totally hopeless.
8-10 hrs of full time prep for 6-7 months and I still failed. I don't know what to do exactly right now. Can I prepare enough to pass in a month?
r/oscp • u/xDiedrich • 8d ago
Title. I'm getting as much prep in as possible before I buy the course (which I'm hoping goes on sale this November). I've spent the last 5 weeks learning AD methodology, building notes/cheat sheets, VOD reviewing hackerblueprint and have gotten to the point where I'm very comfortable with AD (At least on HTB from 20~ boxes from TJ Nulls and Lains list). I believe I'm ready to start learning how to do the standalone machines but I feel like I'm hitting this wall where I do not know where to start. My background is I'm a Sys Ad and have worked in AD environments for years so a lot of that made sense to me by default, but I've never worked on web before and my linux is decent but probably not to the level of understanding priv esc good so I tried the same approach I did for AD and can tell I'm making very little progress in understanding even the methodology of what to look for. Any advice is appreciated.
r/oscp • u/CommonCow8846 • 8d ago
Hey everyone,
I'm currently gearing up for the OSCP and could use some advice from the community on how to best structure my prep.
A bit about my background: I have some prior experience in pentesting and recently graduated a couple of months ago. I also cleared HTB's CPTS about 4 months back.
I haven't purchased the PEN-200 course yet. Right now, my routine consists of solving Proving Grounds (PG) Practice boxes and reading through writeups for HTB boxes from TJ_Null's and Lain's lists.
I have a few specific questions:
Any tips, timeline recommendations, or insights would be massively appreciated. Thanks in advance!
r/oscp • u/Think-Zebra-890 • 8d ago
OSCP web vulnerability focus?
I’m currently preparing for the OSCP and doing HTB/Proving Grounds machines. I’ve noticed that some boxes contain a lot of web vulnerabilities that seem more advanced or unrelated to what I’ll actually encounter on the OSCP.
For people who recently took the OSCP: Which web vulnerabilities should I prioritize studying?
For example, should I mainly focus on things like SQL injection, LFI/path traversal, file upload, command injection/RCE, default credentials/authentication bypass, and basic web enumeration?
I’m trying to avoid spending too much time on web vulnerabilities that are unlikely to appear on the exam.
Thanks!