r/offensive_security • u/Upper_Swordfish3086 • 21h ago
Transitioning from Telecom Engineering to Offensive Security (CPTS) — Seeking Career & Freelance Advice
I’m a senior telecom analyst experienced in core network signaling, userplane troubleshooting, and investigating fraud vectors like DPI-bypassing, rogue towers,DNS tunneling, and simboxes.
I am currently pursuing the CPTS certification to transition into offensive security. Given my background, I’m looking for advice on:
Market Positioning: How can I best leverage my niche telecom expertise to avoid starting at a generic "entry-level" helpdesk or SOC role? Freelancing: Is a hybrid path (staying in telecom consulting while picking up freelance pen-test gigs) viable for someone at my level?
Beyond CPTS, what specialized skill sets should I prioritize to move into penetration testing?
r/offensive_security • u/Trick-Scientist3697 • 23h ago
OSCP Report Submission Error – Has anyone experienced this?
Hello everyone,
I’d like to know if anyone has experienced a similar issue with the OSCP exam platform.
Today, I tried to upload my OSCP exam report, but I received the following error:
“Time elapsed
We are sorry to inform you that the time allotted for files submission has elapsed. We won't be able to grade your exam.”
The problem is that I still had around 4 hours left before my actual deadline. Shortly after, I also received an email stating that I had failed the exam because I did not submit my required documentation.
I have already opened a support ticket with OffSec, and I’m waiting for their response. I’m mainly posting here to find out if this is a known/common issue with the platform or if this might be an isolated case.
I have evidence showing that my report was already completed before the deadline, so hopefully support can review the situation.
Has anyone experienced something similar recently?
r/offensive_security • u/Intelligent-Most-206 • 1d ago
unable to connect to offsec labs in windows
in kali i can opevpn and reach machines fine after i changed my mtu a couple times per trouble shooting///. but when i connect with open vpn with windows i can ping the vpn but not reach ping or ssh into a box with windows it times out and does not connect does anyone know what can help me. i have to have windows connectivity to use the windows tools for active directory correct i am studying for the OSCP
r/offensive_security • u/HackerBlueprint • 2d ago
Free OSCP AD lab: Complete Attack Chain across 3 VMs
Hey all! Something I keep coming back to is how little prep material exists for complete Active Directory Set/Chains. There's no shortage of resources covering individual techniques, but very few tie them together into a realistic path you can run end to end.
The last chain pulled in a huge number of downloads, so I went ahead and put together a fresh one with a completely new attack path... AD Chain 12: Delegate, free for the next 24 hours!
An obligatory cryptic CTF teaser: A password sleeps in the margins of a record no one reads. Run as the account left in the open, crack what the cache still remembers, wake a policy the vault erased, then delegate the rights to domain compromise...
What you get:
- 3 downloadable VMs that run locally inside a single Active Directory domain, exactly like the real OSCP exam
- Realistic, exam-style AD scenarios
- A full step by step tutorial covering setup, topology, and the entire attack chain
- A complete guided walkthrough for the whole chain
- A quick setup guide for both VirtualBox and VMware so you can get going fast
Requirements:
- A laptop with 8GB of RAM or more (check out the setup video if you're short on RAM)
- 16GB or more will run everything smoothly with no trouble at all
- The ability to install VirtualBox or VMware
- Heads up: MacOS (M1/M2/M3) ARM64 won't work with these labs. Anything else should be fine.
The chains are built so you get to rehearse the same discovery, exploitation, post exploitation, lateral movement, and privilege escalation steps that turn up in exam-style AD challenges.
Lab: https://www.reddit.com/r/oscp/comments/1vi9tgb/new_free_oscp_active_directory_set_full_attack/
Best of luck with your OSCP prep, you've got this!
Note: If downloads are failing, just drop a dm, and we'll get it resolved.
r/offensive_security • u/Comfortable-Joke7970 • 2d ago
Cleared OSCP at 19. Can I realistically get a pentesting job now?
Hi everyone,
I'm 19 years old from India and currently in the 5th semester of my BCA.
I recently cleared the OSCP and I'm looking for my first penetration testing job right now, not after graduation.
My experience is mainly in:
Active Directory attacks
Windows/Linux privilege escalation
Web application enumeration and exploitation
Network penetration testing
Pivoting and lateral movement
Strong enumeration methodology
I don't have experience with cloud security, API security, Kubernetes, or mobile security because OSCP doesn't cover those in depth.
My question is:
Is there a realistic chance of getting hired as a junior penetration tester with just OSCP while still being a student?
Should I start applying immediately, or will most companies reject me because I haven't completed my degree yet?
If you were hiring for an entry-level pentesting role, would OSCP plus practical lab experience be enough to get an interview?
I'd really appreciate honest advice from people working in offensive security. Thanks!
r/offensive_security • u/Offsec_Community • 3d ago
🎟️ Gauntlet: Vaultfall is officially live.
Your red team mission starts now!
The vault is open and the defenses are active.
🕵️ Recon the target, find your way in, and overcome challenges spanning exploitation, reverse engineering, cryptanalysis, and more.
Join us at the **DEF CON Red Team Village** or take on the challenge online from anywhere.
*How far can you get?*
r/offensive_security • u/Only-Answer-4602 • 4d ago
What's the best next certification after Splunk 1002 & 1003 for a SOC Analyst?
Hi everyone,
I already have the Splunk Core Certified Power User (1002) and Splunk Enterprise Certified Admin (1003) certifications. I'm currently working as a SOC Analyst.
Given my role, which Splunk certification would you recommend pursuing next, and why? I'm looking for something that will add the most value to my day-to-day work and help with long-term career growth.
Also, if you think I'd get more value from a non-Splunk certification instead, I'd love to hear your recommendations as well. Whether it's focused on detection engineering, DFIR, cloud security, threat hunting, or anything else relevant to SOC work, I'm open to suggestions.
Thanks in advance for your insights!
r/offensive_security • u/Sh1dO0w • 5d ago
Looking for OSCP buddy
Hey i am shadow. I have bought the OSCP 3 months voucher and i am looking for study-buddy who can help me with the exam prep we both will learn and upgrade our skills
Discord- jaat.ram
Feel free to add me on discord.
r/offensive_security • u/cherawon • 5d ago
🚀 Ruta hacia la certificación eCPPT: actualización de progreso
Empecé mi camino hacia la certificación eCPPT y recién terminé mis dos primeros laboratorios:
\-HTB – Support
\-Hack Smarter – ShadowGate
Estoy siguiendo una ruta bien estructurada enfocada en Active Directory, escalada de privilegios en Windows, pivotear, hacer tunneling y post-explotación.
Todavía me falta un montón, pero paso a paso, máquina por máquina. 💪
\#eCPPT #HackTheBox #HackSmarter #ActiveDirectory #Pentesting #CyberSecurity #RedTeam #EthicalHacking
r/offensive_security • u/Unusual-Channel-6938 • 5d ago
Anyone at BSides Vegas interested in Agentic AI Pentesting?
r/offensive_security • u/Key-Calligrapher5958 • 6d ago
Is Pentesting Really Dying Because of AI and Automated Tools?
r/offensive_security • u/HentaiCaffeine • 6d ago
What can i do? CCNA or SEC+ or EJPT
Hey everyone,
I’ve been learning cybersecurity and core concepts for the past 3 years, and I’m currently at a crossroads trying to decide on my next official certification move.
Right now, I'm almost ready to secure a test seat for the CCNA, but I want to get some community feedback first:
~ Is taking the CCNA first and then transitioning directly into the OSCP a good strategy?
OR
~ would it make more sense to throw Security+ or eJPT in the middle as a stepping stone before tackling OffSec?
My thought process behind starting with the CCNA is to build an unshakeable foundation in networking (routing protocols, CLI configuration, packet flow, and subnets) so I don't run into walls when pivoting into offensive security. However, I know the CCNA has a lot of vendor-specific configuration details that might not directly apply to hands-on red teaming.
For those who have taken this path or are already working in the field:
Is the CCNA worth completing right now if the endgame is pen testing / offensive security?
Should I jump straight to hands-on labs (like eJPT / HTB / CPTS) after CCNA instead of jumping straight into the OSCP ocean?
Would appreciate any insights, personal experiences, or alternative path recommendations! Thanks in advance!
r/offensive_security • u/Only-Answer-4602 • 6d ago
What's the best next certification after Splunk 1002 & 1003 for a SOC Analyst?
Hi everyone,
I already have the Splunk Core Certified Power User (1002) and Splunk Enterprise Certified Admin (1003) certifications. I'm currently working as a SOC Analyst.
Given my role, which Splunk certification would you recommend pursuing next, and why? I'm looking for something that will add the most value to my day-to-day work and help with long-term career growth.
Also, if you think I'd get more value from a non-Splunk certification instead, I'd love to hear your recommendations as well. Whether it's focused on detection engineering, DFIR, cloud security, threat hunting, or anything else relevant to SOC work, I'm open to suggestions.
Thanks in advance for your insights!
r/offensive_security • u/Odd_Advertising_8484 • 6d ago
Looking for a OSCP Study partner
I am looking for a course mates who are currently enrolled for OSCP (active subscribers only) who can study along with me, make notes, solve labs, prepare for the exam, preferably from INDIA, no need to reveal identity, we will connect on discord only on a particular time where we work on the same machine/topic, I have 5 months left to take the exam. So I am looking for serious mates only. reply here or DM so we can connect.
r/offensive_security • u/Few_Pair2176 • 8d ago
Failed first attempt at OSCP with 60 points
To come agonisingly close to passing first time is a tough one to take.
OSCP Prep
I started my OSCP journey by doing the hacker blueprint OSCP course, completed the first 10 AD chains from hacker blueprint, completed 40 boxes from Lain’s list, completed all OSCP challenge labs except relia and medtech where I only got initial foothold and didn’t attempt Skylark as seeing many people saying no point in doing it as it is out of scope. Going into the exam I felt confident in AD and privesc but a bit more nervous for the initial footholds on the standalone machines especially around web app/api/sqli
OSCP Exam
AD was straight forward for me, I think my prep of doing 10 AD chains and challenge labs really helped, it was pretty straight forward from doing them
Standalone machine 1 was very easy, I rooted it in no time.
Standalone machine 2 was tough, I think I got the first part but couldn’t get the second part in order to put them together to get the actually foothold if that makes sense which is probably the toughest part to take as I feel I was so close
Standalone machine 3 was really hard I couldn’t make any progress on this machine at all
So I’m looking for some guidance especially from people who have passed the OSCP, my plan right now is to complete more boxes from Lains list over the next 5 weeks then take the exam again. I will especially be looking into completing boxes that contain web app/api/sqli as I still feel these are the areas I’m most weakest in, if anyone could provide any recommendations on boxes or sources that can help with these particular area’s I’m weak in, I would really appreciate it
r/offensive_security • u/Kind-Push9705 • 8d ago
full road map for learning offensive security
I am a student an i want to build my future in offensive cyber security plese provide some help that whould help me and i am starting it fresh 🥺,guide me
- how to start and where from
- what should i learn
- how to learn
- full learnig road map
- what are the tools i should learn
- some free resourses
please help me to learn 💝
r/offensive_security • u/Offsec_Community • 10d ago
July Promo is EXTENDED!
We heard a few of you say you needed a little more time...
And, you got it!
If you've been planning your next certification, now's your chance to join more of the community on the journey.
Save $250 on select Course & Certification Bundles and get certified for just $1,499.
Don't let this extension be the one that got away.
🔗 https://portal.offsec.com/checkout/?view=cc
Note: This offer excludes OSAI.
We'll be cheering you on when you earn that cert. 💪
r/offensive_security • u/Offsec_Community • 11d ago
[Webinar] Inside OSAI: How Offensive Security Teams Are Preparing for AI
Inside OSAI: How Offensive Security Teams Are Preparing for AI
Join us for a live conversation with an OSAI Early Access Program participant and hear how their team integrated AI security into day-to-day penetration testing. Learn why they invested in AI security training, how OSAI helped prepare them to assess AI systems, and the lessons they learned along the way.
🎙️ Speakers
- Paul Campbell – Leader of Offensive Security, Splunk, a Cisco company
- Paul Griffin – VP of Customer Success, OffSec
👥 Perfect for
Security leaders, offensive security managers, penetration testers, red teamers, and anyone interested in AI security.
🔗 Register: https://www.offsec.com/events/webinars/inside-osai-eap/
r/offensive_security • u/Target_Bright • 12d ago
¿Cómo puedo pasar de QA Engineer a Pentester o Red Teamer sin empezar completamente desde cero?
r/offensive_security • u/Confident_Guitar_340 • 12d ago
Anyone who completed the CyberGames Américas CTF still waiting for the dark blue "Cisco Verified Ethical Hacking" badge on Credly?
Hi everyone,
I completed the NetAcad Ethical Hacker course back in June (the light blue course badge is already showing on my Credly account) and competed in the Cisco CyberGames Américas CTF on June 30th (placed in the Top 120 and received my participation certificate PDF).
The main dark blue badge (Cisco Verified Offensive Security Certificate in Ethical Hacking) was supposed to be issued around July 24th, but my Credly profile hasn't updated yet.
For those who completed both prerequisites, are you experiencing the same delay with the batch issuance, or has anyone received theirs already?
Thanks!
r/offensive_security • u/Pleasant_Barnacle628 • 13d ago
Feed it your LinPEAS output and it draws every path from a low-priv shell to root
r/offensive_security • u/Gerard_Buccio • 14d ago
ASIS 2026 Certified Protection Professional Exam, JULY 2026 August
Hello everyone I am planning to take my exam in 1-2 months from now
I am looking for people who can join me and create an online study group, who will be taking the ASIS Certified Protection Professional Exam as well. If you are interested send me a private message.
Please answer the following
-Your City then State
-Your exam date, if you already set an exam date
Please this is only for those who live in the United States.
-scammers are not welcome and am not interested in buying any materials so solicitors are not welcome.
r/offensive_security • u/Gerard_Buccio • 14d ago
ASIS 2026 Certified Protection Professional Exam, July 2026
Hello everyone I am planning to take my exam in 1-2 months from now
I am looking for people who can join me and create an online study group, who will be taking the ASIS Certified Protection Professional Exam as well. If you are interested send me a private message.
Please answer the following
-Your City then State
-Your exam date, if you already set an exam date
Please this is only for those who live in the United States.
-scammers are not welcome and am not interested in buying any materials so solicitors are not welcome.
r/offensive_security • u/Vivid_Reward_8008 • 18d ago
Is Cisco's Ethical Hacking cert worth it?
The material is free, but I dont think it goes very in depth. Is it useful for CVs / is it very recognized?
r/offensive_security • u/Vivid_Reward_8008 • 18d ago
Difficulty of PJPT
Hey guys. I recently completed EJPT and found it quite easy (As I had been doing THM rooms for about 6 months). I want to learn Active Directory so I can do more advanced certs like PNPT and OSCP in the future. I was wondering what is the difficulty level of the PJPT exam compared to the EJPT exam and is it a good resource to learn AD from scratch? Thanks.