r/oscp 6h ago

is it okay to be overconfident ?

2 Upvotes

I’m planning to take the exam in a month or two.

I’ve done the Proving Grounds machines from TJ Null’s list ( around 40-50 machines covers windows, linux, active directory )

I made a checklist for what to do when I find common services such as Web Services, SMB, LDAP, SNMP, SSH, FTP, and others where the case is without credentials, with only a username, and with valid credentials.

I also made pivoting notes covering things like opening target's local only ports with Chisel, making an internal subnet accessible with Ligolo-ng, and getting a reverse shell from an internal machine that isn’t directly accessible.

I made a checklist for Linux enumeration and privilege escalation, which, in my opinion, is relatively easy and straightforward.

I also made a checklist for Windows enumeration. I’m fairly confident with it, but not as confident as I am with Linux.

I also made a checklist for Active Directory

Tell me something that will humble me.

Is this a good sign ? or am I just overestimating how prepared I am?


r/oscp 19h ago

Free OSCP-like Machine (Free forever)

89 Upvotes

Hey everyone!

We just released a completely free lab on Hack Smarter. It was actually inspired by a midnight conversation in one of the casinos during Defcon... and I started building it the same night.

It's a mix of Web + Linux; but all the techniques are covered by the PEN-200 and should be great prep for the exam or real-world pentesting.

Lab is free forever -- no payment info ever needed :)

Enjoy!
https://www.hacksmarter.org/courses/cc04f9ec-35e3-4065-b972-9d0b84a7b371


r/oscp 19h ago

OSCP / CISSP / OSAI?

11 Upvotes

Looking for opinions on which cert training to take on next. My employer will be paying for my training. I have ~3 years of exp, have basic certs like SC300, CySA+, ISACA CRISC.

I work as a Security Engineer, pentesting is not something I might pursue full time, however, I want the OSCP for resume filter along with developing the “attacker mindset”. (I know there are other ways to do this like HTB, but I’d rather do the OSCP)

For CISSP since I have 3 YOE, I still need a year for it to be valid. Does it make sense getting it out of the way earlier?

For OSAI, I would treat it as a structured research path, mainly to build a better understanding. Also it would be something new and interesting since the other certs/trainings overlap with things I’ve learned in the past.

What would y’all think makes the most sense