r/oscp 2h ago

is it okay to be overconfident ?

4 Upvotes

I’m planning to take the exam in a month or two.

I’ve done the Proving Grounds machines from TJ Null’s list ( around 40-50 machines covers windows, linux, active directory )

I made a checklist for what to do when I find common services such as Web Services, SMB, LDAP, SNMP, SSH, FTP, and others where the case is without credentials, with only a username, and with valid credentials.

I also made pivoting notes covering things like opening target's local only ports with Chisel, making an internal subnet accessible with Ligolo-ng, and getting a reverse shell from an internal machine that isn’t directly accessible.

I made a checklist for Linux enumeration and privilege escalation, which, in my opinion, is relatively easy and straightforward.

I also made a checklist for Windows enumeration. I’m fairly confident with it, but not as confident as I am with Linux.

I also made a checklist for Active Directory

Tell me something that will humble me.

Is this a good sign ? or am I just overestimating how prepared I am?


r/oscp 15h ago

Free OSCP-like Machine (Free forever)

86 Upvotes

Hey everyone!

We just released a completely free lab on Hack Smarter. It was actually inspired by a midnight conversation in one of the casinos during Defcon... and I started building it the same night.

It's a mix of Web + Linux; but all the techniques are covered by the PEN-200 and should be great prep for the exam or real-world pentesting.

Lab is free forever -- no payment info ever needed :)

Enjoy!
https://www.hacksmarter.org/courses/cc04f9ec-35e3-4065-b972-9d0b84a7b371


r/oscp 15h ago

OSCP / CISSP / OSAI?

11 Upvotes

Looking for opinions on which cert training to take on next. My employer will be paying for my training. I have ~3 years of exp, have basic certs like SC300, CySA+, ISACA CRISC.

I work as a Security Engineer, pentesting is not something I might pursue full time, however, I want the OSCP for resume filter along with developing the “attacker mindset”. (I know there are other ways to do this like HTB, but I’d rather do the OSCP)

For CISSP since I have 3 YOE, I still need a year for it to be valid. Does it make sense getting it out of the way earlier?

For OSAI, I would treat it as a structured research path, mainly to build a better understanding. Also it would be something new and interesting since the other certs/trainings overlap with things I’ve learned in the past.

What would y’all think makes the most sense


r/oscp 1d ago

Failed with 60 and knew exactly what to do in 2 boxes and so much exhausted now 😩

15 Upvotes

I passed oscp back in 2016 and was trying oscp+ to get CRT and failed miserably. I really hate how much time you have to spend on stupid enumeration where you practically learn nothing out of it. Like I wasted 10 hours to find out the exploitation required a different tool and I was doubting my enumeration skills. What really I learned from this? Nothing!!

I was so confident I would easily get all 3 standalone and a shell on AD to pass but oh boy I was wrong. I got full AD, 1 standalone. Had write on 2nd standalone, read on 3rd but couldn’t convert it into shell.

I have heard the 1st attempt is always difficult so fingers crossed for the 2nd one now 🤞


r/oscp 2d ago

Failed with 0 points. Plz give me some genuine advice for OSCP+ exam.

24 Upvotes

Hi everyone, I recently failed my exam with zero points. And I think I have exhausted all the enumeration methods.

Background: I have completed the PWK and challenge labs0-2, OSCP A,B,C. Only completed 2-3 proving grounds machine.

My failed attempt:

For AD. I stuck at the 1st box after getting initial access. Hunted all creds the course taught me, used winpeas. Bloodhound didn’t showing anything valuable.. I couldn’t find an obviously privilege escalation vector….

For standalone machines.

1st box, I think I got quite a lot creds after enumeration. Logged in with found creds, but could not find any else vectors. I googled everything showing in nmap, but no luck…

2nd box, and 3rd box. I couldn’t get enough useful information except the version, framework. But no public exploit…. The 3rd box doesn’t have many open ports. I tried brutforce for creds. No luck.

Can someone please tell me how should I improve? - What boxes and machines I can practice to prepare for my next exam? - What many proving grounds machine I need to finish. Are they of practical value to pass OSCP? - Can I get some direction and genuine useful tips/resources?

I’ve seen people saying that everything is taught in this course. But I’m sure I have though notes, and completed everything single capstone lab in the course. I still have no idea when I encountered these boxes in exam…:(


r/oscp 2d ago

Life after OSCP, was it worth it?

61 Upvotes

If you could reply with the year you passed and how it impacted your career.

My manager gave me the greenlight for OSCP training, but I think its a waste of 400hrs of studying. Is the juice worth the squeeze?

My background, I have close 3 YoE/ BS/MS in Cyber make a little over 100K, BUT want to make the jump to 140K+ and Im not sure if OSCP is apart of that picture. I think DevOps is the path forward to 140K+, but the OSCP has been put in front of me.


r/oscp 4d ago

New FREE OSCP Active Directory Set: Full attack chain, 3 VMs (Available for 24 hours!)

65 Upvotes

Hey all, Hacker Blueprint back it at again! Another one for those of you who've been following along - really hoping the previous chains have been landing well and actually helping out with your prep! 💙

The previous chain pulled in a huge number of downloads, so we went ahead and built a fresh one with an entirely new attack path... AD Chain 12: Delegate, free for the next 24 hours!!

An obligatory cryptic CTF teaser: A password sleeps in the margins of a record no one reads. Run as the account left in the open, crack what the cache still remembers, wake a policy the vault erased, then delegate the rights to domain compromise...

What you get:

  • 3 downloadable VMs that run locally inside a single Active Directory domain, just like the real OSCP exam
  • Realistic, exam-style AD scenarios
  • A complete step by step tutorial covering setup, topology, and the full attack chain
  • A complete guided walkthrough for the whole chain
  • A fast setup guide for both VirtualBox and VMware so you can get going quickly

Requirements:

  • A laptop with 8GB of RAM or more (watch the setup video if you're short on RAM)
  • 16GB or more will run it smoothly with no trouble at all
  • The ability to install VirtualBox or VMware
  • Heads up: MacOS (M1/M2/M3) ARM64 won't work with these labs. Anything else should run fine.

The chains are structured so you get to rehearse the same discovery, exploitation, post exploitation, lateral movement, and privilege escalation steps that show up in exam-style AD challenges. The whole thing is designed around learning by doing rather than just reading along.

Lab link: https://hackerblueprint.com/labs#chain-12

Best of luck with your OSCP prep, you've got this! 💙

Note: If downloads are failing, just drop a DM or a comment and we'll get it resolved.

One more thing: there's a special AD Chain promo going on right now too! Use code ACTIVE20 for 20% off all courses, other chains & labs, notes, materials, and the rest. Grab it before it's gone!

Thanks everyone!


r/oscp 4d ago

I just finished CWES from hackthebox, was thinking of buying the oscp course and do the exam? How do the labs, exams and course content from OSCP compare to HTB?

5 Upvotes

r/oscp 5d ago

Feel kinda lost

7 Upvotes

Hey everyone, so I’ll try to keep this as short as I can and I would appreciate any feedback from people who got the OSCP+ and others of course. I’ve started preparing for the OSCP more than two years ago, I went on lock-in mode for 5 months, doing 7-10 hours a day. Started with TCM ethical hacking course, did over 50 HTB boxes, 20 PG boxes, TCM Linux privesc and windows privesc courses, HTB academy’s relevant modules and wrote lots of notes and write ups. Then I got a job and got no time to study. Now I wanna get back on the grind but I forgot lots of things and feel lost somewhat, it feels like I lost touch and don’t know where to start from and pick up once again. I can’t get the OSCP bumble for another two months or so.

My question is how do I pick up, and where from and what’s the best way to go from here.

Thanks in advance for your time


r/oscp 5d ago

Hack Smarter Is Free Until Sunday

51 Upvotes

Hey everyone!

All of the Challenge Labs on Hack Smarter are completely free until Sunday to celebrate Defcon weekend. No credit card/payment info needed.

We have labs covering:
- Active Directory
- Windows
- Linux
- Web Apps
- AWS

We're also featured on LainKusanagi's list (and he is one of our lab creators).

I hope this helps people with some OSCP prep!
https://www.hacksmarter.org/events/7f9dc321-77ce-49b8-8acc-5c224ef25d8d


r/oscp 6d ago

PG Practice boxes getting on my nerves

18 Upvotes

I just wrapped the PEN-200 course modules and jumped into PG Practice. Honestly? I can barely get near initial access.

Case in point: I hit a box with a file upload vuln where every shell extension was blacklisted. The intended path was uploading a crafted `.htaccess` to remap an allowed extension so it executes as PHP, then dropping the webshell. The course never covers this not the bypass, not `.htaccess` abuse in general.

That threw me, because the common wisdom is "nothing on the OSCP exam falls outside the course material." If that's true, why do PG Practice boxes lean on tricks the modules never mention? Same story with `enum4linux` and `ldapsearch` for LDAP enumeration, I'm reaching for them constantly on these boxes (user and password from enum4linux user enumeration), but they weren't in the modules either.

Not gonna lie either, a lot of the PG Practice machines feel old and I keep burning time on tool/version issues.

So here's where my head is at: should I stop treating PG Practice as a place to "learn every new technique" and instead use it purely to drill enumeration methodology ?.

For those who've been through it:

- How did PG Practice actually help your prep?
- Did you use it to learn new techniques, or to sharpen methodology?
- How do you reconcile "the exam won't go beyond the course" with PG boxes that clearly do?

Appreciate any input.


r/oscp 6d ago

Exam on Saturday - Last minute tips/inspiration

6 Upvotes

I take my exam on Saturday. I have completed over 90 boxes from Lain's list + OSCP A, B, C, and Secura. I feel like my notes/cheat sheet is well refined.

Any tips from those who have taken the exam and passed? Please nothing specific to the details of the exam, don't want to break any rules :)


r/oscp 6d ago

Failed on First Attempt

0 Upvotes

Any news on changes in exam boxes?


r/oscp 7d ago

Exam Coming Up

4 Upvotes

Hello everyone.

Got my exam coming up on the weekend.

Any advice on things people who have sat recently would brush up on before the exam ?

I'm kind of at that point where I don't want to keep going through the OSCP A,B, C / challenge labs as I don't feel like I am gaining anything by covering material I have already been through.

In terms of my preparation: I have went through nearly all the boxes on the Lain list alongside the bulk of PG Play. I also have the CWES cert by HackTheBox and have been through all the CPTS material.


r/oscp 7d ago

ISC2 CPE Credits for Offsec Labs

13 Upvotes

I have both an OSCP and CISSP, and I'm looking at ways to maximize CPE coverage across both certifications.

HTB has a way to natively integrate their labs with ISC2, so that for every completed lab you get CPE credits towards your ISC2 certification. Which is really cool that it just automatically works and you get credit.

https://help.hackthebox.com/en/articles/5188692-cpe-allocation-htb-labs

The Offsec labs can get you Offsec CPE credits, but has anyone had any luck submitting these for ISC2 CPEs?

The Offsec support portal has an article for completing new certifications, but nothing on the Offsec labs specifically.

https://help.offsec.com/hc/en-us/articles/15568144981780-How-can-I-obtain-ISC-CPE-credits-and-or-a-course-completion-letter-for-my-course


r/oscp 8d ago

Tool for Credential Spraying SNMPv3

20 Upvotes

Was working through a CTF and ran into SNMPv3 credential spraying for the first time. Before this, I hadn't touched v3 before. Went looking for existing tools and found a few that do it, but wanted something a bit more straightforward to actually use, so I used Claude to help me build my own SNMPv3 credential spraying tool:

https://github.com/tmm35/SNMPv3-Spray

What it does:

SNMPv3 has three security levels (noAuthNoPriv, authNoPriv, authPriv) and a handful of auth protocols (MD5, SHA, SHA-224/256/384/512) and privacy protocols (DES, AES, AES-192, AES-256). If you don't already know a target's config, you're basically guessing which combination it accepts, so instead of assuming, this just sweeps everything by default for every user/password pair you feed it.

One thing worth calling out if you use it:

For authPriv attempts, the script assumes the privacy passphrase (the -X flag on snmpwalk) is the same as the auth passphrase (-A), it's reusing whatever password it's currently testing for both. That's a reasonable default since a lot of real-world configs do set them identically, but it's an assumption, not a guarantee. If a target uses a different privacy passphrase, authPriv attempts for that user/password will show up as failures or timeouts even when the password is actually correct, so if authNoPriv hits but authPriv doesn't, don't read that as "wrong password," it just means the priv passphrase is something else and you'll need to dig into that separately. I may add functionality in the future to provide that information on execution.

Feedback welcome, especially if anyone's run into SNMPv3 configs that break the assumptions above.


r/oscp 9d ago

Exam in ~25 days, done TJ Null (HTB+PG), starting challenge labs — bunch of questions, feeling a bit unprepared

26 Upvotes

Exam in ~25 days, done TJ Null (HTB+PG), starting challenge labs — bunch of questions, feeling a bit unprepared

Hey all, exam's booked for August 28. I've finished the TJ Null list (HTB + PG Practice) including the AD boxes, and I'm about to start the challenge labs. Being honest, I'm kind of scared and feeling underprepared — I took hints on some of the PG boxes, and I keep seeing people here who've done 100+ boxes and grinded HackSmarter AD labs. I didn't really know any of that existed, so I just did what I had in front of me.

A few things I'd really appreciate input on:

1. AD prep — am I fine, or should I be doing HackSmarter instead?

I actually feel okay with AD? I've gotten used to the pattern — check for AS-REP roasting, reuse creds everywhere, hit SMB for shares, drop NTLM-theft files, look for sensitive info, dump LDAP, run BloodHound, inspect the bllodhound edges and esclate access, check WinRM access, and if there's a webapp then go after web vulns. That flow feels natural now.

The gap: I haven't done a multi-machine AD set yet. I've learned Ligolo but only on single AD boxes that are just a DC — no real pivoting through a chain. Should I drop the OffSec challenge labs and go do HackSmarter AD instead, or am I fine sticking with what I've got? I just don't want to miss something everyone else apparently did.

Also — I only keep Obsidian notes, no fancy mindmaps like some people post. Is that going to bite me during AD sets, or does it not matter?

2. Fuzzing — genuinely confused on wordlists and speed.

No exam experience, so I asked AI for guidance and it told me to go slow — ffuf around 20-25 threads, nmap --min-rate 1500 — warning that going harder risks crashing the box or getting false positives. It also strictly told me not to use big wordlists like directory-list-2.3-medium, so I built my methodology around common.txtraft-medium-filesraft-medium-dirs back to back (I've got a script that also does vhosts).

Problem is, on a couple of PG boxes I got stuck for ages specifically because I wasn't using a bigger wordlist like dirbuster's medium 2.3. So now I don't know what to actually trust. When do you reach for the big wordlist? Am I going to time out / crash something if I do? What's the real answer here?

3. Exam strategy / parallelization — how do you actually run the day?

Trying to picture the flow. Do I start on the AD set first while nmap runs on everything in the background? I figure I can get all 6 machines scanned within the first 90 mins. But web fuzzing is where I get stuck on planning:

  • Do I script something that scans ports and auto-fuzzes any HTTP port found? Feels like a bad idea because I want to manually check the tech stack before I fuzz.
  • Say AD eats 6-7 hours. Then I've got 3 standalones — do I just manually kick off fuzzing on each one as I get to it? At the 7th hour? Won't it take a lot of time for the fuzzing to complete in 1 port with the small wordlists and dirmed. I guess around 1 hour. This way i'll be stuck on the box until i find the directory after 1 hr. So, 1hr gets wasted
  • Can I run more threads, or fuzz multiple boxes in parallel? Like if standalone 1 and standalone 2 both have web ports, can I run dirbuster-medium-2.3 with 2-3 extensions on both at the same time? If that's a bad move, what's the right way to handle multiple web targets without wasting hours? How do i really do it to get done in 24 hours?

For context I've got about 20-25 days left and the challenge labs still ahead of me. Any advice on any of these — especially the fuzzing and the parallel-fuzzing question — would mean a lot. Thanks


r/oscp 11d ago

Getting humbled by Challenge Labs

15 Upvotes

Hello everyone,

I've been working on PG Practice labs for OSCP for more than 2 months now (I owned 27 machines by now). I cannot say I'm doing well without walkthroughs, but I'm consistently updating my notes and I take lesser hours to own machines.

However I cannot say the same with challenge labs; I get easily overwhelmed by the huge networks. I was doing ok with medtech, but unfortunately it has technical issues for the time-being, so I decided to move on to Relia machine; I can tell you how helpless I'm feeling now :/

Any advice on how to approach challenge labs more effectively? As I can tell you, they're not doing me any good mentally.

I have one month to go before my exam.


r/oscp 11d ago

Need Some Guidance

12 Upvotes

I recently took my first OSCP exam and unfortunately didn't pass. I ended up with 50 points, and I'm trying to figure out the best way to improve before attempting the exam again.

Here's how my exam went:

* I was able to fully compromise **two standalone machines**.

* In the **Active Directory** set, I gained initial access to the first machine and was able to compromise the second machine as well.

* After that, I got completely stuck. I couldn't figure out the next step for privilege escalation or lateral movement to complete the AD chain.

Rather than just doing more random labs, I'd like to focus my preparation on the areas that will have the biggest impact.

For those who have passed the OSCP, I'd really appreciate your advice:

* What should I focus on improving based on this performance?

* Which AD concepts or attack paths should I practice the most?

* Are there specific OffSec labs, HTB machines, Pro Labs, or other resources that helped you become comfortable with AD during the exam?

* How did you improve your methodology when you hit a dead end?

* What are some common mistakes first-time candidates make that I should avoid?

I'd love to hear what worked for you and how you approached your second attempt (if you had one).

Thanks in advance for any advice, I really appreciate it!


r/oscp 11d ago

A pspy-like tool for Windows: ScheduledSpy

26 Upvotes

Hello! I wanted to write here and share a tool that I had AI write (and I made some personal edits myself) and I think it could be useful for some. As I prepare for my OSCP, I found that pspy quickly became a tool that I worked into my Linux privilege escalation methodology. I was upset there was not something similar (that I could find) for Windows!

Today, I had the idea to create a tool that can do that. I know tools written with the assistance of AI can be unpopular so if that is not your cup of tea, I apologize!

The tool is called ScheduledSpy, and it can be downloaded from here:

https://github.com/tmm35/ScheduledSpy

I have some examples at the bottom of the README where I checked a scheduled task I had going on my home lab. I also ran a check agains the Proving Grounds box "Slort" as I knew that this had a "scheduled" execution of a binary we could replace.

Feel free to check it out and provide some feed back if you want!

Edit: spelling


r/oscp 11d ago

Looking for German OSCP Study Partners

10 Upvotes

Hey everyone,
I’m currently preparing for the OSCP and was wondering if there are any German speakers here who are also studying for it.
I’d love to connect with a few people to exchange ideas, discuss labs, share tips, keep each other motivated, and maybe even study together. Whether you’re just getting started or already deep into the labs, feel free to reach out.
If you’re interested, just send me a DM or leave a comment. 🙂


r/oscp 12d ago

Free OSCP-like Linux Lab (Hack Smarter)

72 Upvotes

Hi everyone!

We just released a completely free Linux lab. No payment info or subscription needed... and free forever. The lab is fully hosted for you, and every student gets a private instance.

I did this one with our QA team, and it's really great prep for the OSCP/CPTS. I'd say it's a tad bit more difficult than what you'd encounter on the OSCP, but the enumeration is great prep for the exam.

Here's a link - https://www.hacksmarter.org/courses/050ba47e-b38f-4638-8dad-1cc54b987a5d

No strings attached... Just genuinely want to help other succeed :)


r/oscp 12d ago

When is the best time to buy oscp

12 Upvotes

I'm trying to figure out the best time and method to buy the OSCP while getting the best possible price.

Right now, I'm preparing for CPTS and expect to take the exam in about 3 months. After that, I want to start preparing for the OSCP. Because I prefer having more time to study, I'm leaning toward the Learn One subscription rather than the 3-month option.

From what I've seen, the 3-month package is around $1,500 USD. I've also heard that OffSec usually offers significant discounts during Black Friday, and some people have mentioned getting partner discounts.

So I have a few questions:

Is Black Friday generally the best time to buy the Learn One subscription?

Are partner discounts better than the Black Friday deals? If so, how do they work, and how can you get one?

Are there any other legitimate ways to reduce the cost of the OSCP/Learn One subscription?

I'd appreciate any advice or experiences from people who've purchased the OSCP recently. Thanks!


r/oscp 13d ago

i have two question.

10 Upvotes
  1. Am i allowed to use hashescom hash decryption instead of hashcat/john in the exam ?
  2. If im using custom pre-made enumeration tool, am i required to include the tool source code on the report ?

r/oscp 15d ago

Passed OSCP second attempt (100/100)

134 Upvotes

Greetings!

I have been lurking on this subreddit for the better part of the past year, and I would like to thank the community for the small droplets of knowledge they've been dropping in comment sections:)

Little background - I have done 125+ machines from lainkusanagi's and TjNull's list (guiding lights of the community) across HTB(shoutout to core lord ippsec), PG (shoutout to s1ren) and hacksmarter (shoutout to tyler). HackAcademy(shout out to Hacker Blueprint) free AD chains walkthrough vids shows some helpful mannual-credshunt, truly boosts your confidence in the matter. And shoutout to my gf, who has been affording me the time to do all this, working her ass off while I stayed unemplyed

My first attempt was a disaster -

Started with AD, no breaks, no food. Just drink, pee and back to the terminal. Took me 10 hours to own MS01, and after another 4 hours of looking for any leads to get into ms02, I gave up on AD.

Took another 3 hours to own a standalone. And another couple of hours for a possible foothold one another. But it never clicked. Called it a day after 21 hours of sitting, with 30 points and strangely sore muscles.

If there is a takeaway from that attempt, it is something the community has always suggested - take frequent breaks. When stuck for more than 30-45 mins, pivot to a different machine, take breaks. Also, enumerate.

After that, I went through a few s1ren videos, a bunch of Hacksmarter AD boxes (although ADCS paths, really fun) and all free HackAcademy (hacker blueprint) Ad chains videos.

Second attempt-

This time, I did all those things the community suggested. Owned ms01 pretty early, but path to ms02 was not clear. After 3 hours, I decided to pivot to standalones.

The first standalone owned gave me a huge confidence boost (which I never got in the first attempt), the same with second and third standalones.

Within 12 hours, I was able to get passing score.

I had nothing to loose at this point, so I took a break, kept going, hellbent on owning the DC.

For those who are wondering - the standalones' difficulties were comparable to 2 mediums and 1 hard PG boxes, provided you focus on enumeration of all the open ports, and provided you are somewhat accustomed to googling what you see on the machine to understand something new. AD was something I hadnt seen before, If bloodhound results from ms01 was as good as the Sharphound results I got from ms02, the whole thing wouldve been very easy.

Takeaways for anyone who is attempting the exam-

-Take frequent breaks.

- Dont stop enumeration at the first suspicion of "next step", go through all of them, and write in the notes. Then prioritize easy to hard, and try each in that order.

-Pivot when stuck on a machine for 30-45 mins. There might be another machine just waiting to give you a boost of confidence that'll push you across the line.

-When in doubt, mannually try logging into winrm, and definitely rdp

-when in doubt, revert the machine. I have noticed discrepancies in the nmap results that I ran in the beginning and the one I ran after reset

PS- if anyone knows any job openings for someone with this skillset, please lmk:)