OSCP Offensive Security: The Real Roadmap from Someone Who Passed
24-hour practical exam, no multiple choice, no mercy. Honest OSCP prep roadmap from someone who failed once and passed the second time.
OSCP humbled me. I failed my first attempt at 65 points - 5 short of passing. The second attempt I passed with 100 points and a 40-page report. Nothing about OSCP is easy, but every hour of prep pays off with a job offer that's 30–60% higher than CEH-holder equivalents. Here's what I wish someone had told me before I started PWK.
§What OSCP actually is
Offensive Security's flagship penetration testing cert. 24-hour hands-on practical exam followed by a 24-hour report writing window. No multiple choice. You compromise 5–6 machines in a private lab and must submit a professional pentest report. Pass mark: 70 out of 100 points. USD 1699 for the PEN-200 course + one exam attempt (USD 1999 with Learn One subscription).
§Changes in 2024/2025 you need to know
- Buffer overflow removed from the exam (huge relief; it was a memorization trap anyway)
- Active Directory now worth 40 points across a chain of 3 boxes - pass it or you likely fail
- 3 standalone machines worth 20 points each
- 10 bonus points for lab exercises + PWK exercises submissions (mostly free - take them)
- Report must be professional-grade; sloppy reports fail regardless of the point total
§The realistic 6–9 month roadmap
- Months 1–2: Linux privilege escalation. Do every TryHackMe Linux PrivEsc + HackTheBox 'Linux Fundamentals' path
- Months 3–4: Windows privilege escalation + Active Directory basics. Do TryHackMe's Attacktive Directory and every HTB easy AD box
- Month 5: PWK PEN-200 official course. Watch every module video, do every exercise
- Month 6: PWK lab machines. Aim to compromise 25+ boxes. Take notes with screenshots
- Month 7: TJ Null's public OSCP-like HTB list. Do 40–60 boxes
- Month 8: Full 24-hour practice exams (LainKusanagi, OffSec Proving Grounds Practice)
- Month 9: Report writing template. Practice writing a full report in 4 hours
§The 24-hour exam strategy that actually works
There are 100 hours between exam start and report submission. Sleep is not optional - plan for it. Rough schedule that worked for me on the second attempt:
- Hour 0–1: Read all machine descriptions, run initial nmap scans across all 6 targets in parallel
- Hour 1–8: Attack the standalone boxes first (each worth 20 points, easier)
- Hour 8–10: Take a 90-minute break. Eat properly. Not just coffee.
- Hour 10–20: Attack the Active Directory chain. If you can't get initial foothold in 4 hours, move on to alternate paths
- Hour 20–22: Second break. Sleep for 90 min if possible.
- Hour 22–28: Return with fresh eyes to whatever is stuck
- Hour 28–36: Final scoring pass. Verify you have all screenshots + proof files
- Hour 36–48: Write the report. Don't lowball this.
"On my first attempt I hit 65 points and figured the report was a formality. Offensive Security failed me because I missed the local.txt proof screenshot on one box. On the second attempt I over-documented everything and passed with room to spare. Documentation is the exam."
§Tools I actually used on exam day
- nmap - for the initial recon phase
- gobuster / ffuf - web content discovery
- linpeas + winpeas - privilege escalation enumeration
- BloodHound + SharpHound - Active Directory pathfinding
- impacket suite - psexec, wmiexec, secretsdump
- hashcat + john the ripper - offline password cracking
- burpsuite community - the free version is enough
- netcat - always. Reverse shells, port relays, everything
§Salary - where OSCP pays off
| Location | OSCP + 1 yr | OSCP + CRTP + 3 yrs |
|---|---|---|
| Dhaka, Bangladesh | BDT 150k–280k/mo | BDT 300k–550k/mo |
| Dubai, UAE | AED 22k–32k/mo | AED 38k–55k/mo |
| Riyadh, KSA | SAR 24k–35k/mo | SAR 42k–60k/mo |
| Remote pentest gigs | USD 6k–10k/mo | USD 12k–20k/mo |
This is the cert that changes bank statements. OSCP + hands-on experience typically doubles your salary within 18 months. Every OSCP holder I know has been headhunted more than once.
§Free/cheap prep resources worth using
- TJ Null's OSCP-like HackTheBox list - the gold standard practice list
- TryHackMe Offensive Pentesting learning path - cheap starting point
- IppSec's YouTube walkthroughs - every retired HTB box explained beautifully
- OffSec Proving Grounds Practice - closest to real exam boxes (USD 19/mo)
- HackTheBox Academy CPTS content - parallel prep, high quality
§FAQ
Can I skip PWK and self-study?
No. You must purchase PEN-200 to get an exam attempt. But you can absolutely prep with community resources and use PWK content as the final polish.
How long is OSCP valid?
3 years (updated policy). Renewal via CPE points, retaking exam, or earning higher OffSec certs (OSEP, OSED, OSWE).
Should I take CRTP or OSCP first?
CRTP first if AD is your weakness - it's cheaper and focused. OSCP first if you want the broader résumé line.
Is the 24-hour exam really 24 hours?
Yes. Non-stop. You can take short breaks (bathroom, food) with proctor approval, but the clock keeps running.
Certified practitioner and lead curriculum architect at KNScert. Writes about cert strategy, exam tactics, and the real-world skills employers actually pay for.
Stop reading. Start passing.
Verified Q&A, hands-on simulators, and expert workbooks - updated monthly to match the live exam.
Discussion(0)
More from the Journal
Palo AltoPalo Alto PCNSA Study Guide 2026: Pass on Your First Attempt
An honest, lab-tested PCNSA roadmap for 2026 - exam blueprint, real prep timeline, salary impact, and the mistakes that fail most first-timers.
CompTIAIs CySA+ Worth It in 2026? Salary, Jobs & Full Breakdown
A no-fluff look at CySA+ pay bands, hiring demand, and how it stacks up against Security+ and CASP+.
DevOpsSplunk vs Datadog: Side-by-Side Comparison for 2026
Logs, metrics, pricing, certification paths - which observability stack wins for your team in 2026.
Explore certification practice material
Get verified practice questions and exam dumps with a 100% pass guarantee.
