The OSEP is OffSec's advanced penetration testing certification, earned through the PEN-300 course "Evasion Techniques and Breaching Defenses". You pass it by compromising a hardened, defended network inside a 48-hour proctored exam, then writing it up. This plan covers what the course teaches, how the exam works, what it costs and how to spend your preparation time.
What the OSEP Actually Tests
PEN-300 builds on PEN-200, the course behind the OSCP+. OffSec describes it as advanced techniques against hardened targets in mature organisations with an established security function. That is the key difference from the OSCP+: you are no longer popping an unpatched box. You are getting past antivirus, application whitelisting and network filters, then moving through Active Directory.
OffSec lists the prerequisites as PEN-200 or equivalent knowledge, comfort with Linux, TCP/IP and scripting, and a working grasp of enumeration, privilege escalation and Active Directory. If you have not sat the OSCP+ or a comparable lab exam, read the OSCP 12-week study plan first.
OSEP Exam Format, Cost and Validity
| Detail | What OffSec publishes |
|---|---|
| Exam length | 47 hours 45 minutes, advertised as a 48-hour proctored exam |
| Report | A further 24 hours to submit documentation |
| Pass condition | Reach the objective on the control panel, or collect at least 100 points |
| Flags | Ten flags at 10 points each |
| Proctoring | Proctored by OffSec staff over a private VPN |
| Challenge labs | Seven, included with the course |
| Course and exam bundle | $1,749, with 90 days of lab access |
| Learn One subscription | $2,749 a year |
| Validity | The OSEP does not expire |
Prices change, so confirm them on the OffSec PEN-300 page before you buy. The exam guide and FAQ on OffSec's help centre are the source for scoring and conduct rules. Read both before booking, because the rules on tools and reporting are strict.
Exam Tip: Your report counts. Screenshot each flag in its original location, include the network configuration output, and write the steps so a technical reader could repeat them. Start the report template before the exam, not after.
What PEN-300 Covers
The syllabus runs to more than twenty modules. The ones that decide the exam fall into five groups.
Initial access and code execution
Client-side code execution with Office and JScript, then process injection and migration. You write loaders in C# and PowerShell, so scripting practice is not optional.
Evasion
Introductory and advanced antivirus evasion, application whitelisting bypasses and bypassing network filters. This is the part that separates the OSEP from earlier courses, and the part most candidates underestimate.
Post exploitation and credentials
Windows and Linux post exploitation, Windows credential extraction and kiosk breakouts.
Lateral movement
Windows and Linux lateral movement, Microsoft SQL attacks and Active Directory exploitation. Expect to chain these.
Combining the pieces
The final modules, "Combining the Pieces" and "Trying Harder", tie everything into multi-stage attacks. The challenge labs then rehearse the exam shape.
An 8-Week OSEP Study Plan
This assumes about 12 to 15 hours a week and a 90-day lab period. Adjust the pace to your own background.
- Week 1: foundations. Revise operating system theory and refresh C# and PowerShell basics. Build your own loader that runs shellcode, even if antivirus catches it.
- Week 2: client-side attacks. Work through the Office and JScript modules and rebuild each payload yourself rather than copying the course code.
- Week 3: injection and evasion. Process injection, then antivirus evasion. Keep notes on which technique defeated which control.
- Week 4: filters and whitelisting. Application whitelisting and network filter bypasses. Practise recovering when your first approach is blocked.
- Week 5: post exploitation and credentials. Windows and Linux post exploitation, credential theft and kiosk breakouts.
- Week 6: lateral movement and SQL. Lateral movement on both operating systems and the Microsoft SQL modules.
- Week 7: Active Directory and the challenge labs. Start the challenge labs and treat the first two as practice runs.
- Week 8: full-length rehearsal. Run a timed 48-hour attempt on an unseen challenge lab, with a written report at the end.
If you want a lighter Active Directory warm-up first, the HTB CAPE plan and the CRTP study plan cover similar ground.
Exam Strategy for 48 Hours
- Enumerate before you exploit. A hardened network punishes noisy scanning, so map what you can see first.
- Test payloads in your own lab. Work out which evasion technique survives a similar defence before you use it against the exam target.
- Sleep. Forty-eight hours is long enough to plan a proper rest. Candidates who push through lose more time to mistakes than they gain.
- Keep a running log. Paste commands and output into your notes as you go, so the report is mostly assembly.
- Know your stopping point. Reaching the control panel objective passes the exam, so do not burn hours hunting every flag once you have it.
OSEP vs CRTO, CRTP and CPTS
The OSEP is not the only route into advanced Active Directory and evasion work. Each alternative suits a different budget and goal, and the comparison of OSEP, CRTO, CRTP and CPTS walks through the choice. For a path that starts earlier, the HTB CPTS plan is a common stepping stone.
Building Fundamentals First
CertCrush does not offer a course for the OSEP exam, and no CertCrush course prepares you for it. If you are still building the underlying penetration testing knowledge, the CompTIA PenTest+ course covers the methodology and tooling concepts that PEN-200 and PEN-300 build on, and the PenTest+ study plan shows how to pace it.
Frequently Asked Questions
What is the OSEP certification?
The OSEP is OffSec's Experienced Penetration Tester certification, earned by passing the exam that follows the PEN-300 course. It tests evasion of defences, lateral movement and Active Directory exploitation against a hardened network.
How long is the OSEP exam?
The exam gives you 47 hours and 45 minutes, usually described as 48 hours, followed by 24 hours to submit your report. All exams are proctored by OffSec staff.
Does the OSEP expire?
No. OffSec states that the OSEP does not expire, unlike the OSCP+, OSIR and OSTH.
Is the OSEP harder than the OSCP+?
It is a step up. The OSCP+ tests whether you can find and exploit weaknesses. The OSEP assumes defenders are watching and requires evasion and chained attacks, so most candidates take the OSCP+ or equivalent first.
Ready to Start Practising?
The OSEP rewards hands-on repetition, and there is no shortcut around lab time. If you are earlier in your penetration testing journey, create a free CertCrush account and practise the foundations first.
