← All Certifications
OffSec

OffSec OSCP Certification

PEN-200 · Practical

Last updated: March 31, 2026

Exam Syllabus & Domains

The OffSec OSCP certification exam covers the following domains. Focus your training time proportionally to each domain's weight.

Domain 1 15%

Penetration Testing Fundamentals

  • 1.1 Understand penetration testing methodology and rules of engagement
  • 1.2 Set up and configure Kali Linux attack environment
  • 1.3 Apply effective note-taking and documentation practices
  • 1.4 Understand legal and ethical considerations in penetration testing
Pentest MethodologyRules of EngagementKali LinuxBash ScriptingReport WritingScope DefinitionLegal ConsiderationsNote-Taking ToolsVirtual Lab SetupOSCP Exam Format
Domain 2 20%

Information Gathering & Enumeration

  • 2.1 Perform passive and active information gathering techniques
  • 2.2 Enumerate services including DNS, SMB, SNMP, and HTTP
  • 2.3 Conduct vulnerability scanning and analysis
  • 2.4 Identify and prioritize attack vectors from enumeration data
Nmap ScanningDNS EnumerationSMB EnumerationSNMP EnumerationWeb EnumerationDirectory Brute-ForcingVulnerability ScanningService FingerprintingGoogle DorkingOSINT Techniques
Domain 3 20%

Web Application Attacks

  • 3.1 Identify and exploit common web vulnerabilities
  • 3.2 Perform SQL injection attacks including blind and UNION-based
  • 3.3 Exploit file inclusion vulnerabilities (LFI/RFI)
  • 3.4 Attack web applications through XSS, command injection, and file upload
SQL InjectionCross-Site ScriptingCommand InjectionLocal File InclusionRemote File InclusionFile Upload AttacksDirectory TraversalWeb ShellsBurp SuiteAuthentication Bypass
Domain 4 20%

System Exploitation & Privilege Escalation

  • 4.1 Exploit Windows and Linux systems using public and custom exploits
  • 4.2 Perform Windows privilege escalation techniques
  • 4.3 Perform Linux privilege escalation techniques
  • 4.4 Transfer files and establish reverse/bind shells
Buffer OverflowsWindows Priv EscLinux Priv EscSUID/SGID ExploitsKernel ExploitsToken ImpersonationService ExploitsReverse ShellsBind ShellsFile Transfers
Domain 5 15%

Active Directory Attacks

  • 5.1 Enumerate Active Directory environments and trust relationships
  • 5.2 Perform AD attacks including Kerberoasting and AS-REP roasting
  • 5.3 Execute lateral movement techniques across the domain
  • 5.4 Achieve domain dominance through credential-based attacks
AD EnumerationKerberoastingAS-REP RoastingPass-the-HashPass-the-TicketLateral MovementBloodHoundMimikatzGolden/Silver TicketsDomain Persistence
Domain 6 10%

Post-Exploitation & Reporting

  • 6.1 Perform post-exploitation data gathering and exfiltration
  • 6.2 Establish persistence and maintain access
  • 6.3 Pivot through compromised hosts to reach internal networks
  • 6.4 Write professional penetration testing reports
Port ForwardingSSH TunnelingPivotingPersistence MechanismsData ExfiltrationAntivirus EvasionChisel/LigoloReport StructureExecutive SummaryRemediation Guidance

Where to Focus Your Study Time

Domains with higher weight have more exam questions — allocate your study hours accordingly.

D1 Penetration Testing Fundamentals
15%
D2 Information Gathering & Enumeration
20%
D3 Web Application Attacks
20%
D4 System Exploitation & Privilege Escalation
20%
D5 Active Directory Attacks
15%
D6 Post-Exploitation & Reporting
10%

Study Tips

Free Study Resources

๐Ÿ“‹

Study Roadmap

Week-by-week study plan with free resources

โœ…

Study Tracker

Track objective completion with progress dashboard

๐Ÿ’ฐ

Cost Calculator

Total cost breakdown and ROI analysis

๐Ÿงช

Practice Quiz

Test your knowledge with free practice questions

Practice Quiz

Test your knowledge before the exam with our free practice quiz.

Take the OffSec OSCP Practice Quiz

Related Comparisons

Not sure if OffSec OSCP is the right choice? Compare it with similar certifications:

OSCP vs CEH OSCP vs PenTest+

Get the OffSec OSCP Study Planner

Fillable PDF with 16-week schedule, domain trackers, flashcard templates, progress tracking, and quick reference sheets. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

Get the Study Planner — $5.99

Also available as a 4-Format Bundle for $15.99

CyberFolio

Earned your certs? Show employers.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →

Free Training Resources

Use these free tools to support your OffSec OSCP certification training:

Frequently Asked Questions

What is the OffSec OSCP certification?

The OffSec OSCP (PEN-200) is a professional IT certification that validates your knowledge and skills in the exam domains covered. It is recognized globally by employers and is a valuable credential for career advancement in cybersecurity and IT.

What does the OffSec OSCP certification syllabus cover?

The OffSec OSCP exam syllabus covers Practical. Each domain is weighted differently, so focus your training on higher-weighted domains first. Review the complete domain breakdown above for objectives and key concepts.

How should I study for OffSec OSCP?

Create a structured study plan covering all exam domains, use practice tests to identify weak areas, and review key concepts regularly. A fillable study planner can help you organize your training with weekly schedules and progress tracking.

How long does it take to prepare for OffSec OSCP?

Preparation time varies by experience level. Most candidates spend 8-12 weeks of dedicated training. Using a structured study planner with domain-by-domain breakdown helps ensure you cover all certification objectives efficiently.