← All Roadmaps
OffSec

OffSec OSCP Study Roadmap

PEN-200 / OSCP · 16-week plan · Free

Last updated: March 30, 2026

Progress:
0/16

Domain Weight Distribution

D1: Penetration Testing Fundamentals
15%
D2: Information Gathering & Enumeration
20%
D3: Web Application Attacks
20%
D4: System Exploitation & Privilege Escalation
20%
D5: Active Directory Attacks
15%
D6: Post-Exploitation & Reporting
10%

Week-by-Week Study Plan

Week 1

Domain 1: Pentest methodology, Kali Linux setup, bash scripting, report templates

Week 2

Domain 2: Passive recon — OSINT, Google dorking, Whois, DNS enumeration

Week 3

Domain 2: Active scanning — Nmap, service enumeration, SMB/SNMP/HTTP

Week 4

Domain 3: Web attacks — SQL injection (UNION, blind, error-based), sqlmap

Week 5

Domain 3: Web attacks — LFI/RFI, XSS, command injection, file uploads

Week 6

Domain 4: Windows exploitation — Buffer overflows, public exploits, Metasploit

Week 7

Domain 4: Windows privilege escalation — Token impersonation, service exploits, unquoted paths

Week 8

Domain 4: Linux exploitation & privilege escalation — SUID, cron, kernel exploits, capabilities

Week 9

Domain 5: Active Directory — Enumeration, BloodHound, Kerberoasting, AS-REP roasting

Week 10

Domain 5: AD lateral movement — Pass-the-hash, pass-the-ticket, Mimikatz, domain persistence

Week 11

Domain 6: Post-exploitation — Pivoting, port forwarding, SSH tunneling, Chisel/Ligolo

Week 12

Lab Practice: Work through OSCP lab machines, document methodology

Week 13

Lab Practice: Challenge labs, timed exercises, try harder machines

Week 14

Lab Practice: Full mock exam — 5 machines in 24 hours with report

Week 15

Report Writing: Practice professional report writing, refine templates

Week 16

Final Review: Weak areas, exam strategy, rest and preparation

Free Resources

Proving Grounds

Related Tools

FixTheVuln Store

Get the OffSec OSCP Study Planner

Fillable PDF with 16-week schedule, domain trackers, flashcard templates, and progress tracking.

Get the Study Planner — $5.99