OffSec OSCP Study Roadmap
Last updated: March 30, 2026
Domain Weight Distribution
Week-by-Week Study Plan
Domain 1: Pentest methodology, Kali Linux setup, bash scripting, report templates
Domain 2: Passive recon — OSINT, Google dorking, Whois, DNS enumeration
Domain 2: Active scanning — Nmap, service enumeration, SMB/SNMP/HTTP
Domain 3: Web attacks — SQL injection (UNION, blind, error-based), sqlmap
Domain 3: Web attacks — LFI/RFI, XSS, command injection, file uploads
Domain 4: Windows exploitation — Buffer overflows, public exploits, Metasploit
Domain 4: Windows privilege escalation — Token impersonation, service exploits, unquoted paths
Domain 4: Linux exploitation & privilege escalation — SUID, cron, kernel exploits, capabilities
Domain 5: Active Directory — Enumeration, BloodHound, Kerberoasting, AS-REP roasting
Domain 5: AD lateral movement — Pass-the-hash, pass-the-ticket, Mimikatz, domain persistence
Domain 6: Post-exploitation — Pivoting, port forwarding, SSH tunneling, Chisel/Ligolo
Lab Practice: Work through OSCP lab machines, document methodology
Lab Practice: Challenge labs, timed exercises, try harder machines
Lab Practice: Full mock exam — 5 machines in 24 hours with report
Report Writing: Practice professional report writing, refine templates
Final Review: Weak areas, exam strategy, rest and preparation
Free Resources
Related Tools
OffSec OSCP Study Guide
Complete exam objectives and domain breakdown
✅Study Tracker
Track objective completion with progress dashboard
💰Cost Calculator
Total cost breakdown and ROI analysis
🧪Practice Quiz
Test your knowledge with free practice questions
FixTheVuln Store
Get the OffSec OSCP Study Planner
Fillable PDF with 16-week schedule, domain trackers, flashcard templates, and progress tracking.
Get the Study Planner — $5.99