OffSec OSWE Study Roadmap
Last updated: March 30, 2026
Domain Weight Distribution
Week-by-Week Study Plan
Domain 1: Source code review fundamentals — Data flow, taint tracking, code auditing methodology
Domain 1: Language-specific patterns — PHP, Java, Python, .NET vulnerability patterns
Domain 2: Authentication bypass — Type juggling, loose comparison, JWT manipulation
Domain 2: Advanced auth attacks — Custom auth implementations, role manipulation, SSO bypass
Domain 3: Advanced SQLi — Source-level identification, parameterized query bypass, ORM injection
Domain 3: NoSQL injection — MongoDB, second-order SQLi, out-of-band extraction
Domain 3: Custom exploit scripting — Python scripts for automated data extraction
Domain 4: Deserialization — Java deserialization, ysoserial, gadget chain construction
Domain 4: PHP/NET deserialization — Object injection, PHPGGC, .NET gadgets, magic methods
Domain 5: SSTI — Jinja2, Twig, Freemarker, Thymeleaf exploitation and sandbox escapes
Domain 5: RCE techniques — Exploit chaining, file write RCE, custom exploit development
Lab Practice: Source code review exercises, vulnerability identification drills
Lab Practice: Full application assessments, exploit development, chaining attacks
Lab Practice: Timed mock exam — Complete application compromise with report
Report Writing: Professional report writing practice, methodology documentation
Final Review: Weak areas, exam strategy, tool preparation
Free Resources
Related Tools
OffSec OSWE Study Guide
Complete exam objectives and domain breakdown
✅Study Tracker
Track objective completion with progress dashboard
💰Cost Calculator
Total cost breakdown and ROI analysis
🧪Practice Quiz
Test your knowledge with free practice questions
FixTheVuln Store
Get the OffSec OSWE Study Planner
Fillable PDF with 16-week schedule, domain trackers, flashcard templates, and progress tracking.
Get the Study Planner — $5.99