OSED Exam Prep & Study Resources

OffSec certification · 2 products

EXP-301 | OffSec Exploit Developer

Study materials for OSED

Frequently asked questions

What is the OSED certification?

OSED (OffSec Exploit Developer) is an advanced certification from OffSec based on the EXP-401 course, Windows User Mode Exploit Development. It validates skills in custom exploit development for Windows applications, including reverse engineering, shellcode creation, and bypassing modern memory protections like DEP and ASLR. OSED is aimed at experienced security professionals who want to specialize in vulnerability research and exploit development.

How hard is the OSED exam?

OSED is one of the most difficult certifications OffSec offers. The exam is a grueling 48-hour proctored practical assessment where candidates must develop working exploits for real vulnerabilities in provided Windows applications. Candidates need deep knowledge of x86 assembly, WinDbg debugging, and custom shellcode techniques. Simply memorizing course material will not suffice, genuine problem-solving ability and comfort with low-level Windows internals are essential.

What are the prerequisites for OSED?

There are no formal prerequisites enforced by OffSec, but OSED is an expert-level certification that assumes significant prior experience. Candidates should be comfortable with x86 assembly language, Windows internals, debugging with WinDbg, and basic exploit development concepts such as buffer overflows and structured exception handler overwrites. Holding the OSCP is recommended as a baseline, and familiarity with C or C++ programming is extremely helpful for understanding the vulnerability classes covered in EXP-401.

What topics does OSED cover?

OSED covers advanced Windows user-mode exploit development topics including reverse engineering with IDA Pro and WinDbg, custom shellcode encoding and development, stack-based and SEH-based buffer overflow exploitation, DEP bypass techniques using Return Oriented Programming (ROP), ASLR bypass methods, format string vulnerabilities, and egghunter shellcode development. The course is heavily focused on understanding memory corruption at a low level and building reliable exploits from scratch.

How long does it take to prepare for OSED?

Most candidates spend four to eight months preparing for OSED after completing the EXP-401 course material. The timeline varies significantly based on prior experience with assembly language and low-level debugging. Candidates with a background in vulnerability research or reverse engineering may be ready in three to four months. Those coming directly from OSCP without exploit development experience should expect a longer preparation window and should invest substantial time practicing shellcode writing and ROP chain construction.

What is the OSED exam format?

The OSED exam is a 48-hour proctored practical assessment. Candidates receive a set of vulnerable Windows applications and must develop working exploits that demonstrate specific techniques covered in the EXP-401 course. After the 48-hour exploitation window, candidates have an additional 24 hours to write and submit a detailed report documenting their methodology, exploit code, and proof of successful exploitation. Every exploit must be developed from scratch with clear documentation of the approach.

Is OSED worth it for my career?

OSED is highly valuable for professionals targeting roles in vulnerability research, exploit development, or advanced red teaming. It is one of the few certifications that validates genuine exploit development skills through a hands-on practical exam. Employers in government contracting, security research firms, and advanced threat emulation teams recognize OSED as proof of elite technical capability. However, it is a niche certification, so its value is greatest for those specifically pursuing exploit development or VR career paths.

How does OSED compare to OSCP and OSEP?

OSED is a fundamentally different certification from OSCP and OSEP. While OSCP tests network penetration testing and OSEP focuses on advanced red team operations with evasion, OSED is entirely focused on developing custom exploits for software vulnerabilities. OSED requires deep knowledge of assembly, debugging, and memory corruption that is not tested in OSCP or OSEP. All three certifications contribute toward the OSCE3 designation, and together they represent mastery across penetration testing, red teaming, and exploit development.

What study resources help with OSED preparation?

The EXP-401 course material and lab exercises are the primary preparation resource and should be completed thoroughly before attempting the exam. Supplementary resources include the Corelan exploit writing tutorial series, the book 'The Shellcoder's Handbook,' and practicing with vulnerable applications from Exploit Education and VulnServer. Building a personal Windows lab environment for debugging practice is essential. Familiarity with IDA Pro, WinDbg, and writing Python-based exploit scripts will significantly improve exam readiness.

What is the OSED retake policy and cost?

The EXP-401 course with one exam attempt is priced in the range of $1,599 to $1,799 USD depending on the subscription tier purchased. If you fail the exam, retake attempts can be purchased separately, and OffSec enforces a cooling-off period between attempts. The exact retake pricing varies by subscription plan. Given the difficulty of the exam, many candidates do not pass on their first attempt, so budgeting for at least one retake is a reasonable approach when planning your certification investment.

Related

All OffSec certifications · Browse cheatsheets