OSEP Exam Prep & Study Resources
OffSec certification · 2 products
PEN-300 | OffSec Experienced Penetration Tester
Study materials for OSEP
OffSec Experienced Penetration Tester
OSEP remote passing with payment after passing and EMI options
$999$1500
View →OffSec Experienced Penetration Tester
DeHospital Management Panel with Hosts: WEB07, DC02, FILE02, DC01, CDC01, JUMP01, MAIL01, CLIENT01, APPSRV01, SQL02, SQL03, CLIENT02
$299$499
View →Frequently asked questions
What is OSEP and who is it for?
OSEP (Offensive Security Experienced Penetration Tester) is OffSec's advanced red team certification, based on the PEN-300 course. It is designed for experienced penetration testers who want to develop skills in advanced evasion, custom C# tooling development, sophisticated Active Directory exploitation, and bypassing modern endpoint and network defenses. OSEP is aimed at professionals who already hold the OSCP or have equivalent real-world experience. It teaches candidates how to operate in hardened enterprise environments where standard techniques are caught by EDR solutions and where custom tradecraft is necessary to achieve objectives.
How hard is the OSEP exam?
OSEP is significantly harder than OSCP. The exam is a 48-hour proctored practical assessment set inside a simulated enterprise environment with modern security controls in place. To pass, you must chain multiple compromises across the network while actively evading antivirus and EDR solutions. Simply running public exploits or known tooling will not work, custom tool development, shellcode modification, or payload obfuscation is typically required. Candidates who underestimate the exam or lack strong Active Directory and Windows internals knowledge often fail. It is one of OffSec's most demanding certifications.
Do I need OSCP before attempting OSEP?
OSCP is not a formally enforced prerequisite for OSEP enrollment, but it is strongly recommended by OffSec and the broader community. OSEP assumes you already have deep familiarity with Windows internals, Active Directory attack chains, common exploitation techniques, and the ability to write or modify offensive tools. Candidates who attempt OSEP without OSCP-level skills (or equivalent professional experience) almost always struggle with the pace and complexity of the PEN-300 material. If you are not yet comfortable exploiting standalone machines and performing basic AD attacks, OSCP is the right starting point.
What topics does OSEP cover?
OSEP covers a broad range of advanced offensive techniques including process injection and hollowing, custom shellcode development and loaders, antivirus and EDR evasion, Active Directory lateral movement, credential theft and Pass-the-Hash/Pass-the-Ticket, Kerberoasting and AS-REP roasting, DCOM and WMI abuse, MSSQL server attacks, phishing campaigns using Office macros, and complete enterprise kill-chain simulations. The course is heavily Windows-focused and designed to simulate the techniques used by sophisticated threat actors operating inside enterprise environments with mature security teams.
How long does it take to prepare for OSEP?
Experienced penetration testers typically spend three to five months preparing for OSEP after completing the PEN-300 course. Candidates transitioning directly from OSCP may need additional time specifically to build C# development skills, shellcode writing capabilities, and evasion techniques that are not covered in PEN-200. Practicing in environments with EDR solutions (such as HTB Pro Labs or a personal home lab with Windows Defender enabled) is essential preparation. Reading up on Windows internals, process injection techniques, and modern defense evasion tactics alongside the course material significantly improves exam readiness.
OSEP vs OSCP, which is harder?
OSEP is considerably harder than OSCP in both content complexity and exam difficulty. OSCP focuses primarily on standalone machine exploitation and basic Active Directory compromise in environments without modern defenses. OSEP targets enterprise environments with full security controls including antivirus, EDR, and application whitelisting, requiring custom tooling development and sophisticated evasion techniques. The OSEP exam is also 48 hours long compared to OSCP's 24 hours, reflecting the increased complexity. Most professionals consider OSEP a true advanced certification that requires years of offensive security experience to pass comfortably.
Is OSEP worth it?
Yes, especially for red teamers, senior penetration testers, and adversary simulation specialists. OSEP demonstrates that you can operate in hardened enterprise environments, develop custom offensive tooling, and simulate sophisticated threat actor tradecraft, skills that are directly applicable in high-end red team engagements. The certification is respected within the offensive security community and often appears in requirements for senior red team and adversary emulation roles. For professionals aiming to specialize in full-scope red team operations, OSEP is one of the most valuable credentials available.
What is the OSEP exam format?
The OSEP exam is a 48-hour proctored practical assessment conducted on an enterprise-like simulated network. You must compromise the environment, collect specific flags placed throughout the network, and demonstrate a successful full attack chain. After the 48-hour hacking window closes, you have an additional 24 hours to write and submit a comprehensive professional penetration test report documenting your methodology, findings, and evidence. The report quality is evaluated as part of the overall assessment, and a passing score must be achieved on both the network compromise and the report submission.
What labs help prepare for OSEP?
The most effective preparation resources for OSEP beyond the PEN-300 course itself are Hack The Box Pro Labs, specifically Offshore, RastaLabs, and Cybernetics, which simulate enterprise environments with layered defenses. Altered Security's CRTP and CRTE courses provide focused Active Directory attack training that directly applies to OSEP content. Setting up a personal home lab with Windows Server, Active Directory, and Windows Defender enabled to test your evasion techniques is also highly recommended. Practicing C# development and shellcode loading in a realistic lab environment will build the practical skills the exam demands.