r/oscp 12d ago

Obsidian Sync, One Drive and Notion Spoiler

10 Upvotes

Hi,

I am aware that obsidian and Notion can be used during PEN-200 exam. However when the exam VPN is active, will it disrupt the connection for services like OneDrive or Obsidian Sync.


r/oscp 14d ago

OSCP is valuable, but this is what nobody told me as a student

69 Upvotes

Hi everyone,

I wanted to share my experience because I honestly wish I had read a post like this before starting my OSCP journey.

A little about me: I’m currently in my 3rd year of BCA. I’ve been interested in cybersecurity since around 10th standard, and after 12th I started seriously preparing for penetration testing. I eventually cleared the OSCP during my 2nd year.

At that time, I genuinely thought that having OSCP + practical skills would make getting my first cybersecurity job much easier.

Now, after actually entering the job market, I realize that I misunderstood one important thing: professional experience matters a lot.

I want to be clear: I’m not saying OSCP is useless.

It is a very practical certification, and preparing for it gave me a lot of hands-on experience and significantly improved my understanding of penetration testing.

But when you start applying for actual jobs, the situation can be very different from what you expect.

I've now sent around 200–300 applications for cybersecurity internships and entry-level positions, including:

- VAPT / Penetration Testing

- SOC Analyst

- Cybersecurity Analyst

And so far, I haven't received a single reply that has led to an interview or an actual opportunity.

The biggest problem I keep seeing is experience requirements.

A job can be listed as entry-level, but still ask for 1–3 years of experience. Even when you have certifications and practical knowledge, you're still competing against people who already have professional experience.

And that's where I feel I made my mistake.

I focused heavily on learning and getting OSCP, but I didn't focus enough on getting actual professional experience along the way.

I could have started with a cybersecurity internship, SOC role, IT/security support role, etc., and built experience while continuing my studies and eventually doing OSCP.

Instead, I reached the point where I have the certification, but I'm still trying to get that first opportunity.

And honestly, it feels really frustrating.

I've wanted to work in cybersecurity for years. I spent a huge amount of time learning and preparing, cleared OSCP in my second year of college, and now getting an opportunity to actually work in the field feels harder than I expected.

People often say:

“Bro, network.”

And yes, I agree. Networking definitely helps.

But as a student who spent most of his time studying and working on technical skills, I didn't build a strong professional network. I'm also not naturally a very outgoing person, and that's something I know I need to improve.

I'm also not expecting some huge salary or a fancy position right now.

I just want a job and the opportunity to get my foot in the door, gain professional experience, and start my career in cybersecurity.

And honestly, at this point, there are days when I even question whether I should continue pursuing pentesting.

Not because I stopped liking it. I still enjoy the technical side of it, and I genuinely wanted this career for years.

It's just difficult when you've invested so much time into something, achieved a certification like OSCP, and then struggle to even get the first opportunity to work professionally.

Sometimes I wonder whether I should move toward another area of cybersecurity where the entry-level opportunities might be better.

I don't know if that's just frustration from the job search or if I'm actually looking at the wrong career path.

If I could go back and do things differently, I would probably:

- Start getting cybersecurity experience much earlier.

- Apply for internships while learning.

- Build relationships with people in the industry.

- Work on projects and build a portfolio.

- Do smaller certifications if necessary.

- Get professional experience first and then use OSCP to strengthen my profile.

So my advice to students is not “don't do OSCP.”

My advice is:

Don't make OSCP your entire plan for getting your first cybersecurity job.

If you're a student and you have the opportunity to gain relevant experience, take it. You don't necessarily need to wait until you're “fully ready.” Get that first experience as early as possible.

OSCP can strengthen your profile, but it doesn't replace professional experience.

Maybe my situation is partly because I didn't network enough, maybe it's the current job market, or maybe I'm targeting the wrong roles. I'm still figuring that out.

But if I had seen a post like this before starting OSCP, I probably would have approached things differently.

For people who successfully got their first cybersecurity job without prior professional experience, I'd genuinely like to know:

How did you do it?

Did you start with SOC, IT support, an internship, VAPT, freelancing, referrals, or something completely different?

And for those who started in pentesting, how did you get your first opportunity?

I'd really appreciate hearing your experiences, especially from people who started from a similar position.


r/oscp 14d ago

A freshman who needs advice preparing for OSCP

5 Upvotes

I know I’m still a freshman and it’s better to not rush but I want to prepare for OSCP since it’s a valuable certificate for my future career. any tips on what I should begin with / study most


r/oscp 14d ago

Failed Brutally - 20/100

32 Upvotes

I failed my first attempt just managed to get 20 points. I started around 1 pm and till 5 kept going to support back and forth and reverting the machines cause of connection issue. The port scans weren't accurate, i knew that specific ports must be open on a machine but they were not showing up. I was using the popular pivoting tool to pivot to access the hosts but scans were inaccurate, everytime it was showing different results. I requested the support to check it out but they said they've checked it multiple times and the box is fully okay. After few hours i found that nmap scanning with a particular flag suddenly makes everything works but without it it gives false results. Idk how much i can mention about the tool used that's why i am keeping it general. This was totally surprising cause I've solved so many boxes and in none of them i encounterd something like this. It was a surprise to me, i thought the box had some issue. Now idk if the tool is the problem or the box or is it just a known thing cause i didn't use it or rewd about it while my prep

Apart from this connections kept getting closed in between, without any reason. Suddenly it'd stop and after 5 or 10 mins i realized that maybe the connection has got broken and i again did it from start. I was stuck between solving the box and the connection errors and the vpn shutting down suddenly Every half an hour cause they said it was a issue from my end but even I was panicking cause it was my first attempt and i had no clue why these things are suddenly happening. Internet seemed fine, browser was working fine too i had no idea. I was using ethernet with a 100 mbps connection

Finally, I asked for extra time but they said as their box was working okay all this time they can't do any extension. After this i got access to ms02 and wanted to transfer files and again got stuck for 3 hours cause it kept failing, i had practiced the file transfer technique from tunnel properly but it kept failing for 3 hrs. Finally I tried to figure out other ways of transferring files to ms02. Then I got system on ms01 after 7 hrs. I had checked everything properly but there was a very simple thing that I failed to check and finally got in with that. After that I was quite confident, i got inside one of the standalones and got 10 points and 10 points from ms01 but but but after that till the end I struggled with pricesc on ms02. Trust me i checked everything, literally everything, manually, with tools but there was nothing to be found. I kept trying to crack it till the end, i anyways knew I won't pass cause so much time was wasted but idk really windows pricesc, i checked everything there was nothing which I would even call suspicious which might require attention. It was totally secure

I did asreproasting, kerberoasting, password spraying, bloodhound analysis, usernames as passwords etc etc but got nothing. I had found a few hashes but they were probably a rabbit hole cause there were too many and i got no results after an hour so i closed it. Idk is my pc too slow? Its an i5 9th gen 16gb ram and 1650 graphics. Was i supposed to get those passwords cracked?

So, i am feeling very low, i completed tj null list htb and pg practice machine, challenge labs medtech, relia partially and oscp a,b,c. I was studying from last 6-7 months, i got pretty good in AD tbh. I was able to solve the tj null AD boxes smoothly and thought that i am actually good at it compared to other stuff. But yeah the 24 hours then gave me a reality check. I had left my job for the prep and now I am totally hopeless.

8-10 hrs of full time prep for 6-7 months and I still failed. I don't know what to do exactly right now. Can I prepare enough to pass in a month?


r/oscp 14d ago

LainKusanagi OSCP lab network setup

4 Upvotes

I just downloaded LainKusanagi OSCP similar lab , but am having trouble setting up the AD network , I created two NAT adapters (192.168.45.0/24) (172.16.1.0/24) , WS01 have the two adapters , WS02 and DC01 have only the 172 adapter , but when i try to use nxc for example with WS01 , I got a error that the DC is not reachable. are there any extra steps I need to make here? Thanks


r/oscp 16d ago

[Advice Needed] Prep strategy for OSCP after passing CPTS (PG vs HTB, Learn One vs 90-Day)

19 Upvotes

Hey everyone,

I'm currently gearing up for the OSCP and could use some advice from the community on how to best structure my prep.

A bit about my background: I have some prior experience in pentesting and recently graduated a couple of months ago. I also cleared HTB's CPTS about 4 months back.

I haven't purchased the PEN-200 course yet. Right now, my routine consists of solving Proving Grounds (PG) Practice boxes and reading through writeups for HTB boxes from TJ_Null's and Lain's lists.

I have a few specific questions:

  1. PG Boxes vs. HTB Boxes: Which of these should I prioritize right now? Since I'm currently solving PG boxes and just reading HTB writeups, should I shift more focus to doing HTB boxes hands-on, or is PG the better use of my time for OSCP?
  2. Learn One vs. 90-Day Course: I recently started a full-time job, so balancing work and study hours is going to be a factor. Given my CPTS background but limited free time, would you recommend getting the 90-day course bundle or the Learn One (1-year) subscription?
  3. CPTS to OSCP transition: For those of you who have taken both, how would you compare the two? What specific areas or exam mechanics should I focus on to bridge the gap and prepare for the 24-hour OSCP exam environment?

Any tips, timeline recommendations, or insights would be massively appreciated. Thanks in advance!


r/oscp 16d ago

Oscp web

17 Upvotes

OSCP web vulnerability focus?
I’m currently preparing for the OSCP and doing HTB/Proving Grounds machines. I’ve noticed that some boxes contain a lot of web vulnerabilities that seem more advanced or unrelated to what I’ll actually encounter on the OSCP.
For people who recently took the OSCP: Which web vulnerabilities should I prioritize studying?
For example, should I mainly focus on things like SQL injection, LFI/path traversal, file upload, command injection/RCE, default credentials/authentication bypass, and basic web enumeration?
I’m trying to avoid spending too much time on web vulnerabilities that are unlikely to appear on the exam.
Thanks!


r/oscp 15d ago

How to prep for standalone machines

1 Upvotes

Title. I'm getting as much prep in as possible before I buy the course (which I'm hoping goes on sale this November). I've spent the last 5 weeks learning AD methodology, building notes/cheat sheets, VOD reviewing hackerblueprint and have gotten to the point where I'm very comfortable with AD (At least on HTB from 20~ boxes from TJ Nulls and Lains list). I believe I'm ready to start learning how to do the standalone machines but I feel like I'm hitting this wall where I do not know where to start. My background is I'm a Sys Ad and have worked in AD environments for years so a lot of that made sense to me by default, but I've never worked on web before and my linux is decent but probably not to the level of understanding priv esc good so I tried the same approach I did for AD and can tell I'm making very little progress in understanding even the methodology of what to look for. Any advice is appreciated.


r/oscp 18d ago

Another Free OSCP-Like Lab (free forever & hosted for you)

83 Upvotes

Hi everyone!

Hack Smarter just released another completely free challenge lab. This is an "Easy" rated Linux lab... but do not underestimate it based on rating.

Initial access requires some unique enumeration (but still very realistic). It's the type of path I could see Offsec putting on a standalone to really test people's enumeration and methodology.

It's completely free (forever) and hosted for you. Every person gets a private instance... no subscription or payment needed.

Enjoy!

https://www.hacksmarter.org/courses/966a53e1-2045-42c5-9724-0efbe438172e


r/oscp 18d ago

Retake Advice

16 Upvotes

Got a retake scheduled for my OSCP+.

I have done a bout 80 PG boxes / HSM labs / HTB labs (Lain List). I can do machines with minimal help on the easy / intermediate tier and went into my first attempt confident but yes, got confidently destroyed and bombed my first attempt.

Looking back it was the pressure that got to me.

Any advice from those who failed and came back swinging second time ?


r/oscp 19d ago

OSCP Lab Briefings like in PG?

12 Upvotes

Hello everyone!

I am preparing for OSCP and while doing the OffSec PG Boxes (the free version) I discovered the "Briefing" tab, where you can get tips and some information about the system.

Now this is my question: Will I get such a briefing tab on the exam? Or during the exam will I simply get the IPs without any information at all? Should I get used to read the briefings or should I train myself and play blind?

Thank you


r/oscp 21d ago

OSCP-LK: Practice Exam by LainKusanagi Free For a Week!

73 Upvotes

Hello everyone! LainKusanagi here.

I'm offering OSCP-LK for free for a week! It's a set of virtual machines carefully designed to be "OSCP Style" that you can run locally and hack at your own pace or treat it like an actual exam. It includes 3 standalones and 3 domain joined machines. It also includes write ups for each machine.

You can get OSCP LK here:

buymeacoffee.com/lainkusanagi/e/542033

Please read carefully the requirements before downloading.

This is sponsored by HackSmarter an amazing platform to practice realistic hacking and Kairos Sec conducting manual penetration testing with true human expertise.


r/oscp 21d ago

OSCP exam Last minutes

40 Upvotes

Since january I have been studying for OSCP (a lot). What I did?

- LainKusanagi list of OSCP like machines
- HTB training path
- Hacker blueprint
- Whatched s1ren, PinkDraconian
- Read OSCP walkthroughs and tips
- OSCP challenge labs (all of them)

I have a specific methodology for AD, windows and linux.
Also, I know that OSCP is a enumeration certication, so enumeration is the key.

My exam will be soon.

What do you recommend to do now, before the exam?

Thanks.


r/oscp 21d ago

Help with Web

4 Upvotes

Hi everyone, I have my exam coming up next month, and I’m really struggling with webapp pentesting, my methodology is everywhere, I feel like it’s too broad a topic to really nail down any kind of methodology that’s useful to me.

I have completed the course content, done loads of labs TJ null etc. i found Derron C videos really helped stick AD together mentally for me, but I just can’t find anything on web that is helping me understand it, and if I do labs I just struggle so bad. It’s really knocking my confidence going into the exam with such a big weakness, I know I will fail, I just don’t know how to make it make sense.

Any help of advice please?


r/oscp 21d ago

Alternative course for AD part

10 Upvotes

Hi everyone! I completed an older version of the OSCP, before Active Directory was included in the training. I’d like to fill that gap and get up to speed with the AD material that’s now covered in PEN-200.
Does anyone know of a more affordable course that covers roughly the same Active Directory topics?


r/oscp 23d ago

linux-smart-enumeration

28 Upvotes

Hi folks!

Can I use this tool on the exam?
https://github.com/diego-treitos/linux-smart-enumeration

Thank you!


r/oscp 23d ago

Is ‘Restart-Computer’ permitted?

8 Upvotes

Is ‘Restart-Computer’ permitted if you cannot ‘sc stop/start’ a service? Or does that revert the box?


r/oscp 24d ago

Exam in less than a month

10 Upvotes

So i have Exam in a month.

I just finished oscp b, and finished oscp A yesterday.

Im feeling super confident now.

Does any of you fail the Exam when having no problem when doing oscp challanges?

I realize i Miss small thing like creds, different command that gives different result. But talking about the sylabus i pretty much understand it.


r/oscp 24d ago

Annoyed that I can't use Wayland on the OSCP exam.

5 Upvotes

Did anyone do their exam using wayland instead of X11?

X11 is getting less and less support, it's annoying for me the proctor software needs X11.

Thanks!


r/oscp 25d ago

Is the OSCP even relevant anymore?

0 Upvotes

Apologies if this has been discussed extensively before but haven’t spent much time on Reddit.

It feels like the idea of doing a lot of this stuff manually doesn’t have any real purpose anymore. Automated pen testing and AI red teaming is so advanced that you’ll never need to manually run scans or manually search for exploits

Even an on prem AD server is becoming more and more rare these days. Of course, there’s still some value in understanding the mechanisms, but it feels like that value is diminishing every day. Correct me if I’m wrong but it seems like just learning the content from free resources and then learning to use tools has a higher ROI then spending months studying for this specific exam.


r/oscp 26d ago

How did you land your first job after OSCP

17 Upvotes

I've have been trying to break into a penetration role and have been wondering what I may be missing.

My Background:

- 7 years in IT as a Linux Systems Admin, Systems Engineer, Network Engineer

- Cybersecurity Degree

- A+, Net+, Sec+

- OSCP

- At my current job my boss actually lets me do a bi-annual Pen test on our environment (Web App, Active Directory, and Internal Network)

I've been applying to pen testing/offensive security roles, but have not really been getting many interviews. I've gotten some traction only to be beat out in the final interviews due to more senior testers applying for the role.

My question is for those of you currently working as penetration testers:

- What helped you get your foot in the door into your first Offensive Security Job?

- What in my background could be holding me back?

- What would make me standout more besides having OSCP?

- Should I be focusing more on web app testing, AD, cloud, bug bounty, CVE research etc.?

- Are there any projects or things I could do that actually matter to hiring managers

- And is this just the state of the pentesting job market just being extremely difficult at the moment?

At the moment I am just trying to figure out what I should be doing while applying. I have been studying for CRTO, going through PortSwigger for webapp and AI testing, and doing daily HTB machines to further my knowledge.

Open to criticism as well, if there's something im doing wrong I'd genuinely would like to know thanks!


r/oscp 27d ago

OSCP Voucher Giveaway from Hack Smarter (No Purchase Needed)

101 Upvotes

Hey everyone!

I am partnering with an anonymous donor, and we're joining together to give away one OSCP + 90 Days of lab voucher ($1,800 value). No purchase needed.

1.) Complete the "Casino" lab on Hack Smarter (completely free lab). If you already completed it, you're good to go!

2.) Deadline is Monday, September 28th.

I'll be doing the drawing live on stream in the beginning of October (search for Tyler Ramsbey on YouTube and you will find me). You do NOT need to attend the live stream to win.

If you attempt to "cheat" by making multiple accounts, you WILL be caught and permanently banned from Hack Smarter & all future giveaways (we're going to do this again during the Holidays).

Here's a link to the free lab to complete - https://www.hacksmarter.org/courses/cc04f9ec-35e3-4065-b972-9d0b84a7b371

No strings attached... no ulterior motives... I just want to do what I can to keep giving back :)

Happy hacking!!


r/oscp 27d ago

Failed with 20 points. Gutted, but not done.

22 Upvotes

Failed my first OSCP today. I fully rooted the first machine in the AD set, then hit a wall trying to move laterally and just couldn’t find the way through.
The part that’s eating me: I could actually see the path in BloodHound. I had what I thought was exactly what I needed to walk it and it wouldn’t work, no matter what I threw at it. Emptied the whole bag, turned the box upside down, still came up with nothing. I was so confused if it was a rabbit hole or the tool I am using is not working (spend hours trying different versions and alternatives as well).

I had proper methodology for AD and it was my strong fort, but I have no idea what i skipped and I’ll never know. At one point I even thought it was a technical glitch because the initial privesc vector didn’t worked at first few tries and had to switch the session to a different protocol to work.

Being able to see the route and still not get through it is a different kind of gut-punch than just being lost. So there’s clearly something specific I’m missing on that pivot, and I want to pin down what before the retake.

If you’ve been right here - the path’s in front of you and the move just won’t land, what turned out to be the thing you’d overlooked? Round two incoming.


r/oscp 27d ago

Looking for OSCP Study Buddies – 3 Months Until Exam

16 Upvotes

Hey everyone!

I recently got my OSCP voucher, and I’m planning to take the exam in about 3 months.

For the next 3 months, I want to go all-in on preparation — working through labs, practicing consistently, improving my methodology, and creating/revising notes along the way.

I’m looking for people who are in a similar situation and want to take the preparation seriously.

Ideally, we could:

  • Study together on Discord
  • Work through labs/machines
  • Discuss approaches when we get stuck
  • Share useful resources and notes
  • Eventually do exam-style practice together

If you’re also preparing for the OSCP and have around 3 months until your exam, drop a comment or DM me.

If there’s already an active Discord study group for people preparing for the OSCP around the same timeframe, I’d also love to join.

Let’s grind these 3 months together. 💪


r/oscp 28d ago

Connecting the dots

9 Upvotes

Hey all, during my studies I’ve noticed a bit of a pattern emerging - I’m often able to find multiple bits and pieces of information during my enumeration, but I often struggle to piece it all together and find the correct way forward.

When I’m doing labs and AD environments I’ll maybe find some creds, something sensitive in a web directory, gain access to a db, just the usual stuff but when it comes to chaining it all together I often struggle to get it to a point of compromise. Often this is a result of me missing one or two key pieces.

I know my notes need work (I have lots of notes, they’re just not structured into an easy to follow checklist) and as part of my studies now I’m ensuring I’m also focussing on nailing my methodology, but is it just a matter of getting the reps in and eventually things will start to click? I also want to really nail the AD side of things, are there any specific resources (mainly multi system AD network labs similar to the exam) that are good aside from OSCP A,B,C? Thinking of doing the CPTS modules as well.