
Offensive Security Certified Professional (OSCP)
Exam PEN-200 OffSec Advanced
A 24-hour practical exam with no multiple choice. The most respected hands-on offensive certification, and the hardest work on this list.
Free resources
The path
Step 1 — Learn the OSCP approach
Enumerate exhaustively, exploit manually, document as you go.
1 course
Learn
- CourseOffensive Security Certified Professional (OSCP) Training 🔒 StationX Unlimited
1 section · 0 lectures
- First Section 0
Free resources
Step 2 — Linux and command line fluency
Live in a shell — non-negotiable for the exam.
37 labs
Learn
- CourseCovered in Offensive Security Certified Professional (OSCP) Training — Linux and shell sections 🔒 StationX Unlimited
Practise
- Labs+Linux Command Line Introduction — 18 labs 🔒 StationX Labs+
- Backup and Restore Files with CPIO in Linux [Guided]
- Backup and Restore Files with Tar in Linux [Guided]
- Can You Create Files from Parts of Other Files? [Advanced]
- Can You Extract, Label, and Organize Data? [Expert]
- Can You Manage Directories and Files in Linux? [Advanced]
- Can You Navigate and Search in a Manpage? [Advanced]
- Can You Use the Grep and Sort Commands Together? [Advanced]
- Can You use Find and Locate to Search for Files in Linux? [Advanced]
- Configure Links in Linux [Guided]
- Configure Standard Permissions in Linux [Guided]
- Configure the Display of a File [Guided]
- Display Manpage Information by Using Sections [Guided]
- Edit Text Files in Linux [Guided]
- Getting Started with Linux Command Line Fundamentals [Getting Started]
- Manage Storage in Linux [Guided]
- Search Linux Manpages by Using the Command Line [Guided]
- Search for Files by Using Wildcards [Guided]
- Sort Files [Guided]
- Labs+Linux System Administration — 19 labs 🔒 StationX Labs+
- Assign Environment and Shell Variables in Linux [Guided]
- Automate Administration Tasks by Using Linux Shell Scripts [Guided]
- Can You Configure Advanced Permissions in Linux? [Expert]
- Can You Configure Kickstart Installations in Linux? [Advanced]
- Can You Configure a Yum Repository in Linux? [Advanced]
- Can You Create a Scheduled Linux Backup Script? [Advanced]
- Can You Manipulate Data and Create a Shell Script in Linux ? [Expert]
- Can You Perform Command-Line Tasks by Using Shell Operators and a Shell Script? [Advanced]
- Can You Perform a Network Vulnerability Assessment by Using Nmap? [Advanced]
- Can You Use Linux Command-Line Tools to Simplify Administration Tasks? [Advanced]
- Control Data Streams in Linux [Guided]
- Create and Manage Linux Users and Groups [Guided]
- Edit Data by Using Linux Command-Line Tools [Guided]
- Getting Started with Linux System Administration Tasks [Getting Started]
- Manage Services in Linux [Guided]
- Perform Conditional Decision Making in a Linux Shell Script [Guided]
- Perform Linux Command-Line Operations by Using Boolean and Arithmetic Operators [Guided]
- Perform Linux Command-Line Operations by Using File Test and Relational Operators [Guided]
- Simplify Linux Administration Tasks by Using Xargs [Guided]
Free resources
Step 3 — Exploitation and privilege escalation
The core exam skill, on both platforms.
31 labs
Learn
- CourseCovered in Offensive Security Certified Professional (OSCP) Training — exploitation and escalation sections 🔒 StationX Unlimited
Practise
- Labs+Operating System Exploits — 11 labs 🔒 StationX Labs+
- Can You Exploit Windows with Metasploit and Code Analysis? [Advanced]
- Can You Exploit Windows? [Advanced]
- Can You Find Flaws with OSINT and Vulnerability Scanning? [Advanced]
- Can You Perform Open-source Intelligence (OSINT)-Gathering Operations? [Expert]
- Discover and Exploit Targets by Using Metasploit [Guided]
- Exploit Common Windows Flaws [Guided]
- Exploit Flawed Code [Guided]
- Gain Remote Access to a Windows System [Guided]
- Perform Open System Intelligence (OSINT) Gathering [Guided]
- Perform Post-Exploit Activities [Guided]
- Schedule and Perform Network Vulnerability Scans [Guided]
- LabsPentesting and Network Exploitation — 15 labs 🔒 StationX Unlimited
- Basics of Metasploit
- Client-Side Exploitation with Social Engineering
- Cybersecurity Testing with Core Impact
- Evasive Maneuvers and Post Exploitation
- Intro To Linux - Backing Up, Compression, and Scheduling
- Intro to Linux - Routing and SSH Tunnels
- Linux Exploitation
- Network Miner
- Open Source Password Cracking
- Pentesting & Network Exploitation - Linux Target Analysis Labs
- Pentesting & Network Exploitation: DMZ Exploitation
- Pentesting & Network Exploitation: LAN Exploitation
- Pentesting & Network Exploitation: Windows Target Analysis Labs
- Post Exploitation and Pivoting
- Windows Exploitation
- LabsLinux x64 Binary Exploitation — 5 labs 🔒 StationX Unlimited
Free resources
Step 4 — Web attack chains
Get a foothold through the web layer.
27 labs
Learn
- CourseCovered in Offensive Security Certified Professional (OSCP) Training — web attack sections 🔒 StationX Unlimited
Practise
- LabsAdvanced Web Application Exploitation — 14 labs 🔒 StationX Unlimited
- Web 201 - Lab 1: Recon Tools
- Web 201 - Lab 2.1: Detecting and Exploiting Hard to Find SQL injections
- Web 201 - Lab 2.2: Advanced Sqlmap
- Web 201 - Lab 2.3: Manual Blind SQL Injection
- Web 201 - Lab 2.4: NoSQL Injection
- Web 201 - Lab 3.1: Cross Site Scripting Filter Evasion
- Web 201 - Lab 3.2: Exploiting Misconfigured CORS
- Web 201 - Lab 4: Advanced OS Command Injection
- Web 201 - Lab 5: Advanced Local File Inclusion
- Web 201 - Lab 6: Advanced CSRF
- Web 201 - Lab 7.1: XXE to Obtain Arbitrary Files
- Web 201 - Lab 7.2: Out of Band XXE Attacks
- Web 201 - Lab 8: Server Side Request Forgery
- Web 201 - Lab 9: Insecure Deserialization in Python and Java
- LabsIntroduction To OWASP Top Ten — 13 labs 🔒 StationX Unlimited
- OWASP Top Ten 2025 - A01 Broken Access Controls
- OWASP Top Ten 2025 - A02 Security Misconfiguration
- OWASP Top Ten 2025 - A03 Software Supply Chain Failures
- OWASP Top Ten 2025 - A04 Cryptographic Failures
- OWASP Top Ten 2025 - A05 Injection
- OWASP Top Ten 2025 - A06 Insecure Design
- OWASP Top Ten 2025 - A07 Authentication Failures
- OWASP Top Ten 2025 - A08 Software or Data Integrity Failures
- OWASP Top Ten 2025 - A09 Security Logging & Alerting Failures
- OWASP Top Ten 2025 - A10 Mishandling of Exceptional Conditions
- OWASP Top Ten 2025 - Capstone
- OWASP Top Ten 2025 - Capstone (pt.1)
- OWASP Top Ten 2025 - Capstone (pt.2)
Free resources
Step 5 — Exploit development
Understand what you are running, not just that it worked.
7 labs
Learn
- CourseCovered in Offensive Security Certified Professional (OSCP) Training — exploit-development sections 🔒 StationX Unlimited
Practise
- LabsExploit Development — 1 labs 🔒 StationX Unlimited
- LabsPython for Cybersecurity Tool Development — 6 labs 🔒 StationX Unlimited
Free resources