?

OSCP Review

cert Yep, I finally did it! and what better than to yap a lot about it..?

My Journey

Even though my first two attempts at conquering Pen-200 was a bust, I managed to get it right on my 3rd attempt. To be quite frank, I did feel a bit ashamed to fail the first times... On my first attempt, I had done around 30+ HTB machines. The second - almost all the machines from LainKusanagi's famous OSCP prep list. The third time I had redid those PG boxes and some more (including HackSmarter, which I highly recommend!). I recognised that each attempt I did that there was something that was missing and that something was what caused me to fail.

The first time, I honestly didn't really get a feel for the exam environment since I had only done HTB machines. I reeeally underestimated the value and relevance of PG Practice; HTB follows a different kind of mindset that you have to get into to do them. I believe this is a reason that a lot of people who are used to doing labs on other platforms or other certs struggle with the OSCP - it just forces you to properly enumerate - which I'll get into later.

The second time, I realised that even after all the labs I did that I didn't really build a proper methodology - and honestly, before now I adopted a really chaotic way of going about things. My mind worked like that, and probably the downfall of this way of enumerating OSCP boxes is that without proper notes, a proper checklist, a way to go about things that you end up trying things over and over again without realising - or overlooking VERY simple things.

The third time, I managed to keep both of those factors in check, and compromised the AD set in about 4 hours and got 80 points in 8. I used the remaining time to work on my report.

The Actual Review

I often hear the debate that OSCP is not as worth it now, or that the material is not as good as some other certificates (CPTS or PNPT, namely). To these I would personally disagree, unsponsored opinion and all, not because OSCP is so HR wanted (let's put that aside, and simply consider the knowledge value) but because OSCP teaches you a discpline that's just not there in any other certificate.

To some degree, this just makes it harder to take so people often have to retake and spend money to retake it, but it's also true that the ban on AI and focus on learning manual tools rather than focusing on automatic exploitation forces the average joe to be comfortable with the fundamentals rather than skip 3 steps ahead.

However, I'd agree that the materials in CPTS are more comprehensive. They were a help for me in understanding concepts such as SQLi which are presented in an easier to understand way (what it looks like in the source code, why it happens) rather than just knowing how to do them. It's overkill if you want to use it to pass the OSCP though.

That's not to say the OffSec material isn't bad. It goes from zero to hero and does cover a lot of valuable things. I remember I had technical trouble with the labs before but eh I don't know how relevant that is now because they changed it a lot. I do remember that they were alright.

Along with that, rather than simply use what you learned to pass, you have to go the extra mile to learn how to adapt to things like needing to understand an exploit to fix it on the spot. Try harder is honestly an accurate way to describe it, and from what I've (personally) seen the opportunity to try harder does presents itself most in OSCP compared to other entry level pentest certs.

An observation for people who want to get this certificate - I noticed that a lot of people, even after doing a bunch of PG practice/HTB/etc. machines end up failing their first try (including me), and I read a lot of people who have simply focused on doing the challenge labs passing on their first attempt. 'Course this is pretty anecdotal, but I think it really shows that for the OSCP understanding the way the OffSec structured it is more important than knowing how to do everything and anything. The challenge labs (or OSCP-LK) are honestly a must for this.

Okay Let's Get Technial

Things I couldn't do without include:

General tips:

What's next? Probably CRTO & CRTE. The PPP for CRTO is really just fantastic, massive respect to them.

thumbsup