OSCP (PEN-200) Training & Certification
Offensive Security Certified Professional – Hands-On Penetration Testing Course
The OSCP (PEN-200) Training by Macksofy Trainings is an advanced, hands-on penetration testing program designed to prepare professionals for the globally respected Offensive Security Certified Professional (OSCP) certification by Offensive Security.
This course focuses on real-world ethical hacking, not theory. You will learn how to identify, exploit, and document vulnerabilities across live systems using industry-standard penetration testing methodologies and Kali Linux.
OSCP (PEN-200) is a globally recognized hands-on penetration testing certification by Offensive Security, validating real-world ethical hacking and red team skills through a 24-hour practical exam.
Why Choose OSCP (PEN-200) Training with Macksofy?
OSCP is considered one of the most challenging and respected certifications in cybersecurity. At Macksofy, we bridge the gap between theory and real-world attack simulation.
What makes our OSCP training different:
- 100% hands-on penetration testing labs
- Real-world attack scenarios (not simulated MCQs)
- Expert OSCP-certified mentors
- Focus on exam strategy + report writing
- One-to-one doubt-clearing & mentorship support
- Designed for first-attempt success
What You Will Learn in OSCP (PEN-200)
This course equips you with practical skills used by professional penetration testers, red teamers, and security consultants.
Core Skills You Will Master:
- Penetration testing methodology (PTES & real-world workflows)
- Information gathering & reconnaissance (active and passive)
- Network scanning & enumeration
- Vulnerability identification and exploitation
- Linux & Windows privilege escalation techniques
- Active Directory attack fundamentals
- Buffer overflow exploitation (exam-relevant)
- Web application exploitation basics
- Post-exploitation & lateral movement
- Professional penetration testing report writing
Tools & Technologies Covered in OSCP (PEN-200) Training
You will gain hands-on experience with industry-standard tools, including:
- Kali Linux
- Nmap, Netcat, Wireshark
- Burp Suite
- SQLmap
- Metasploit (selective usage as per OSCP guidelines)
- Custom Bash & Python scripts
- Manual exploitation techniques (core OSCP focus)
OSCP (PEN-200) Exam Overview
The OSCP exam is a 24-hour fully practical penetration testing exam, followed by 24 hours for report submission.
Exam Highlights:
- Real vulnerable machines (no MCQs)
- Minimum 70 points required to pass
- Exploit machines and document findings
- Clear, professional penetration testing report is mandatory
This course prepares you exactly for the exam environment, including stress handling and time optimization.
Who Should Take OSCP (PEN-200) Training?
This course is ideal for:
- Ethical Hackers & Penetration Testers
- SOC Analysts looking to move into Red Team roles
- Cybersecurity Professionals
- Bug bounty hunters
- Network & System Administrators
- CEH / CPENT certified professionals upgrading skills
Prerequisites for OSCP (PEN-200)
To succeed in OSCP, you should have:
- Basic understanding of networking (TCP/IP)
- Familiarity with Linux command line
- Fundamental scripting knowledge (Bash / Python preferred)
- Strong problem-solving mindset
CEH or equivalent knowledge is recommended but not mandatory.
Career Opportunities After OSCP
OSCP certification opens doors to high-value cybersecurity roles such as:
- Penetration Tester
- Red Team Engineer
- Security Consultant
- Ethical Hacker
- Vulnerability Researcher
- Cybersecurity Analyst
OSCP professionals are in high demand globally, with premium salary packages in India and abroad.
Why OSCP Is One of the Most Respected Certifications
- Fully practical, no theoretical shortcuts
- Recognized globally by employers
- Proves real hacking capability
- Preferred certification for penetration testing roles
Frequently Asked Questions (FAQs)
What is OSCP (PEN-200) Training?
OSCP is a hands-on penetration testing certification by Offensive Security that tests real-world hacking skills through a 24-hour practical exam.
Is OSCP difficult?
Yes. OSCP is challenging, but with proper training, labs, and strategy, it is achievable on the first attempt.
How long does OSCP preparation take?
Typically 2–4 months of focused practice, depending on prior experience.
Is OSCP worth it in India?
Absolutely. OSCP is highly valued by Indian and global cybersecurity employers.
Do you provide lab practice?
Yes. Our training emphasizes extensive lab practice aligned with OSCP exam expectations.
Enroll in OSCP (PEN-200) Training Today
If you are serious about building a career in penetration testing and ethical hacking, OSCP is the certification that sets you apart.
👉 Enroll now with Macksofy Trainings and prepare to crack OSCP with confidence.
Related Reading
- OSCP Training in Mumbai — Complete 2026 Guide
- OSCP vs OSWE: Detailed Comparison
- OSEP vs OSCP: Red Team Certification Comparison
- OSCP Certification Cost in India (2026)
- OffSec Learn One India — Pricing + ROI
- Top 10 Penetration Testing Tools in 2026
Want accelerated OSCP prep? Macksofy also runs a focused 5-day intensive — see the OSCP+ Bootcamp for cohort schedules and mentor-supported lab time.
Related Macksofy Certifications
Candidates who want Kali fundamentals locked down before PEN-200 often start with the Kali Linux Certified Professional (KLCP / PEN-103). Once OSCP is in hand, the natural OffSec progression is OSEP training and certification in India (PEN-300) for advanced AD and evasion work.
Toolkit covered in the OSCP (PEN-200) bootcamp
OSCP examiners reward methodology over tool memorisation, but they assume fluency with the standard offensive Linux toolchain. The Macksofy OSCP exam-prep bootcamp drills every tool below to the point where command syntax fades into reflex — so you spend exam hours on enumeration logic, not on man-pages.
- Nmap (full NSE) + masscan. Service enumeration, version detection, and parallel sweeps for the OSCP lab subnets. We cover NSE scripts beyond the defaults (smb-vuln-*, http-enum, ldap-rootdse) and how to chain masscan → nmap for time-boxed exam recon.
- Burp Suite Community. Manual HTTP attack workflows: Repeater chains for IDOR/SSRF, Intruder for fuzzing, the Comparer for response-diffing. Pro is not required for OSCP — we drill the same workflows on Community so cost isn’t a barrier.
- Metasploit Framework (limited use). OffSec restricts Metasploit usage on the exam (one auto-exploit per attempt). We teach msfvenom payload crafting and post-modules so you know when MSF saves time and when manual exploitation is mandatory.
- BloodHound + SharpHound. Active Directory attack-path graphing. Bootcamp covers ingestor flags, custom Cypher queries for shortest-path-to-DA, and ACL abuse chains (GenericAll, GenericWrite, AddSelf, WriteDACL).
- CrackMapExec / NetExec. AD lateral-movement and credential validation across SMB/WinRM/RDP/MSSQL. Includes Kerberos abuse (ASREPRoast, Kerberoasting) and password-spray hygiene.
- Impacket suite. psexec.py, wmiexec.py, smbexec.py, GetUserSPNs.py, secretsdump.py — the AD attack tax. We cover when each is detected vs evaded by Defender + Sysmon.
- Responder + ntlmrelayx. Multicast poisoning, NTLMv2 capture, relay chains to SMB/LDAP/HTTP. Includes the MS08-068 / mitigation-bypass discussion.
- Linux PrivEsc kit (linpeas, pspy, GTFOBins lookups). Local enumeration speed-runs. PEAS suite tuning for the OSCP timebox; pspy for short-lived cron and process leak hunts.
- Windows PrivEsc kit (winPEAS, PowerUp, Seatbelt). Service mis-permissions, unquoted paths, AlwaysInstallElevated, token impersonation. Bootcamp covers the SeImpersonate → PrintSpoofer / GodPotato path that’s recurring on OSCP.
- Buffer-overflow workflow (Immunity Debugger, mona.py, msfvenom). Pattern_create/offset, EIP control, JMP ESP discovery, badchar detection, bind/reverse shellcode generation. Macksofy classroom hours include hands-on OSCP-style BOF practice machines.
- Web-payload arsenal. PHP/ASPX/JSP web-shells, polyglot uploads, command-injection payloads, SSRF/LFI/RFI chains, deserialisation primers (PHP, Java, .NET).
- Tunnel/pivot toolkit. Chisel, ligolo-ng, sshuttle, socat, plink. The bootcamp’s AD lab demands pivoting to internal subnets — we drill all four pivoting tools so you can pick whichever survives the exam network restrictions.
What the Macksofy OSCP lab environment looks like
The bootcamp lab is built to mirror OffSec’s PWK lab topology: an entry subnet of ‘easy’ boxes, a depth subnet of ‘medium’ boxes, and a small Active Directory forest with two trust relationships. You’ll work through it across 12 weeks of mentored sessions plus unmonitored after-hours practice.
- Weeks 1-3 (foundations): Linux/Windows enumeration depth, service abuse on FTP/SMB/SSH/HTTP/MSSQL, password attacks, web-app exploitation primer.
- Weeks 4-6 (privilege escalation): Linux PE (kernel, sudo, capabilities, SUID, NFS) and Windows PE (services, schtasks, AlwaysInstallElevated, JuicyPotato family). Buffer-overflow drills with mona.py.
- Weeks 7-9 (Active Directory): AS-REP roasting, Kerberoasting, NTLM relay, BloodHound path-walking, DCSync, Golden/Silver tickets. Two parallel forests so you get cross-trust attack practice.
- Weeks 10-11 (full chain rehearsals): Mock 24-hour exam attempts on Macksofy-built challenge boxes — the closest available approximation to OSCP exam pressure.
- Week 12 (exam-prep sprint): Report-writing rehearsals against the OffSec report template, time-boxing playbook, retake strategy if a flag is missed.
Total hands-on hours across cohort + after-hours: ~280 hours over the 12-week program. Mentor office hours run twice weekly on Tuesday/Saturday evenings (IST).
OSCP exam structure and the OSCP+ continuous-renewal update
The OSCP exam is a 24-hour hands-on attack window followed by a 24-hour report-writing window (48 hours total). OffSec sets the exam network with five target machines: an AD set (three machines, +40 points proxy/relay/DA path, marked atomically as one chain) and two standalone machines (20 points each, partial credit for local + root). Pass mark is 70/100 — typical pass paths are AD-full + 1 standalone full + 1 standalone local, OR AD-full + 2 standalones full.
Bootcamp exam-day playbook: First hour is enumeration-only (no exploitation tunnels yet) on every target. Hours 2-12 prioritise AD chain (highest point density). Hours 12-18 swing to standalones. Hours 18-24 are buffer time for re-enumeration of any missed footholds. Sleep is non-negotiable — the report window is unforgiving when fatigued.
OSCP+ (introduced late 2024): The OSCP+ designation is a continuous-renewal version of OSCP that requires 40 continuing professional education credits every three years. Pricing and exam content are identical to legacy OSCP; OSCP+ is automatically issued to anyone who passes the current PEN-200 exam. Legacy OSCP holders retain lifetime validity but won’t be issued OSCP+ unless they re-sit.
Retake strategy: If your first attempt comes back short, OffSec lets you retake at the standard exam fee (one attempt at a time, 14-day cooldown). The Macksofy bootcamp includes one post-exam debrief session for any cohort member who needs to retake — we walk through the score breakdown and target the specific machine class (PE vs initial access vs AD pivot) where points were lost.
OSCP career outcomes in the India market — 2026
OSCP is the single most-mentioned cert in Indian penetration-tester JDs. Of 200 sampled India pentest roles in Q1 2026 (Naukri + LinkedIn + Hirist), 78% list OSCP as ‘required’ or ‘strongly preferred’. The credential maps cleanly to TCS/Wipro/Infosys/HCL cyber consulting tracks, Big 4 (Deloitte/EY/PwC/KPMG India), pure-play firms (NotSoSecure, Lucideus, Payatu, K7 Computing, Aujas), and product-security teams at fintech/SaaS unicorns (Razorpay, Cred, Swiggy, Zomato, Atlassian Bangalore, Microsoft IDC, Adobe NCR).
Salary bands (India, 2026):
- 0-2 years + OSCP: ₹8-14 LPA at consultancies, ₹12-18 LPA at product firms.
- 2-5 years + OSCP: ₹16-28 LPA at consultancies, ₹22-38 LPA at product firms / GCCs.
- 5-8 years + OSCP + secondary cert (CRTO/OSCE3/OSEP): ₹32-55 LPA at lead-pentester / red-team-lead roles.
- Bug bounty supplement: Active hunters with OSCP report ₹3-15 LPA from HackerOne/Bugcrowd disclosures.
Average time-to-first-offer after passing OSCP, per recent Macksofy cohort surveys: 6-10 weeks for candidates with 1+ years prior IT/security experience; 12-20 weeks for career-switchers without prior cyber roles. The Macksofy placement cell maintains warm-intro relationships with 40+ India hiring partners; cohort members get direct referral channels during weeks 10-12 of the program.
OSCP vs adjacent certs — when to pick what
OSCP vs CPTS (HackTheBox Certified Penetration Testing Specialist): CPTS is younger, cheaper (~$490 vs OSCP’s ~$1,749), and the exam permits unrestricted Metasploit. It signals strong infrastructure-pentest skills. India recruiter recognition of CPTS is rising but still 10x lower than OSCP — by H2 2026, expect 1-in-10 JDs to accept CPTS as an OSCP substitute. Pick CPTS if you’re early-career, on a budget, and the target employer’s JD doesn’t name OSCP specifically. Pick OSCP if the JD lists it or you want the broadest market acceptance.
OSCP vs PNPT (TCM Security Practical Network Penetration Tester): PNPT is exam-only $399 (no lab subscription), 5-day exam, focuses on internal AD-heavy assessments. Cheaper, faster, externally-graded. Recognition in India is small but growing. Pick PNPT if you have prior AD attack experience and want to validate it inexpensively. OSCP remains the safer recruiter-facing credential.
OSCP vs CRTP (Pentester Academy Certified Red Team Professional): Different scope. CRTP is AD-only and uses MS C2 frameworks (Covenant/Empire/Cobalt-style). OSCP includes Linux/web/buffer-overflow plus AD. Pick CRTP after OSCP as an AD specialisation, not instead of.
OSCP vs eJPT (eLearnSecurity Junior Pen Tester): eJPT is an entry-level tier; takes 1-2 weeks of prep, $200 exam, no lab. Pick eJPT as a stepping-stone before OSCP if you’ve never used Burp / Nmap / Metasploit. Not a substitute for OSCP at hiring time.
Sample bootcamp walkthrough — ‘jeeves’-style AD foothold
To make the methodology concrete, here’s the playbook a Macksofy cohort member runs on a representative classroom box (‘Jeeves’, a Windows AD foothold machine modelled on the well-known HackTheBox retired set):
- Enumeration (10 min): Nmap full-port scan reveals 80 (Jetty), 50000 (Jetty), and 445 (SMB). Jetty fingerprinting flags a Jenkins CI server.
- Initial access (15 min): Jenkins admin console is unauthenticated. Groovy script-console executes Java payload; reverse shell to attacker box.
- User pivot (20 min): Shell runs as SYSTEM but we want domain-context creds. Search desktops for KeePass file (jeeves.kdbx), exfil over web, john-format KeePass2John → hashcat → master password.
- Privilege escalation (10 min): KeePass yields domain creds. SeImpersonate privilege detected → JuicyPotato (legacy) or PrintSpoofer (modern) → SYSTEM persists across sessions.
- Domain pivot (30 min): SharpHound runs against the now-credentialed user. BloodHound shortest-path query reveals user has GenericWrite on a service account → password-reset via Set-DomainUserPassword → service account is Kerberoastable → DA-equivalent shadow-credential attack.
- Report (45 min): Screenshot every step, capture commands, write the OffSec-style executive summary + technical chain + remediation block.
Total time on a familiar box: ~2 hours. The exam variant will be unfamiliar but follows the same shape: enumeration → foothold → user privilege → DA path. Drilling the workflow until it’s muscle-memory is what the Macksofy bootcamp practises.
Readiness checklist before joining the OSCP bootcamp
The bootcamp succeeds for candidates who arrive with the following baseline. Use this as a self-assessment — if you can confidently tick 8+ of 12, you’re ready.
- Comfortable in a Linux terminal — file ops, redirection, find, grep, awk, ssh.
- Can write 50-line Python or Bash scripts (loops, args, file I/O) without copy-paste.
- Understand TCP/UDP, the OSI layers, basic routing, NAT, DNS, HTTP request/response shape.
- Have used Nmap with -sC -sV on a lab box at least once.
- Have used Burp Suite (Community is fine) to intercept and modify a request.
- Can read SQL injection / XSS / CSRF — recognise the bug class from a sink, even if you can’t yet exploit it cleanly.
- Have spun up a VM (VMware/VirtualBox/Hyper-V) and installed Kali Linux from scratch.
- Have rooted at least 3-5 ‘easy’ boxes on HackTheBox, TryHackMe, or VulnHub.
- Understand Windows file paths, services, scheduled tasks, the registry at a basic level.
- Familiar with Active Directory at a concept level — domain, user, group, GPO, DC, the trust idea.
- Can commit 12-15 study hours/week consistently for 12 weeks.
- Have a workstation with 16GB+ RAM (24GB+ recommended for AD lab on local hypervisor).
If you tick fewer than 5, we’ll route you through the ‘OSCP Foundations’ 4-week bridge module before the main cohort starts. The bridge adds ₹15,000 to the program fee and is non-negotiable when prerequisites are thin — students who skip foundations historically fail OSCP on the first attempt at 3x the cohort average.
Frequently asked questions — OSCP bootcamp
Is Macksofy an Offensive Security Authorized Training Partner?
No. Macksofy Trainings runs an independent exam-prep bootcamp for OSCP (PEN-200). We are not an Offensive Security Authorized Training Partner. OffSec exam vouchers, lab subscriptions, and the official PEN-200 courseware must be purchased directly from OffSec.com. Our bootcamp fee covers Macksofy-built lab infrastructure, mentored sessions, and exam-prep methodology only.
How much does the OSCP exam cost outside the bootcamp fee?
OffSec charges approximately USD 1,749 for an OSCP exam attempt bundled with a 90-day lab subscription. Pricing changes — confirm current rates at offsec.com/pricing. The Macksofy bootcamp fee is exclusive of OffSec charges; students purchase the exam voucher and lab subscription directly from OffSec at the appropriate point in the program.
Can I pass OSCP without buying the official OffSec lab?
Not recommended. The Macksofy lab covers the same attack-class breadth as the OffSec PWK lab, but the OffSec exam dial-in process is itself a graded skill — VPN dropouts, target IP rotation, and OffSec’s screenshot-naming convention all matter. The 30 days of OffSec lab time bundled with the exam voucher is for getting comfortable with the test infrastructure, not just for additional practice.
Is Buffer Overflow still on the OSCP exam in 2026?
OffSec removed the dedicated 25-point BOF machine in the early-2023 PEN-200 update. BOF concepts can still appear as part of standalone machine privilege escalation chains, but they’re no longer a single-machine isolated requirement. Our bootcamp keeps a 4-hour BOF practical session because the underlying skills (debugger fluency, shellcode crafting) generalise to other exam classes.
How is the bootcamp structured for working professionals?
Live sessions run Tuesday and Saturday evenings IST (90 minutes each), recorded for catch-up. Lab access is 24/7. Mentor office hours are scheduled around the typical 9-to-7 working day. Most cohort members are working full-time IT/security roles and commit 12-15 hours/week (sessions + lab + reading) for 12 weeks.
Will I get placement assistance if I pass the OSCP?
Macksofy’s placement cell maintains warm-intro relationships with 40+ India hiring partners across consultancies, Big 4 cyber practices, and product-security teams. We run resume-review and mock-interview sessions during weeks 10-12 of the bootcamp. The cell makes direct referrals on request; we do not guarantee placement, and historically 70-80% of cohort members who pass OSCP and apply actively secure a relevant role within 12 weeks of passing.
What happens if I fail the OSCP exam on my first attempt?
OffSec permits retakes at the standard exam fee with a 14-day cooldown. Macksofy includes a post-exam debrief for any cohort member who needs to retake — we walk through the OffSec score breakdown, identify the machine class (initial access, privilege escalation, AD pivot) where points were lost, and target a 4-week focused practice plan before re-sitting. About 25% of first-attempt failures pass on retake within 8 weeks; another 50% pass on the second retake.
How is OSCP different from CEH or Security+?
CEH and CompTIA Security+ are multiple-choice theory exams that test recognition of attacks. OSCP is a hands-on practical exam that tests your ability to execute attacks against a live network and write a professional report. Recruiters use them differently — Security+ is a baseline ‘understands security’ signal; CEH is the EC-Council ATC-pathway signal often required for India government / DSCI / CERT-In adjacent roles; OSCP is the practical-skills signal that gates senior pentest interviews.
Do I need prior hacking-CTF experience?
Helpful but not required. The bootcamp pre-work module includes 4 weeks of foundational labs (Nmap, Burp, basic web vuln classes, Linux/Windows enumeration) for candidates without CTF background. Candidates with HackTheBox or TryHackMe progress (Easy and below rooted) skip the bridge and start with the main cohort directly.
Are the Macksofy lab machines the same as OSCP exam machines?
Absolutely not. The Macksofy lab is independently designed to drill the same attack classes that appear on OSCP — privilege escalation patterns, AD attack chains, web-app exploitation, buffer overflow, post-exploitation. We have no knowledge of current OffSec exam infrastructure and do not, and would not, attempt to mirror it. The lab’s purpose is methodology and reflex-building, not exam-machine memorisation.
Curriculum
- 10 Sections
- 9 Lessons
- 126 Hours
- Module 1: Introduction to Penetration Testing1
- Module 2: Information Gathering & Enumeration1
- Module 3: Vulnerability AssessmentEmploy advanced ethical hacking techniques and tools like Nmap and Shodan to meticulously map target systems, uncover potential entry points, and discover exploitable vulnerabilities.0
- Module 4: Exploitation Techniques1
- Module 5: Privilege Escalation1
- Module 6: Active Directory Basics1
- Module 7: Buffer Overflow Essentials1
- Module 8: Post-Exploitation & Pivoting1
- Module 9: OSCP Exam Preparation1
- Module 10 : Real World Labs1








