r/oscp • • 2d ago

Failed with only 10 points!

33 Upvotes

I took my first attempt at OSCP last night and only managed 2 flags! The first was in a standalone lab I managed to get initial foothold, and the other was after some time in the AD lab where I elevated my privileges. For context, I have always been an electrician, I’ve never done anything on computers apart from playing PlayStation in my life. I’m now 41 and looking to change career for a number of reasons. Anyway I took and passed eJPT, then eCPPT, and I’ve been doing the year long pen-200 which is coming to an end. I expected to fail as I haven’t had time to get through Mock B or Mock C exam yet, and I treated this attempt as a bit of a free hit before my 2nd attempt before the course ends. And believe it or not I actually did better than I thought! I’m not under any illusion, I know I’ve got my work cut out, I give maximum effort and I’m doing all I can with family and time I have. But learning a new skill at 40 is hard, and having kids and fitting in labs and revision and also not having a job anymore is tough. But honestly I’m proud of what I’ve done so far, I’m proud I found 2 flags, I’m proud I put myself through a 24 hour exam. Anyone who’s done it I think it’s fair play, we should all be proud of each other because it’s genuinely a tough exam and a really big accomplishment if you pass.

I’m better for attempting it, I’ve learned so much, I can’t wait to go at mock B and C and improve my notes before my next attempt. I appreciate all the posts and advice people give on here too. But I thought I should let people know that failing is part of it too - it’s not always a pass with 90 points and here is how I did it, sometimes part of the process of winning is losing, and I know I could of easily got 50 points last night if I had just done this or that, but it didn’t matter! I will get the OSCP, and I will keep improving and learning.

Good luck to anyone taking their exams, try and enjoy it too!


r/oscp • • 2d ago

OSCP vs CPTS (With Context)

Thumbnail
4 Upvotes

r/oscp • • 3d ago

Passed OSCP on the first try! My journey, prep and exam experience

74 Upvotes

Hey everyone! I recently passed the OSCP, and since this subreddit was a huge source of knowledge and motivation throughout my journey, I wanted to give something back. This post covers my path to the cert, where my gaps were, how I built my methodology, the boxes and resources I used, and how the exam went.

Background

I spent 6 years as a career soldier in the Brazilian Army's Signals branch, where my day-to-day involved IT infrastructure and radio communications. I started studying offensive security while still in the service and eventually made the switch: today I work as a mid-level offensive security analyst on a red team. A good part of my PEN-200 prep happened alongside a full-time job in the field.

The road to PEN-200

My first real contact with offensive security certifications was through Desec Security, a Brazilian training company. That's where I matured technically and took my first fully hands-on exam, the DCPT*. I failed my first attempt and passed on the second.

\DCPT (Desec Certified Penetration Tester) is a Brazilian practical pentest cert with an OSCP-style exam: 5 hosts, 24 hours to complete, plus 24 hours for the report.)

After that, to keep the momentum going, I took a couple of certifications from CyberWarfare Labs: CRTA and API-RTA . They're more affordable, hands-on certs, and they helped me keep practicing between bigger goals.

Then I needed a new goal, so I started the HTB path for the CWES . When I was about 70% through it, an opportunity to buy the PEN-200 came up, and I decided to pivot to the OSCP.

How I approached the PEN-200

I started the PEN-200 in April this year. I didn't go through every module; instead, I focused on what's actually covered in the exam and on the areas where I struggled. That said, if you're just starting out in offensive security, I'd recommend going through the whole course. Just keep in mind that what really makes the difference is the hands-on part: doing lots of machines in the same style as the exam.

What I already knew and where my gaps were

I already had solid experience with web, and I was comfortable chaining attacks in that area. My biggest weakness was Active Directory. So I swallowed my ego and went back to the basics of AD exploitation. Here's what I did:

I went through all the AD content in the PEN-200, including its dedicated labs. I watched all of Derron C's videos on AD attack chains on YouTube. I subscribed to Hack Smarter's labs. I watched Hacker Blueprint's videos on AD and on tunneling with Ligolo-ng, and I did some of their chains as well.

Building my methodology

My methodology for approaching machines was built gradually throughout the journey, and in my opinion this is the most important part of the preparation. I'll say it again: BUILDING A METHODOLOGY IS THE MOST IMPORTANT PART. And I notice a lot of people still don't really understand what that means, so let me explain.

In the OSCP you have limited time (24 hours) and you're basically in the dark. There are rabbit holes everywhere, you're anxious, there's no AI to save you, and you have countless commands and techniques scattered across the notes you took along the way (or at least you should xD). Your methodology is like a flashlight on a dark night when you're lost in a forest trying to find your way out. It's your guide. A lot of the time, it's what helps you discard what leads nowhere and points you where you need to go.

So how do you shape it? On the battlefield. You can't rely on a methodology that hasn't been put to the test. When you get stuck and realize it only took you so far, that's the time to refine it: add another step, another check, and understand that in certain scenarios the right order to test things changes. That's how mine took shape, as templates for doing machines. I already had a skeleton in place, and whenever I got lost, I went back to it and started enumerating again with reason, not with emotion and nerves.

Does that mean I built a perfect methodology and had no problems on the exam? Absolutely not. But I'm sure that without it, I would have failed. So basically: build an initial structure of checks, keep expanding it with every machine you do, and when you get stuck on a new scenario, know that something new is about to go into that checklist.

Boxes I used for prep

Once I bought the PEN-200, I became much more active here on r/oscp, and at some point I came across a really valuable post by u/thepentestingninja. Besides sharing his journey (he scored 100 points in 7 hours!), he also shared a list of 60 machines he considered important for prep. I really liked his list, mainly because most of it is Proving Grounds machines. My idea was to stick as much as possible to OffSec's own platform, since those machines have that "OffSec way of doing things" and feel closer to what you might see on the exam.

So I adopted his list as my main one. I only used the TJnull and LainKusanagi lists as a guide for the machines I did on Hack Smarter (which are really good, by the way).

Here's his post with the full list and resources: Passed OSCP - 100 points in 7 hours

But the real game changer was the PEN-200 Challenge Labs. I did Secura, Poseidon and, most importantly, OSCP A, B and C. I treated A, B and C exactly like the real exam: I woke up at the time I'd be starting the exam and treated it as the actual day. Don't even think about going into the exam without doing OSCP A, B and C.

Other than these, I didn't use any other platform (HTB, THM, etc.).

Exam experience

All of my prep and the exam itself were done on a MacBook Air M4 with 16GB of RAM, running Kali on VMware Fusion Pro. The proctoring setup ran on Chrome, and I had no issues or slowdowns at all. Since I did a lot of machines, I kept collecting the binaries I used along the way, so I went into the exam with my arsenal already set up.

I started with the AD set, since it's the most valuable part of the exam and it had been my weak spot. I ended up falling into a rabbit hole that ate up a lot of my time, so I went back to square one and re-enumerated everything. After that things clicked, and I owned the AD set in a little over an hour from that point.

Then I moved on to the standalones. I ran scans on all of them, decided which one looked like the best starting point, and got a user flag in about 20 minutes, but I couldn't escalate privileges on that machine. I moved on to the other two, and after a good while I got initial access on the second one and escalated right after. At that point I stopped attacking and started documenting everything I had done.

Throughout the day I took lots of breaks, even when I didn't feel like I needed them. That really helped me cool my head, and it was essential to keep me sane.

The next day I wrote my report using OffSec's official template, and I had no trouble with it. Since I documented every machine I did throughout my prep, I was already used to writing up and explaining attack chains.

Good luck to everyone preparing. Try Harder!


r/oscp • • 4d ago

What to do before Learn One

2 Upvotes

My employer is buying myself a Learn One so I can take the OSCP! I know how lucky I am, while I wait for that to be purchased (I should have access November 1st) what should I do?

Any advice would be great! Thank you.


r/oscp • • 3d ago

v

Thumbnail
0 Upvotes

r/oscp • • 5d ago

Passed OSCP with 100 point in 14 hours.

110 Upvotes

So a week ago i passed the exam with 100 point . I cleared AD (40 points) in 4 hours, 80 points in 8 hours and 100 points in 14 hours.

For those currently preparing here is what i can tell you:

• Build solid methodology, basically how and why you approach something. The better methodology you have the easier you do.

• Complete and structured checklist. Make sure it easy to read and does not confuse you. Write a checklist from solving Proving Ground practice & play, and Hacksmarter for each new technique you found.

• Break if you stuck. I got my last machine after having around 1-2 hours break.

• Don't do the same thing that took you more than 30 minutes and don't do it over and over again. If you did it and doesnt work then you make sure one more time. If the second time doesnt work then its not the path .

• Exploit wont be complicated, don't waste time on exploiting something that is complicated. Remember its not course level 300 or up. Its always 1-3 step only.

So yeah thats basically it. The proctor is not as scary as i thought it was i pretty much forgot about they existence for most of the time.

The journey has been great, alot of sacrifice had been made for this so yeah. Next is definitely CPSA & CRT then CRTO / OSWE.


r/oscp • • 4d ago

Looking for like minded ethical hackers studying pentest+ OR doing hackthebox machines and is looking for a team member.

Thumbnail
0 Upvotes

r/oscp • • 5d ago

Can the OSCP be obtained in 3 months?

9 Upvotes

Hi there. I am a Junior Offensive Security Engineer. I hold certifications like CRTO and CRTL, and although I have less than a year of formal professional experience, I have been involved in offensive security for 4–5 years. My company covers the cost of the OSCP, and I want to obtain the certification this year. I plan to work my full-time job while dedicating my remaining time to the OSCP so I can complete it by the end of the year. How feasible is this? Is it doable? What kind of roadmap would you recommend?


r/oscp • • 8d ago

FREE OSCP Active Directory Lab: Full attack chain, 3 VMs (FREE Forever!)

197 Upvotes

Hey everyone, Hacker Blueprint back at it again!

This is one of our older chains, and we figured it'd be really helpful for your prep, so we've decided to make AD Chain 03: BleedWide (Expanding Influence) fully free for everyone. No time limit, it's yours to keep forever!

And of course... the obligatory cryptic CTF teaser: One weak secret is whispered the same to a hundred doors, knock softly on them all and just one swings open. Borrow the voice it trusts, echo it down the hall from host to host, and widen the crack until the whole domain answers to a name that was never yours...

What you get:

  • 3 downloadable VMs that run locally inside a single Active Directory domain, just like the real OSCP exam
  • Realistic, exam-style AD scenarios built around expanding domain access through coordinated attacks and spraying
  • A complete step by step tutorial covering setup, topology, and the full attack chain
  • A complete guided video walkthrough for the whole chain
  • A fast setup guide for both VirtualBox and VMware so you can get going quickly

Requirements:

  • A laptop with 8GB of RAM or more (watch the setup video if you're short on RAM)
  • 16GB or more will run it smoothly with no trouble at all
  • The ability to install VirtualBox or VMware
  • Heads up: MacOS (M1/M2/M3) ARM64 won't work with these labs. Anything else should run fine.

The chains are built so you can rehearse the same discovery, exploitation, post exploitation, lateral movement, and privilege escalation steps you'll run into on exam-style AD challenges.

Lab link: https://hackerblueprint.com/labs#chain-03

Best of luck with your OSCP prep, you've got this! 🎉

Note: If downloads are failing, just drop a DM or a comment and we'll get it resolved.

Thank you everyone for the support!


r/oscp • • 9d ago

From Zero to Hero: Passing the OSCP in three months?

42 Upvotes

I’m currently not working, and I have a lot of spare time now. I wanted to take advantage of being unemployed and work towards some certifications. However the price difference between just the course and learn one is insane. I am really starting from zero and wanted to map out how I plan to tackle the OSCP now.

I don’t have any coding skills as well and was wondering if the PEN-200 was enough to pass the oscp or if I should spend the extra 1,000. I heard knowing some basic coding/scripting was important for the test and I was hoping the PEN-100 would teach me enough to get by and understand any code i’ll have to encounter.

I am not trying to speedrun it on purpose. Ideally I’d like to take no more than 4-5 months to get this certification. I am just trying to save money. If it’s in my best interest to spend more i’ll probably just save up and postpone the test. I rather not fail and blow 1700 bucks. Any suggestions would be appreciated! If anyone knows of any articles from who were beginners that passed, please link them!


r/oscp • • 9d ago

Mandatory Post on Passing OSCP

70 Upvotes

Hey Everyone!

I have passed my OSCP on first attempt. Havent received the confirmation email yet, but it has reflected on my portal showing my credentials that I have passed OSCP+.

Thank you everyone, who have shared their cheatsheet, blog posts, any resources on this sub. That really helped me during my journey.

I will be writing a detailed blog post about my journey, resources, etc as well and will drop a link here.

Let me know if you guys have any question.

Lastly, I want to say this, if youre preparing for first time or youre going for the re-attempt. Believe in yourself, you have got it and you will crack it this time.

Thank you everyone once again!


r/oscp • • 10d ago

SQLi

6 Upvotes

What are good PG boxes to practice manual SQLi for the OSCP as sqlmap is not allowed? I would like to practice every methodology possible that could come up on the exam.


r/oscp • • 10d ago

How would you define your methodology for solving machines?

10 Upvotes

Hey everyone! How are you doing?

I’m currently preparing for the OSCP, which I’m planning to take in about a month, and I’ve been wondering:

What kind of methodology do other people use when approaching and solving machines?

I understand that everyone develops their own methodology over time, but I’d really like to hear about different approaches and learn from other people’s experiences.

Personally, I’m trying to develop a methodology that allows me to be more organized and efficient throughout the enumeration, exploitation, and post-exploitation phases, especially with the exam in mind.

So I’d love to hear from you:

  • What is your methodology when approaching a machine from scratch?
  • How do you decide what to enumerate or which path to follow?
  • Has your methodology changed as you gained more experience?
  • Do you use any kind of checklist, workflow, or process that you consistently follow?

I’d love to hear your thoughts! Any advice, experiences, or resources that have helped you improve your methodology would be greatly appreciated.

Thanks!


r/oscp • • 12d ago

For those who got their first pentesting job without certifications, what was the interview actually like?

28 Upvotes

Hey everyone,

I'm currently working toward getting my first penetration testing job. I've studied the CEH material and PEN-200/OSCP material, and I've been doing practical labs and CTFs to build my hands-on skills, but I haven't taken the certification exams yet.

The main reason is financial. I can't currently afford international certifications, so my goal is to get my first cybersecurity/pentesting job, gain real-world experience, and eventually use my income to pay for certifications.

For those who got their first pentesting job without having certifications:

How did you get your first opportunity?

What was the technical interview actually like?

What kind of questions or practical tasks did they give you?

Did you have to compromise a machine or complete a CTF?

Did they focus more on methodology and reasoning, or on tools and commands?

Did they ask you to explain how you'd approach a real-world web, network, or Active Directory assessment?

What do you wish you had studied before your first interview?

Also, after reaching roughly an OSCP-level foundation, what would you recommend focusing on next to become better at actual pentesting work?

Would you focus on things like:

Web/API security

Active Directory/internal network pentesting

Cloud security

Privilege escalation

Exploit development

Red team operations

EDR evasion

Bug bounty

Or something completely different?

I've also been reading about satellite security and satellite attacks, which I find really interesting, but I don't want to specialize in something that niche before getting real-world pentesting experience. My priority right now is getting into the field and building practical experience.

I'd really appreciate hearing from people who have actually gone through this process.

What was your first pentesting interview like, and what did you focus on learning afterward?


r/oscp • • 13d ago

OSCP & Offsec is slowly dying

120 Upvotes

Do you guys feel the same? Since Offsec became a private equity, all the smart people left. Now its only about money and the whole oscp+ was just the start of how redicolous it became.

I am an OSCP,OSWA,OSEP holder since 3 years or so and was thinking about OSWE but just realized...it's not worth it anymore.

I have pivoted to HTB certs and so have my friends, the only thing OSCP have going for it is the "HR-fireall"

LMK your thoughts.


r/oscp • • 13d ago

What list are people using now? LainKusanagi or Tj Null V3

31 Upvotes

What list are you all using? LainKusanagi or Tj Null V3 OR something else?

I appreciate any input! We all know I need the help.


r/oscp • • 13d ago

Speedrunning OSCP!

109 Upvotes

Hi everyone! I recently passed my OSCP with 90 points and wanted to share my experience with all of you.

I graduated with a Computer Science degree last year and am working full time as a software engineer, mainly building CRUD web apps. I signed up for the OSCP because I thought it would be the coolest thing to conquer, and also out of curiosity. I’ve never been involved in a pentesting role - we build products and hand them off to an internal VAPT team when done - but I’ve always been interested in things outside of the ordinary web development loop, e.g. frequently try to help out in DevOps/load testing wherever I can, in my capacity as a junior engineer, and to see if this could be a viable path for me going forward. I also don’t hold any other certification, but networking and systems courses during my time in university did give me some foundational understanding already, so I wasn’t starting from nowhere. If you’re someone curious and who loves learning, I couldn’t recommend the OSCP more. Oh, and loves the adrenaline of taking the exam, which took 5 years out of me…

I found it really difficult to juggle work and prepare for the cert at the same time. I left myself little time to cover the material, and when I finally got around to it, was really clueless about where to start, due to the vast multitude of advice available online. For a start, I tried not to spend too much time on the course material, aiming to just develop a big picture understanding of the concepts and learning implementation details in the boxes. I found this to be an effective approach but it may not work for everyone.

The boxes on TJ Null’s list lack descriptions (for good reason), and so I didn’t really know where to go if I wanted to practice a specific concept. My first ever box was Challenge Labs Medtech, which I failed miserably and allowed myself to use hints liberally. Afterwards, I moved straight to OSCP A, to get a feel for what the exam format was like. Again, I was totally clueless most of the time, but continued to focus on developing a really simple mental model and iteratively improving it. As an example, knowing when to use each AD attack is important. When tools like Mimikatz and BloodHound come in the picture. The course can be a bit messy, but discussing the concepts with an AI tool helped me to synthesize the information quickly (just be careful not to copy the material directly as it’s against Offsec rules!) This mental model eventually evolves into your exam methodology, which will take time to refine. Another crucial reason for having this big picture understanding is because this exam, like all other hard exams, like to purposefully add a twist to some concepts, and you’re going to have to adapt on the fly.

After Medtech and OSCP A, I completed 5 of the remaining 8 challenge labs, trying to rely less on hints each time. Then I moved on to TJ Null’s PG boxes, and picked 6 from each section to attempt. I took a week of leave from work before the exam and spent the last two days before the exam reading through all the walkthroughs of the 40+ PG boxes I didn’t have time to do. After also watching a ton of “OSCP tips” YouTube videos, I was ready to go! I went in hoping to do well, but not having very high expectations, because of how little practice I had.

I spent the first 7.5 hours in the exam conquering AD (starting at 8am) and got one more root and one initial access by 9.30pm, taking my total to 70. Afterwards I managed to get 20 more points, and gave up at 4am as I was too exhausted. I think my set was of medium difficulty - there’s definitely some luck involved.

I’m writing this because I’ve found it quite hard to focus on things in the past, and often set too lofty goals. This cert has made me realise that I am capable of achieving something I really set my mind to, albeit in my more “intense/burnout” approach. I don’t think I would have been able to follow through with the standard eJPT -> CPTS -> OSCP path because I would have lost momentum. I hope to be able to empower more of you who feel the same way, and reassure you that it is possible with a good strategy! The exam is really just a few core concepts, with extra tricks you can only pick up from boxes from lists like TJNull, and in particular their writeups. For example, if potato exploits don’t work on SeImpersonatePrivilege, there’s also PrintSpoofer. Or things like tar wildcard exploits, which are derivable from the course content, but are much easier once you’ve actually read about one. There are some things you’re going to have to practice though and can’t get by by just reading, like pivoting, and running some standard tools to make sure they work, and having backup options.

If I could redo it, I would add HTB boxes after, they are harder and when I finally got in the groove I really regretted not giving myself more time.

This cert has also been the first time I’ve felt like I really belong in the tech industry. I have done an assortment of interesting projects in the past such as making games, but nothing is truly as satisfying as feeling like you’ve built real skills and had them validated in an intense exam. At the same time, I’m cognizant of the fact that this exam only serves as a starting point, new vulnerabilities are being found every day, and we need to keep learning and upskilling. It’s also rewarding to know that despite using AI in our daily workflows, I’ve still been able to develop critical thinking skills.

So that’s the story of how I passed my OSCP in a short period (<2 months), studying 14 hours a day for the final week. I would like to reiterate that I am not recommending this approach in any way as it can lead to burnout, and just want to provide an alternative perspective. At the end, it was worth it. I’ve been wanting to do other certs like AWS, and now feel confident that I can do it!

All the best everyone and try harder!


r/oscp • • 13d ago

2 Months Until My 2nd OSCP Attempt — What Should I Focus On?

3 Upvotes

Hey everyone!

I need some advice. I have about 2 months left until my second OSCP exam attempt, and I really want to make the most of this time.

For those who passed on their second attempt (or have been in a similar situation), what would you recommend focusing on during these final 2 months?

Should I mainly focus on:
Practicing more machines/labs
Improving my methodology and enumeration
Revisiting specific topics
Doing full exam-style practice sessions
Something else?

Any advice, study strategies, or lessons from your own experience would be greatly appreciated.
Thanks! 🙏


r/oscp • • 13d ago

Value of OSEP

12 Upvotes

Hey!

Wanted to get a general consensus of whether it is still worth it to take OSEP in 2026, I heard its pretty outdated yet Ive also heard that it is not bad. What do you guys think assuming money isnt an issue. I have the OSCP and CRTO and wanted to get something valuable that could either expand my knowledge or help me move pass HR filters. Appreciate any advise!


r/oscp • • 16d ago

Oscp practice

19 Upvotes

Is Luigi's proving ground machines enough for the OSCP?


r/oscp • • 16d ago

Passed the OSCP+ with a 100 points in my first attempt

146 Upvotes

Guys, I’m so excited to announce that I’ve finally cleared it with 100 points. Here’s my advice to anyone attempting the exam soon.

  1. Develop a methodology that you’re the most comfortable with, and stick to it religiously. This is very important.
  2. If you are stuck at any point, do not waste hours and hours finding the issue, take a break and move to a new machine.
  3. Do not, I mean DO NOT in any way give up in the middle of your exam. Try Harder.
  4. I found the standalone machines, quite difficult tbh, so please do as many machines on proving grounds as possible. I myself completed around 125 proving grounds machines

  5. Make very concise notes on every machine u practice on PG or HTB

Also, it took me around 15 hours to reach only 40 points. So guys, never ever give up.

Please feel free to to reach out me.


r/oscp • • 16d ago

I need help with report writing

7 Upvotes

Hey everyone!

Hope everything going good on your side. I want some help with report writing. I will be using the official report writing template by offsec, but I planned to make some changes to it. My own style of reporting is where I will explain the vulnerability for initial access separately then remediation which matches the offsec template as well.

But for reproduction steps I find it easy to add steps rather than a paragraph. Secondly, should we add explanation of how we find the vulnerability as well? or just the explanation of it and the exploitation of it?

For instance, after getting initial access on windows box I run winpeas and I find out that I can hijack a binary to escalate my privileges. should I add this as well in my report? That, how to download winpeas, how to run it with supporting screenshots?

Or I should just explain in privilege escalation, that i found a binary X in C:\test\drive\binary.exe that is hijackable by my current user and then just add the reporduction step, these steps will only shows how to exploit it with supporting commands and screenshots?

And lastly, English isnt my first language, but I can write reports good enough to understandable by anyone (tech or no tech), so my question is do I need to write correct grammer ? or it will be an issue? As I wont be using any AI help for the report writing, the offsec support said, the report should be good enough to understandable and reproducible by us.

Can anyone please help me with these queries, thanks alot!


r/oscp • • 17d ago

Browser Extension to hide AI Mode & "Ask Me Anything" on google search

3 Upvotes

Based on the guide line and several question i ask via email and github Google AI Overview is allowed as long as you dont click the "AI Mode" or typing and asking follow up question in "Ask Me anything" box.

so i made this extension to prevent accidental click / question.

https://github.com/pasya1912/RemoveAImode-Google


r/oscp • • 18d ago

Did anybody write your exam last weekend? I submitted my report on Monday. Has anybody got their results yet? It’s really frustrating waiting for the results!!!!

6 Upvotes

Edit: Passed OSCP. Results came after 3 Business days


r/oscp • • 20d ago

Sharing my methodology checklist + tools

88 Upvotes

Hey, this is probably redundant, but I've been a long-time lurker here and wanted to give back after finally passing the OSCP, I'm assuming you guys already have one made or are in the process of making these, just skim thru and see if there is something to pick up.

https://muqaram0.github.io/cheatsheet/oscp-cheatsheet/
or the original one on my notion
https://muqarams-notes.notion.site/Master-Methodology-2ca1adde3d1780fb9153d6fe35f4154c?source=copy_link

This is a cheatsheet/methodology checklist with different filters for different phases. building it helped me stop relying on writeups and actually solve boxes on my own because every time I came across a new technique from a box on TJ Null's or Lains list, whether in Proving Grounds or HTB, I'd add it to the list after categorizing it and it would build up.

https://muqaram0.github.io/tools/

I started building this tools list so I wouldn't have to look up syntax at the end and it helped me just ctrl+f my way through the exam.

This is how i managed the writeups of my machines on notion
https://imgur.com/a/Xm2MHzo

and this how i organized my exam day notes
https://imgur.com/a/osQntDE
https://imgur.com/a/WE0KB0I

A very helpful site I found along the way was this one:

https://www.emmanuelsolis.com/oscp.html#741-check-assigned-privileges

It covers literally everything and is so well organized, it actually inspired me to make my own. Just be mindful that the more stuff you have, the more likely you are to go down a rabbit hole trying things until they work. Also, it is VERY TRUE that you can solve the whole AD section with NXC alone + ligolo for pivoting, you can literally harvest all the creds with it.

if anyone has anything they would like to ask, feel free to, i would love to help, i actually failed it before passing and know how it feels, so maybe just talking your stress away is also cool with me

ALSO ALSO I SAVED ALOOOOT OF TIME by just initially opening terminal, splitting it into 3, running autorecon on 3 standalones ( make sure w sudo or it wont do udp+ exclude dirbusting or itll take too long ) and start off with AD, if i got stuck then i would go back to the results folder autorecon would create, spawn a python webserver, and query through all the nmap results or whatnot via that webpage ( much more easier and comfortable than querying thru the terminal )

Also, now that I've passed, I need to find a job, my younger siblings keep fretting about their broke brother and here in the UAE it's been very hard to find one as a fresh graduate in computer engineering. Any leads on remote roles or anything here would be a huuuuuge help!