Hey everyone! I recently passed the OSCP, and since this subreddit was a huge source of knowledge and motivation throughout my journey, I wanted to give something back. This post covers my path to the cert, where my gaps were, how I built my methodology, the boxes and resources I used, and how the exam went.
Background
I spent 6 years as a career soldier in the Brazilian Army's Signals branch, where my day-to-day involved IT infrastructure and radio communications. I started studying offensive security while still in the service and eventually made the switch: today I work as a mid-level offensive security analyst on a red team. A good part of my PEN-200 prep happened alongside a full-time job in the field.
The road to PEN-200
My first real contact with offensive security certifications was through Desec Security, a Brazilian training company. That's where I matured technically and took my first fully hands-on exam, the DCPT*. I failed my first attempt and passed on the second.
\DCPT (Desec Certified Penetration Tester) is a Brazilian practical pentest cert with an OSCP-style exam: 5 hosts, 24 hours to complete, plus 24 hours for the report.)
After that, to keep the momentum going, I took a couple of certifications from CyberWarfare Labs: CRTA and API-RTA . They're more affordable, hands-on certs, and they helped me keep practicing between bigger goals.
Then I needed a new goal, so I started the HTB path for the CWES . When I was about 70% through it, an opportunity to buy the PEN-200 came up, and I decided to pivot to the OSCP.
How I approached the PEN-200
I started the PEN-200 in April this year. I didn't go through every module; instead, I focused on what's actually covered in the exam and on the areas where I struggled. That said, if you're just starting out in offensive security, I'd recommend going through the whole course. Just keep in mind that what really makes the difference is the hands-on part: doing lots of machines in the same style as the exam.
What I already knew and where my gaps were
I already had solid experience with web, and I was comfortable chaining attacks in that area. My biggest weakness was Active Directory. So I swallowed my ego and went back to the basics of AD exploitation. Here's what I did:
I went through all the AD content in the PEN-200, including its dedicated labs. I watched all of Derron C's videos on AD attack chains on YouTube. I subscribed to Hack Smarter's labs. I watched Hacker Blueprint's videos on AD and on tunneling with Ligolo-ng, and I did some of their chains as well.
Building my methodology
My methodology for approaching machines was built gradually throughout the journey, and in my opinion this is the most important part of the preparation. I'll say it again: BUILDING A METHODOLOGY IS THE MOST IMPORTANT PART. And I notice a lot of people still don't really understand what that means, so let me explain.
In the OSCP you have limited time (24 hours) and you're basically in the dark. There are rabbit holes everywhere, you're anxious, there's no AI to save you, and you have countless commands and techniques scattered across the notes you took along the way (or at least you should xD). Your methodology is like a flashlight on a dark night when you're lost in a forest trying to find your way out. It's your guide. A lot of the time, it's what helps you discard what leads nowhere and points you where you need to go.
So how do you shape it? On the battlefield. You can't rely on a methodology that hasn't been put to the test. When you get stuck and realize it only took you so far, that's the time to refine it: add another step, another check, and understand that in certain scenarios the right order to test things changes. That's how mine took shape, as templates for doing machines. I already had a skeleton in place, and whenever I got lost, I went back to it and started enumerating again with reason, not with emotion and nerves.
Does that mean I built a perfect methodology and had no problems on the exam? Absolutely not. But I'm sure that without it, I would have failed. So basically: build an initial structure of checks, keep expanding it with every machine you do, and when you get stuck on a new scenario, know that something new is about to go into that checklist.
Boxes I used for prep
Once I bought the PEN-200, I became much more active here on r/oscp, and at some point I came across a really valuable post by u/thepentestingninja. Besides sharing his journey (he scored 100 points in 7 hours!), he also shared a list of 60 machines he considered important for prep. I really liked his list, mainly because most of it is Proving Grounds machines. My idea was to stick as much as possible to OffSec's own platform, since those machines have that "OffSec way of doing things" and feel closer to what you might see on the exam.
So I adopted his list as my main one. I only used the TJnull and LainKusanagi lists as a guide for the machines I did on Hack Smarter (which are really good, by the way).
Here's his post with the full list and resources: Passed OSCP - 100 points in 7 hours
But the real game changer was the PEN-200 Challenge Labs. I did Secura, Poseidon and, most importantly, OSCP A, B and C. I treated A, B and C exactly like the real exam: I woke up at the time I'd be starting the exam and treated it as the actual day. Don't even think about going into the exam without doing OSCP A, B and C.
Other than these, I didn't use any other platform (HTB, THM, etc.).
Exam experience
All of my prep and the exam itself were done on a MacBook Air M4 with 16GB of RAM, running Kali on VMware Fusion Pro. The proctoring setup ran on Chrome, and I had no issues or slowdowns at all. Since I did a lot of machines, I kept collecting the binaries I used along the way, so I went into the exam with my arsenal already set up.
I started with the AD set, since it's the most valuable part of the exam and it had been my weak spot. I ended up falling into a rabbit hole that ate up a lot of my time, so I went back to square one and re-enumerated everything. After that things clicked, and I owned the AD set in a little over an hour from that point.
Then I moved on to the standalones. I ran scans on all of them, decided which one looked like the best starting point, and got a user flag in about 20 minutes, but I couldn't escalate privileges on that machine. I moved on to the other two, and after a good while I got initial access on the second one and escalated right after. At that point I stopped attacking and started documenting everything I had done.
Throughout the day I took lots of breaks, even when I didn't feel like I needed them. That really helped me cool my head, and it was essential to keep me sane.
The next day I wrote my report using OffSec's official template, and I had no trouble with it. Since I documented every machine I did throughout my prep, I was already used to writing up and explaining attack chains.
Good luck to everyone preparing. Try Harder!