OSCP / OSCP+ · PEN-200
The OSCP is OffSec's flagship hands-on penetration testing certification and one of the most respected — and most feared — credentials in offensive security. This is not a multiple-choice test: you spend nearly 24 hours actually breaking into live machines, then a further 24 hours writing a professional report. A pass opens doors to red-team, pentest, and security-engineering roles; a fail costs a four-figure retake and weeks of lost momentum. This page breaks down exactly how the exam is built, scored, and proctored — and how to get it done right.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How the OSCP exam is built — at a glance
3 + 3
Three independent standalone hosts plus a three-machine Active Directory set. You enumerate, exploit, and escalate to capture a proof file from each.
23h 45m
A near-24-hour, continuously proctored block to compromise as many targets as possible and collect the local.txt and proof.txt files that prove access.
+24h
After the lab closes you get 24 hours to submit a professional penetration-test report. A perfect compromise with a missing or sloppy report still fails.
The exam is scored out of 100 points and you need 70 to pass. Each of the three standalone machines is worth 20 points (60 total), and the Active Directory set is worth 40 points as a chain. Under the current OSCP+ format there are no course-based bonus points — every point must be earned on the exam itself.
For every machine you compromise you must capture screenshots, commands, and the proof file from the target, then write them up clearly enough for a reviewer to reproduce. The report is graded for completeness and reproducibility — missing steps or unverifiable claims can cost you the points you earned in the lab.
The point split across the exam targets — bars show each target's share of the 100 points
Three independent hosts, 20 points each. Each requires service enumeration, finding and exploiting a foothold vulnerability, then a privilege-escalation path to root or SYSTEM. Linux and Windows targets both appear.
A three-machine domain, scored as a chain. You start from a provided low-privilege credential (an "assumed breach"), then pivot host-to-host — 10 points for the first machine, 10 for the second, and 20 for compromising the Domain Controller.
The skills under test span the full kill chain: enumeration, web and service exploitation, buffer-overflow-style memory corruption, password attacks, lateral movement, and privilege escalation on both Linux and Windows. Because the AD set is worth 40 points as a unit, many candidates who clear the standalone boxes still fall short — domain compromise is where most attempts are won or lost.
How you sit the exam — and what OffSec watches on test day
There is no test center. You schedule a slot, then connect over a VPN from your own computer into OffSec's exam environment, where the target machines live. You use your own Kali setup and tools, which makes the exam realistic — but also means your environment, connection, and stamina are entirely on you.
A live OffSec proctor monitors you continuously for the full 23h45m through your webcam and a shared screen. Before the exam unlocks you complete an identity check, a webcam room scan, and a system check. The proctor can see everything you do, so the exam tests genuine skill under sustained observation.
A valid, unexpired government photo ID whose name matches your OffSec account. The proctor verifies it on camera before connecting you to the VPN.
A webcam room scan, a clear workspace, and continuous screen sharing. Only approved tools are allowed — no automated exploitation frameworks beyond the documented limits.
You may take breaks, but you must notify the proctor and stay within view of the camera when you return. Managing fatigue across a near-24-hour window is part of the challenge.
The OSCP is built for working and aspiring offensive-security pros
No formal gatekeeping — but one of the hardest exams in IT
Difficulty: The OSCP is widely considered one of the toughest entry-to-mid-level security certifications. The "try harder" philosophy means there are no hints and no partial credit for getting close — you either capture the proof file or you don't. Most candidates invest several months of lab practice, and first-attempt fails are common. That sustained pressure is exactly what our help is designed to manage.
The OSCP is a brutal, near-24-hour practical with a four-figure retake cost on the line. Exam Assist pairs you with a vetted offensive-security specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: just an honest feasibility answer and a verified result before you settle.
Tell us your scheduled exam date, your OffSec plan (PEN-200 bundle or standalone), and your current skill level. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and the exam's proctoring constraints and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with an OSCP specialist who maps the work around the standalone boxes, the Active Directory chain, and the report deliverable — discreetly and confidentially.
You only pay once your passing result is confirmed by OffSec. No verified result, nothing owed.
Tell us your exam date and target, and get an honest, no-obligation feasibility answer first.
Straight answers about the OSCP exam
Book your help and compare sibling security exams
Pair with a vetted offensive-security specialist on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Book your exam CEHEC-Council's broad, knowledge-based hacking certification — a common stepping stone or alternative to the OSCP's hands-on approach.
View exam GPENSANS/GIAC's penetration testing certification — another respected pentest credential, with a proctored exam format.
View exam GXPNAn advanced GIAC certification covering exploit development and advanced penetration testing — a natural next step after the OSCP.
View examGet expert OSCP help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.