Skip to content
Macksofy Technologies
OSCP — Penetration Testing with Kali Linux (PEN-200)
OffSec
OSCP / PEN-200
Hands-on certification bootcamp
OSCP / PEN-200ProfessionalPopular

OSCP — Penetration Testing with Kali Linux (PEN-200)

Try harder. Pass with proof.

OSCP is the gold standard for hands-on penetration testing — a 24-hour live exam against a real network plus a professional report. Macksofy runs a 60+ hour instructor-led bootcamp alongside OffSec's official PEN-200 curriculum, with mentor support that continues until you pass.

12-week bootcamp + 90-day OffSec lab + 24-hour exam 25 modules Hybrid · Mentor-led with full OffSec lab access
In short

What is the OSCP certification?

The Offensive Security Certified Professional (OSCP, OffSec) is the industry's benchmark hands-on penetration-testing certification, earned by compromising machines in a 24-hour proctored lab exam. Macksofy runs an intensive OSCP exam-prep bootcamp with 60+ hours of mentor-led labs in India.

What you’ll be able to do

Outcomes — concrete, measurable.

Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.

SKILL GRAPH · 5 CAPABILITIES
01 / 05
Skill 01 · Offensive

Compromise standalone Windows, Linux and Active Directory machines under exam pressure

Status
Unlocked
Position
1/5
Category
Offensive
Up next · skill 02
Develop and modify public exploits, write Bash/Python tooling on the fly
This unlocks roles like
  • Penetration Tester₹12–20 LPA
  • Senior Pen-Test Consultant₹20–30 LPA
  • Red Team Operator₹25–40 LPA
Who it’s for

Is OSCP right for you?

  • Working pen-testers ready to level up to elite credentials
  • Bug bounty hunters who want methodology rigor
  • Security engineers moving into red-team or AppSec roles
  • CEH holders ready for the next challenge
Before you start

What we assume you know

  • Strong networking + Linux fundamentals
  • Comfort with Bash and basic Python scripting
  • CEH or 6+ months of hands-on pen-test practice strongly recommended
Curriculum

25 modules. 12-week bootcamp + 90-day OffSec lab + 24-hour exam.

Search modules and topics, and switch between Split and Track views to see how every module flows into the next.

Modules
25
Topics
82
    • OffSec report standards
    • Note-taking discipline
    • Markdown / Pandoc workflow
    • Passive recon — DNS, WHOIS, certificate transparency
    • Active recon — DNS brute, SMB / SMTP enumeration
    • Service banner grabbing
    • Nessus essentials
    • Nmap scripting engine for vuln checks
    • Manual triage of scanner output
    • HTTP request / response
    • Burp Suite proxy & repeater
    • Common architectures
    • Directory traversal
    • File inclusion (LFI / RFI)
    • File-upload bypass
    • Command injection
    • Manual in-band SQLi
    • Blind & time-based SQLi
    • sqlmap automation
    • DB-specific syntax (MySQL, MSSQL, Postgres)
    • Macro-enabled documents
    • Microsoft Office attack vectors
    • Browser-side payloads
    • ExploitDB workflow
    • GitHub research patterns
    • Identifying applicable CVEs
    • Modifying public PoCs to fit target
    • Recompiling binaries
    • Cross-compiling Windows from Linux
    • Static signature avoidance
    • Encoders & packers
    • Custom payloads with msfvenom variants
    • Hashcat & John the Ripper
    • Kerbrute & password spraying
    • SSH / RDP / WinRM brute-forcing
    • Hash dumping (Mimikatz)
    • Service / registry / scheduled-task abuse
    • Token impersonation
    • AlwaysInstallElevated, UAC bypass
    • WinPEAS / PrivescCheck workflow
    • SUID / SGID exploitation
    • Sudo misconfigurations
    • Cron-job abuse
    • Kernel exploits (carefully)
    • LinPEAS workflow
    • Local & remote SSH tunneling
    • Dynamic SOCKS proxying
    • rinetd, socat
    • Chisel HTTP tunneling
    • ligolo-ng pivoting
    • DNS tunneling concepts
    • Module structure & search
    • msfvenom payload generation
    • Meterpreter sessions & post-modules
    • AD objects, OUs, trusts
    • BloodHound + PowerView mapping
    • LDAP queries
    • AS-REP roasting
    • Kerberoasting
    • Password spraying with confidence
    • NTLM relay / coercion (PetitPotam)
    • Pass-the-hash / pass-the-ticket
    • WinRM, WMI, PsExec, smbexec, dcomexec
    • DCSync & golden / silver tickets
    • AWS CLI fundamentals
    • IAM enumeration
    • S3 / EC2 / Lambda discovery
    • Pacu modules
    • Privilege escalation paths
    • Lambda & metadata-service abuse
    • S3 misconfiguration exploitation
    • End-to-end engagement walkthrough
    • Note-taking → exploitation → reporting
    • RBCD & shadow credentials
    • ADCS abuse (ESC1-ESC8)
    • Custom AD lab walkthroughs
    • Exam playbook & time allocation
    • Two full 24-hour mock exams with mentor review
    • Report deliverable rubric
    • Official PDF + video curriculum
    • OffSec Discord community
    • Challenge labs (OSCP A / B / C)
25 modules · 12-week bootcamp + 90-day OffSec lab + 24-hour exam
Tools you’ll operate

The same toolkit our consultants use on real engagements.

Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.

Tooling stack
Kali LinuxNmap (advanced)Burp Suite ProMetasploitBloodHoundPowerViewMimikatzImpacket suiteResponderCrackMapExecEmpire / CovenantPowerSploitWinPEAS / LinPEASHashcatChiselligolo-ng (pivoting)
Career outcomes

What roles open up after you complete this.

RoleSalary bandExperience
Penetration Tester₹12–20 LPA2–4 years
Senior Pen-Test Consultant₹20–30 LPA4–6 years
Red Team Operator₹25–40 LPA5+ years
Application Security Engineer₹18–28 LPA3–5 years
Placement support

We don’t promise jobs. We open doors.

OSCP-certified hires are in heavy demand. Our placement desk works with BFSI giants, Big-4 consulting and product companies who actively seek OSCP holders.

  • 1:1 mentorship until you pass — including post-bootcamp lab guidance
  • Mock interviews modeled on real BFSI / Big-4 hiring loops
  • Direct intros to hiring partners (HSBC, PwC, EY, Mahindra, fintechs)
  • Career coaching for Indian + UAE markets
FAQ

Things students ask before enrolling.

The official OffSec PEN-200 + 90-day lab + exam bundle is around ₹1,70,000 (USD 1,749). Through Macksofy the same official bundle — course, 90-day PWK lab and exam voucher — is ₹1,45,000 (15% off the standard listing), with EMI across 3 / 6 / 12 months. Macksofy's 60+ hour instructor-led bootcamp and mentor-until-pass support are a separate add-on priced on top of that, so ask for a combined quote. There is no free or pirated path that grants a real OSCP credential.
OSCP+ is OffSec's rebrand of OSCP that took effect in late 2024 and is the current exam in 2026. The new format dropped the buffer-overflow box, expanded the Active Directory set (full AD chain worth ~40 points) and replaced bonus lab points with a CPE-based 3-year recertification. Macksofy's bootcamp is fully aligned to the OSCP+ exam — see our blog post on what changed.
They are different products. CEH (EC-Council) is breadth-first knowledge and a multiple-choice exam — good for HR filters. OSCP+ is a 24-hour hands-on practical against a real network and a professional report — what hiring managers actually trust for pen-test roles. Most senior pen-testers in India list both on their CV but credit OSCP for the offer.
CPTS is a strong free-tier alternative that has gained credibility, but it is still less recognised by Indian / UAE BFSI hiring managers than OSCP. OSCP also has the advantage of 11+ years of brand equity and OffSec's vendor mapping to DoD 8570/8140 roles. Pick OSCP if you want the credential that opens doors fastest.
No. OSCP+ assumes solid Linux + networking + scripting fundamentals. Pure beginners should start with OffSec SEC-100 (OSCC), CEH or our SOC Analyst track for ~3–6 months before attempting OSCP.
Yes — OSCP holders consistently land Pen-Tester / Red Team / AppSec roles in BFSI (HSBC, ICICI, HDFC, Kotak), Big-4 consulting (PwC, EY, Deloitte, KPMG), product companies (Microsoft, Salesforce, Atlassian) and fintechs. Salary band: ₹12–20 LPA at 2–4 years experience, ₹20–30 LPA at 4–6 years. UAE roles add a 30–40% premium.
Realistic timeline: 3–6 months of dedicated study after the bootcamp for working professionals; 2–3 months for full-time learners. Macksofy provides structured weekly milestones, two mock 24-hour exams and AD lab time inside the 12-week bootcamp window.
Across our 2024–25 cohorts, 78% of students who completed the bootcamp and the recommended 90-day lab schedule passed within their first attempt; 94% pass within two attempts. We continue free mentor support until you pass.
OffSec's standard policy applies — exam retakes are paid (~$249). Macksofy provides free post-fail mentorship, a 1:1 weak-area review and a guided remediation plan so attempt #2 is a different conversation.
Absolutely. OSCP is mandated or strongly preferred by UAE banking regulators, ADGM- and DIFC-licensed entities, telcos (e2, du) and major consulting firms. Our UAE alumni are placed at Mashreq, ADCB, Emirates NBD, PwC ME, EY ME and Big-4 advisory units across Dubai and Abu Dhabi.
Three common paths: (1) Web specialisation — OSWA → OSWE; (2) Red team — OSEP (PEN-300); (3) Exploit dev / vulnerability research — OSED → OSMR. We help you pick at the end of the OSCP bootcamp based on your strengths and target roles.
Yes — Macksofy runs live online OSCP cohorts pan-India and corporate-batch delivery on-site in Delhi, Bengaluru, Hyderabad, Pune, Chennai, Kolkata, Ahmedabad, Gurugram, Noida and Dubai. The Mumbai BKC HQ runs weekend in-person bootcamps for learners willing to travel.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements