
OSCP — Penetration Testing with Kali Linux (PEN-200)
Try harder. Pass with proof.
OSCP is the gold standard for hands-on penetration testing — a 24-hour live exam against a real network plus a professional report. Macksofy runs a 60+ hour instructor-led bootcamp alongside OffSec's official PEN-200 curriculum, with mentor support that continues until you pass.
What is the OSCP certification?
The Offensive Security Certified Professional (OSCP, OffSec) is the industry's benchmark hands-on penetration-testing certification, earned by compromising machines in a 24-hour proctored lab exam. Macksofy runs an intensive OSCP exam-prep bootcamp with 60+ hours of mentor-led labs in India.
Outcomes — concrete, measurable.
Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.
Compromise standalone Windows, Linux and Active Directory machines under exam pressure
- Penetration Tester₹12–20 LPA
- Senior Pen-Test Consultant₹20–30 LPA
- Red Team Operator₹25–40 LPA
Is OSCP right for you?
- Working pen-testers ready to level up to elite credentials
- Bug bounty hunters who want methodology rigor
- Security engineers moving into red-team or AppSec roles
- CEH holders ready for the next challenge
What we assume you know
- Strong networking + Linux fundamentals
- Comfort with Bash and basic Python scripting
- CEH or 6+ months of hands-on pen-test practice strongly recommended
25 modules. 12-week bootcamp + 90-day OffSec lab + 24-hour exam.
Search modules and topics, and switch between Split and Track views to see how every module flows into the next.
- OffSec report standards
- Note-taking discipline
- Markdown / Pandoc workflow
- Passive recon — DNS, WHOIS, certificate transparency
- Active recon — DNS brute, SMB / SMTP enumeration
- Service banner grabbing
- Nessus essentials
- Nmap scripting engine for vuln checks
- Manual triage of scanner output
- HTTP request / response
- Burp Suite proxy & repeater
- Common architectures
- Directory traversal
- File inclusion (LFI / RFI)
- File-upload bypass
- Command injection
- Manual in-band SQLi
- Blind & time-based SQLi
- sqlmap automation
- DB-specific syntax (MySQL, MSSQL, Postgres)
- Macro-enabled documents
- Microsoft Office attack vectors
- Browser-side payloads
- ExploitDB workflow
- GitHub research patterns
- Identifying applicable CVEs
- Modifying public PoCs to fit target
- Recompiling binaries
- Cross-compiling Windows from Linux
- Static signature avoidance
- Encoders & packers
- Custom payloads with msfvenom variants
- Hashcat & John the Ripper
- Kerbrute & password spraying
- SSH / RDP / WinRM brute-forcing
- Hash dumping (Mimikatz)
- Service / registry / scheduled-task abuse
- Token impersonation
- AlwaysInstallElevated, UAC bypass
- WinPEAS / PrivescCheck workflow
- SUID / SGID exploitation
- Sudo misconfigurations
- Cron-job abuse
- Kernel exploits (carefully)
- LinPEAS workflow
- Local & remote SSH tunneling
- Dynamic SOCKS proxying
- rinetd, socat
- Chisel HTTP tunneling
- ligolo-ng pivoting
- DNS tunneling concepts
- Module structure & search
- msfvenom payload generation
- Meterpreter sessions & post-modules
- AD objects, OUs, trusts
- BloodHound + PowerView mapping
- LDAP queries
- AS-REP roasting
- Kerberoasting
- Password spraying with confidence
- NTLM relay / coercion (PetitPotam)
- Pass-the-hash / pass-the-ticket
- WinRM, WMI, PsExec, smbexec, dcomexec
- DCSync & golden / silver tickets
- AWS CLI fundamentals
- IAM enumeration
- S3 / EC2 / Lambda discovery
- Pacu modules
- Privilege escalation paths
- Lambda & metadata-service abuse
- S3 misconfiguration exploitation
- End-to-end engagement walkthrough
- Note-taking → exploitation → reporting
- RBCD & shadow credentials
- ADCS abuse (ESC1-ESC8)
- Custom AD lab walkthroughs
- Exam playbook & time allocation
- Two full 24-hour mock exams with mentor review
- Report deliverable rubric
- Official PDF + video curriculum
- OffSec Discord community
- Challenge labs (OSCP A / B / C)
The same toolkit our consultants use on real engagements.
Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.
What roles open up after you complete this.
| Role | Salary band | Experience |
|---|---|---|
| Penetration Tester | ₹12–20 LPA | 2–4 years |
| Senior Pen-Test Consultant | ₹20–30 LPA | 4–6 years |
| Red Team Operator | ₹25–40 LPA | 5+ years |
| Application Security Engineer | ₹18–28 LPA | 3–5 years |
We don’t promise jobs. We open doors.
OSCP-certified hires are in heavy demand. Our placement desk works with BFSI giants, Big-4 consulting and product companies who actively seek OSCP holders.
- 1:1 mentorship until you pass — including post-bootcamp lab guidance
- Mock interviews modeled on real BFSI / Big-4 hiring loops
- Direct intros to hiring partners (HSBC, PwC, EY, Mahindra, fintechs)
- Career coaching for Indian + UAE markets
Things students ask before enrolling.

OSEP — Evasion Techniques & Breaching Defenses (PEN-300)
Bypass EDRs. Breach modern defenses.

OSWE — Advanced Web Attacks & Exploitation (WEB-300)
White-box web exploitation. Source-code-driven.

OSED — Windows User Mode Exploit Development (EXP-301)
Develop your own Windows exploits.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
