
OSED — Windows User Mode Exploit Development (EXP-301)
Develop your own Windows exploits.
OSED is the entry point to OffSec's exploit-development track. Reverse engineer real Windows binaries, find vulnerabilities, build working exploits with custom shellcode and ROP chains.
What is the OSED certification?
The Offensive Security Exploit Developer (OSED, OffSec) certifies Windows exploit-development skills — stack overflows, bypassing mitigations, and writing custom shellcode. Macksofy runs an OSED exam-prep bootcamp for aspiring exploit developers in India.
Outcomes — concrete, measurable.
Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.
Reverse Windows binaries with IDA / x64dbg
- Exploit Developer₹20–40 LPA
- Vulnerability Researcher₹25–50 LPA
Is OSED right for you?
- Exploit developers
- Vulnerability researchers
- Red team developers
What we assume you know
- x86 / x64 assembly familiarity
- C / C++ basics
13 modules. 90-day OffSec lab + 48-hour exam.
Search modules and topics, and switch between Split and Track views to see how every module flows into the next.
- WinDbg essentials & commands
- x86 / x64 register conventions
- PE format basics
- Stack & heap layout
- Vanilla EIP control
- Bad-character analysis
- Shellcode payload selection
- Return-address calculation
- Structured Exception Handler chain
- POP-POP-RET technique
- SafeSEH considerations
- Static analysis workflow
- Function navigation & cross-references
- FLIRT signatures
- Hex-Rays decompiler basics
- Egghunter algorithms
- Optimizing for limited buffers
- Choosing eggs that survive sanitization
- Writing assembly shellcode from scratch
- Position-independent code
- Encoder / decoder design
- Identifying vulnerable functions
- Tracing tainted input
- Recognizing common vulnerability patterns
- Data Execution Prevention (NX) introduction
- Return-Oriented Programming (ROP)
- Building ROP chains with mona.py
- Address-Space Layout Randomization
- Information-leak vulnerabilities
- Partial / full address overwrite
- Format-string vulnerability theory
- Reading arbitrary memory
- Stack-frame disclosure
- Writing arbitrary memory with %n
- Achieving RCE via format strings
- Three full exploit chains
- Reverse + exploit + payload chain
- 48-hour exam preparation
- Modern Windows targets
- Bypass-mitigation case studies
- Mock 48-hour exam
The same toolkit our consultants use on real engagements.
Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.
What roles open up after you complete this.
| Role | Salary band | Experience |
|---|---|---|
| Exploit Developer | ₹20–40 LPA | 3+ years |
| Vulnerability Researcher | ₹25–50 LPA | 4+ years |
We don’t promise jobs. We open doors.
Macksofy's placement desk works directly with 80+ hiring partners across India and the UAE. Resume coaching, mock interviews and direct intros included.
- 1:1 resume + LinkedIn rewrite with our hiring desk
- Mock interviews with active practitioners
- Direct intros to BFSI, fintech and Big-4 partners
- UAE placement support (Dubai, Abu Dhabi)
Things students ask before enrolling.

OSCP — Penetration Testing with Kali Linux (PEN-200)
Try harder. Pass with proof.

OSEP — Evasion Techniques & Breaching Defenses (PEN-300)
Bypass EDRs. Breach modern defenses.

OSWE — Advanced Web Attacks & Exploitation (WEB-300)
White-box web exploitation. Source-code-driven.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
