Skip to content
Macksofy Technologies
OSED — Windows User Mode Exploit Development (EXP-301)
OffSec
OSED / EXP-301
Hands-on certification bootcamp
OSED / EXP-301Professional

OSED — Windows User Mode Exploit Development (EXP-301)

Develop your own Windows exploits.

OSED is the entry point to OffSec's exploit-development track. Reverse engineer real Windows binaries, find vulnerabilities, build working exploits with custom shellcode and ROP chains.

90-day OffSec lab + 48-hour exam 13 modules Hybrid · Macksofy mentorship + OffSec course
In short

What is the OSED certification?

The Offensive Security Exploit Developer (OSED, OffSec) certifies Windows exploit-development skills — stack overflows, bypassing mitigations, and writing custom shellcode. Macksofy runs an OSED exam-prep bootcamp for aspiring exploit developers in India.

What you’ll be able to do

Outcomes — concrete, measurable.

Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.

SKILL GRAPH · 4 CAPABILITIES
01 / 04
Skill 01 · Analysis

Reverse Windows binaries with IDA / x64dbg

Status
Unlocked
Position
1/4
Category
Analysis
Up next · skill 02
Identify exploitable bugs (BoF, format strings, UAF)
This unlocks roles like
  • Exploit Developer₹20–40 LPA
  • Vulnerability Researcher₹25–50 LPA
Who it’s for

Is OSED right for you?

  • Exploit developers
  • Vulnerability researchers
  • Red team developers
Before you start

What we assume you know

  • x86 / x64 assembly familiarity
  • C / C++ basics
Curriculum

13 modules. 90-day OffSec lab + 48-hour exam.

Search modules and topics, and switch between Split and Track views to see how every module flows into the next.

Modules
13
Topics
41
    • WinDbg essentials & commands
    • x86 / x64 register conventions
    • PE format basics
    • Stack & heap layout
    • Vanilla EIP control
    • Bad-character analysis
    • Shellcode payload selection
    • Return-address calculation
    • Structured Exception Handler chain
    • POP-POP-RET technique
    • SafeSEH considerations
    • Static analysis workflow
    • Function navigation & cross-references
    • FLIRT signatures
    • Hex-Rays decompiler basics
    • Egghunter algorithms
    • Optimizing for limited buffers
    • Choosing eggs that survive sanitization
    • Writing assembly shellcode from scratch
    • Position-independent code
    • Encoder / decoder design
    • Identifying vulnerable functions
    • Tracing tainted input
    • Recognizing common vulnerability patterns
    • Data Execution Prevention (NX) introduction
    • Return-Oriented Programming (ROP)
    • Building ROP chains with mona.py
    • Address-Space Layout Randomization
    • Information-leak vulnerabilities
    • Partial / full address overwrite
    • Format-string vulnerability theory
    • Reading arbitrary memory
    • Stack-frame disclosure
    • Writing arbitrary memory with %n
    • Achieving RCE via format strings
    • Three full exploit chains
    • Reverse + exploit + payload chain
    • 48-hour exam preparation
    • Modern Windows targets
    • Bypass-mitigation case studies
    • Mock 48-hour exam
13 modules · 90-day OffSec lab + 48-hour exam
Tools you’ll operate

The same toolkit our consultants use on real engagements.

Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.

Tooling stack
IDA ProGhidrax64dbgWinDbgmona.pyPython (exploit dev)
Career outcomes

What roles open up after you complete this.

RoleSalary bandExperience
Exploit Developer₹20–40 LPA3+ years
Vulnerability Researcher₹25–50 LPA4+ years
Placement support

We don’t promise jobs. We open doors.

Macksofy's placement desk works directly with 80+ hiring partners across India and the UAE. Resume coaching, mock interviews and direct intros included.

  • 1:1 resume + LinkedIn rewrite with our hiring desk
  • Mock interviews with active practitioners
  • Direct intros to BFSI, fintech and Big-4 partners
  • UAE placement support (Dubai, Abu Dhabi)
FAQ

Things students ask before enrolling.

OffSec EXP-301 + 90-day lab + exam bundle is ~₹1,70,000. Through Macksofy the same official bundle — course, 90-day lab and exam voucher — is ₹1,45,000 (15% off, EMI available). The Macksofy bootcamp with CTF practice and exploit walkthroughs, plus mentor support, is a separate add-on, quoted on top.
Significantly harder for most students. OSED requires fluent x86 / x64 assembly, IDA Pro / WinDbg comfort and patience for multi-day reverse-engineering sessions. Plan for 4–6 months of preparation post-OSCP.
Strongly recommended. OSCP+ teaches you to use exploits; OSED teaches you to write them. Without OSCP-level pen-test maturity the EXP-301 lab is overwhelming. Macksofy gates entry to the OSED bootcamp on OSCP completion or equivalent experience.
OSED is OffSec's stamp on Windows user-mode exploit dev — strong, hands-on, mid-cost. SANS GREM is reverse-engineering-focused (malware). SANS GXPN is offensive-security-research-focused with broader scope. OSED has the best price-to-recognition ratio for vulnerability researchers in India.
48-hour proctored hands-on exam against custom Windows binaries. You must reverse-engineer the targets, identify exploitable bugs and deliver working exploits with custom shellcode + ROP chains. A professional report is required.
Exploit Developer (₹20–40 LPA at 3+ years), Vulnerability Researcher (₹25–50 LPA at 4+ years), Senior Reverse Engineer (₹30 LPA+). Common employers: ZSCALER, Microsoft Security, Apple, F-Secure, Palo Alto, Indian VR boutiques and government research orgs.
Two paths: (1) OSMR for macOS specialisation and senior vulnerability-research roles; (2) SANS GREM for malware-RE depth. Bug-bounty hunters often combine OSED with hardware-hacking specialisation.
Both — OffSec's PDF + video curriculum is self-paced over 90 days, and Macksofy adds weekly mentor sessions, exploit walkthrough labs, two mock exams and a 1:1 weak-area review schedule.
Yes — live online OSED cohorts pan-India for working professionals. Most OSED candidates are 3+ years into security careers and prefer the online + 1:1 mentor model.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements