Skip to content
Macksofy Technologies
OSEP — Evasion Techniques & Breaching Defenses (PEN-300)
OffSec
OSEP / PEN-300
Hands-on certification bootcamp
OSEP / PEN-300Professional

OSEP — Evasion Techniques & Breaching Defenses (PEN-300)

Bypass EDRs. Breach modern defenses.

OSEP is the natural step after OSCP for aspiring red-team operators. Process injection, custom shellcode, EDR bypass, advanced AD exploitation — Macksofy's bootcamp uses real CrowdStrike, SentinelOne and Defender environments.

90-day OffSec lab + 48-hour exam 18 modules Hybrid · Macksofy mentorship + OffSec course
In short

What is the OSEP certification?

The Offensive Security Experienced Penetration Tester (OSEP, OffSec) is an advanced credential in evading defences, bypassing antivirus/EDR, and compromising hardened Active Directory environments. Macksofy runs an OSEP exam-prep bootcamp for experienced pentesters in India.

What you’ll be able to do

Outcomes — concrete, measurable.

Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.

SKILL GRAPH · 4 CAPABILITIES
01 / 04
Skill 01 · Engineering

Build custom payloads that bypass commercial EDRs

Status
Unlocked
Position
1/4
Category
Engineering
Up next · skill 02
Execute process injection, hollowing and reflective DLL loading
This unlocks roles like
  • Red Team Operator₹25–40 LPA
  • Adversary Emulation Engineer₹20–35 LPA
Who it’s for

Is OSEP right for you?

  • OSCP holders moving into red team
  • Senior penetration testers
  • Adversary emulation engineers
Before you start

What we assume you know

  • OSCP or equivalent practical experience
  • C# / PowerShell scripting comfort
Curriculum

18 modules. 90-day OffSec lab + 48-hour exam.

Search modules and topics, and switch between Split and Track views to see how every module flows into the next.

Modules
18
Topics
59
    • Windows API & PE format internals
    • x64 calling conventions
    • Writing tooling in C# and PowerShell
    • VBA macro payloads
    • DDE attacks
    • Excel 4.0 macros (XLM)
    • JScript / VBScript payloads
    • HTA & WSF payload delivery
    • ScriptControl abuse
    • CreateRemoteThread + LoadLibrary
    • Reflective DLL loading
    • Process hollowing
    • Thread-local-storage callbacks
    • Static signature analysis
    • PE structure modification
    • Custom packers
    • Dynamic / behavioural evasion
    • AMSI bypass techniques
    • ETW patching
    • AppLocker bypass paths
    • WDAC bypass
    • Living-off-the-land binaries (LOLBINs)
    • Domain fronting concepts
    • Proxy / outbound NTLM authentication
    • DNS tunneling
    • Persistence on Linux endpoints
    • Loadable kernel module abuse (concept)
    • Pivoting from Linux
    • Restricted desktop escapes
    • Citrix / RDP breakouts
    • Group-Policy enforcement bypass
    • LSASS dumping techniques
    • DPAPI secrets
    • Credential Guard considerations
    • Mimikatz advanced workflows
    • Pass-the-hash / pass-the-ticket
    • Overpass-the-hash
    • Token impersonation
    • WMI, WinRM, PsExec, DCOM
    • SSH agent forwarding abuse
    • Trust relationships on Linux
    • Pivoting via misconfigured services
    • xp_cmdshell exploitation
    • Linked-server attacks
    • Trustworthy database abuse
    • MSSQL Kerberos attacks
    • Kerberos delegation — unconstrained, constrained, RBCD
    • Shadow Credentials (msDS-KeyCredentialLink)
    • ADCS attacks (ESC1-ESC11)
    • Forest & domain trust attacks
    • End-to-end goal-based engagement
    • EDR-bypass case studies
    • MITRE ATT&CK mapping of TTPs
    • Live bypass walkthroughs
    • Custom payloads in real EDR environments
    • Detection-engineering handoff
    • Two mock exams with mentor review
    • Time-allocation playbook
    • Professional report deliverable
18 modules · 90-day OffSec lab + 48-hour exam
Tools you’ll operate

The same toolkit our consultants use on real engagements.

Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.

Tooling stack
Cobalt StrikeSliverMythicBloodHoundMimikatzRubeusImpacketCustom C# / PowerShell tooling
Career outcomes

What roles open up after you complete this.

RoleSalary bandExperience
Red Team Operator₹25–40 LPA5+ years
Adversary Emulation Engineer₹20–35 LPA4+ years
Placement support

We don’t promise jobs. We open doors.

Macksofy's placement desk works directly with 80+ hiring partners across India and the UAE. Resume coaching, mock interviews and direct intros included.

  • 1:1 resume + LinkedIn rewrite with our hiring desk
  • Mock interviews with active practitioners
  • Direct intros to BFSI, fintech and Big-4 partners
  • UAE placement support (Dubai, Abu Dhabi)
FAQ

Things students ask before enrolling.

Yes — OSEP demands deep Active Directory knowledge, custom C# / PowerShell tooling and an EDR-bypass mindset. Most successful candidates have 1+ year of pen-test experience post-OSCP and run their own tooling on real engagements.
Standard OffSec PEN-300 + 90-day lab + exam bundle is ~₹1,70,000. Through Macksofy the same official bundle — course, 90-day lab and exam voucher — is ₹1,45,000 (15% off, EMI available). The Macksofy red-team bootcamp with EDR-bypass labs and mentor support is a separate add-on, quoted on top.
Yes — our lab includes CrowdStrike Falcon, SentinelOne and Microsoft Defender for Endpoint test instances. Students work through documented bypasses and write detection-engineering hand-offs at the end.
Yes — the OSEP curriculum plus Macksofy bootcamp cover Cobalt Strike (where the licence permits), Sliver and Mythic. We focus on tradecraft (BOFs, sleep masks, malleable C2) rather than tool button-mashing.
Red Team Operator (₹25–40 LPA), Adversary Emulation Engineer (₹20–35 LPA) and Senior Pen-Test Lead (₹30–45 LPA) at 4–6+ years. UAE bands add 30–40% premium. Common employers: BFSI red teams (HDFC, ICICI), Big-4 (Mandiant, PwC, EY, KPMG), product security at Microsoft / Atlassian / Razorpay, and ADCB / Mashreq red teams in the UAE.
OSEP is OffSec's vendor-controlled red-team cert with a 48-hour practical exam — strongest brand for hiring. CRTO (ZeroPoint) is excellent C2 / OPSEC training but lab-style assessment. CRTE (Altered Security) is laser-focused on AD. Macksofy recommends OSEP if you can only pick one; CRTO/CRTE pair well as supplements.
Strongly recommended but not strictly enforced. OSEP assumes you can already pen-test confidently end-to-end and read / write tooling. Without OSCP-level experience, the OSEP labs become overwhelming.
Yes — OSEP is the most-cited red-team credential in UAE banking-sector job descriptions, alongside CRTO and SANS GXPN. ADCB, Mashreq, Emirates NBD and ADGM-licensed firms actively recruit OSEP-certified consultants.
Common paths: (1) OSED → OSMR for vulnerability research; (2) GXPN / GREM for SANS-track red teamers; (3) bug-bounty specialisation with OSWE; (4) Macksofy's senior consulting track for adversary-emulation leadership roles.
Yes — live online OSEP cohorts pan-India plus corporate red-team bootcamps in Delhi, Bengaluru, Hyderabad, Pune, Gurugram and Dubai.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements