← Back to list

Everything You Need to Know About OSCP | My Full Review

The only OSCP review you need to get a realistic idea of the exam, what to expect, and how to prepare for it.

Strikoder · 2026-05-17 07:09 · 4 claps · 8.2 min read
#oscp #oscp-preparation #oscp-certification #penetration-testing #offensive-security
Open on Medium ↗

Everything You Need to Know About OSCP | My Full Review

The only OSCP review you need to get a realistic idea of the exam, what to expect, and how to prepare for it.

Table of Contents

**WHOAMI (id) [What Even Is The OSCP?](#4975) [My Experience Before OSCP](#3e18) [LABS](#54e1) [How I Prepared](#3c1c) [My Two Attempts (Deeply explained in the YT video)](#cdc8) [Exam Day](#6a08) [Report & What’s Next?](#d3cf) [Resources](#d878) [Final Thoughts](#5d9b)**

WHOAMI (id)

As I always start my YT videos:

مرحبا جميعا, Hallo zusammen, Всем привет, Hello everyone!

My name is Amin (strikoder), a normal tech enthusiast who studied Computer Science in Moscow, and a while ago moved to Germany, worked across different areas in IT, and recently passed the OSCP/OSCP+/Offensive Security Certified Professional/HR gateway/Try Harder cert & many more.

What Even Is The OSCP?

First of all, for those who don’t know the exam (I envy you), it’s probably the most well known certification in the offensive cybersecurity realm.

It costs a lot of money, time, and effort to pass, and after all of that it’s still considered an entry-level certification in penetration testing (please if you have a dirty mind, google the term and then keep reading) or hacking if you want to call it that.

Come 2–3 years to Berlin and forget

Come 2–3 years to Berlin and forget

My Experience Before OSCP

Let’s get back to experience and knowledge.

I started learning networking and security around April 2025, when I bought the eJPT + ICCA voucher during a huge sale. I took the eJPT shortly after and passed on the first try.

After that I thought I was basically the top hacker of the 21st century, so naturally I bought the OSCP 3-month bundle.

I bought the course around July, but I set the courese to start in October to be more perpared. Nevertheless, it was part of a discounted offer through one of OffSec’s partners. I don’t really want to advertise anyone here, but OffSec usually only discounts the Learn One bundles, so partner offers are worth checking sometimes.

https://partnerportal.offsec.com/?utm_source=offsec/#/page/partner-locator

B!tch Better Have My Money

B!tch Better Have My Money

Then TryHackMe released PT1, and I managed to get both the course content and the exam voucher for free. I took the exam in August and passed it on the first try as well.

RIP THM

RIP THM

Then I took the PNPT on sales as well, and failed on the first try in October (tnx for the free second attempt), and that was my first real shellshock. Don’t worry though, I passed it a month ago.

Gonna miss you, Heath :(

Gonna miss you, Heath :(

Ever since the eJPT, I had been solving at least one machine a day no matter what happened, but the PNPT showed me that I basically knew nothing about Active Directory.

Around December, I was busy suffering together with ‘Suna’ through OSCP A, B, and C sets (More on that in the YT video).

Don’t F with cats!

Don’t F with cats!

Then I took the OSCP on January 6th, 2026, and honestly I got depressed after that.

We regret to inform you :((((

We regret to inform you :((((

Since then I barely did anything besides solving seasonal HTB machines and publishing videos on my YouTube channel. I had no motivation for anything and was heavily depressed for a while.

At some point even before the exam, I applied for a remote pentester position and passed the interview process, but deep down I still really wanted the certification.

Let’s take a step back and talk about the course content before getting into the exam experience.

In general, you mainly need to focus on web application security, privilege escalation, pivoting, and Active Directory attacks.

You can check the current PEN-200/PWK modules directly on the OffSec website. I’ll attach some screenshots below of the topics currently covered in the course (I explained a lot more in the youtube video).

CPTS > PWK-200

CPTS > PWK-200

LABS

There are mainly two kinds of labs, and the first ones are the challenge labs.

1- Challenge Labs

Personally, I solved OSCP 0 and 1 completely, and I believe I solved most of 2, 3, and the A/B/C sets almost entirely with either no hints or very minimal hints. Usually I was spending around 16 to 20 hours on them (see the cat photo) with very small breaks in between (more on that in the YT video).

I’m not gonna discuss anything more about the labs here, because I don’t want to run into any issues with OffSec xD, especially since I’m planning to continue with the OSCE3 path later on. Now the A/B/C were identical to the exam structure which is:

  • Active Directory set = 40 points
  • 3 standalone machines = 60 points total

In order to pass you need at least:

  1. 1 AD flag + All 3 standalone flags
  2. 2 AD flags + 5 standalone flags
  3. Full AD set + 2 footholds + 1 PE (Most popular)
  4. Full AD set + 3 footholds

In general, you MUST get the first AD flag to pass.

2- PG Practice Labs

Regarding PG Practice, I subscribed for 2 months (see the payments photo above) and finished all the machines from the strikilist-oscp list.

okay let’s go!

okay let’s go!

But honestly, don’t go into it expecting the same smooth experience you get with HTB machine lists.

PG and even some of the challenge labs break a lot and have way too many issues. Out of my 60-day subscription, I probably lost around 7 to 14 days because of broken machines, instability, VPN issues, or things simply not working as intended. I was constantly reporting bugs during that period.

Personally, I think that’s way too much for such a well-known and very expensive certification that has existed publicly for this long.

mangekyou sharingan!

mangekyou sharingan!

How I Prepared

This is probably the interesting part for most people, so here’s how I prepared for the OSCP.

I mainly relied on a few creators and resources throughout the journey:

  1. IppSec while eating.
  2. S1ren before sleeping.

She has a playlist on the OffSec YouTube channel, and honestly her methodology is great. A lot of my notes and scripts were directly inspired by her approach.

You know that teacher that tells you “focus on this part, it’s probably going to be in the exam”, and then it actually appears? That literally happened to me in both attempts :D

  1. 0xdf whenever I forgot a tool syntax and was too lazy to read the help menu in the terminal.

He also inspired the structure of my CTF repository where I publish solutions in a way that makes tools and techniques easy to find later. I also like that he goes deeper into post-root and explains details instead of just speedrunning boxes, so I usually used his walkthroughs when approaching something for the first time.

  1. Rana Khalil’s OSCP prep list whenever I wanted quick methodology revision before the exam or needed to refresh certain ideas fast.

All of these people influenced me directly or indirectly during preparation, and because of that I ended up making this:

[embed]Strikoder - Penetration Tester & Security Consultant Strikoder - Certified Penetration Tester (OSCP, PNPT, PT1, eJPTv2, ICCA). Cybersecurity professional specializing in…strikoder.com

My Two Attempts (Deeply explained in the YT video)


+------------------------------+----------------------------------+
| First Attempt                | Second Attempt                   |
+------------------------------+----------------------------------+
| 30 points in 1 hour.         | 70 points in around 8 hours      |
| I spent too much             |                                  |
| time going into rabbit       |                                  |
| holes on the AD and never got|                                  |                                  |
| stable progress going.       |                                  |
+------------------------------+----------------------------------+
| The machines felt extremely  | I got the first AD flag within   |
| hard to me, especially the   | around 30 minutes even though    |
| standalone ones. I also      | I started late and was already   |
| completely failed to get     | under pressure from the start.   |
| into the AD set.             |                                  |
+------------------------------+----------------------------------+
| Got completely burned out    | Happy as Larry.                  |
| and depressed after the      |                                  |
| attempt.                     |                                  |
+------------------------------+----------------------------------+

The real submssion time was ± 5 min to the table above

The real submssion time was ± 5 min to the table above

Exam Day

On the day of the exam, I was waiting for the email around 9:30 since my exam was supposed to start at 10:00 (Berlin time).

By 9:45 I still didn’t get anything, so I sent an email as you can see in the screenshots below. In the end, I didn’t get connected until around 10:20.

Hello

Hello

it’s me

it’s me

I was wondering if after all these attempts you’d like to meet

I was wondering if after all these attempts you’d like to meet

When the exam finally started, I showed my ID and went through the verification process normally. Later on they randomly asked me again about my date of birth, probably because they were surprised I was doing the OSCP almost on my birthday xD.

To be fair, they gave me extra time since the delay was on their side.

I officially started the exam around 10:30, and honestly I was already frustrated before even touching the VPN. I took a quick 2-minute water and mental reset break before starting with the AD set (Again, more in the YT video).

Report & What’s Next?

For the report I only documented the 70 points and ended up with 45 pages

I actually found the other 20 points later on, but by that time I was already almost done with the report inside SysReptor and didn’t want to risk missing a screenshot or a POC code, So I just followed the classic ICPC and SWE mentality:

“If it works, don’t touch it” xD (more on that here https://youtu.be/dT7XgN8uuSU?si=hvNhwK2QIihtnybh)

And for now I will probably improve my web-pentesting skills and then purse the next certs (Including HTB certs):

I know eWPTx sucks, but I needed a 4th cert for the gird pic

I know eWPTx sucks, but I needed a 4th cert for the gird pic

Resources

Honestly, everything I personally used during preparation is already collected here:

https://strikoder.com/oscp

You’ll find notes, methodology, tools, scripts, preparation resources, playlists, and pretty much everything I think is useful for OSCP prep.

I also highly recommend checking the GitHub repository: Strikoder-OSCP-Prep

That repo is basically a huge collection of OSCP-related preparation resources.

And finally, if you liked my work or any of the resources I shared, you can support me here:

[embed]Strikoder - Penetration Tester & Security Consultant Strikoder - Certified Penetration Tester (OSCP, PNPT, PT1, eJPTv2, ICCA). Cybersecurity professional specializing in…strikoder.com

Final Thoughts

At the end of the day, OSCP is still just a certification.

People overhype it a lot online, and others completely underestimate it, but the reality is somewhere in the middle.

For me personally, it was dealing with burnout, pressure, failing, self doubt, and forcing myself to continue studying after bad days and a failed attempt.

If you’re currently preparing for it, just stay consistent. Solve machines daily, improve your methodology, document everything properly, and don’t ignore the basics because most of the time the exam punishes weak fundamentals more than lack of advanced knowledge.

And most importantly, don’t compare your journey to people on Twitter claiming they passed in 30 days in 3 hours whilst solving machines blindfolded from a Nokia phone or a Samsung Fridge.

Good luck Have Fun!


메타데이터
post_id
47f9f6efb25e
slug
strikoder-oscp-review-47f9f6efb25e
url
https://medium.com/@strikoder/strikoder-oscp-review-47f9f6efb25e
canonical_url
https://medium.com/@strikoder/strikoder-oscp-review-47f9f6efb25e
author_url
https://medium.com/@strikoder
status
ok
fetched_at
2026-08-11 01:05:30