Everything You Need to Know About OSCP | My Full Review
The only OSCP review you need to get a realistic idea of the exam, what to expect, and how to prepare for it.
Everything You Need to Know About OSCP | My Full Review
The only OSCP review you need to get a realistic idea of the exam, what to expect, and how to prepare for it.
Table of Contents
**WHOAMI (id) [What Even Is The OSCP?](#4975) [My Experience Before OSCP](#3e18) [LABS](#54e1) [How I Prepared](#3c1c) [My Two Attempts (Deeply explained in the YT video)](#cdc8) [Exam Day](#6a08) [Report & What’s Next?](#d3cf) [Resources](#d878) [Final Thoughts](#5d9b)**
WHOAMI (id)
As I always start my YT videos:
مرحبا جميعا, Hallo zusammen, Всем привет, Hello everyone!
My name is Amin (strikoder), a normal tech enthusiast who studied Computer Science in Moscow, and a while ago moved to Germany, worked across different areas in IT, and recently passed the OSCP/OSCP+/Offensive Security Certified Professional/HR gateway/Try Harder cert & many more.
What Even Is The OSCP?
First of all, for those who don’t know the exam (I envy you), it’s probably the most well known certification in the offensive cybersecurity realm.
It costs a lot of money, time, and effort to pass, and after all of that it’s still considered an entry-level certification in penetration testing (please if you have a dirty mind, google the term and then keep reading) or hacking if you want to call it that.

Come 2–3 years to Berlin and forget
My Experience Before OSCP
Let’s get back to experience and knowledge.
I started learning networking and security around April 2025, when I bought the eJPT + ICCA voucher during a huge sale. I took the eJPT shortly after and passed on the first try.
After that I thought I was basically the top hacker of the 21st century, so naturally I bought the OSCP 3-month bundle.
I bought the course around July, but I set the courese to start in October to be more perpared. Nevertheless, it was part of a discounted offer through one of OffSec’s partners. I don’t really want to advertise anyone here, but OffSec usually only discounts the Learn One bundles, so partner offers are worth checking sometimes.
https://partnerportal.offsec.com/?utm_source=offsec/#/page/partner-locator

B!tch Better Have My Money
Then TryHackMe released PT1, and I managed to get both the course content and the exam voucher for free. I took the exam in August and passed it on the first try as well.

RIP THM
Then I took the PNPT on sales as well, and failed on the first try in October (tnx for the free second attempt), and that was my first real shellshock. Don’t worry though, I passed it a month ago.

Gonna miss you, Heath :(
Ever since the eJPT, I had been solving at least one machine a day no matter what happened, but the PNPT showed me that I basically knew nothing about Active Directory.
Around December, I was busy suffering together with ‘Suna’ through OSCP A, B, and C sets (More on that in the YT video).
Don’t F with cats!
Then I took the OSCP on January 6th, 2026, and honestly I got depressed after that.

We regret to inform you :((((
Since then I barely did anything besides solving seasonal HTB machines and publishing videos on my YouTube channel. I had no motivation for anything and was heavily depressed for a while.
At some point even before the exam, I applied for a remote pentester position and passed the interview process, but deep down I still really wanted the certification.
Let’s take a step back and talk about the course content before getting into the exam experience.
In general, you mainly need to focus on web application security, privilege escalation, pivoting, and Active Directory attacks.
You can check the current PEN-200/PWK modules directly on the OffSec website. I’ll attach some screenshots below of the topics currently covered in the course (I explained a lot more in the youtube video).

CPTS > PWK-200
LABS
There are mainly two kinds of labs, and the first ones are the challenge labs.
1- Challenge Labs
Personally, I solved OSCP 0 and 1 completely, and I believe I solved most of 2, 3, and the A/B/C sets almost entirely with either no hints or very minimal hints. Usually I was spending around 16 to 20 hours on them (see the cat photo) with very small breaks in between (more on that in the YT video).
I’m not gonna discuss anything more about the labs here, because I don’t want to run into any issues with OffSec xD, especially since I’m planning to continue with the OSCE3 path later on. Now the A/B/C were identical to the exam structure which is:
- Active Directory set = 40 points
- 3 standalone machines = 60 points total
In order to pass you need at least:
- 1 AD flag + All 3 standalone flags
- 2 AD flags + 5 standalone flags
- Full AD set + 2 footholds + 1 PE (Most popular)
- Full AD set + 3 footholds
In general, you MUST get the first AD flag to pass.
2- PG Practice Labs
Regarding PG Practice, I subscribed for 2 months (see the payments photo above) and finished all the machines from the strikilist-oscp list.

okay let’s go!
But honestly, don’t go into it expecting the same smooth experience you get with HTB machine lists.
PG and even some of the challenge labs break a lot and have way too many issues. Out of my 60-day subscription, I probably lost around 7 to 14 days because of broken machines, instability, VPN issues, or things simply not working as intended. I was constantly reporting bugs during that period.
Personally, I think that’s way too much for such a well-known and very expensive certification that has existed publicly for this long.

mangekyou sharingan!
How I Prepared
This is probably the interesting part for most people, so here’s how I prepared for the OSCP.
I mainly relied on a few creators and resources throughout the journey:
- IppSec while eating.
- S1ren before sleeping.
She has a playlist on the OffSec YouTube channel, and honestly her methodology is great. A lot of my notes and scripts were directly inspired by her approach.
You know that teacher that tells you “focus on this part, it’s probably going to be in the exam”, and then it actually appears? That literally happened to me in both attempts :D
- 0xdf whenever I forgot a tool syntax and was too lazy to read the help menu in the terminal.
He also inspired the structure of my CTF repository where I publish solutions in a way that makes tools and techniques easy to find later. I also like that he goes deeper into post-root and explains details instead of just speedrunning boxes, so I usually used his walkthroughs when approaching something for the first time.
- Rana Khalil’s OSCP prep list whenever I wanted quick methodology revision before the exam or needed to refresh certain ideas fast.
All of these people influenced me directly or indirectly during preparation, and because of that I ended up making this:
My Two Attempts (Deeply explained in the YT video)
+------------------------------+----------------------------------+
| First Attempt | Second Attempt |
+------------------------------+----------------------------------+
| 30 points in 1 hour. | 70 points in around 8 hours |
| I spent too much | |
| time going into rabbit | |
| holes on the AD and never got| | |
| stable progress going. | |
+------------------------------+----------------------------------+
| The machines felt extremely | I got the first AD flag within |
| hard to me, especially the | around 30 minutes even though |
| standalone ones. I also | I started late and was already |
| completely failed to get | under pressure from the start. |
| into the AD set. | |
+------------------------------+----------------------------------+
| Got completely burned out | Happy as Larry. |
| and depressed after the | |
| attempt. | |
+------------------------------+----------------------------------+

The real submssion time was ± 5 min to the table above
Exam Day
On the day of the exam, I was waiting for the email around 9:30 since my exam was supposed to start at 10:00 (Berlin time).
By 9:45 I still didn’t get anything, so I sent an email as you can see in the screenshots below. In the end, I didn’t get connected until around 10:20.

Hello

it’s me

I was wondering if after all these attempts you’d like to meet
When the exam finally started, I showed my ID and went through the verification process normally. Later on they randomly asked me again about my date of birth, probably because they were surprised I was doing the OSCP almost on my birthday xD.
To be fair, they gave me extra time since the delay was on their side.
I officially started the exam around 10:30, and honestly I was already frustrated before even touching the VPN. I took a quick 2-minute water and mental reset break before starting with the AD set (Again, more in the YT video).
Report & What’s Next?
For the report I only documented the 70 points and ended up with 45 pages
I actually found the other 20 points later on, but by that time I was already almost done with the report inside SysReptor and didn’t want to risk missing a screenshot or a POC code, So I just followed the classic ICPC and SWE mentality:
“If it works, don’t touch it” xD (more on that here https://youtu.be/dT7XgN8uuSU?si=hvNhwK2QIihtnybh)
And for now I will probably improve my web-pentesting skills and then purse the next certs (Including HTB certs):

I know eWPTx sucks, but I needed a 4th cert for the gird pic
Resources
Honestly, everything I personally used during preparation is already collected here:
You’ll find notes, methodology, tools, scripts, preparation resources, playlists, and pretty much everything I think is useful for OSCP prep.
I also highly recommend checking the GitHub repository: Strikoder-OSCP-Prep
That repo is basically a huge collection of OSCP-related preparation resources.
And finally, if you liked my work or any of the resources I shared, you can support me here:
Final Thoughts
At the end of the day, OSCP is still just a certification.
People overhype it a lot online, and others completely underestimate it, but the reality is somewhere in the middle.
For me personally, it was dealing with burnout, pressure, failing, self doubt, and forcing myself to continue studying after bad days and a failed attempt.
If you’re currently preparing for it, just stay consistent. Solve machines daily, improve your methodology, document everything properly, and don’t ignore the basics because most of the time the exam punishes weak fundamentals more than lack of advanced knowledge.
And most importantly, don’t compare your journey to people on Twitter claiming they passed in 30 days in 3 hours whilst solving machines blindfolded from a Nokia phone or a Samsung Fridge.
Good luck Have Fun!
메타데이터
- post_id
- 47f9f6efb25e
- slug
- strikoder-oscp-review-47f9f6efb25e
- url
- https://medium.com/@strikoder/strikoder-oscp-review-47f9f6efb25e
- canonical_url
- https://medium.com/@strikoder/strikoder-oscp-review-47f9f6efb25e
- author_url
- https://medium.com/@strikoder
- status
- ok
- fetched_at
- 2026-08-11 01:05:30