← Back to list

AD vs. Evasion: CAPE/OSEP and the Myth about them

Helloooo once again readers, I had the opportunity to take the Certified Active Directory Pentesting Expert (CAPE) exam offered by…

Zumi Yumi · 2026-07-10 22:51 · 1 claps · 7.0 min read
#osep #penetration-testing #av-evasion #active-directory #hacking
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🎮 · Gaming 🎬 · Film & Television

AD vs. Evasion: CAPE/OSEP and the Myth about them

Helloooo once again readers, I had the opportunity to take the Certified Active Directory Pentesting Expert (CAPE) exam offered by HackTheBox (HTB) quite recently. I ended up with 9/10 flags and submitted a 81 page report resulting in me passing! Since then I’ve gotten some requests and questions regarding the differences between CAPE and OffSec Experienced Penetration Tester (OSEP) courses. I also would like to dispel a common myth regarding them (that I believed as well) as being similar courses.

This post will cover some of the major differences between the two courses, where I think their strengths and weaknesses are. In what cases I would recommend a pentester either course or in some cases both courses. I’ll try to remain objective when it comes to evaluating these courses but I should state before hand I am a Community Companion (volunteer) for OffSec in case of any bias.

CAPE

Let’s briefly cover the content covered by CAPE:

  • Active Directory (AD) Enumeration
  • MSSQL, SCCM, Exchange Attacks
  • AD Attacks
  • C2 Intro (Sliver)
  • Windows Evasion
  • Pivoting and Lateral movement
  • Post-Exploitation Techniques/Tactics

This course focuses greatly on Active Directory attacks/enumeration, which should not be surprising based on the name.

The windows evasion section is very very light, and should be considered as nearly beginner’s level when it comes to evading defenses like Defender. Many of the techniques demonstrated will not work on modern defender without many iterations and experimentation. It also lacks the fundamentals that OSEP covers in that course, but I’m jumping ahead here.

Don’t expect to be an expert at evading base Defender after taking and passing CAPE. The section covering Sliver is rough and out-dated, I was not very impressed by the content in this section. I think HackSmarter has a better course if you want to learn Sliver specifically, there’s also CRTO and other courses that teach OpSec and general C2 operations. I would suggest those if you need to learn C2s, NOT CAPE for that.

Here is where CAPE’s strengths are:

  • AD Enumeration, it covers extensively many, many different ways of enumerating AD manually, automated, from linux, from windows, pivoted, and even using GUI consoles.
  • AD Protocol Attacks, netNTLMv2 and kerberos based attacks are extensively discussed. You will likely have unconstrained, constrained and RBAC definitions memorized by the end of this course. It demonstrates many of the functions and capabilities Responder, ntlmrelayx, krbrelayx hold when it comes to relay based attacks. The environment it sets up for this is great for experimentation and I enjoyed playing around in the relay module seeing what all I could do.
  • AD Attacks, there are tons of attacks covered, demonstrated, and executed in this course. We have the simple things like AS-REProasting, kerberoasting, DACL attacks, but it dives into more complex attack paths like delegation, GPO abuse, mssql linked servers, SCCM, ADCS, Trust Attacks, Exchange attacks, cross-forest, child-parent cross attacks. You cannot and should not rely on BloodHound/Adalanche output for the course/exam, it also applies to real life pentesting. Those collectors and tools are going to miss DACL connections between Objects in AD. Even simple things you’d expect it to catch they will miss. Manually enumerate everything if you are stuck/don’t know where to go!
  • The Exam, the exam is interesting, complex (yet simple in hindsight), and realistic to some degree. I highly recommend doing the exam even if you cannot dedicate 10 complete days to it. I learned a lot from doing the exam, perhaps almost more than from the course itself. It really pushed me and challenged me to reread the content, research attacks, and troubleshoot to determine why something wasn’t working. Without breaking rules of exam disclosure I want to say don’t expect attacks to just work. Be prepared to troubleshoot, experiment, and figure out why something isn’t working, or even why it did work. Many steps in the exam are chains of exploits, not simple one step actions. One major difference between CAPE exam and OSEP exam is difficulty. I found CAPE to be far more challenging.

I think generally if you want to specialize in Active Directory pentesting or get better at it, this is the course to do that. The other things CAPE teaches are too surface level for me to recommend it for those. It’s more affordable than OSEP as well. It’s absolutely overkill to take to prep for OSEP. It has its niche as an AD course and fills it very nicely.

OSEP

Now let’s briefly cover the content covered by OSEP:

  • Active Directory (AD) Enumeration
  • AD Attacks
  • MSSQL Attacks
  • Kiosk Escapes
  • AppLocker Bypasses
  • Client-Side Code Execution Office, Jscript
  • Process Injection/Migration
  • Windows Evasion
  • Pivoting and Lateral movement (Windows and Linux)
  • Post-Exploitation Techniques/Tactics

This course focuses greatly on Antivirus Evasion and defeating defenses rather than performing specific exploits.

Where CAPE’s evasion section was relatively light, evasion makes up roughly 40% of the content of OSEP. It starts you off with learning how to define win32 API calls in C# using things like P/Invoke, and reading Microsoft documentation on structs. I think this fundamental teaching and how the content pushes you to research on your own how to define certain calls or perform different attacks in different ways is the strength of the course. Yes, the defined evasion techniques can all be defeated by modern Defender. But I literally put a hour or two more work into some of the techniques shown and was defeating modern Defender. Same with the AMSI bypasses shown, I got a little creative and was able to use the same AMSI bypasses with obfuscation. Or even discover my own techniques.

I enjoyed the kiosk escape section, in my line of work running into kiosks is incredibly common. Getting some extra practice never hurts and I appreciated it being included. The client-side code execution attacks, especially macros is extremely outdated and essentially useless these days. The AppLocker bypass techniques shown still work to some degree but are well known and signatured to hell so if you are trying to evade alerts this isn’t the place to learn techniques for that.

The Active Directory sections to include ADCS were extremely lacking/simple. Although this course gets compared to CAPE a lot, it is nothing like CAPE in terms of learning AD. The REAL value of AD related attacks in this course is it focuses a lot more on Linux joined AD machines. You pull off a lot of attacks that involve Linux AD machines, something CAPE does not cover to the same degree. That is one significant piece that is missing from CAPE content.

Again don’t expect to take the material from OSEP and go defeat modern Defender. It’s not going to work, you need to play around with evasion on your own/take other courses or do MalDev Academy to do this. A lot of people complain about OSEP being outdated for evasion and I understand their feelings but I think what it is good is teaching you how to approach evasion and how to begin the process of learning it. I’m certainly not even close to an expert but I felt more confident afterwards in performing my own research and have been successful.

I found the exam to be super simple compared to CAPE, I had a passing score in 6 hours and 100% (of what I could determine) in 11 hours. Others report similar outcomes so its not just me being a 1337 haxxors or something, its genuinely easy.

Here is where OSEP’s strengths are:

  • AD Attacks Involving Linux, as mentioned previously this is a unique feature of OSEP including Linux machines when compared to CAPE. It is an important skillset to have in knowing how to approach these machines.
  • Evasion Building Blocks, the course is great at pointing the student to resources and saying “Go figure it out”. A lot of malware/tradecraft is like this, you have to go and experiment.
  • Kiosk Escapes, if you are very green to these, the concepts covered here are excellent in getting a student familiar with.

I think generally if you need a way of bridging your skillset from junior pentester level knowledge of finding vulnerabilities to defeating defenses this is a good course to begin that journey. I would call it a stepping stone on the path to being a Red Teamer. Not a Red Teaming certification at all, but a way to get your feet wet. It sets you up for more difficult evasion certs like Offensive Development Practitioner Certification (ODPC) offered by White Knight Labs (in combination with some user land level binary exploitation experience).

Recap

So to kind of summarize my long-winded yapping I’ll list out what I consider pros and cons of each course:

CAPE Pros:

  • Heavy AD Focus (Enum and Attacks)
  • Complex AD Attack Paths
  • Modern AD Attack Paths
  • Very Detailed Content

CAPE Cons:

  • Light evasion module (Not its focus)
  • Light C2 module (Not its focus)
  • Difficulty (Can be overwhelming/intimidating)
  • Overly verbose (Although I listed detailed content as a pro, it also drags and is redundant in sections)

OSEP Pros:

  • Heavy Evasion Focus
  • Linux AD Attack Paths
  • Maldev Building Blocks
  • Kiosk Escape Intro

OSEP Cons:

  • Outdated material
  • Does not explain material very well in some areas/disjointed content
  • Expensive Course
  • Light AD Enumeration and Attacks (Not its focus)

Final Thoughts

And yes, I do think its worth doing both. I did both and got a lot out of them. I think they are good courses overall with OSEP being overpriced for what it is. I always complain about OffSec courses in that regard, they are very cost prohibitive for many testers around the world. I think it’s unfortunate the price just seems to be rising with OffSec. CAPE is expensive but not like OSEP. In general when people talk about OSEP vs CAPE its comparing an Orange to an Apple. They aren’t really focused on the same thing, I also fell into that trap of thinking they were similar courses.

For me I’m going to start OSED’s content sometime in October, considering reverse engineering, assembly, and binary exploitation as some of my weakest areas I’m not expecting to take the exam until the second half of 2027. I’ll pivot to OSWE afterwards, then ODPC as a bridge between taking OSEE.

That should keep me pretty busy until 2029 lol.

Hope this was useful to someone out there, feel free to add me on Discord @zumiyumi or on LinkedIn at: https://www.linkedin.com/in/astrea-y/


메타데이터
post_id
caab7a4b1789
slug
ad-vs-evasion-cape-osep-and-the-myth-about-them-caab7a4b1789
url
https://medium.com/@zumiyumi/ad-vs-evasion-cape-osep-and-the-myth-about-them-caab7a4b1789
canonical_url
https://medium.com/@zumiyumi/ad-vs-evasion-cape-osep-and-the-myth-about-them-caab7a4b1789
author_url
https://medium.com/@zumiyumi
status
ok
fetched_at
2026-07-11 21:25:18