← Back to list

Playing your "Dead Man's Hand" during the OSCP exam.

The Dead Man's Hand in poker consists of two black aces, and two black 8 cards, often considered by superstitious folks to be the most…

Seccult · 2025-09-20 08:44 · 9 claps · 2.1 min read
#oscp #offsec #oscp-preparation #hacking #offensive-security
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Playing your "Dead Man's Hand" during the OSCP exam. An unconventional strategy to make the most out of inescapable failure.

Making the most out of a bad hand.

Making the most out of a bad hand.

The Dead Man's Hand in poker consists of two black aces, and two black 8 cards, often considered by superstitious folks to be the most unlucky set of cards in the game, as this was the hand Wild Bill Hickok held before being assassinated in a game of poker in Deadwood.

Although the hand is unlucky, it does have some play value, one could theoretically still win, or make the most out of these set of cards to bluff, and survive for the next game.

As with poker there is an element of luck involved with the OSCP exam, you may get a set of boxes that plays to your strength’s, or you may be dealt a bad hand.

These are strategies to make the most out of ones OSCP exam when failure is certain.

  • Metasploit everything: If you're at low, (or zero points), and only have 4 hours left, you may as well execute any potential relevant Metasploit payloads against all the targets. If it lands a hit you won't be able to get points awarded for multiple machines where Metasploit was used, but it may give you useful intel for the next time, especially if the Metasploit attack leads to a full compromise, and you get one of the same machines again on your next attempt. May as well sqlmap everything too.
  • Write a report: Regardless of whether you pass or fail, still write the report. Aside from good practice, if you managed to root a box, you'll know how to do it again next time if you get the same machine. If you didn't root a box, you might have a better idea how to attack it by viewing your enumeration output later when the pressure is off.
  • Don't submit the report: The feedback is going to be very generic, don't waste your time. Also if you did get points by using Metasploit, or sqlmap against a target, you don't want the people reviewing your report to think you're trying to cheat them, just accept the loss and move on.
  • Take time to evaluate the exam experience: What went right, and what went wrong, where were you weak, and build to strengthen that.
  • Revert the machines: Before the exam ends take one final opportunity to revert the machines, and rerun nmap in case a port was missing. Sometimes a machine will be missing the vulnerable vector due to it not be initially spawned, it'll give you piece of mind, or potentially give you an opportunity to get more time, or rechallenge for free if the issue was from offsec's end (keep valid documentation of the issue if it was).
  • Don't be too hard on yourself: The OSCP exam is prestigious because it's so difficult, you failing just means you need to re-adjust and try again, the fact you attempted the exam is an accomplishment in and of itself, that's something positive you can focus on.

메타데이터
post_id
274f1e87c310
slug
playing-your-dead-mans-hand-during-the-oscp-exam-274f1e87c310
url
https://medium.com/@seccult/playing-your-dead-mans-hand-during-the-oscp-exam-274f1e87c310
canonical_url
https://medium.com/@seccult/playing-your-dead-mans-hand-during-the-oscp-exam-274f1e87c310
author_url
https://medium.com/@seccult
status
ok
fetched_at
2026-06-24 11:06:28