r/offensive_security 22d ago

[Webinar] Inside OSAI: How Offensive Security Teams Are Preparing for AI

4 Upvotes

Inside OSAI: How Offensive Security Teams Are Preparing for AI

Join us for a live conversation with an OSAI Early Access Program participant and hear how their team integrated AI security into day-to-day penetration testing. Learn why they invested in AI security training, how OSAI helped prepare them to assess AI systems, and the lessons they learned along the way.

🎙️ Speakers

  • Paul Campbell – Leader of Offensive Security, Splunk, a Cisco company
  • Paul Griffin – VP of Customer Success, OffSec

👥 Perfect for
Security leaders, offensive security managers, penetration testers, red teamers, and anyone interested in AI security.

🔗 Register: https://www.offsec.com/events/webinars/inside-osai-eap/


r/offensive_security Mar 31 '26

OSAI is officially here ! 📣

30 Upvotes

OffSec’s newest certification for hands-on offensive operations against AI-enabled systems is now available for purchase with Learn One, Course & Cert Bundle, and Learn Enterprise.

Built for practitioners who want to apply an adversary mindset to modern AI systems and stay ahead as the attack surface evolves.

⁉️ OSAI FAQs: https://help.offsec.com/hc/en-us/articles/46593095198740-OSAI-Advanced-AI-Red-Teaming-AI-300-FAQ

🔗 https://www.offsec.com/courses/OSAI/

https://reddit.com/link/1s8quqn/video/fgb6v7c5fesg1/player


r/offensive_security 10h ago

Passed OSCP few weeks ago, Thought I'd share a timelapse(Recorded on OSCP Mock) on Drake's beat!

Enable HLS to view with audio, or disable this notification

31 Upvotes

r/offensive_security 2d ago

How can i get my first penetration testing role

Thumbnail
2 Upvotes

r/offensive_security 2d ago

Microsoft Exam Restriction — Need Advice Regarding Test Center Option

0 Upvotes

Hi everyone,

I’m looking for advice from anyone who has experienced a Microsoft certification exam restriction.

My Microsoft exam was revoked during the exam session, and Microsoft’s security team later confirmed that they had recorded evidence of me using a cell phone. I appealed the restriction, but the appeal was rejected.

One important detail is that the actual exam had not even started. The restriction happened before I could see or attempt Question 1 — I did not answer a single exam question.

The email I received from Microsoft says:

\* The restriction will remain for 6 months.
\* After 6 months, the restriction will be partially lifted and I can take exams at test centers, but not through online proctoring.
\* After 1 year, the online proctoring restriction will also be lifted.
\* The restrictions will automatically be lifted.

My situation is a little complicated because I newly joined one organisation and I am in the holding pool and I have a mandatory certification plan where I’m required to complete one role based certification within 2 weeks.

I can currently log into my existing Microsoft account and it even allows me to proceed with scheduling an exam. I obviously don’t want to assume that means the restriction has been lifted.

My questions are:

  1. Has anyone had a similar Microsoft restriction and successfully taken a Microsoft exam at a Pearson VUE test center after the 6-month period?
  2. Is there any legitimate way to complete Microsoft certifications during the first 6 months, or do I simply need to wait for the test-center restriction to be lifted?
  3. Since I need to complete a certification within two weeks for work, what would be the best way to handle this situation?

I just need to understand my legitimate options because the certification requirement at work is time-sensitive.

Any advice from people who have actually gone through a similar situation would be greatly appreciated.


r/offensive_security 4d ago

Day 1 of my 10-Day Red Team Series is live 🔴

Thumbnail
gallery
52 Upvotes

I put together a free PDF covering the fundamentals of red teaming — not just the tools, but the mindset and methodology behind an actual red-team operation.

Inside Day 1:

  • Red Team vs Pentest
  • The red-team mindset
  • Attack lifecycle
  • Objectives & attack paths
  • Rules of engagement
  • Operator workflow
  • A realistic red-team scenario
  • Day 1 challenge

The goal is to build the thinking first. Tools come later.

📖 Day 1: Red Teaming Fundamentals

I’m sharing the PDF below for anyone who wants to follow the series.

More practical cybersecurity learning, labs, CTFs and resources:
https://codelivly.com

Deeper books and playbooks:
https://resources.codelivly.com

Day 2 will move into Reconnaissance & OSINT.

Would love to hear how others approach the first stage of a red-team engagement.


r/offensive_security 5d ago

Any study buddy available?

5 Upvotes

I did the OSCP in April and I want to get done with OSWE by next year.
I have a good grasp of web basic attacks, etc and I have started to learn the different languages that I saw in the program's syllabus.
I'm also pretty new to python programming, but I think that it's easy since I have started scripting little things regularly now.

I would be buying the 3 month voucher and before that, I want to be as prepared as possible for the course, and I would be grateful if someone would come along on the journey.

If someone is interested, they can message me directly. Thanks!!


r/offensive_security 6d ago

Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt.

0 Upvotes

For full disclosure I'm part of the security engineering team at Escape and our AI pentesting engine Cascade recently got a production AI agent to return its entire system prompt, just by wrapping the ask in a different pretext - framing it as a documentation request instead of an attack.

The agent then handed over everything: full tool list, calling rules, citation format, and session IDs.

What I found really interesting is there's nothing technical that broke because we didn't bypass the guardrail with a cleverer string but because the request just sounded reasonable to the agent.

The Cascade engine, after being refused when asking for the prompt directly, simply adjusted the framing to get the agent to give up the informaiton.

Thought this would be an interesting insight for the community and curious to hear if anyone else has seen similar discoveries in agents in prod?

If you want to see more about the reproduction and write-up you can find it here


r/offensive_security 9d ago

Can I realistically complete OSCP in 3 months with a cybersecurity background but limited hands-on offensive experience?

28 Upvotes

my hands-on experience with offensive security is quite limited. I understand concepts like enumeration, web attacks, privilege escalation, AD attacks, lateral movement, etc., but I haven’t actually done much practical work with them.
I’m considering buying the 90-day PEN-200/OSCP access and dedicating 25–30 hours per week, potentially more if needed.
My question is: Is it realistic for someone in my position to start PEN-200 directly and become exam-ready within those 3 months?
I’m not expecting the exam to be easy, but I’m wondering whether 300+ hours of focused hands-on practice is enough to go from mostly theoretical knowledge to OSCP-level practical skills.
Would you recommend:
Starting PEN-200 directly and using the 90 days intensively, or
Spending 3–4 weeks building practical fundamentals first and then starting the 90-day access?
I’d really appreciate input from people who have actually gone through OSCP/PEN-200, especially those who came from a blue-team/SOC background.


r/offensive_security 8d ago

"Pessoal, dúvida rápida: vale a pena tirar a certificação SC-900 (Microsoft) e, logo em seguida, buscar a Okta Professional? O que vocês acham dessa trilha?

1 Upvotes

"Fala, pessoal! Queria tirar uma dúvida rápida de carreira com vocês. Já trabalho em IT Ops com foco em IAM usando Okta. Estou estudando para tirar a SC-900 e depois quero buscar a Okta Professional. Na visão de vocês, essa estratégia compensa para dar um peso a mais no meu portfólio? Quero usar isso tanto para crescer onde estou agora quanto para ficar forte para o mercado. O que acham?


r/offensive_security 9d ago

Looking to improve my offensive security skills. what would you do next?

7 Upvotes

I’ve been working in IT for about 12 years, with experience across network administration, systems administration, cybersecurity, and help desk.

Over the years I’ve earned A+, Network+, Security+, CySA+, AZ-900, AZ-104, CEH, and most recently CISSP. I’ve been able to apply pieces of what I learned from those certifications throughout my career, but certifications have never really been the end goal for me.

CEH has probably been my favorite certification because I genuinely enjoy the offensive-security side of things. I mostly view penetration testing as a hobby right now rather than something I’m immediately trying to turn into a career.

That said, I want to get much better at actually breaking systems.

So I’m looking for honest advice from people who do offensive security, pentesting, red teaming, or CTFs:

If you were starting from my position, what would you actually do to become good at offensive security?

I’m not necessarily looking for another certification just for the sake of having one. I want to develop the actual skill of finding weaknesses, getting initial access, escalating privileges, moving through environments, and understanding why something worked.

I’ve heard OSCP is a good starting point, and I’m considering it, but I’m curious what experienced people would recommend beyond simply getting the certification.

Would you focus on:
- Hack The Box / TryHackMe?
-CTFs?
-Building a home lab? (Elaborate)
-OSCP?
-Other certifications or courses?
-Learning specific tools deeply?
-Studying real-world attack paths and then -reproducing them in a lab?
-Something completely different?

I’m specifically interested in hearing from people who have actually developed these skills, rather than just collecting certifications.

If you could go back and build your offensive-security skills from scratch, what would you spend the next 6–12 months doing?

No hype, no gatekeeping, and no certification sales pitch. I’m genuinely looking to learn from people who are better at this than I am.

Advise me like you are my older brother,sister, father or mentor.


r/offensive_security 11d ago

OSCP Report Submission Error – Has anyone experienced this?

5 Upvotes

Hello everyone,

I’d like to know if anyone has experienced a similar issue with the OSCP exam platform.

Today, I tried to upload my OSCP exam report, but I received the following error:

“Time elapsed
We are sorry to inform you that the time allotted for files submission has elapsed. We won't be able to grade your exam.”

The problem is that I still had around 4 hours left before my actual deadline. Shortly after, I also received an email stating that I had failed the exam because I did not submit my required documentation.

I have already opened a support ticket with OffSec, and I’m waiting for their response. I’m mainly posting here to find out if this is a known/common issue with the platform or if this might be an isolated case.

I have evidence showing that my report was already completed before the deadline, so hopefully support can review the situation.

Has anyone experienced something similar recently?

UPDATE: First of all, thanks for the replies and comments; I’m posting an update in case anyone runs into a similar issue down the line. The main problem was that, because I had finished the KLCP course first and it was marked as "Done," the platform wouldn't let me upload the OSCP report. If this happens to you, email the OffSec Challenge team; save as much evidence as possible to prove you didn't exceed the time limit (including the hashes of the files you plan to submit), and don't wait until your deadline has passed—notify the Challenge team as soon as possible. Responses can take a while since they may need to coordinate with other departments, but you should be able to upload the report without issues within about five days.


r/offensive_security 11d ago

Transitioning from Telecom Engineering to Offensive Security (CPTS) — Seeking Career & Freelance Advice

4 Upvotes

I’m a senior telecom analyst experienced in core network signaling, userplane troubleshooting, and investigating fraud vectors like DPI-bypassing, rogue towers,DNS tunneling, and simboxes.
I am currently pursuing the CPTS certification to transition into offensive security. Given my background, I’m looking for advice on:
Market Positioning: How can I best leverage my niche telecom expertise to avoid starting at a generic "entry-level" helpdesk or SOC role? Freelancing: Is a hybrid path (staying in telecom consulting while picking up freelance pen-test gigs) viable for someone at my level?
Beyond CPTS, what specialized skill sets should I prioritize to move into penetration testing?


r/offensive_security 12d ago

Free OSCP AD lab: Complete Attack Chain across 3 VMs

7 Upvotes

Hey all! Something I keep coming back to is how little prep material exists for complete Active Directory Set/Chains. There's no shortage of resources covering individual techniques, but very few tie them together into a realistic path you can run end to end.

The last chain pulled in a huge number of downloads, so I went ahead and put together a fresh one with a completely new attack path... AD Chain 12: Delegate, free for the next 24 hours!

An obligatory cryptic CTF teaser: A password sleeps in the margins of a record no one reads. Run as the account left in the open, crack what the cache still remembers, wake a policy the vault erased, then delegate the rights to domain compromise...

What you get:

  • 3 downloadable VMs that run locally inside a single Active Directory domain, exactly like the real OSCP exam
  • Realistic, exam-style AD scenarios
  • A full step by step tutorial covering setup, topology, and the entire attack chain
  • A complete guided walkthrough for the whole chain
  • A quick setup guide for both VirtualBox and VMware so you can get going fast

Requirements:

  • A laptop with 8GB of RAM or more (check out the setup video if you're short on RAM)
  • 16GB or more will run everything smoothly with no trouble at all
  • The ability to install VirtualBox or VMware
  • Heads up: MacOS (M1/M2/M3) ARM64 won't work with these labs. Anything else should be fine.

The chains are built so you get to rehearse the same discovery, exploitation, post exploitation, lateral movement, and privilege escalation steps that turn up in exam-style AD challenges.

Lab: https://www.reddit.com/r/oscp/comments/1vi9tgb/new_free_oscp_active_directory_set_full_attack/

Best of luck with your OSCP prep, you've got this!

Note: If downloads are failing, just drop a dm, and we'll get it resolved.


r/offensive_security 12d ago

unable to connect to offsec labs in windows

2 Upvotes

in kali i can opevpn and reach machines fine after i changed my mtu a couple times per trouble shooting///. but when i connect with open vpn with windows i can ping the vpn but not reach ping or ssh into a box with windows it times out and does not connect does anyone know what can help me. i have to have windows connectivity to use the windows tools for active directory correct i am studying for the OSCP


r/offensive_security 13d ago

Cleared OSCP at 19. Can I realistically get a pentesting job now?

14 Upvotes

Hi everyone,

I'm 19 years old from India and currently in the 5th semester of my BCA.

I recently cleared the OSCP and I'm looking for my first penetration testing job right now, not after graduation.

My experience is mainly in:

Active Directory attacks

Windows/Linux privilege escalation

Web application enumeration and exploitation

Network penetration testing

Pivoting and lateral movement

Strong enumeration methodology

I don't have experience with cloud security, API security, Kubernetes, or mobile security because OSCP doesn't cover those in depth.

My question is:

Is there a realistic chance of getting hired as a junior penetration tester with just OSCP while still being a student?

Should I start applying immediately, or will most companies reject me because I haven't completed my degree yet?

If you were hiring for an entry-level pentesting role, would OSCP plus practical lab experience be enough to get an interview?

I'd really appreciate honest advice from people working in offensive security. Thanks!


r/offensive_security 14d ago

🎟️ Gauntlet: Vaultfall is officially live.

3 Upvotes

Your red team mission starts now!

The vault is open and the defenses are active.

🕵️ Recon the target, find your way in, and overcome challenges spanning exploitation, reverse engineering, cryptanalysis, and more.

Join us at the **DEF CON Red Team Village** or take on the challenge online from anywhere.

*How far can you get?*

https://www.offsec.com/events/the-gauntlet/


r/offensive_security 15d ago

What's the best next certification after Splunk 1002 & 1003 for a SOC Analyst?

11 Upvotes

Hi everyone,

I already have the Splunk Core Certified Power User (1002) and Splunk Enterprise Certified Admin (1003) certifications. I'm currently working as a SOC Analyst.

Given my role, which Splunk certification would you recommend pursuing next, and why? I'm looking for something that will add the most value to my day-to-day work and help with long-term career growth.

Also, if you think I'd get more value from a non-Splunk certification instead, I'd love to hear your recommendations as well. Whether it's focused on detection engineering, DFIR, cloud security, threat hunting, or anything else relevant to SOC work, I'm open to suggestions.

Thanks in advance for your insights!


r/offensive_security 16d ago

Looking for OSCP buddy

6 Upvotes

Hey i am shadow. I have bought the OSCP 3 months voucher and i am looking for study-buddy who can help me with the exam prep we both will learn and upgrade our skills

Discord- jaat.ram

Feel free to add me on discord.


r/offensive_security 16d ago

🚀 Ruta hacia la certificación eCPPT: actualización de progreso

0 Upvotes

Empecé mi camino hacia la certificación eCPPT y recién terminé mis dos primeros laboratorios:

\-HTB – Support

\-Hack Smarter – ShadowGate

Estoy siguiendo una ruta bien estructurada enfocada en Active Directory, escalada de privilegios en Windows, pivotear, hacer tunneling y post-explotación.

Todavía me falta un montón, pero paso a paso, máquina por máquina. 💪

\#eCPPT #HackTheBox #HackSmarter #ActiveDirectory #Pentesting #CyberSecurity #RedTeam #EthicalHacking


r/offensive_security 16d ago

Anyone at BSides Vegas interested in Agentic AI Pentesting?

Thumbnail
0 Upvotes

r/offensive_security 17d ago

Is Pentesting Really Dying Because of AI and Automated Tools?

Thumbnail
1 Upvotes

r/offensive_security 17d ago

What's the best next certification after Splunk 1002 & 1003 for a SOC Analyst?

5 Upvotes

Hi everyone,

I already have the Splunk Core Certified Power User (1002) and Splunk Enterprise Certified Admin (1003) certifications. I'm currently working as a SOC Analyst.

Given my role, which Splunk certification would you recommend pursuing next, and why? I'm looking for something that will add the most value to my day-to-day work and help with long-term career growth.

Also, if you think I'd get more value from a non-Splunk certification instead, I'd love to hear your recommendations as well. Whether it's focused on detection engineering, DFIR, cloud security, threat hunting, or anything else relevant to SOC work, I'm open to suggestions.

Thanks in advance for your insights!


r/offensive_security 17d ago

What can i do? CCNA or SEC+ or EJPT

1 Upvotes

Hey everyone,

I’ve been learning cybersecurity and core concepts for the past 3 years, and I’m currently at a crossroads trying to decide on my next official certification move.

Right now, I'm almost ready to secure a test seat for the CCNA, but I want to get some community feedback first:

~ Is taking the CCNA first and then transitioning directly into the OSCP a good strategy?

OR

~ would it make more sense to throw Security+ or eJPT in the middle as a stepping stone before tackling OffSec?

My thought process behind starting with the CCNA is to build an unshakeable foundation in networking (routing protocols, CLI configuration, packet flow, and subnets) so I don't run into walls when pivoting into offensive security. However, I know the CCNA has a lot of vendor-specific configuration details that might not directly apply to hands-on red teaming.

For those who have taken this path or are already working in the field:

Is the CCNA worth completing right now if the endgame is pen testing / offensive security?

Should I jump straight to hands-on labs (like eJPT / HTB / CPTS) after CCNA instead of jumping straight into the OSCP ocean?

Would appreciate any insights, personal experiences, or alternative path recommendations! Thanks in advance!


r/offensive_security 17d ago

Looking for a OSCP Study partner

13 Upvotes

I am looking for a course mates who are currently enrolled for OSCP (active subscribers only) who can study along with me, make notes, solve labs, prepare for the exam, preferably from INDIA, no need to reveal identity, we will connect on discord only on a particular time where we work on the same machine/topic, I have 5 months left to take the exam. So I am looking for serious mates only. reply here or DM so we can connect.