OSEP
OffSec

Offensive Security Experienced Pentester

Expert Advanced practical exam + report submission Pass: Provider does not publicly guarantee fixed cut sc… $1,499

OSEP targets advanced operator tradecraft: evasion-aware payload delivery, lateral movement, and mature Active Directory attack chains. For 2026 readiness, candidates should combine offensive creativity with strong OPSEC and defensible reporting.

Official Page
IssuerOffSec
FormatAdvanced practical exam + report submission
Duration48h exam window + report window (indicative)
Pass ScoreProvider does not publicly guarantee fixed cut sc…
Valid For3y
Cheat Sheets
Exam-Day Workflow (2026)
- Build a strict recon -> validate -> exploit -> prove impact -> report loop. - Record every command/output pair with timestamps. - Keep fallback paths for each objective. - Use indicative timelines: first pass discovery, second pass depth, final pass report polish. - Validate findings twice before documenting business impact.
Reporting Checklist
- Executive risk summary per objective/domain - Technical evidence (request/response, command output, screenshots) - Reproduction steps with minimal ambiguity - Clear remediation with priority and owner suggestions - Retest guidance and residual risk notes