OSCP Guide - Full Free Course

Поділитися
Вставка

КОМЕНТАРІ • 130

  • @jdemiii
    @jdemiii Рік тому +103

    God bless you! Finally someone who is not just talking random generic shit about the OSCP but actually helping with the study process

  • @peesharonn
    @peesharonn 9 місяців тому +23

    I passed the PNPT in July 2023 and passed the GPEN in March 2024. Now, I am planning to purchase the OSCP course and the exam but I needed an idea of the topics and structure of the exam, and your video touched on all of these. Thank you very much.

    • @hexdump1337
      @hexdump1337  9 місяців тому +4

      Keep me updated with your progress, and good luck!

  • @theWerewolf00
    @theWerewolf00 11 місяців тому +12

    This is pure GOLD my dude! This content is amazing and the exact thing I was after. Thanks for taking the time to put together all of this

    • @hexdump1337
      @hexdump1337  10 місяців тому +1

      Glad you appreciate :D

    • @dhruvRajput0579
      @dhruvRajput0579 3 місяці тому +1

      hey man!, i am studying to pursue cyber secutrity domain(am a beginner) and i wanna ask (if you've watch this full course through) is this course worth it? like i am interested in oscp and and as much as I have searched i dont think there is any free course that can really train you with oscp. so should i watch this or do you have any other references to help me train for this field better?

  • @can-do_curran
    @can-do_curran 5 місяців тому +6

    Best OSCP guide and review yet! I'm currently going through the Pen-200 now, this is absolutely solid insight and encouraging -- thank you Leonardo!! I'm enjoying your Windows priv esc video as well...Keep up the great work!

    • @hexdump1337
      @hexdump1337  5 місяців тому +1

      Good luck on your studying, will keep helping ya!

    • @dhruvRajput0579
      @dhruvRajput0579 3 місяці тому

      hey man!, i am studying to pursue cyber secutrity domain(am a beginner) and i wanna ask (if you've watch this full course through) is this course worth it? like i am interested in oscp and and as much as I have searched i dont think there is any free course that can really train you with oscp. so should i watch this or do you have any other references to help me train for this field better?

  • @Cultivation-FitnessMoral-gj3co
    @Cultivation-FitnessMoral-gj3co 7 місяців тому +7

    In the near future, I will achieve the OCSP certification - as a career pipeline of my desired orientation for my career. Sir, I appreciate your creation of this content.

    • @hexdump1337
      @hexdump1337  6 місяців тому +4

      I wish you good luck in your studying, hope my material will help you reach your goals!

    • @Cultivation-FitnessMoral-gj3co
      @Cultivation-FitnessMoral-gj3co 6 місяців тому +2

      @@hexdump1337 Thanks! I'll return to this very comment, once I pass the exam.

  • @markmeredith836
    @markmeredith836 4 місяці тому +3

    This is a really solid course. Thanks for making it. Your English and delivery are superb. I will be checking out your other content

  • @thabeloranthona4455
    @thabeloranthona4455 Рік тому +4

    Finally I got a clear guide I've been searching for 🎉. Thank you Master.

    • @hexdump1337
      @hexdump1337  11 місяців тому

      I hope it will be worth it!

  • @ArnoldBlare-ei1dj
    @ArnoldBlare-ei1dj 22 дні тому +1

    I’m blown away by how well-organized this course is. The pace is perfect and the content is super engaging. Loving every minute!

  • @Whyleys1-of3tb
    @Whyleys1-of3tb 10 місяців тому +2

    Just wanted to say thankyou for putting this together, its so well done

  • @ygorcrod
    @ygorcrod 7 місяців тому +3

    I'm in the first hour of video and I'm stunned with the level of this amazing training and how you put your thoughts and the finest way from "learning to learn" in the process. Thank you so much for this free content.
    At the moment I can't spend any money on the official training but you video permit that I study it following the OffSec site, blog, Discord, exam blueprint, web search and with this guide. God bless you!

  • @rtr0spct210
    @rtr0spct210 4 місяці тому +1

    Thank you for taking the time to make such a thorough course. I will definitely be referencing this along side the PEN-200 course material. Subbed.

    • @hexdump1337
      @hexdump1337  4 місяці тому

      Thanks, hope it provides value

  • @saidalbahri4430
    @saidalbahri4430 11 місяців тому +3

    Great work Leonardo, I am watching your vid while prepping for the exam. I will hopefully remember to update you with the outcome.

    • @hexdump1337
      @hexdump1337  11 місяців тому

      yes please, update all of us, and good luck!

    • @saidalbahri4430
      @saidalbahri4430 4 місяці тому +1

      @@hexdump1337 I just wanna update you that I passed the exam and received the email yesterday. Thank you so much for this video as it helped me understand concepts better.

  • @orca2162
    @orca2162 11 місяців тому +5

    excellent ❤❤❤❤, great information, the best I’ve seen to date, really useful, great explanation, just perfection personified, thank you!!!

  • @erpanterone
    @erpanterone 8 місяців тому +2

    Thank you for the big work and the big share. You deserve the best, Leo.

  • @herotrojan1645
    @herotrojan1645 10 місяців тому +4

    superbly amazing!! thanks!! God bless you brother!

  • @edgarzainullin
    @edgarzainullin 11 місяців тому +1

    Thank you for making this great walkthrough, answered many questions that I had and what to look for and expect from OSCP exam. Keep up great work.

  • @dustinhxc
    @dustinhxc Рік тому +4

    Fantastic complete video, thank you master!!! 🎉❤

    • @hexdump1337
      @hexdump1337  Рік тому +1

      Only good quality here, hope you have a good studying time!

  • @0xTS05
    @0xTS05 3 місяці тому

    I have no words(internally speaking)...thank you

  • @SALTINBANK
    @SALTINBANK 9 місяців тому +2

    God bless Italia : grazie e in bocca al lupo for the rest ...
    ;)

  • @Ticared
    @Ticared Рік тому +2

    Great work, thank you very much for creating this guide

  • @anonymoussaid5986
    @anonymoussaid5986 10 місяців тому

    big up brother👍,thanksfor the video .am about to take OSCP and you give a great guide

  • @simatbirch
    @simatbirch 3 місяці тому

    Amazing resource. Thank you v much!

  • @CyberSquad0007
    @CyberSquad0007 Рік тому +1

    Thank you for sharing this amazing content and it will help me lot for oscp preparation.

  • @AHEPBURN1981
    @AHEPBURN1981 5 місяців тому +1

    I appreciate you content sir...

  • @hackingdemon0764
    @hackingdemon0764 8 місяців тому

    Really thanks for this content man this is what i am searching for 👍

  • @chamodmalshan4708
    @chamodmalshan4708 6 місяців тому +1

    Thank you so much bro. i really appreciate your help. Thank you :)

  • @marlinshanklin-ww7em
    @marlinshanklin-ww7em Рік тому

    Thank you very much sir for your videos. I had no problem understanding your english it's excellent.

  • @magickpalms4025
    @magickpalms4025 10 місяців тому +1

    thank you, lots of good information

  • @MereAYT
    @MereAYT 18 днів тому

    This is amazing.

  • @c0ri
    @c0ri 9 місяців тому +1

    This is extremely helpful thank you so much. i've been studying for 2 years and sometimes I still feel like I'm not ready. I keep finding new stuff I never knew before .. seems endless. I really struggle with understanding when I am ready for the OSCP. I feel like I need a coach to tell me where I am and what I still need to study to pass this. It's too expensive for this test to play around with IMHO.

    • @Ly0242-q7f
      @Ly0242-q7f 8 місяців тому +1

      2 years is crazy. You have imposter syndrome bro just go for it already

    • @c0ri
      @c0ri 8 місяців тому

      @@Ly0242-q7f ya you are right. Thanks for the advice

    • @hexdump1337
      @hexdump1337  8 місяців тому +2

      sadly the cost creates all this anxiety. Try to focus on the experience, do it once already to test out your level, otherwise you will never know if you are ready for it.

    • @c0ri
      @c0ri 8 місяців тому

      @@hexdump1337 You are exactly right. For me that's a tidy sum. I'm pretty much as ready as I'm gunna be so I think I'll take your advice. Thanks mate

  • @Tathamet
    @Tathamet 11 місяців тому

    Great stuff thanks man ! godlike work.

  • @cloudnsec
    @cloudnsec 7 місяців тому

    Awesome content! Subbed!

  • @comosaycomosah
    @comosaycomosah Рік тому

    Sweeeet! Just found you lately digging the content....my issue is im pretty competent with like 80% of the skills just can't afford to take it rn pretty sure it just raised abit too lol some day some day

    • @hexdump1337
      @hexdump1337  Рік тому

      with regards to the price, what I did for example is ask my previous employee to buy it for me. This sort of creates a “chicken-and-egg” scenario, since most people want OSCP to get a job as pentester.
      However, if you’re able to find a job related to computer security in a small local company, and they see that you’re good and want to invest in you, asking for a certification is a good thing
      for a company the price is honestly not that high, however for an individual, especially a young one, it is definitely high.
      Also, since lately there’s also CPTS, which costs much less, in a few years I believe the market will recognize CPTS value and therefore it will be more worth it, making OSCP a little bit less appealing. It will take years tho

  • @rahulraptan
    @rahulraptan 10 місяців тому +1

    Thanks a lot 😊

  • @MajorKassad
    @MajorKassad 10 місяців тому

    Thank you very much!

  • @Kingdd1os
    @Kingdd1os 2 місяці тому

    Amazing!!!!!

  • @martinlastname8548
    @martinlastname8548 Рік тому +2

    Is it better to use a VM for the exam or partition Linux on the hard drive?

    • @hexdump1337
      @hexdump1337  Рік тому +2

      VM all the way, partition needs more attention/maintenance if something breaks down at the user level (say packages gets broken) and cannot revert easily state of OS

  • @-willplaysgames
    @-willplaysgames 4 місяці тому +1

    On your exam did you use Linpeas and Winpeas and if so what edits to the scripts do you have to make in order to make them test legal?

    • @hexdump1337
      @hexdump1337  4 місяці тому +1

      I did not use such script, mainly went with manual enumeration using a personal cheatsheet of useful commands

  • @MajorKassad
    @MajorKassad 6 місяців тому

    I have a question regarding the markdown tool used to generate reports for exam. Is it the case that spelling checks features are available when you type for example a sentence into the report? And also how do you insert images using this markdown tool?

    • @hexdump1337
      @hexdump1337  6 місяців тому

      Hmm, the tool (pandoc) is just the converted. You can try to put a spell checker tool in the editor you use to write the markdown, that could work. Also with respect to images, you just use the typical markdown syntax to add images, and the pandoc tool will link them up in the final pdf, assuming they are reachable when you execute the command.

  • @spencerriley5747
    @spencerriley5747 10 днів тому

    Bonjourno Leonardo, I really appriciate your videos, I am currently watching OSCP Guide, I went on to github to download the cheatsheat, but my windows security flagged it and would not let me download it, any thoughts ? I wish to have this cheatsheat for reference while I learn how to use the tools properly. Also, I am worried if I download Kali, on my laptop that it might corrupt it and then I would have to reinstall windows. Am I better off purchaing an external ssd and intall/run Kali from the ssd ?

    • @hexdump1337
      @hexdump1337  10 днів тому +1

      It gets flagged by security solutions because the files contains various commands which can be used with malicious intent, but by itself is not an executable and it does not really represent a security threat. I would configure the tool you're using to whitelist it. It's just a simple text file with a bunch of commands.
      With respect to the kali setup, you can use a virtual machine if you're worried about that. Either a virtual machine or windows, or a dual-boot (but if you do it wrong it can end up corrupting windows), or yes, also an external SSDs. Personally I went with VM first, then moved on to dual-boot, and now pretty much I only use linux (not kali tho). If I need to use kali I have a dedicated VM.

  • @Rickynoxe
    @Rickynoxe 11 місяців тому +1

    Very good video. I haven’t seen all the video at that time and perhaps you deal with my question, but If not I prefer to ask you some questions.
    For the report writing, You have to describe the way you followed to find the flags. Now imagine that you found 2 vulnerabilities on FTP and web. You can exploit both but FTP is a rabbit hole and only web allow you to continue. Do you explain FTP and web in the report or only web ? Because it is a pentest report I think you have to explain ALL vuln you found. But I am not sure for the exam.
    Other point. You mentioned that exam + report need full energy. So what strategy do you advise. Try to earn the maximum of point if you can and so describe all the flag quest in the report ?. Or stop after you have 70 points and describe less flags quest in the report and have more time to write it ?
    Thanks

    • @hexdump1337
      @hexdump1337  11 місяців тому +1

      For the reporting, you are right in that in “real PT reports” you have to explain all the vulns found, however remember that OSCP exam is not like real world.
      Typically the machine follow a pre-determined and linear path, meaning that if you get inside something then probably that is the way.
      Also in general for the reporting you have to explain all the vulnerabilities that allow you to become root, so once again in a linear fashion. Minor other vulnerabilities are not really that important. Remember the key is to become root and to explain how you did it.

    • @hexdump1337
      @hexdump1337  11 місяців тому +1

      For the second question, I’d say: first full focus on getting those 70 points, once you do that take a break and make sure you have all the screenshot, PoCs and all the notes u need for the final report.
      Then once you’re sure of that you can keep owning more machines if you have time left. The more the merrier!
      After the 70s point the other machine can be more fun also. Just remember when to stop for energy and when to sleep to prepare for next day reporting
      It can be very tiring so just focus on having healthy food around and no extra distractions (if possible)

  • @sundep-nl8pm
    @sundep-nl8pm 3 місяці тому

    help us how to start pentesting from scratch

  • @scorit-zq4yx
    @scorit-zq4yx 2 місяці тому

    I have my sec+ and eJPT, I am considering either the HTB CPTS or OSCP next, or would you recommend something else before tackling those first?

    • @hexdump1337
      @hexdump1337  2 місяці тому +1

      I did not take HTB CPTS myself, but I’ve heard that it is harder than OSCP. Right now OSCP has still better recognition, but in terms of quality and added value I think HTB is higher.
      Gonna expand on this viewpoint in the future

  • @darrenccu
    @darrenccu 10 місяців тому

    Thank a lot❤

  • @TheFraDark
    @TheFraDark 10 місяців тому +1

    Ciao Leonardo, potresti fare lo stesso video ma in Italiano? Grazie in anticipo sei il TOP!❤

    • @hexdump1337
      @hexdump1337  10 місяців тому

      Hi, right now don't have much time, so probably not in these months. Maybe later who knows. Anyhow, this could be a great opportunity to improve your understanding of english!
      (Btw, In this channel I will only reply in english :D)

  • @Ucsd4life
    @Ucsd4life 5 місяців тому

    I’m trying to cram my study, I was given a voucher at work. I don’t know if I’ll make it as my test date is October 26 but I hope this video helps me understand what is going on. I have pentest + and hold a Masters in Cybersecurity but this esa is different.

    • @hexdump1337
      @hexdump1337  5 місяців тому +2

      Try to follow this as well as the web exploitation course and the videos im doing on linux and windows priviege escalation.
      I suggest to do full practice on the labs offsec gives you, as they showcase most of the vulnerabilities you will find in the exam

  • @xinbizz96
    @xinbizz96 8 місяців тому

    grande continua per favore

  • @JacobWestbrook-f2m
    @JacobWestbrook-f2m 11 місяців тому

    Subscribed. Love the video, thank you so much. What are you using for viewing your .md notes in the video? thanks!

    • @hexdump1337
      @hexdump1337  11 місяців тому +2

      Emacs!
      its a very powerful text editor, I’ve made a video about it in the channel

    • @JacobWestbrook-f2m
      @JacobWestbrook-f2m 11 місяців тому

      Really appreciate it!@@hexdump1337

  • @Angbuhang
    @Angbuhang 9 місяців тому

    thanks

  • @edenreyes4276
    @edenreyes4276 6 місяців тому

    Hello,
    Thank you for the guide, I am looking into breaking into the field of cybersecurity. However I have heard that nowadays you cannot get a good start without a college degree, is that correct? I do not want to have to go to college, do you think it would be possible to start a career in this field without it?

    • @hexdump1337
      @hexdump1337  6 місяців тому +1

      I believe it is definitely possible, just gotta increase your technical knowledge and showcase it to the right people at the right time.

    • @edenreyes4276
      @edenreyes4276 6 місяців тому

      @@hexdump1337 Thank you, I needed some words of encouragement, I will continue to study and get certs. The only reason I am fearful is because in the US the market seems over-saturated and too competitive for a beginner without a degree was almost an immediate loss.

  • @HasanthaGimhana
    @HasanthaGimhana 11 місяців тому +1

    Can we use our cheat sheet during the OSCP exam?

    • @hexdump1337
      @hexdump1337  11 місяців тому +3

      yes of course, as long as you respect OSCP policy, you do not cheat by asking for others help or use anti exploitation tools, you are free to use all chestsheets and all searches on google and stuff.
      What they are testing is if you know how to deal with it on your own

    • @HasanthaGimhana
      @HasanthaGimhana 11 місяців тому

      @@hexdump1337 Thank You.

  • @James-li3ro
    @James-li3ro Рік тому

    Hi! Hexdump. You mentioned you have alot of prior experience. Did you do anything other certs before? I don’t recall you saying anything related to external sources so i just want to ask if you use any external source like tj null’s list on hackthebox or vulnhub’s labs? Or did you purely use only use the pen200 and oscp labs? to do the OSCP exam

    • @hexdump1337
      @hexdump1337  Рік тому +1

      While I did not follow specific OSCP preparation material, I had 2-3 years of experience doing general machine on hack the box, some try hack me, and also oding various CTFs. When I started the cert therefore I already knew most of the things, especially related to linux. The only things I did not know where related to windows and active directory.
      I would say, if you have little to no experience, the material offered by OffSec is simply not enough and not well structured to make you understand all the important details.

    • @James-li3ro
      @James-li3ro Рік тому

      Thanks for replying. I do have an ejpt cert. But like you said, i definitely have to do more htb boxes and machines.I have always felt that enumeration was the hardest things. Even after enumeration, it always me being stucked on how to move on to the next step of gaining a hold. Any tips on improving enumeration skills? And any tips on how to gain skills to understand how to gain initial foothold of the machine?

    • @hexdump1337
      @hexdump1337  10 місяців тому +2

      @@James-li3rosorry for late reply, just now saw your message.
      Anyhow, it all comes down to practice, practice and practice. Seeing lots of different things and patterns, and understanding the whys of stuff is key.

  • @ElliotAuditore
    @ElliotAuditore 14 днів тому

    Which terminal you are using?

    • @hexdump1337
      @hexdump1337  13 днів тому

      Emacs with vterm

    • @ElliotAuditore
      @ElliotAuditore 13 днів тому

      @@hexdump1337 and to make notes/cheetsheet ?
      can you make video on that too?
      !

  • @behnam4582
    @behnam4582 2 місяці тому

    Could you make more videos about exam tips in general...like whats best to do or what not to do if someone get stuck....and videos around domain controllers

    • @hexdump1337
      @hexdump1337  2 місяці тому +1

      Thank you, got an idea for an interesting topic to discuss related to OSCP.
      I say to you: do not attach to the OSCP more meaning than it deserves to. Focus on learning and try as much as possible to find the right balance between learning for the sake of karnal and doing certification to go through HR and get a job.
      I know, its hard, especially when you want to change job/lifestyle. However never forget that OSCP is just a cert. What matters in life is so much more. Use the opportunity to learn a lot, but never forget what truly matters.
      Thats my opinion, I will expand on it in a future video! Hope my material is useful to you.
      Also, im almost done with the windows privesc series, then I will start active directory. So its gonna be fun, hope to teach you some cool tricks!

    • @behnam4582
      @behnam4582 2 місяці тому

      @hexdump1337 thank you 😊 much appreciated

  • @Passion-i3v
    @Passion-i3v Рік тому

    Sir, any prerequisite before watch this video. I am beginner into cybersercurity field.

    • @hexdump1337
      @hexdump1337  11 місяців тому +1

      In the video I also talk about pre-requisites for obtaining the OSCP cert

  • @cnrk1832
    @cnrk1832 10 місяців тому

    Can we use linpeas during exam?

    • @hexdump1337
      @hexdump1337  10 місяців тому +1

      you most definitely can use all scripts that simply perform enumeration without doing automatic exploitation. Now, Im not sure if LinPeas also does automatic exploitation, I believe it is a feature that has been added to the script at some point in time, so you might have to be careful with that.
      When unsure, ask yourself: will it perform automatic commands that will result in the exploitation of a vulnerability? If that is the case, then you should not use it, otherwise feel free!
      At the end of the day it is up to you to execute the main commands that will exploit the system. Automatic tools can at most guide your path, but never take your role.

    • @mattlai443
      @mattlai443 10 місяців тому

      linpeas yes, so is winpeas

  • @benyicl92
    @benyicl92 11 місяців тому

    3:56:00

  • @ziajalali3906
    @ziajalali3906 Рік тому

    👍👍👍

  • @SinergiasHolisticas
    @SinergiasHolisticas 8 місяців тому +1

    Gracie!!!!!!!!!!!!!!!!

  • @BeingNahid-oi7mm
    @BeingNahid-oi7mm 11 місяців тому +1

    hey bro where are you from?

  • @Protector7A
    @Protector7A 9 місяців тому

    Did you lose your cert over this homie? Big thanks much bigger than I can text here.

    • @hexdump1337
      @hexdump1337  9 місяців тому +4

      I don't see why I should lose my cert, as I leak no information on specific material used by OffSec and I do not talk in details about the machines for the exam.
      There's nothing in here that goes against OffSec terms as far as I understood them. This is just a description of the knowledge itself that I found myself learning while studying for OSCP, which I heavily restructured in order to make it (in my opinion) much more clear to understand. That is, this is mainly the result of my work, inspired, of course, by the OSCP syllabus material, available for free and for everyone at the following URL: www.offsec.com/courses/pen-200/download/syllabus
      Anyhow, thank you!

  • @Passion-i3v
    @Passion-i3v Рік тому

    Sir, can you make a roadmap for OSCP for beginner. Please, It will be helpful.

    • @James-lx5vk
      @James-lx5vk Рік тому +1

      There are plenty of roadmaps available, have a Google.

    • @Passion-i3v
      @Passion-i3v Рік тому

      too many roadmaps leads me to confusion. So much information. so that's why i commented here. who is actually giving OSCP training for free.@@James-lx5vk

    • @hexdump1337
      @hexdump1337  11 місяців тому +1

      It is true that there are many roadmaps, and honestly it is difficult to define exactly what to do before OSCP. In this video I focused only on the knowledge itself taught by OSCP.
      I can think about it however and maybe prepare something for the future.

    • @Passion-i3v
      @Passion-i3v 11 місяців тому

      thank you! Sure i will be waiting for that video.@@hexdump1337

  • @digitalforensicsalam4009
    @digitalforensicsalam4009 Рік тому +2

    Bash and python scripting oscp upload video sir

    • @hexdump1337
      @hexdump1337  Рік тому +1

      In the future I will make videos about those topics for sure!

  • @stefanvoigt6983
    @stefanvoigt6983 4 місяці тому

    Watched the complete course and took the OSCP exam..... 5/100 points, thanks for nothing bro...

    • @hexdump1337
      @hexdump1337  4 місяці тому +1

      The material is not supposed to have any guarantees, as those are impossible to have in this life.
      It just represents my point of view.
      You might find it helpful or not, it is your choice.

    • @stefanvoigt6983
      @stefanvoigt6983 4 місяці тому

      @@hexdump1337 What would you recommend me to do on top of this Course, it doesnt seem to suffice by its own for OSCP, maybe its not meant to

    • @VideoJunkee
      @VideoJunkee 3 місяці тому +1

      @@stefanvoigt6983I recommend you do the actual OSCP course and complete at least 60 boxes in their lab.

  • @konts6853
    @konts6853 11 місяців тому

    nothing to do in the real world

    • @benyicl92
      @benyicl92 11 місяців тому

      Please explain

    • @hexdump1337
      @hexdump1337  10 місяців тому

      yes, no idea what this means xD

    • @mattlai443
      @mattlai443 10 місяців тому

      @@benyicl92 one key point is the device got hacked in the dmz, in real world there is no way you can chisel and get out from the dmz to connect to any device staged in internal, let alone any PE that offsec is trying to teach you in the course which we would never log in to dmz devices with ad user. Thus the whole oscp is unreal

  • @JasonK-yc1lj
    @JasonK-yc1lj 21 день тому

    This is a pure 🪙