PWK & OSCP
JOURNEY OF MINE
Created by :
Syarif | @fl3xu5
August 27, 2015
1
What’s That ?
★ About PWK & OSCP
★ The Online Training Workflow
★ My Journey to Obtain the OSCP
★ Lesson learned / Tips
2
About PWK & OSCP
• PWK ( Penetration Testing with Kali Linux) is a Penetration Testing
Course created by Offensive Security
• OSCP ( Offensive Security Certified Professional ) is The
Certification for PWK
• More information :
• https://www.offensive-security.com/information-security-
training/penetration-testing-training-kali-linux/
• https://www.offensive-security.com/information-security-
certifications/oscp-offensive-security-certified-professional/
• https://www.offensive-security.com/faq/
3
The Online Training Workflow
Register & Download PWK Materials
Connect to the Offsec Labs
The OSCP Certification
4
My PWK & OSCP Journey
Learning the PWK Materials
5
Doing the Lab Exercises
Writing the PWK Report
Penetration Testing the Exam Servers
Penetration Testing the Internal Labs
Learning the PWK Materials
• PWK Materials Contain of :
• 149 PWK Videos
• 350 Pages of PWK .pdf Guide
• Learn the Materials ( Videos .pdf )
• Practice them ( Hands-on )
• Write a “Study Notes” on the Keepnote
6
Doing the Lab Exercises
• Do all of the Lab Exercises Correctly
• Write the Results on the Keepnote
7
Penetration Testing the Internal Labs
• Offensive Security Team will give :
• A Lab Connectivity Guide + a VPN Credential
• Kali Linux VM Image
• PWK Report Template
• Connect to the Labs through VPN
• Use that VM to Pentest the Internal Lab
• ONLY for Penetration Testing
• Don’t Update the Metasploit / others Software
8
Penetration Testing the Internal Labs
• Hack all of the Target Machines
• Write the Walkthrough Completely
• Take the Screenshot and Grab the Proof files
• Write the Pentest Report on the Keepnote
9
Penetration Testing the Exam Servers
• About the Challenge ( Exam ) :
• 24 Hours Exam Time
• Minimum 70 Points Total to Pass
• Submit “PWK Report” within Next 24 Hours
• Read the Exam Guide Carefully
10
Penetration Testing the Exam Servers
• Connect to the OSCP Exam Lab through VPN
• Hack the Target machines with the Highest
Points first
• Write the Walkthrough Completely
• Take the Screenshot and Grab the Proof files
• Write the Pentest Report on the Keepnote
11
Writing the PWK Report
• Compiling the Report ( Keepnote PWK Report )
• The PWK Report contains of :
• All of the Lab Exercises
• Internal Lab Pentest Report
• Exam Pentest Report
12
Lesson Learned & Tips
• Always Praying to the God
• Focus on Each Steps of the Journey
• Keep Calm & Never Give Up
• Use Offensive Security Motto : “Try Harder”
• Finish the Internal Labs & the Lab Exercises
Report before Taking the Exam
13
References :
• https://www.offensive-security.com/information-
security-training/penetration-testing-training-kali-linux/
• https://www.offensive-security.com/information-
security-certifications/oscp-offensive-security-
certified-professional/
• https://www.offensive-security.com/faq/
• https://www.offensive-security.com/offsec/say-try-
harder/

More Related Content

PDF
Oscp preparation
PPTX
Oscp - Journey
ODP
Automating OWASP ZAP - DevCSecCon talk
ODP
2014 ZAP Workshop 2: Contexts and Fuzzing
PDF
When the internet bleeded : RootConf 2014
PDF
Intro to DefectDojo at OWASP Switzerland
ODP
OWASP WTE - Now in the Cloud!
PPTX
The OWASP Zed Attack Proxy
Oscp preparation
Oscp - Journey
Automating OWASP ZAP - DevCSecCon talk
2014 ZAP Workshop 2: Contexts and Fuzzing
When the internet bleeded : RootConf 2014
Intro to DefectDojo at OWASP Switzerland
OWASP WTE - Now in the Cloud!
The OWASP Zed Attack Proxy

What's hot (20)

ODP
2014 ZAP Workshop 1: Getting Started
ODP
BSides Manchester 2014 ZAP Advanced Features
PPTX
Zap vs burp
ODP
OWASP 2015 AppSec EU ZAP 2.4.0 and beyond..
ODP
OWASP 2013 APPSEC USA Talk - OWASP ZAP
PDF
Automated Security Testing
ODP
JavaOne 2014 Security Testing for Developers using OWASP ZAP
ODP
BlackHat 2014 OWASP ZAP Turbo Talk
PDF
Virtual Security Lab Setup - OWASP Broken Web Apps, Webgoat, & ZAP
PDF
Owasp tds
ODP
JoinSEC 2013 London - ZAP Intro
ODP
OWASP Zed Attack Proxy Demonstration - OWASP Bangalore Nov 22 2014
PDF
“Sensu and Sensibility” - The Story of a Journey From #monitoringsucks to #mo...
PDF
[OWASP Poland Day] Security knowledge framework
ODP
OWASP 2014 AppSec EU ZAP Advanced Features
ODP
OWASP 2013 APPSEC USA ZAP Hackathon
ODP
OWASP 2013 AppSec EU Hamburg - ZAP Innovations
PDF
The Final Frontier, Automating Dynamic Security Testing
PDF
N Different Strategies to Automate OWASP ZAP - OWASP APPSec BUCHAREST - Oct 1...
PDF
[OWASP Poland Day] A study of Electron security
2014 ZAP Workshop 1: Getting Started
BSides Manchester 2014 ZAP Advanced Features
Zap vs burp
OWASP 2015 AppSec EU ZAP 2.4.0 and beyond..
OWASP 2013 APPSEC USA Talk - OWASP ZAP
Automated Security Testing
JavaOne 2014 Security Testing for Developers using OWASP ZAP
BlackHat 2014 OWASP ZAP Turbo Talk
Virtual Security Lab Setup - OWASP Broken Web Apps, Webgoat, & ZAP
Owasp tds
JoinSEC 2013 London - ZAP Intro
OWASP Zed Attack Proxy Demonstration - OWASP Bangalore Nov 22 2014
“Sensu and Sensibility” - The Story of a Journey From #monitoringsucks to #mo...
[OWASP Poland Day] Security knowledge framework
OWASP 2014 AppSec EU ZAP Advanced Features
OWASP 2013 APPSEC USA ZAP Hackathon
OWASP 2013 AppSec EU Hamburg - ZAP Innovations
The Final Frontier, Automating Dynamic Security Testing
N Different Strategies to Automate OWASP ZAP - OWASP APPSec BUCHAREST - Oct 1...
[OWASP Poland Day] A study of Electron security
Ad

Viewers also liked (7)

PDF
Pentest with Metasploit
PDF
PDF
Social Network Security & Backdooring email
PDF
Wireless LAN Security-Bimtek Kominfo
PDF
Prepare Yourself to Become Infosec Professional
PDF
iCrOSS 2013_Pentest
Pentest with Metasploit
Social Network Security & Backdooring email
Wireless LAN Security-Bimtek Kominfo
Prepare Yourself to Become Infosec Professional
iCrOSS 2013_Pentest
Ad

Similar to My pwk & oscp journey (20)

PDF
Quality Management Introduction
PDF
Introduction to the DevNet Sandbox and IVT
PPT
Introduction to the DevNet Sandbox
PDF
Continuous Integration, Deploy, Test From Beginning To End 2014
PDF
Ten Steps To Success
PPTX
Istqb foundation level day 1
PDF
PAC 2019 virtual Bruno Audoux
PPTX
Getting started with Octopus Deploy
PDF
we45 DEFCON Workshop - Building AppSec Automation with Python
PDF
Lars Wolff - Performance Testing for DevOps in the Cloud - Codemotion Amsterd...
PDF
Use Jenkins For Continuous Load Testing And Mobile Test Automation
PDF
Deployment automation framework with selenium
PPTX
Selenium Automation at Incapsula
PPT
Continuous Delivery Agiles 2014 Medellin
PDF
Atlassian's Mystique CLI, Minimizing the Experiment Development Cycle
PPTX
Automated testing on steroids – Trick for managing test data using Docker sna...
PPTX
DEVNET-1102 Introduction to the DevNet Sandbox and IVT
PPTX
AppSec DC 2019 ASVS 4.0 Final.pptx
PPTX
AppSec DC 2019 ASVS 4.0 Final.pptx
PPTX
CMG imPACt2016 - Mobile performance testing - Vendor training - Federico Tole...
Quality Management Introduction
Introduction to the DevNet Sandbox and IVT
Introduction to the DevNet Sandbox
Continuous Integration, Deploy, Test From Beginning To End 2014
Ten Steps To Success
Istqb foundation level day 1
PAC 2019 virtual Bruno Audoux
Getting started with Octopus Deploy
we45 DEFCON Workshop - Building AppSec Automation with Python
Lars Wolff - Performance Testing for DevOps in the Cloud - Codemotion Amsterd...
Use Jenkins For Continuous Load Testing And Mobile Test Automation
Deployment automation framework with selenium
Selenium Automation at Incapsula
Continuous Delivery Agiles 2014 Medellin
Atlassian's Mystique CLI, Minimizing the Experiment Development Cycle
Automated testing on steroids – Trick for managing test data using Docker sna...
DEVNET-1102 Introduction to the DevNet Sandbox and IVT
AppSec DC 2019 ASVS 4.0 Final.pptx
AppSec DC 2019 ASVS 4.0 Final.pptx
CMG imPACt2016 - Mobile performance testing - Vendor training - Federico Tole...

Recently uploaded (20)

PPTX
pharmaceutics-1unit-1-221214121936-550b56aa.pptx
PDF
M.Tech in Aerospace Engineering | BIT Mesra
PDF
Farming Based Livelihood Systems English Notes
PDF
Chevening Scholarship Application and Interview Preparation Guide
PPTX
Diploma pharmaceutics notes..helps diploma students
PPTX
Climate Change and Its Global Impact.pptx
PDF
Disorder of Endocrine system (1).pdfyyhyyyy
PDF
Laparoscopic Colorectal Surgery at WLH Hospital
PDF
African Communication Research: A review
PPTX
ACFE CERTIFICATION TRAINING ON LAW.pptx
PPTX
4. Diagnosis and treatment planning in RPD.pptx
PDF
faiz-khans about Radiotherapy Physics-02.pdf
PDF
LIFE & LIVING TRILOGY - PART (3) REALITY & MYSTERY.pdf
PPTX
Macbeth play - analysis .pptx english lit
PPTX
PLASMA AND ITS CONSTITUENTS 123.pptx
PDF
Fun with Grammar (Communicative Activities for the Azar Grammar Series)
PDF
Health aspects of bilberry: A review on its general benefits
PDF
The TKT Course. Modules 1, 2, 3.for self study
PDF
0520_Scheme_of_Work_(for_examination_from_2021).pdf
PDF
fundamentals-of-heat-and-mass-transfer-6th-edition_incropera.pdf
pharmaceutics-1unit-1-221214121936-550b56aa.pptx
M.Tech in Aerospace Engineering | BIT Mesra
Farming Based Livelihood Systems English Notes
Chevening Scholarship Application and Interview Preparation Guide
Diploma pharmaceutics notes..helps diploma students
Climate Change and Its Global Impact.pptx
Disorder of Endocrine system (1).pdfyyhyyyy
Laparoscopic Colorectal Surgery at WLH Hospital
African Communication Research: A review
ACFE CERTIFICATION TRAINING ON LAW.pptx
4. Diagnosis and treatment planning in RPD.pptx
faiz-khans about Radiotherapy Physics-02.pdf
LIFE & LIVING TRILOGY - PART (3) REALITY & MYSTERY.pdf
Macbeth play - analysis .pptx english lit
PLASMA AND ITS CONSTITUENTS 123.pptx
Fun with Grammar (Communicative Activities for the Azar Grammar Series)
Health aspects of bilberry: A review on its general benefits
The TKT Course. Modules 1, 2, 3.for self study
0520_Scheme_of_Work_(for_examination_from_2021).pdf
fundamentals-of-heat-and-mass-transfer-6th-edition_incropera.pdf

My pwk & oscp journey

  • 1. PWK & OSCP JOURNEY OF MINE Created by : Syarif | @fl3xu5 August 27, 2015 1
  • 2. What’s That ? ★ About PWK & OSCP ★ The Online Training Workflow ★ My Journey to Obtain the OSCP ★ Lesson learned / Tips 2
  • 3. About PWK & OSCP • PWK ( Penetration Testing with Kali Linux) is a Penetration Testing Course created by Offensive Security • OSCP ( Offensive Security Certified Professional ) is The Certification for PWK • More information : • https://www.offensive-security.com/information-security- training/penetration-testing-training-kali-linux/ • https://www.offensive-security.com/information-security- certifications/oscp-offensive-security-certified-professional/ • https://www.offensive-security.com/faq/ 3
  • 4. The Online Training Workflow Register & Download PWK Materials Connect to the Offsec Labs The OSCP Certification 4
  • 5. My PWK & OSCP Journey Learning the PWK Materials 5 Doing the Lab Exercises Writing the PWK Report Penetration Testing the Exam Servers Penetration Testing the Internal Labs
  • 6. Learning the PWK Materials • PWK Materials Contain of : • 149 PWK Videos • 350 Pages of PWK .pdf Guide • Learn the Materials ( Videos .pdf ) • Practice them ( Hands-on ) • Write a “Study Notes” on the Keepnote 6
  • 7. Doing the Lab Exercises • Do all of the Lab Exercises Correctly • Write the Results on the Keepnote 7
  • 8. Penetration Testing the Internal Labs • Offensive Security Team will give : • A Lab Connectivity Guide + a VPN Credential • Kali Linux VM Image • PWK Report Template • Connect to the Labs through VPN • Use that VM to Pentest the Internal Lab • ONLY for Penetration Testing • Don’t Update the Metasploit / others Software 8
  • 9. Penetration Testing the Internal Labs • Hack all of the Target Machines • Write the Walkthrough Completely • Take the Screenshot and Grab the Proof files • Write the Pentest Report on the Keepnote 9
  • 10. Penetration Testing the Exam Servers • About the Challenge ( Exam ) : • 24 Hours Exam Time • Minimum 70 Points Total to Pass • Submit “PWK Report” within Next 24 Hours • Read the Exam Guide Carefully 10
  • 11. Penetration Testing the Exam Servers • Connect to the OSCP Exam Lab through VPN • Hack the Target machines with the Highest Points first • Write the Walkthrough Completely • Take the Screenshot and Grab the Proof files • Write the Pentest Report on the Keepnote 11
  • 12. Writing the PWK Report • Compiling the Report ( Keepnote PWK Report ) • The PWK Report contains of : • All of the Lab Exercises • Internal Lab Pentest Report • Exam Pentest Report 12
  • 13. Lesson Learned & Tips • Always Praying to the God • Focus on Each Steps of the Journey • Keep Calm & Never Give Up • Use Offensive Security Motto : “Try Harder” • Finish the Internal Labs & the Lab Exercises Report before Taking the Exam 13
  • 14. References : • https://www.offensive-security.com/information- security-training/penetration-testing-training-kali-linux/ • https://www.offensive-security.com/information- security-certifications/oscp-offensive-security- certified-professional/ • https://www.offensive-security.com/faq/ • https://www.offensive-security.com/offsec/say-try- harder/