2026 interactive roadmap

OSCP+Roadmap

From zero to exam ready

Built to cover the current OSCP+ knowledge areas and prepare you for independent, exam-style practice.

Estimated duration8–12 Months
Recommended pace2–3 Hrs / Day
Start roadmap
OSCP+ certification logoSecurity+ certification logoeJPT certification logoPNPT certification logoCPTS certification logoCISSP certification logo
2026 learning paths

Cybersecurity certifications,
made simple.

Pick a certification and follow one clear roadmap. No guessing what to learn next and no huge wall of resources.

Certification library

Choose your destination

OSCP+ is available now. More complete roadmaps are being prepared.

2026 coverage reviewed

OSCP+ from zero
to exam ready

Independently mapped against OffSec’s current OSCP+ Body of Knowledge and Exam Guide. This is a study roadmap, not an official OffSec endorsement. Always recheck the official rules before your exam.

0%0 of 78 complete
1Build foundations9 beginner modules
2Learn core skillsPhases 1–13
3Practice independentlyPhases 14–15
Stage 1Start from zero

Complete all nine modules before moving forward.

CORE
Foundation track

Linux, Windows, networking & scripting

The basic vocabulary and tools needed for every later phase.

0/9
Stage 2Build core skills

Learn each discipline, then connect everything into an attack chain.

RECON
RECON track

Pentesting & Information Gathering

Build a repeatable method for discovering hosts, services, and attack surface.

0/6
AUDIT
AUDIT track

Vulnerability Assessment

Read scanner output critically and verify findings by hand.

0/1
WEB
WEB track

Web Security

Practice the web vulnerabilities that repeatedly create initial access.

0/12
EXPLOIT
EXPLOIT track

Public Exploits & Modification

Find, read, adapt, and troubleshoot exploit code safely.

0/5
SHELL
SHELL track

Shells, Payloads & Transfers

Move files reliably and turn fragile access into a usable shell.

0/3
EVADE
EVADE track

Client-Side Attacks & AV Evasion

Cover delivery, endpoint detection, and the exam-relevant client-side surface.

0/4
CREDS
CREDS track

Password Attacks

Build a disciplined workflow for guessing, cracking, relaying, and reusing credentials.

0/3
LINUX
LINUX track

Linux Privilege Escalation

Enumerate local weaknesses and turn access into root methodically.

0/2
WIN
WIN track

Windows Privilege Escalation

Recognize service, permission, task, and token escalation paths.

0/2
PIVOT
PIVOT track

Pivoting & Tunneling

Route traffic through compromised hosts without losing control of the attack chain.

0/3
AD
AD track

Active Directory

The core enterprise phase: enumerate, move laterally, and compromise a domain.

0/6
CHAIN
CHAIN track

Assembling the Pieces

Connect isolated techniques into a complete enterprise attack chain.

0/2
REPORT
REPORT track

Reporting

Create evidence-led reports another technical reader can reproduce.

0/6
Stage 3Practice without help

Work unseen targets and simulate the real exam.

LABS
LABS track

Full Machines

Stop consuming walkthroughs. Build independent rhythm on unseen targets.

0/5
READY
READY track

OSCP Final Preparation

Practice only: no courses, walkthroughs, or AI assistance.

0/9
Final verification

Before you book
the exam

Rules change. Use official sources for the current scope, restrictions, and reporting requirements.

About us

A clearer path into cybersecurity.

CyberPath was created by Saad Douiri to turn overwhelming certification objectives into simple, practical learning paths. Every roadmap is designed to help learners understand what to study, what to practice, and when they are ready to move forward.

We start with OSCP+ and will expand the library with more respected cybersecurity certifications.