2026 interactive roadmap

OSCP+Roadmap

From zero to exam ready

Built to cover the current OSCP+ knowledge areas and prepare you for independent, exam-style practice.

Estimated duration8–12 Months
Recommended pace2–3 Hrs / Day
Start roadmap
OSCP+ certification logoSecurity+ certification logoeJPT certification logoPNPT certification logoCPTS certification logoCISSP certification logo
2026 learning paths

OSCP+ preparation,
made simple.

This page is dedicated to OSCP+. Follow the phases in order, track your work, and build independent exam-style practice.

Original field guides

Make better study decisions

Public, research-led guidance for planning certification study and practising responsibly.

Browse all CyberPath guides
2026 coverage reviewed

OSCP+ from zero
to exam ready

Independently mapped against OffSec’s current OSCP+ Body of Knowledge and Exam Guide. This is a study roadmap, not an official OffSec endorsement. Always recheck the official rules before your exam.

0%0 of 78 complete
Authorized practice only

Learn security without crossing the line.

Use every roadmap resource only in purpose-built labs, exam environments, systems you own, or systems you have explicit permission to test. Public accessibility is never authorization.

Read responsible use
1Build foundations9 beginner modules
2Learn core skillsPhases 1–13
3Practice independentlyPhases 14–15
Stage 1Start from zero

Complete all nine modules before moving forward.

CORE
Foundation track

Linux, Windows, networking & scripting

The basic vocabulary and tools needed for every later phase.

0/9
Stage 2Build core skills

Learn each discipline, then connect everything into an attack chain.

RECON
RECON track

Pentesting & Information Gathering

Build a repeatable method for discovering hosts, services, and attack surface.

0/6
AUDIT
AUDIT track

Vulnerability Assessment

Read scanner output critically and verify findings by hand.

0/1
WEB
WEB track

Web Security

Practice the web vulnerabilities that repeatedly create initial access.

0/12
EXPLOIT
EXPLOIT track

Public Exploits & Modification

Find, read, adapt, and troubleshoot exploit code safely.

0/5
SHELL
SHELL track

Shells, Payloads & Transfers

Move files reliably and turn fragile access into a usable shell.

0/3
EVADE
EVADE track

Client-Side Attacks & AV Evasion

Cover delivery, endpoint detection, and the exam-relevant client-side surface.

0/4
CREDS
CREDS track

Password Attacks

Build a disciplined workflow for guessing, cracking, relaying, and reusing credentials.

0/3
LINUX
LINUX track

Linux Privilege Escalation

Enumerate local weaknesses and turn access into root methodically.

0/2
WIN
WIN track

Windows Privilege Escalation

Recognize service, permission, task, and token escalation paths.

0/2
PIVOT
PIVOT track

Pivoting & Tunneling

Route traffic through compromised hosts without losing control of the attack chain.

0/3
AD
AD track

Active Directory

The core enterprise phase: enumerate, move laterally, and compromise a domain.

0/6
CHAIN
CHAIN track

Assembling the Pieces

Connect isolated techniques into a complete enterprise attack chain.

0/2
REPORT
REPORT track

Reporting

Create evidence-led reports another technical reader can reproduce.

0/6
Stage 3Practice without help

Work unseen targets and simulate the real exam.

LABS
LABS track

Full Machines

Stop consuming walkthroughs. Build independent rhythm on unseen targets.

0/5
READY
READY track

OSCP Final Preparation

Practice only: no courses, walkthroughs, or AI assistance.

0/9
Final verification

Before you book
the exam

Rules change. Use official sources for the current scope, restrictions, and reporting requirements.

About us

A clearer path into cybersecurity.

CyberPath was created by Saad Douiri to turn overwhelming certification objectives into simple, practical learning paths. Every roadmap is designed to help learners understand what to study, what to practice, and when they are ready to move forward.

CyberPath now publishes complete OSCP+ and CompTIA Security+ roadmaps, with more respected certifications in development. Read how information is researched and corrected in our Editorial Policy.