OSCP+Roadmap
From zero to exam ready
Built to cover the current OSCP+ knowledge areas and prepare you for independent, exam-style practice.
OSCP+ preparation,
made simple.
This page is dedicated to OSCP+. Follow the phases in order, track your work, and build independent exam-style practice.
Make better study decisions
Public, research-led guidance for planning certification study and practising responsibly.
Build a realistic OSCP+ study plan
Weekly structure, milestones, reporting habits, mock sessions, and readiness checks.
Read guide02 · Career decisionsChoose the right certification path
Compare role fit, prerequisites, exam style, cost, and market recognition.
Read guide03 · Responsible learningPractise inside clear boundaries
Authorization, scope, lab isolation, data handling, records, and safe stop conditions.
Read guideOSCP+ from zero
to exam ready
Independently mapped against OffSec’s current OSCP+ Body of Knowledge and Exam Guide. This is a study roadmap, not an official OffSec endorsement. Always recheck the official rules before your exam.
Complete all nine modules before moving forward.
COREFoundation trackLinux, Windows, networking & scripting
The basic vocabulary and tools needed for every later phase.
0/9
Linux, Windows, networking & scripting
The basic vocabulary and tools needed for every later phase.
Learn each discipline, then connect everything into an attack chain.
RECONRECON trackPentesting & Information Gathering
Build a repeatable method for discovering hosts, services, and attack surface.
0/6
Pentesting & Information Gathering
Build a repeatable method for discovering hosts, services, and attack surface.
AUDITAUDIT trackVulnerability Assessment
Read scanner output critically and verify findings by hand.
0/1
Vulnerability Assessment
Read scanner output critically and verify findings by hand.
WEBWEB trackWeb Security
Practice the web vulnerabilities that repeatedly create initial access.
0/12
Web Security
Practice the web vulnerabilities that repeatedly create initial access.
EXPLOITEXPLOIT trackPublic Exploits & Modification
Find, read, adapt, and troubleshoot exploit code safely.
0/5
Public Exploits & Modification
Find, read, adapt, and troubleshoot exploit code safely.
SHELLSHELL trackShells, Payloads & Transfers
Move files reliably and turn fragile access into a usable shell.
0/3
Shells, Payloads & Transfers
Move files reliably and turn fragile access into a usable shell.
EVADEEVADE trackClient-Side Attacks & AV Evasion
Cover delivery, endpoint detection, and the exam-relevant client-side surface.
0/4
Client-Side Attacks & AV Evasion
Cover delivery, endpoint detection, and the exam-relevant client-side surface.
CREDSCREDS trackPassword Attacks
Build a disciplined workflow for guessing, cracking, relaying, and reusing credentials.
0/3
Password Attacks
Build a disciplined workflow for guessing, cracking, relaying, and reusing credentials.
LINUXLINUX trackLinux Privilege Escalation
Enumerate local weaknesses and turn access into root methodically.
0/2
Linux Privilege Escalation
Enumerate local weaknesses and turn access into root methodically.
WINWIN trackWindows Privilege Escalation
Recognize service, permission, task, and token escalation paths.
0/2
Windows Privilege Escalation
Recognize service, permission, task, and token escalation paths.
PIVOTPIVOT trackPivoting & Tunneling
Route traffic through compromised hosts without losing control of the attack chain.
0/3
Pivoting & Tunneling
Route traffic through compromised hosts without losing control of the attack chain.
ADAD trackActive Directory
The core enterprise phase: enumerate, move laterally, and compromise a domain.
0/6
Active Directory
The core enterprise phase: enumerate, move laterally, and compromise a domain.
CHAINCHAIN trackAssembling the Pieces
Connect isolated techniques into a complete enterprise attack chain.
0/2
Assembling the Pieces
Connect isolated techniques into a complete enterprise attack chain.
REPORTREPORT trackReporting
Create evidence-led reports another technical reader can reproduce.
0/6
Reporting
Create evidence-led reports another technical reader can reproduce.
Work unseen targets and simulate the real exam.
LABSLABS trackFull Machines
Stop consuming walkthroughs. Build independent rhythm on unseen targets.
0/5
Full Machines
Stop consuming walkthroughs. Build independent rhythm on unseen targets.
READYREADY trackOSCP Final Preparation
Practice only: no courses, walkthroughs, or AI assistance.
0/9
OSCP Final Preparation
Practice only: no courses, walkthroughs, or AI assistance.
Before you book
the exam
Rules change. Use official sources for the current scope, restrictions, and reporting requirements.

A clearer path into cybersecurity.
CyberPath was created by Saad Douiri to turn overwhelming certification objectives into simple, practical learning paths. Every roadmap is designed to help learners understand what to study, what to practice, and when they are ready to move forward.
CyberPath now publishes complete OSCP+ and CompTIA Security+ roadmaps, with more respected certifications in development. Read how information is researched and corrected in our Editorial Policy.




