⚠️ Malware / Trojaner / VirenWindows 11: Microsoft entfernt WMIC-Tool gegen Ransomware - ad-hoc-news.de(14.09.2026 um 07:58 Uhr)
🕵️ SicherheitslückenMicrosoft schließt Rekordzahl an Sicherheitslücken - techbook(14.09.2026 um 09:00 Uhr)
🪟 Windows ServerPC-COLLEGE: Tipp 383: Nachlese IFA 2026 in Berlin - MÖBELMARKT(14.09.2026 um 11:47 Uhr)
🤖 Android TippsSamsung knöpft sich die AirPods Max von Apple vor(14.09.2026 um 12:49 Uhr)
🪟 Windows TippsGoogle Gemini: Neue Windows-App holt die KI aus dem Browser(14.09.2026 um 06:00 Uhr)
🤖 Android TippsSamsung plant Preiserhebung im Galaxy-Ökosystem(14.09.2026 um 13:00 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11: Microsoft entfernt WMIC-Tool gegen Ransomware - ad-hoc-news.de(14.09.2026 um 07:58 Uhr)
🕵️ SicherheitslückenMicrosoft schließt Rekordzahl an Sicherheitslücken - techbook(14.09.2026 um 09:00 Uhr)
🪟 Windows ServerPC-COLLEGE: Tipp 383: Nachlese IFA 2026 in Berlin - MÖBELMARKT(14.09.2026 um 11:47 Uhr)
🤖 Android TippsSamsung knöpft sich die AirPods Max von Apple vor(14.09.2026 um 12:49 Uhr)
🪟 Windows TippsGoogle Gemini: Neue Windows-App holt die KI aus dem Browser(14.09.2026 um 06:00 Uhr)
🤖 Android TippsSamsung plant Preiserhebung im Galaxy-Ökosystem(14.09.2026 um 13:00 Uhr)

🕵️ Hacking 🕛 vor 2 Monaten 11 Min Lesezeit
0

The OSCP Is a Mental Game

↗ Quelle (infosecwriteups.com)
🗣️ Stimme:
📑 Inhaltsübersicht
📺
infosecwriteups.com

Yes, Another OSCP Blog Post. Bear With Me.

Well, I got my OSCP a couple of weeks back and it was quite an experience. The last 3 months of preparation paid off and the main challenge wasn’t even the technical stuff. It was the mental ability to keep trying and not give up.

I’ll touch on the prep approach and resources, but the main thing I want to talk about is your mental state during the 24 hours of the exam. There are literally an infinite number of blogs and walkthroughs out there covering how to prepare and which resources to use (I looked at them and you will too), which is great, but I won’t bore you with more of the same.

Let’s get into it.

Background

Before we get into it, a bit of context on where I’m coming from.

I’m currently a graduate student in Cybersecurity with around 2 years of professional experience in AppSec and DevSecOps. Offensive security isn’t my forte and my background is on the defensive side but I’ve kept my hands dirty through HTB, THM, and occasional CTFs, which gave me a reasonable foundation going in.

Before attempting the OSCP, I also completed the PNPT certification, which I’d recommend as a stepping stone. It gave me a structured way to think about penetration testing methodology before diving into something more complicated. You can read more about that experience

I went through the first 4 of these. They’re useful for getting familiar with the AD environment, though they don’t really cover the pivoting side of things that you’d expect in the exam. Still a solid resource. Feel free to pick up some of the later labs as well, since I’ve heard the pivoting is better covered in those.

  • Derron C’s AD Playlist:

Everything I took down throughout my prep got consolidated here. You don’t need to use it, but it was all I needed to quickly pull up commands during the exam, especially for the Windows and AD side of things.

C. Challenge Labs

Save the challenge labs for the final stretch, ideally 1 to 2 weeks before your exam date. These are the closest thing you’ll get to the real experience, so treat them as dress rehearsals.

  • Secura — AD focused, and in my opinion a bit easier than what you’ll see in the exam. Still good practice for building confidence.
  • Medtech — A larger network with more techniques than the OSCP actually expects, but it’s fun and great for sharpening your skills.
  • Zeus and Poseidon — More difficult and complex than the expected exam difficulty. Only take these on if you have time to spare, otherwise consider them optional.
  • OSCP A,B,C — The closest to the actual exam in terms of difficulty and structure. Do these as near to your exam date as possible, and time-bound yourself to mimic the real exam conditions. Treating them like the real thing is the best way to test your stamina and pacing before the day itself.

D. Pivoting

For pivoting, I relied on ligolo-ng, which I’d strongly recommend. Beyond pivoting itself, it covers two other use cases that are just as important on the exam:

  • Transferring files from your attacker machine to a host inside the internal network.
  • Catching a reverse shell back to your attacker machine from a host inside the internal network.

Both of these, along with the full ligolo-ng setup, are documented in my  — An online reverse shell generator for quickly creating reverse shell payloads in just about any language or format.

  •  — You’ve got to walk the dog. Gives you a clear overview of all the users, groups, and attack paths in your AD environment.
  • —Catches reverse shells and auto-upgrades them, so you don’t have to do the hard work manually.
  •  — The classic Linux enumeration script for privilege escalation.
  •  — A PowerShell script that hunts for common Windows privilege escalation misconfigurations.
  • — A friend’s OSCP medium post which helped me prepare for the OSCP.
  • Final Thoughts

    Looking back, the OSCP taught me less about hacking and more about persistence. The technical skills matter, of course, but plenty of people with the right skills still walk away without a pass. What gets you through those 24 hours is the willingness to keep going when you’re stuck, exhausted, and convinced the path forward doesn’t exist.

    What worked for me might not map perfectly onto your situation. I went in with a defensive background, prior CTF experience, and the PNPT under my belt, and I still got humbled for the better part of a day.

    A few things I’d leave you with:

    • The exam rewards patience, not panic. Almost every wall I hit had a simpler answer than I was giving it credit for.
    • Take breaks. Genuinely. Some of my clearer ideas came after stepping away from the screen.
    • One breakthrough can change everything. I sat at 50 points for the better part of a day. Thirty minutes was all it took to get to 80. Don’t give up before that moment arrives.

    If you want to learn more or just chat about the OSCP journey, feel free to reach out to me on was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.

    Vollständiger Original-Bericht
    Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf infosecwriteups.com.
    ↗ Original-Artikel auf infosecwriteups.com lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 0%
    🟡 In Evaluierung 0%
    🟢 Keine Auswirkung 0%
    Spannende Innovation 0%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    6 Quellen
    CVE-2026-89613 | Linux Kernel up to 7.2.3 ntfs input validation (Nessus ID 345345)
    5 Quellen
    CVE-2026-87431 | Google Chrome up to 152.0.7977.82 Extensions improper authorization (WID-SEC-2026-3238)
    2 Quellen
    CVE-2026-49853 | tornadoweb Tornado up to 6.5.5 Redirect redirect (Nessus ID 345570)
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten The OSCP Is a Mental Game

    Thematisch verwandte Begriffe: OSCP, Mental, Game · 6 Treffer

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...