Ver el plan de examen oficial en Cert Atlas
Ver
OSCP Offensive Security Certified Professional Practice Test
Examen: OSCP Offensive Security Certified Professional Descripción: Certificación práctica de pruebas de penetración que requiere la explotación de vulnerabilidades reales en un entorno de laboratorio de 24 horas, abarcando desbordamientos de búfer, ataques web y escalada de privilegios.
Examen de certificación
Professional
Nivel
Oportunidades profesionales y salario
Security TesterPenetration TesterPrincipal Penetration Testergrowing mercado
Plan de Estudio
01Active Directory Enumeration and AttacksEnumerate AD (PowerShell, BloodHound), Kerberos attacks (Kerberoasting, Silver/Golden tickets, AS-REP roasting), Lateral movement (WMI, WinRM, PsExec, Pass-the-Hash)
02Antivirus EvasionAV detection engines, Manual and automated AV evasion
03Assembling the PiecesEnumerate and attack a public network, Pivot into an internal network, Chain to compromise a domain controller
04Client-Side AttacksTarget reconnaissance and client fingerprinting, Office macros and library files, Windows shortcut abuse
05Information GatheringPassive information gathering (OSINT, DNS), Active information gathering (port scanning, SMB/SMTP/SNMP enumeration)
06Linux Privilege EscalationEnumerate Linux permissions and system trails, Abuse cron jobs, SUID, capabilities, sudo, and kernel vulnerabilities
07Locating and Fixing Public ExploitsFind exploits (SearchSploit), Analyze and safely execute public exploits, Fix memory corruption and web exploits
08Password AttacksAttack SSH, RDP, HTTP POST logins, Crack passwords with wordlists and rules, Obtain, crack, pass, and relay NTLM hashes
09Port Redirection and TunnelingPort forwarding with Socat and Windows tools, SSH local/dynamic/remote forwarding, HTTP and DNS tunneling (Chisel, dnscat)
10Report Writing for Penetration TestersNote-taking and documentation structure, Write technical penetration testing reports
11SQL Injection AttacksManual UNION, error-based, and blind SQL injection, SQLmap, MSSQL xp_cmdshell
12The Metasploit FrameworkAuxiliary and exploit modules, Meterpreter and post-exploitation, Pivoting and resource scripts
13Vulnerability ScanningVulnerability scanning theory, Nessus, Nmap Scripting Engine
14Web Application AttacksWeb assessment methodology and OWASP Top 10, Burp Suite, XSS, directory traversal, file inclusion, file upload, command injection
15Windows Privilege EscalationEnumerate Windows privileges and access control, Hijack service binaries and DLLs, Abuse scheduled tasks
Recursos de Estudio
OffSec Learning Library (PEN-200/WEB-300/EXP-301)
Course material, lab time, and one exam attempt typically bundled together
Preguntas Frecuentes
Reseñas y Calificaciones
Aún sin reseñas
¡Sé el primero en reseñar este examen y ayuda a otros estudiantes!
Comparte Tu Experiencia
Inicia sesión para dejar una reseña
Comparte tu experiencia y ayuda a otros estudiantes a tomar decisiones informadas.
¿No ves tu examen?
Crea un examen de práctica con tu propio material de estudio.