An unhandled error has occurred. Reload X
View official blueprint on Cert Atlas

OffSec Exploit Developer (OSED) Practice Test

130 questions available

The OffSec Exploit Developer (OSED) exam is a rigorous, hands-on assessment of advanced Windows exploit development skills. It tests a candidate's ability to methodically analyze software, identify vulnerabilities, and craft reliable exploits in constrained, realistic environments. The exam focuses on defeating modern exploit mitigations like Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) on 32-bit Windows systems, requiring deep understanding of stack-based overflows, structured exception handler (SEH) overwrites, and Return-Oriented Programming (ROP). Successful candidates demonstrate not just theoretical knowledge, but the practical discipline to reverse engineer binaries, write custom shellcode, and chain techniques to achieve code execution. This exam is designed for penetration testers, red teamers, malware analysts, and security researchers who need to move beyond using public exploits and develop their own capabilities. Passing validates a practitioner's ability to conduct sophisticated offensive security research and handle custom, unknown vulnerabilities.

Certification exam
24 hours Time Limit
Career Opportunities & Salary
Entry – Security Tester $80,000 - $121,000
Mid-Career – Penetration Tester $113,000 - $172,000
Senior – Principal Penetration Tester $147,000 - $224,000
Security TesterPenetration TesterPrincipal Penetration Testergrowing market
Why This Certification Opens Doors

In real-world security assessments, public exploits are often unavailable, patched, or unreliable against customized targets. The ability to independently develop a working exploit from a discovered vulnerability is a critical, high-value skill. It transforms a security finding from a theoretical risk into a demonstrable proof of impact, essential for convincing stakeholders and accurately gauging risk. This skill is fundamental for advanced red team operations, vulnerability research, and developing a deeper understanding of how defenses work and how they can be circumvented, ultimately leading to more resilient systems.

Exam Blueprint
01Bypassing DEP and ASLR
02Egg Hunters
03Format String Vulnerabilities
04Return-Oriented Programming (ROP)
05SEH (Structured Exception Handling) Exploits
06Stack-Based Buffer Overflows
07Windows x86 Assembly and Shellcoding
Exam Details OSED | $1499 USD | 24 hours
Exam Code OSED
Vendor OffSec
Exam Cost $1499 USD
Passing Score 75
Time Limit 24 hours
Question Types Practical/Hands-On (exploit vulnerable machines, submit proof.txt files)
Retake Policy Retake attempts can be purchased separately. No mandatory waiting period. Retake pricing varies by course bundle.
Exam Format Practical / Penetration Test Lab
Online Proctoring Available
Available In
English
Study Resources
OffSec Learning Library (PEN-200/WEB-300/EXP-301)
OffSecFree
Course material, lab time, and one exam attempt typically bundled together
View
Frequently Asked Questions

How much assembly and reverse engineering knowledge is truly required?

A strong, practical foundation is mandatory. You must be comfortable reading and tracing x86 assembly, understanding calling conventions, recognizing stack frames, and navigating code in a debugger. You do not need to be a master reverse engineer of complex software, but you must be adept at analyzing the relevant code paths around a vulnerability to understand program flow and locate useful instructions/gadgets.

Is the exam solely about writing shellcode from scratch?

While you need to understand shellcode structure and can modify existing code, the exam's heavy focus is on the exploit primitives and chains that get you to the point of executing shellcode. This includes crafting stack pivots, building ROP chains to call APIs like VirtualProtect, and bypassing mitigations. You will work with shellcode, but the core challenge is engineering the reliable exploit framework that delivers it.

How important is time management during the exam?

Critical. The exam is a marathon of focused analysis and development. Effective time management stems from a practiced methodology. You must quickly triage the vulnerability, efficiently hunt for ROP gadgets, and systematically build and debug your exploit. Spending too long on a single debugging issue without a structured approach is a common pitfall. Practice under timed conditions.

Can I rely on public tools like Metasploit or automated ROP compilers?

No. The exam tests your ability to develop exploits manually using a debugger, a Python script, and your knowledge. You are expected to write your own exploit code, manually find and chain ROP gadgets, and craft your payload. Automation is limited to the scripts you write yourself during the process.

What is the biggest shift in mindset needed from OSCP to OSED?

The shift is from breadth of attack surface to depth of technical execution. OSCP emphasizes systematic network exploitation using various tools. OSED demands deep, concentrated focus on a single vulnerability, requiring low-level understanding of memory, the CPU, and operating system internals to construct a weaponized exploit from first principles. It's a specialized, research-oriented skill set.

Reviews & Ratings
No reviews yet

Be the first to review this exam and help other learners!


Share Your Experience