Skip to content
8bytes
· Career

OSCP retrospective: what I would do differently

Notes on what worked, what didn't, and what I'd change about my OSCP preparation if I were starting over today.

Contents

I sat the OSCP in 2024 and passed first try. This is the post I wish I had read while preparing.

What worked

  • HackTheBox over PWK labs. The PWK labs that ship with the course are fine, but HackTheBox has more active boxes, more variety, and a stronger writeup culture. I solved roughly forty HTB boxes in the run-up.
  • Note-taking from day one. I kept a personal knowledge base of every command, every binary, every exploit step. By the time the exam came around, I was searching my own notes faster than I could Google.
  • Active Directory practice. The OSCP exam weighs AD heavily. The PWK course materials are decent but the depth comes from doing more boxes. HTB Pro Labs and Offensive Security’s own Proving Grounds are worth the money for this.

What I would change

  • Less buffer-overflow practice. I spent two weeks on traditional stack-based BOF for the OSCP, and the exam format has since moved away from heavy BOF reliance. Diminishing returns past a single working template.
  • More note-taking automation. I wrote notes manually. Tools like Obsidian or even a custom Hugo blog would have made it easier to cross-reference between machines later.
  • Earlier practice exam. I did a full 24-hour practice exam two weeks before the real one. I should have done it four weeks earlier — the gap exposed a category of mistake (time management on enumeration) that I needed time to fix.

What I would not change

The certification itself was worth it. Not because of what it taught — most of the learning came from boxes, not the course — but because of what it signalled. Every engagement scoping call since has been easier. Whether that is fair or not, OSCP remains the credential offensive-security buyers know.

Tags

oscp certifications career