OffSec Live-PEN200
OffSec Live-PEN200
OffSec Live-PEN200
OffSec Live: PEN-200 is our scheduled and open streaming offering that includes a learning
journey designed to facilitate learning, improve engagement and ultimately increase
Offensive Security Certified Professional (OSCP) certification preparedness and
achievement designed for OffSec students currently enrolled in PEN-200.
OffSec Live’s weekly Twitch streaming is open to the public, and no additional fees will be
charged to active OffSec subscription holders. Currently enrolled OffSec PEN-200 and
Learn Unlimited subscription holders will also be provided access to an overall PEN-200
learning journey, recorded Twitch streaming sessions, specialized demonstration lab
exercises, and an OffSec Live Discord channel. Those who do not have a current OffSec
PEN-200 or Learn Unlimited subscription will have access to the weekly OffSec Live Twitch
streaming sessions.
For additional questions, please see our OffSec Live: PEN-200 FAQs here.
1
Getting Ready
To prepare for PEN-200, please see quick reference guidance that will help you get started
with the OffSec Training Library (OTL) platform and improve your learning experience.
*All currently enrolled PEN200 students will have access to the OffSec Live - PEN200 Discord
channel.
2
Preparing for OffSec Live: PEN-200 - weekly sessions guidance:
Recommended approach
1) Read content for the PEN-200 course Topic covered in the week.
2) Watch videos for PEN-200 Topic covered in the week.
3) Complete the topic exercises covered in the week.
4) Attempt the demo labs for the weekly topic prior to OffSec Live Wednesday
session.
5) Attempt the PG-Play machine for the week prior to OffSec Live Friday session.
6) Complete the target lab exercises each week.
Please note this is a recommendation for preparing for each OffSec Live weekly session
only. Please follow the recommended best approach + the Learning Journey below to most
effectively prepare for the OSCP exam.
PG Play & Practice is not a substitute for the PEN200 lab environment. PG Play & Practice
demonstrations are meant to augment the PEN200 learning experience only. Successful
completion of PEN200 requires active and consistent engagement in the PEN200 lab
environment. Those students who successfully complete all topic exercises and more than
50 PEN200 lab machines have a significantly higher OSCP pass rate than those who do not
do so.
3
OffSec Live- PEN-200 Learning Journey:
Learning 10
time (Hours)
Lab None
exercises to
complete
4
Week 2 : Learning 1) Understand some practical tools that are found in every pentester's
Practical Objectives toolkit.
Tools 2) Understand packet structures and learn how to sniff traffic.
3) Identify the difference between reverse and bind shells.
Learning 10
time (Hours)
Lab None
exercises to
complete
5
Week 3: Learning 1) Learn the importance of Passive Information Gathering.
Passive Objectives 2) Practical examples that show the impact of online presence.
Information
Gathering Learning 10
time (Hours)
6
Week 4: Learning 1) Understand some common active information gathering techniques
Active objectives including port scanning and DNS, SMB, NFS, SMTP, and SNMP
Information enumeration.
Gathering
Learning 10
time (Hours)
OffSec Live Friday, July 15, 12 pm - 1 pm (ET): Getting Started with PWK Labs - Jeremy
Weekly Miller, PG Play - Born2root
Demo
7
Week 5: Learning 1) Understand automated and manual vulnerability scanning.
Vulnerability objectives
Scanning
Learning 10
time (Hours)
8
Week 6: Web Learning 1) Learn web application vulnerability enumeration and exploitation.
Application objectives 2) Demonstrate the exploitation of several common web application
Attacks vulnerabilities listed in the OWASP Top 10.
Learning 15
time (Hours)
9
Week 7: Web Learning 1) Learn web application vulnerability enumeration and exploitation.
Application Objectives 2) Demonstrate the exploitation of several common web application
Attacks vulnerabilities listed in the OWASP Top 10.
Learning 15
time (Hours)
10
Week 8 : Learning None
Catch-up objectives
Week
Learning None
time (Hours)
Readings: None
Topic in LMS
Watch: None
Videos in
LMS
Topic None
exercises to
complete
Lab None
exercises to
complete
11
Week 9: Learning 1) Learn the principles behind a buffer overflow attack.
Introduction objectives 2) Discover and exploit a remote buffer overflow.
to Buffer
Overflows Learning 15
and Windows time (Hours)
Buffer
Overflows Office Hours Monday, August 15 - 12 pm - 1 pm (ET)
Lab None
exercises to
complete
12
Week 10: Learning 1) Introduction Linux buffer overflows.
Linux Buffer objectives
Overflows
Learning 15
time (Hours)
13
Week 11: Learning 1) Identify factors that are important to consider for client-side attacks.
Client-Side objectives 2) Learn exploitation scenarios involving malicious HTML Applications and
Attacks Microsoft Word documents.
Learning 15
time (Hours)
14
Week 12: Learning 1) Identify online resources that host exploits for publicly known
Locating and objectives vulnerabilities.
Fixing Public 2) Learn how to modify public exploit code to fit a specific attack platform
Exploits
and target.
Learning 15
time (Hours)
15
Week 13: File Learning 1) Identify various file transfer methods that can be used in an assessment.
Transfers and objectives: 2) Learn how to bypass antivirus software on target machines.
Anti Virus
Bypass Learning 18
time (Hours)
OffSec Live Wednesday, September 14 - 1 pm - 2 pm (ET): File Transfers and Anti Virus
Weekly Bypass
Demo
16
Week 14: Learning 1) Learn privilege escalation techniques to elevate privileges on Windows
Privilege objectives and Linux-based targets from non-privileged user accounts.
Escalation
(Linux, Learning 18
Windows) time (Hours)
17
Week 15: Learning 1) Learn privilege escalation techniques to elevate privileges on Windows
Windows objectives and Linux-based targets from non-privileged user accounts.
Privilege
Escalation Learning 20
Vectors time (Hours)
Readings: None
Topic in LMS
Watch: None
Videos in
LMS
Topic None
exercises to
complete
18
Week 16: Learning 1) Learn how to leverage password attacks to gain access to a
Password objectives Windows-based target.
Attacks
Learning 20
time (Hours)
19
Week 17 : Learning 1) Understand various forms of port redirection, tunneling, and traffic
Port objectives encapsulation.
Redirection 2) Manipulate the directional flow of targeted traffic in restricted network
and
environments.
Tunneling
Learning 20
time (Hours)
20
Week 18 : Learning 1) Learn the basic concepts of Active Directory.
Active objectives 2) Demonstrate Active Directory enumeration, authentication, and lateral
Directory movement techniques.
Attacks (Part
1) Learning 20
time (Hours)
21
Week 19: Learning 1) Learn the basic concepts of Active Directory
Active objectives 2) Demonstrate Active Directory enumeration, authentication, and lateral
Directory movement techniques.
Attacks (Part
2) Learning 20
time (Hours)
Readings: None
Topic in LMS
Watch: None
Videos in
LMS
Topic None
exercises to
complete
22
Week 20: Learning 1) Conduct a simulated penetration test inspired by real-world findings.
Assembling objectives:
the pieces
Learning 20
time (Hours)
Topic None
exercises to
complete
23
Week 21: Learning 1) Practice concepts with PWK Lab machines/Challenge Labs.
objectives:
Learning 20
time (Hours)
Readings: None
Topic in LMS
Watch: None
Videos in
LMS
Topic None
exercises to
complete
24
Week 22 Learning 1) Practice concepts with PWK Lab machines/Challenge Labs.
objectives:
Learning 20
time (Hours)
Readings: None
Topic in LMS
Watch: None
Videos in
LMS
Topic None
exercises to
complete
25
Week 23 Learning 1) Practice concepts with PWK Lab machines/Challenge Labs.
objectives:
Learning 20
time (Hours)
Readings: None
Topic in LMS
Watch: None
Videos in
LMS
Topic None
exercises to
complete
26
Week 24 Learning 1) Practice concepts with PWK Lab machines/Challenge Labs.
objectives:
Learning 20
time (Hours)
Readings: None
Topic in LMS
Watch: None
Videos in
LMS
Topic None
exercises to
complete
27
Week 25 Learning 1) Attempt the Mock Exam.
objectives:
Learning 20
time (Hours)
Readings: None
Topic in LMS
Watch: None
Videos in
LMS
Topic None
exercises to
complete
28