How I Passed OSCP in Under 7 Hours on My First Try
Hey everyone, I'm H3racl3s. Today I want to share how I passed the OSCP exam on my first attempt, along with the methodology I used and how I prepared for it
How I Passed OSCP in Under 7 Hours on My First Try
My Story
Hey everyone, I’m H3racl3s. Today I want to share how I passed the OSCP exam on my first attempt, along with the methodology I used and how I prepared for it. If you want to skip straight to the good stuff, feel free to jump ahead using the section headers below.
First, let me tell you a bit about who I am. I graduated in Electrical and Electronics Engineering in 2024. During my engineering courses at university, I got introduced to Arduino, and it made me fall in love with coding. I learned how devices worked and how to make them do different things, but as time went on, I found myself drawn more and more to the coding side and the time I spent in front of a computer. In my last years of university, I discovered TryHackMe, and that’s how my first cybersecurity adventure began. I had always wondered how hackers actually managed to break into a website. I started practicing on TryHackMe and watching tutorials on YouTube.
Eventually I realized how important certifications were in cybersecurity, and I needed to get my first one. I started researching and settled on eJPT as my starting point — this was May 2025. For three months I practiced heavily and took notes, and by the end of that stretch I felt ready. I took the exam — my very first pentesting exam ever, and I was incredibly nervous since I’d never had an experience like that before. I passed eJPT on my first attempt and I was thrilled.
After passing, I kept practicing and started looking for the next mid-level certification. That’s when I first heard about OSCP. As someone at the eJPT level, I always looked up to people who held OSCP with a kind of envy, thinking “wow, these guys are elite-level hackers — will I ever get there?” I got an HTB membership and kept practicing, learning something new every day, taking notes more consistently, and continuing my research. I needed to pick a new certification target, but at the time I knew absolutely nothing about Active Directory — it felt incredibly difficult, and I had zero experience attacking AD environments.
That’s when I discovered TCM Security’s PNPT certification. I bought it in July 2025 — it came with a year of access, but I gave myself six months to earn it. I started watching TCM’s videos and taking notes step by step, and slowly but surely I began learning a lot about AD. I started feeling more confident, practicing on HTB and gaining real experience with Active Directory. AD stopped being an invisible mountain and became something I actually had experience with. By the end of the sixth month, it was time to take the exam. After a 5-day exam window, I passed PNPT successfully and felt incredibly happy. AD was no longer a mystery to me — it had become something I genuinely enjoyed. I learned so much from CyberMentor that the PNPT course is, in my opinion, the best course I’ve ever taken. It wasn’t just “pass the exam, get the cert” — it was pure, career-relevant knowledge. I still go back and use my PNPT notes to this day.
With eJPT and PNPT behind me, the big moment had arrived: it was time to take OSCP. I didn’t know if I was ready. I constantly felt like I was missing something, always wondering if my knowledge was actually at the level needed to pass this exam.
My OSCP Journey
Two Months Before Buying the Exam
Two months before purchasing the exam, I gave myself time to work on my weak points and get in as much practice as possible, because once you buy PEN-200, you only get three months total — and during that time you’re both practicing and working through the lab or exam content.
First, I kept solving modules on HTB Academy and taking notes, and finished roughly 86% of it.
Around the same time, I decided to work through LainKusanagi’s list and solve every machine on it across HTB, TryHackMe, and VulnHub.
For a full month I worked through HTB, TryHackMe, and VulnHub machines and took really solid notes. This is when I started properly organizing my notes.
Remember: a good pentester always has good notes. Don’t ask other people for their notes — write your own.
One Month Before Buying PEN-200
With one month left before the OSCP exam, I already had a roadmap in my head for how I’d prepare — I always knew what I’d focus on this month and what I’d practice the next. It was time to get a PG Practice and HackSmarter membership. PG Practice cost around $19,
and HackSmarter was $10,
so for a total of $30 I had a full month of practice ahead of me.
I’d wake up at 7 AM like I was heading to work, practice non-stop until around 4 PM, then go to the gym, have dinner, and get back to practicing around 7 PM. I kept this routine up for months.
Time to Buy PEN-200
By this point I’d gathered a lot of knowledge about the exam content and had done enough practice — it was time to buy the PEN-200 course. I used money I’d been saving up for months to purchase the OSCP exam. I’d never been so nervous in my life — believe it or not, my heart was racing so fast at OffSec’s checkout page :D. And just like that, I’d bought PEN-200.
Time to Lock In!!
While working on my master’s, dealing with school, and working part-time to make money, I was also grinding through the PEN-200 course, taking notes, and working through the labs. I learned something new every single day, and I got through about 75% of the PEN-200 course.
One Month Before the Exam (July)
With one month left before the exam, I bought another month of PG Practice and got back to practicing — but this time, I didn’t look at any walkthroughs. If I got stuck, I only referred to my own notes. That last month of PG Practice genuinely added a huge amount of value. I noticed that when I went back to review my notes, I kept finding different ways to pwn the same machine. That was a great sign — I’d reached a level where I could solve EASY–MEDIUM machines with zero hints.
Two Weeks Before the Exam
With two weeks left, it was time to tackle the challenge labs. I completed Secura, Medtech, OSCP-ABC, Zeus, Poseidon, and Laser — and took extremely thorough notes.
OSCP-ABC is incredibly important — I’ll say it again: use these labs, and use them well.
Six Days Before the Exam
At this point I stopped practicing entirely and shifted my focus to reporting — how to write a good report, what tips matter, what doesn’t. With 2–3 days left before the exam, I started reading through everything about the exam itself: the rules, what gets you disqualified, what gets you a pass.
https://help.offsec.com/hc/en-us/articles/360040165632-OSCP-Exam-Guide
After reading through all of that, I stopped sitting at my computer for the last few days. Instead, I went to the park to spend some time with myself — I needed distance from the screen and needed my mental state to be in a good place. The night before the exam, I prepped two days’ worth of meals and put them in the fridge, and picked up some tea and snacks.
Exam Day
Exam day had finally arrived!! My exam started at 10 AM. First, I showed the proctor my room and under my desk — I was extremely nervous. My notes were ready, and after months of this journey, the moment had finally come. I had to trust myself — I had to pass this exam.
I started the exam and gave myself a rule: I’d stay on any one machine for 2–2.5 hours max. I began with Active Directory, but I found absolutely nothing — no foothold at all. I kept telling myself, “AD is supposed to be your favorite part, and you can’t find anything? Are you actually going to fail this exam?” Those thoughts started creeping in, and I had to step away from the desk. I felt genuinely devastated. I rested for a while and told myself: this is just an exam, you’ve worked hard, you’re going to pass this, you’re the one who’s going to make this happen.
After resting, I sat back down, skipped AD for the moment, and moved to the standalone machines. I started on the first one but couldn’t find anything there either — I felt like a total loser. Three hours had passed and I had nothing to show for it. I moved to the second machine, and suddenly everything changed. I got a foothold on the first machine, found a way to escalate privileges, and fully compromised it. That gave me an enormous morale boost. I moved on to the next machine and slowly started finding footholds there too.
Then I told myself: if I can fully clear the AD set now, I’ll have more than enough points to pass. I left the standalone machines and went back to AD, enumerating and pushing through it. By around the 7-hour mark, I had fully compromised the AD set as well. At that point I was confident I’d passed — I had more than enough for a passing score. I went back through my notes and re-walked every path I’d pwned, to make sure I hadn’t missed anything, because I knew that a sloppy report could still cost me the exam. I checked my notes 2–3 times to make sure I could reproduce every compromise. Once I was done with the technical side, I put together a solid report from my notes, using OffSec’s own report template.
And I Passed!
Four days later, I got an email from OffSec: “We are pleased to inform you that you have successfully completed…” I can’t even describe how happy I was in that moment — months of hard work and effort, all paying off. I used to ask myself sometimes, “is this field even right for me, can I actually do this?” And now I had passed OSCP, and I was overjoyed.
What I can say is that one of the smartest things I did throughout this whole process was always having a roadmap. I always knew what I’d be working on the following month. Every single night, when I put my head on the pillow, I believed I was going to pass this exam. I always told myself I needed to trust myself.
A Few Words on Motivation
“I don’t stop when I’m tired. I stop when I’m done.” — David Goggins
The reason I’m including this section is that, at the end of the day, we all have different stories, but we’re all on the same road. Throughout this exam journey, I never had a mentor or anyone telling me “do this, do that.” I had to understand, on my own, that I needed to wake up early every morning and sit down at that computer — that I needed discipline.
In 2025, I moved to a different country, away from my family. Missing my family and feeling lonely weighed on me. Despite all of that, I made myself a promise that I was going to make this happen. Some people laughed at me and thought I’d fail. Some people gave up on me along the way. I still believed in myself, and I wanted to complete this journey on my own.
If you’re reading this, here’s the biggest piece of advice I can give you: right now, never — ever — give up, okay? When people tell you that you won’t make it, don’t hang your head — keep going. This is your passion, and you’re going to do great things down the line. Maybe nobody’s told you lately how hard you’ve been working. Maybe this whole journey feels long and exhausting to you right now. But I believe in you. One day, when you get this certification, you’ll finally take a deep breath — and you’ll also realize that this certification is just one small step in a much bigger career.
I’m talking directly to you, the person reading this: I’m proud of you, always. You’re going to make it — you are going to make it. I want you to look in the mirror and say that to yourself. Never, ever give up, okay? I don’t believe in “failure” the way most people do. Did you take the exam and not pass? That’s not a failure — you didn’t fail, you just gained experience. You’ll take the exam, apply what you learned, and if you don’t pass, you’ll come out of it more experienced and stronger for the next attempt. I believe in you. Take care of yourself, take care of your mental health, okay? This exam isn’t the end of your life — enjoy the process.
My Exam Advice — Summary
Okay, enough talking — in this section I’ll share resources and advice more directly focused on the exam itself.
1. Practice, practice, practice!!
The first piece of advice I want to give is this: before you sit the exam, get real hands-on reps. I solved around 92 machines on HTB, close to 300 rooms on TryHackMe, 93 machines on PG Practice, 50 machines on PG Play, and a large number of machines on HackSmarter. The bottom line is that it’s all about practice — watching YouTube videos alone won’t get you there. You need to actually open that terminal and pwn machines yourself.
Like everyone else, I worked through the machines on Lain’s and TJ Null’s lists:
https://docs.google.com/spreadsheets/u/1/d/1dwSMIAPIam0PuRBkCiDI88pU3yzrqqHkDtBngUHNCw8/htmlview
If you don’t know about HackSmarter, I highly recommend checking it out — I solved a ton of machines there.
For AD practice specifically, these machines are excellent:
https://www.hacksmarter.org/catalog
Everyone knows ippsec — his videos helped me enormously.
https://www.youtube.com/@ippsec
Mike’s methodology write-ups were an excellent resource during my preparation and helped me improve my overall methodology.
https://hackwithmike.gitbook.io/oscp
0xb0b’s write-ups are also great — I learned a lot of commands and methodology from them that I didn’t know before.
https://0xb0b.gitbook.io/writeups
DarrenC’s AD playlist is excellent — I’d strongly recommend it.
https://www.youtube.com/watch?v=gY_9Dncjw-s&list=PLT08J44ErMmb9qaEeTYl5diQW6jWVHCR2
Definitely use OffSec’s Discord!! I met incredible people there — I’d recommend using it regularly.
https://discord.com/invite/offsec
Definitely use Reddit — read people’s pass/fail write-ups and learn from their experiences.
https://www.reddit.com/r/oscp/
2. Improve your methodology
Work on developing how you approach attacks while you study. Always keep a checklist — the more you refine your methodology, the better off you’ll be. Methodology only improves through practice — never forget that.
3. Take notes! I passed the exam thanks to my notes
While studying, I always made sure to take notes. Every time I solved a machine, I took notes specific to that box, and I always used the same format: machine name, then the technique — for example, “king – CVE-2021-43857 – sudo privesc.” I’d recommend the same format to you. Later, when I search for “sudo privesc,” every machine I solved using that technique pops right back up so I can review it.
4. Check out these GitHub repos
This one can help as a checklist:
https://github.com/intotheewild/OSCP-Checklist
I prepared my local toolkit before the exam, and this repository was one of the resources that helped me organize useful tools and binaries for my preparation.
https://github.com/emmasolis1/OSCP
5. Use RustScan!
RustScan genuinely saved me a huge amount of time — I’d recommend starting to use it right away.
https://github.com/bee-san/rustscan
You can use this format:
1
rustscan -b 500 -a <ip> -- -sC -sV -Pn -oN <ip>
6. Learn to use Ligolo!
https://github.com/nicocha30/ligolo-ng
I used Ligolo for pivoting and didn’t run into any issues. Practice with it and use it.
7. Learn NetExec (nxc) in depth
I used nxc for most of the exam — its modules were honestly lifesavers. Here’s a small cheat sheet:
Basic Connection & Auth
1
2
3
4
nxc smb <ip> -u user -p pass
nxc smb <ip> -u user -H <hash>
nxc smb <ip> -u user -p pass -d domain
nxc smb <ip/range> -u users.txt -p pass
Enumeration
1
2
3
4
5
6
7
nxc smb <ip> -u user -p pass --shares
nxc smb <ip> -u user -p pass --sessions
nxc smb <ip> -u user -p pass --loggedon-users
nxc smb <ip> -u user -p pass --users
nxc smb <ip> -u user -p pass --groups
nxc smb <ip> -u user -p pass --local-users
nxc smb <ip> -u user -p pass --pass-pol
LDAP
1
2
3
4
5
6
nxc ldap <ip> -u user -p pass --users
nxc ldap <ip> -u user -p pass --groups
nxc ldap <ip> -u user -p pass --bloodhound -c All
nxc ldap <ip> -u user -p pass --kerberoasting out.txt
nxc ldap <ip> -u user -p pass --asreproast out.txt
nxc ldap <ip> -u user -p pass --trusted-for-delegation
Credential Dump
1
2
3
4
5
6
nxc smb <ip> -u user -p pass --sam
nxc smb <ip> -u user -p pass --ntds
nxc smb <ip> -u user -p pass -M lsassy
nxc smb <ip> -u user -p pass -M nanodump
nxc smb <ip> -u user -p pass -M handlekatz
nxc smb <ip> -u user -p pass -M dpapi_hash
Execution
1
2
nxc smb <ip> -u user -p pass -x "whoami"
nxc smb <ip> -u user -p pass -X "whoami"
Modules
1
2
3
4
5
6
7
8
nxc smb <ip> -u user -p pass -M wifi
nxc smb <ip> -u user -p pass -M powershell_history
nxc smb <ip> -u user -p pass -M gpp_password
nxc smb <ip> -u user -p pass -M enum_logins
nxc smb <ip> -u user -p pass -M spider_plus
nxc smb <ip> -u user -p pass -M teams_localdb
nxc smb <ip> -u user -p pass -M enum_av
nxc smb -L
WinRM
1
2
3
nxc winrm <ip> -u user -p pass
nxc winrm <ip> -u user -H <hash>
nxc winrm <ip> -u user -p pass -x "whoami"
Try these out, practice with them, and learn how to actually use them properly.
8. Start using Penelope
Penelope is a genuinely great tool — trying to upgrade a shell to a full PTY manually with nc can be frustrating, and this tool just handles it for you. Use it, but don’t forget the -O flag — -O, --oscp-safe, enables OSCP-safe mode, which matters for the exam.
https://github.com/brightio/penelope
9. What the hell is enumeration?
Everyone says “enumeration is key,” but nobody actually explains what that means. What is it, really? I want to break that down here, because it’s not just important for the OSCP exam — it matters just as much for PNPT or real-world pentesting engagements. Most of hacking isn’t actually about exploitation or quickly taking over a system — the more information you gather from a system, the better off you are. Let me give an example: say you find an FTP server. When you find one, don’t just look at it from the outside — go in and see what files are actually sitting inside it. Or say there’s an MSSQL instance and you somehow gain access and log in — once you’re in, you need to check what files you can read and how far that access actually extends. Whenever you get initial access to a system, ask yourself: what privileges do I have, what can I actually read? That’s enumeration, in its entirety. Gather information, information, information — dig and research!!
10. How to avoid falling into rabbit holes
Yes, the exam has plenty of rabbit holes waiting for you, as expected. Without going too deep into it, here’s my short piece of advice: before you attack anything, scan absolutely everything first, and don’t jump straight into exploitation. Take good notes and build yourself a map. Look at that map and ask yourself: what’s the shortest path here, which point could I get in and exploit first? But if you jump into the very first opening you find without enumerating the machine thoroughly enough, that’s exactly how you end up stuck in a rabbit hole. So: enumerate first, exploit second.
11. Last piece of advice
The exam really isn’t impossibly hard — you just need a lot of practice and exposure to different scenarios, and you need to get good at taking notes. That’s genuinely it. It’s not some insurmountable “super boss” of an exam — you just need to prepare properly. Trust yourself — you’ll get there.
Thank you for reading!
H3racl3s.





















