Skip to content
Exploit Labs
03 / Professional Certifications

OffSec Certifications

Every OffSec certification we mentor as an official channel and learning partner - with the entry bar, the exam format and what we add on top of the course. Pick the certification first, the package second.

14 active courses and certifications

Attack

PEN-210Foundational

OSWP - OffSec Wireless Professional

Foundational Wireless Network Attacks

PEN-210 covers attacks against wireless networks: reconnaissance, authentication mechanisms, WPA variants, enterprise WLAN with RADIUS, and the usual misconfigurations. It leads to the OSWP certification.

View OSWP details
PEN-200Intermediate

OSCP - OffSec Certified Professional

Penetration Testing with Kali Linux

PEN-200 is OffSec's foundational course leading to the OSCP certification: enumeration, web and service exploitation, privilege escalation on Linux and Windows and Active Directory fundamentals, ending in a 24-hour practical exam.

View OSCP details
WEB-200Intermediate

OSWA - OffSec Web Assessor

Foundational Web Application Assessments

WEB-200 is OffSec's black-box web course leading to OSWA: injection classes, authentication and session flaws, access control, SSRF, deserialisation and chaining multiple weaknesses.

View OSWA details
PEN-300Advanced

OSEP - OffSec Experienced Penetration Tester

Advanced Evasion Techniques and Breaching Defenses

PEN-300 (OSEP) is the advanced evasion and breaching course: antivirus and EDR evasion, application whitelisting, advanced Active Directory attacks and lateral movement in monitored networks.

View OSEP details
WEB-300Advanced

OSWE - OffSec Web Expert

Advanced Web Attacks and Exploitation

WEB-300 is the whitebox advanced course (OSWE): source review with an attacker mindset, authentication bypasses, and building your own exploit chains up to remote code execution in real applications.

View OSWE details
EXP-301Advanced

OSED - OffSec Exploit Developer

Windows User Mode Exploit Development

EXP-301 (OSED) covers Windows exploit development: assembly, debugging with WinDbg, reverse engineering, stack overflows, SEH, ROP and bypassing modern protections such as DEP and ASLR.

View OSED details
AI-300Advanced

OSAI - OffSec AI Security Specialist

Offensive Security for AI Systems

AI-300 (OSAI) covers attacks against AI systems: prompt injection, manipulating agents and tool calls, attacks on data pipelines and model supply chain, and hardening LLM applications.

View OSAI details
EXP-401Expert

OSEE - OffSec Exploitation Expert

Advanced Windows Exploitation

EXP-401 (OSEE) is the most demanding course in the OffSec catalogue: exploiting modern Windows targets, complex memory corruption, browser and kernel surfaces, and bypassing current mitigations.

View OSEE details

Defend

SOC-200Intermediate

OSDA - OffSec Defense Analyst

Foundational Security Operations and Defensive Analysis

SOC-200 (OSDA) shows attacks from the defender's seat: what traces common techniques leave, how they surface in SIEM data, and how to separate real attacks from noise.

View OSDA details
IR-200Intermediate

OSIR - OffSec Incident Responder

Foundational Incident Response

IR-200 (OSIR) covers the incident response lifecycle: preparation, detection, containment, evidence preservation, recovery and lessons learned - including communications and case management.

View OSIR details
TH-200Intermediate

OSTH - OffSec Threat Hunter

Foundational Threat Hunting

TH-200 (OSTH) covers threat hunting: forming hypotheses, data sources and coverage, hunting attacker behaviour rather than signatures, and turning findings into durable detections.

View OSTH details

Build

SEC-100Foundational

OSCC-SEC - OffSec CyberCore Certified - Security Essentials

CyberCore - Cybersecurity Essentials

SEC-100 is OffSec's entry course and covers attack, defend and build in one: 40 modules and roughly 138 hours of content on network and system fundamentals, scripting, cloud, secure coding and defensive analysis. The exam has an Attack, a Defend and a Build section.

View OSCC-SEC details
PEN-103Foundational

KLCP - Kali Linux Certified Professional

Kali Linux Revealed

PEN-103 (Kali Linux Revealed) covers the distribution itself: installation, configuration, Debian package management, custom images and running Kali cleanly in test environments - around 181 hours of content. It is free with every OffSec account and leads to the KLCP certification.

View KLCP details
SJD-100Foundational

OSCC-SJD - OffSec CyberCore Certified - Secure Java Development

Secure Java Development Essentials

SJD-100 covers secure Java development from a developer's perspective: ten modules and roughly 41 hours on input validation, output encoding, cookie and session security, logging and error handling, misconfiguration and secure database access, each with hands-on labs. Not an attack course.

View OSCC-SJD details

How access is purchased

CyberCore

Entry access to the 100-level content - the route into the first certifications without prior experience.

Course + Cert Bundle

One single 200 or 300-level course, 90 days of access, one exam attempt.

Learn One

One course, 365 days of access, two exam attempts - for candidates with a full-time job.

For whole teams, access runs through Learn Enterprise with reassignable licences and progress reporting. Concrete price bands live on the training overview and on Learn Enterprise.

Confidential

Request scoping - confidentially.

Describe in a few sentences what needs testing. We come back with concrete questions, the right type of exercise and an effort range - before you commit to anything.

Not ready to talk yet? The Scope Check returns exercise type, tester-days and a budget range in two minutes - no email gate.