EXP-301: Windows User Mode Exploit Development - on the way to OSED.
EXP-301 (OSED) covers Windows exploit development: assembly, debugging with WinDbg, reverse engineering, stack overflows, SEH, ROP and bypassing modern protections such as DEP and ASLR.

- Certification
- OSED - OffSec Exploit Developer
- Level
- Advanced
- Discipline
- Attack
- Audience
- For individual practitioners
Who this course is for
Testers and reverse engineers who want to develop Windows exploits themselves.
Not the right course yet if
- -You have never used a debugger
- -You will not use it day to day - PEN-300 delivers more value
- →Reverse binaries and find your own vulnerabilities
- →Write working exploits including ROP chains
- →Bypass modern protections in practice
- ·Solid Windows and networking understanding
- ·Assembly basics and one scripting language
- ·Stamina for debugging
Not sure whether you meet them? We run a short placement conversation before you buy.
What EXP-301 covers.
- x86 assembly and debugging
- Reverse engineering binaries
- Stack overflows and SEH
Course content, labs and the OSED exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Labs with real Windows applications where vulnerabilities are found and exploited.
Exam and credential
48-hour practical exam with a report. Passing awards the OSED certification.
The packages that include EXP-301.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +Office hours with operators who use exploit development in live engagements
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
Only if you need to write your own exploits. For standard engagements OSEP gives more value.
Basics are enough to start; the course builds on them.
Not sure whether EXP-301 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.
From training to the engagement: our testing services
- Red TeamingThreat intelligence-led red teaming: attack paths, detection testing and proven business impact.Read more
- Pentest as a ServiceContinuous testing at release cadence instead of one audit per year.Read more
- Hybrid PentestAutomated coverage plus manual depth - evidence for ISMS, DORA and NIS2.Read more
- DORA TLPTThreat-led penetration testing under DORA: scoping, run-through and regulator documentation.Read more