PEN-200: Penetration Testing with Kali Linux - on the way to OSCP.
PEN-200 is OffSec's foundational course leading to the OSCP certification: enumeration, web and service exploitation, privilege escalation on Linux and Windows and Active Directory fundamentals, ending in a 24-hour practical exam.

- Certification
- OSCP - OffSec Certified Professional
- Level
- Intermediate
- Discipline
- Attack
- Audience
- For individual practitioners
Who this course is for
People entering or moving into penetration testing, plus admins who need to understand the attacker side.
Not the right course yet if
- -You are still uneasy on the Linux command line - start with SEC-100
- -You have less than 10 hours a week to study
- →Independently enumerate a network and prioritise attack surface
- →Reliably exploit known weaknesses instead of only scanning
- →Escalate privileges on Linux and Windows and move laterally
- →Write a pentest report that survives review
- ·Solid TCP/IP and networking knowledge
- ·Linux and Windows administration at the command line
- ·Basic Bash or Python
Not sure whether you meet them? We run a short placement conversation before you buy.
What PEN-200 covers.
- Enumeration and information gathering
- Web exploitation basics
- Privilege escalation on Linux/Windows
Course content, labs and the OSCP exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Course modules plus dedicated lab networks and challenge labs that model a complete attack path.
Exam and credential
24-hour practical exam followed by a report. Passing awards the OSCP certification.
The packages that include PEN-200.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +Mentoring in German or English by practising operators
- +A study plan and checkpoints instead of pure self-study
- +An exam simulation before your OSCP attempt
- +Procurement and invoicing in EUR through a German entity
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
Experienced pentesters and red team operators who have to succeed against EDR and hardened environments.
People entering application security, developers with a security remit, and testers who want a structured route into web attacks.
Realistically three to six months at ten to fifteen hours a week, depending on your background.
The Course + Cert Bundle includes one, Learn One includes two. Extra attempts can be purchased.
Yes. XPLT invoices in EUR through a German entity, with VAT shown.
Not sure whether PEN-200 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.
From training to the engagement: our testing services
- Red TeamingThreat intelligence-led red teaming: attack paths, detection testing and proven business impact.Read more
- Pentest as a ServiceContinuous testing at release cadence instead of one audit per year.Read more
- Hybrid PentestAutomated coverage plus manual depth - evidence for ISMS, DORA and NIS2.Read more
- DORA TLPTThreat-led penetration testing under DORA: scoping, run-through and regulator documentation.Read more