PEN-300: Advanced Evasion Techniques and Breaching Defenses - on the way to OSEP.
PEN-300 (OSEP) is the advanced evasion and breaching course: antivirus and EDR evasion, application whitelisting, advanced Active Directory attacks and lateral movement in monitored networks.

- Certification
- OSEP - OffSec Experienced Penetration Tester
- Level
- Advanced
- Discipline
- Attack
- Audience
- Teams and individuals
Who this course is for
Experienced pentesters and red team operators who have to succeed against EDR and hardened environments.
Not the right course yet if
- -You have not passed OSCP or reached an equivalent level
- -Active Directory is new territory for you
- →Build payloads that survive common protections
- →Deliberately bypass application whitelisting and hardening
- →Execute complex AD attack paths in monitored environments
- ·OSCP-level or equivalent hands-on experience
- ·Solid Windows internals and Active Directory knowledge
- ·Experience with C# or PowerShell
Not sure whether you meet them? We run a short placement conversation before you buy.
What PEN-300 covers.
- Antivirus and EDR evasion
- Bypassing application whitelisting
- Advanced AD attacks
Course content, labs and the OSEP exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Extensive labs with hardened networks and multi-domain challenge labs.
Exam and credential
48-hour practical exam with a report. Passing awards the OSEP certification.
The packages that include PEN-300.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +Transfer into your own EDR landscape in a purple teaming session
- +Office hours with operators from live red team engagements
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
For infrastructure and red team paths, yes. For web paths, WEB-300 is the follow-on.
Yes, at least working-level C# or PowerShell.
Not sure whether PEN-300 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.