SEC-100: CyberCore - Cybersecurity Essentials - on the way to OSCC-SEC.
SEC-100 is OffSec's entry course and covers attack, defend and build in one: 40 modules and roughly 138 hours of content on network and system fundamentals, scripting, cloud, secure coding and defensive analysis. The exam has an Attack, a Defend and a Build section.

- Certification
- OSCC-SEC - OffSec CyberCore Certified - Security Essentials
- Level
- Foundational
- Discipline
- Build
- Audience
- Teams and individuals
Who this course is for
Career changers, IT support, admins and students who need a solid security base before committing to attack or defence.
Not the right course yet if
- -You already work as a pentester - PEN-200 is your starting point
- -You are looking for a purely managerial certification
- →Confidently explain and operate networks, operating systems and cloud basics
- →Follow and document a simple attack path
- →Read and triage logs and alerts instead of just forwarding them
- →Back up a job application with a hands-on, proctored credential
- ·Basic computer and networking literacy
- ·No prior programming or security experience required
Not sure whether you meet them? We run a short placement conversation before you buy.
What SEC-100 covers.
- Networking, Linux and Windows fundamentals
- Scripting with Bash and Python
- Offensive basics, enumeration and how a pentest actually runs
Course content, labs and the OSCC-SEC exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Guided modules with hands-on labs across all three phases (Attack, Defend, Build).
Exam and credential
Six-hour proctored practical exam in three sections - Attack, Defend and Build, roughly two hours each. No report required; results are available immediately after submission. Passing awards the OSCC-SEC certification.
The packages that include SEC-100.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
Entry route without prior experience.
- ▸ 365 days of access to the 100-level courses
- ▸ 2 exam attempts
- ▸ Proving Grounds Play
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +A placement conversation: SEC-100 or straight to PEN-200
- +A 12-week study plan with fixed checkpoints
- +Procurement and invoicing in EUR through a German entity
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
People entering or moving into penetration testing, plus admins who need to understand the attacker side.
SOC analysts, detection engineers and teams who want to understand attacks rather than only clear alerts.
No. SEC-100 assumes general IT literacy and builds networking, systems and scripting from the ground up.
No. SEC-100 is the layer underneath. If you want to go into pentesting afterwards, continue with PEN-200.
Six hours proctored, split into Attack, Defend and Build sections of roughly two hours each. No report is required and results appear immediately after submission.
Through CyberCore, or through Learn Fundamentals or Learn Enterprise. The Course + Cert Bundle only covers 200- and 300-level courses.
Not sure whether SEC-100 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.