Skip to content
Exploit Labs
Capability development

Training as a holistic programme for teams.

Pins, badges and certifications are not a checklist that ends after one or two certificates. They are a continuous journey: pins and progress badges as the weekly signal, path badges for every newly opened domain, certifications as a level reached - and then the next path starts. Because every person sits at a different point on that journey, the track is tailored to their position in the team.

Credential ladder

Four different ways to measure progress.

This ladder is the measurement layer on top of the Upskill Program stages: a placement assessment sets the starting point, every completed stage becomes visible through pins, progress and path badges, and a certification marks the level reached. Progress stays reportable at team level without anyone maintaining attendance lists.

See the six stages of the Upskill Program
Pinweekly

100% of a skill path. Issued only inside the OffSec portal.

Progress badgecontinuous

Partial progress inside a learning path - the signal that someone is still moving.

Path badgemonthly to quarterly

Learning path completed: 80% assessment flags in one attempt plus 80% module labs. Examples: PEN-100, SOC-100, WEB-100, OWASP Top 10-2021, Cloud Essentials.

Certificationannual

Course plus a proctored exam: OSCP/PEN-200, OSEP/PEN-300, OSWA/WEB-200, OSWE/WEB-300, OSED/EXP-301, OSDA/SOC-200, OSTH/TH-200, OSIR/IR-200, OSAI/AI-300, OSCC-SEC/SEC-100, OSCC-SJD/SJD-100.

Capability matrix

Attack, Defend, Build: the training domains.

Filter by role and domain, then click a cell: you see its path badges, pins and certifications plus the next step on the path. A team is not ready when one person holds OSCP - it is ready when every column is staffed at every relevant level.

Filter by role
Filter by domain

Click a cell to see its path badges, pins and the next step.

Capability matrix: attack, defend and build capability domains across four seniority levels. Cells are clickable.
LevelAttackIdentify and exploit vulnerabilitiesOffSec taxonomyDefendHarden defences and detectOffSec taxonomyBuildArchitect and ship securelyOffSec taxonomy
Baseline
Practitioner
Senior
Lead

No cell selected. Click a cell to open the tailored learning path.

Attack, defend and build are OffSec's own skill categories.

Journey timeline

Pin, progress badge, path badge, certification - always current.

Training for every role the team needs.

  1. 01weekly
    Pin100% of a skill path, visible only inside the OffSec portal.
  2. 02monthly
    Progress badgePartial progress on a learning path - the interim state becomes visible.
  3. 03quarterly
    Path badgeLearning path completed: 80% assessment flags in one attempt plus 80% module labs.
  4. 04annual
    CertificationCourse plus a proctored exam - a level reached, not the end of the road.
Choose a role

Practitioner with first pentest experience.

  1. Cycle 1Network and Active DirectoryPin to certification
    PinActive Directory Skill Path
    Progress badgePEN-200 (Teilfortschritt)
    Path badgePEN-200 Learning Path
    CertificationOSCP / PEN-200

    OutcomeRuns internal and external pentests independently.

  2. Cycle 2Evasion and monitored environmentsPin to certification
    PinAntivirus Evasion Skill Path
    Progress badgePEN-300 (Teilfortschritt)
    Path badgePEN-300 Learning Path
    CertificationOSEP / PEN-300

    OutcomeOperates against active defence and leads sub-engagements in the red team.

  3. Cycle 3Exploit developmentPin to certification
    PinWindows Internals Skill Path
    Progress badgeEXP-301 (Teilfortschritt)
    Path badgeEXP-301 Learning Path
    CertificationOSED / EXP-301

    OutcomeDevelops own exploits and validates other people's findings.

  4. The cycle starts again

    Then: towards OSCE3 or a move into the cloud and AI domains - the cycle keeps running.

Role tracks

One platform for the whole team.

AI Red Team
  1. 1LLM Red Teaming
  2. 2Skill Pins
  3. 3OSAI / AI-300
  4. 4Validation Engagement
Enterprise Pentest
  1. 1PEN-100
  2. 2OSCP / PEN-200
  3. 3OSEP / PEN-300
  4. 4Red Team Engagement
Web & AppSec
  1. 1WEB-100
  2. 2OSWA / WEB-200
  3. 3OSWE / WEB-300
  4. 4Code-Review-Mandat
Defensive Analysis & IR
  1. 1SOC-100
  2. 2OSDA / SOC-200
  3. 3OSTH / TH-200
  4. 4OSIR / IR-200
Secure Build / DevSecOps
  1. 1SSD Essentials
  2. 2Intermediate Secure Dev I + II
  3. 3DevSecOps Essentials
  4. 4GitOps / Kubernetes
Junior Baseline
  1. 1CyberCore SEC-100
  2. 2OSCC-SEC
  3. 3PEN-100
  4. 4Erste Domäne wählen
Evidence

Progress you can prove: modules, labs, assessment flags.

Per track you see which units count as evidence, which thresholds must be met and where each proof comes from. Pick a track, then export as CSV or print to PDF - the table drops straight into an ISMS or audit evidence pack.

Passed = 80% module labs and 80% assessment flags on the first attempt.

Junior Baseline

First 12 months, fundamentals and first domain.
Evidence for Junior Baseline
UnitModulesLabsAssessment flagsCredentialSource
SEC-100 CyberCore18 / 1880 %80 %OSCC-SECLearn Enterprise reporting
Networking / Linux Skill Paths100 %--PinsOffSec portal (pins, module progress)
PEN-10024 / 2480 %80 %Path-BadgeAccredible (badge/certificate link)
PEN-21012 / 1280 %80 %OSWPAccredible (badge/certificate link)

Enterprise Pentest

Network, Active Directory, evasion, exploit development.
Evidence for Enterprise Pentest
UnitModulesLabsAssessment flagsCredentialSource
PEN-20026 / 2680 %80 %OSCPAccredible (badge/certificate link)
Active Directory Skill Path100 %--PinOffSec portal (pins, module progress)
PEN-30022 / 2280 %80 %OSEPAccredible (badge/certificate link)
EXP-30114 / 1480 %80 %OSEDAccredible (badge/certificate link)

Web & AppSec

Web fundamentals, assessment, white box review.
Evidence for Web & AppSec
UnitModulesLabsAssessment flagsCredentialSource
WEB-100 / OWASP Top 10-2021100 %80 %-Path-BadgeAccredible (badge/certificate link)
WEB-20020 / 2080 %80 %OSWAAccredible (badge/certificate link)
WEB-30016 / 1680 %80 %OSWEAccredible (badge/certificate link)
Source Code Review Skill Path100 %--PinOffSec portal (pins, module progress)

AI Red Team

AI attack surfaces and the AI supply chain.
Evidence for AI Red Team
UnitModulesLabsAssessment flagsCredentialSource
AI-300100 %80 %80 %OSAIAccredible (badge/certificate link)
LLM Red Teaming Skill Path100 %--PinOffSec portal (pins, module progress)
Offensive Cloud Foundations100 %80 %-Path-BadgeAccredible (badge/certificate link)

Defensive Analysis & IR

Triage, detection engineering, hunting and IR.
Evidence for Defensive Analysis & IR
UnitModulesLabsAssessment flagsCredentialSource
SOC-100100 %80 %-Path-BadgeLearn Enterprise reporting
SOC-20022 / 2280 %80 %OSDAAccredible (badge/certificate link)
TH-200100 %80 %80 %OSTHAccredible (badge/certificate link)
IR-200100 %80 %80 %OSIRAccredible (badge/certificate link)

Secure Build / DevSecOps

Secure coding, pipeline, architecture.
Evidence for Secure Build / DevSecOps
UnitModulesLabsAssessment flagsCredentialSource
SSD Essentials100 %80 %-Path-BadgeLearn Enterprise reporting
DevSecOps Essentials100 %80 %-Path-BadgeLearn Enterprise reporting
Cloud Essentials100 %80 %-Path-BadgeLearn Enterprise reporting
Intermediate Secure Development I + II100 %80 %-Path-BadgeAccredible (badge/certificate link)
Kubernetes / Container Skill Paths100 %--PinsOffSec portal (pins, module progress)

Security Lead / CISO

Coverage per domain and evidence reporting.
Evidence for Security Lead / CISO
UnitModulesLabsAssessment flagsCredentialSource
Abdeckung Attack / Defend / Buildje Rolle--Capability-ReportLearn Enterprise reporting
Zertifizierungsquote je Rolle---Accredible-LinksAccredible (badge/certificate link)
ATT&CK coverage

Individual path badges map directly to MITRE ATT&CK tactics.

That lets you argue coverage tactic by tactic instead of course by course. The strip is schematic - which tactics your team can actually evidence comes out of your own account reporting.

TA0043Recon
TA0042Res Dev
TA0001Initial Access
TA0002Execution
TA0003Persistence
TA0004Priv Esc
TA0005Def Evasion
TA0006Cred Access
TA0007Discovery
TA0008Lateral
TA0009Collection
TA0011C2
TA0010Exfil
TA0040Impact
From person to organisation

Reporting on team progress - in real time.

Reassignable licences

From five seats you reassign licences from the admin account - the path follows the role, not the person.

Real-time usage reporting

Progress per person and per domain, usable as training evidence for your ISMS.

Cyber Range and Proving Grounds

Practice surfaces between certifications - including CyberCore and the full learning library.

Six exam attempts per year

Per certification, per year. Enough headroom for a team running several paths in parallel.

Okta SSO

Access runs through your identity management, not private logins.

Learn Unlimited ends 2026

On 1 January 2026 Learn Unlimited folds into Learn Enterprise - a good moment to recut how paths are distributed.

Learn Enterprise licence details

Confidential

Discuss a capability programme

We look at your role distribution and cut the paths to fit it - including licence allocation through Learn Enterprise.

Not ready to talk yet? The Scope Check returns exercise type, tester-days and a budget range in two minutes - no email gate.