So… I’ve decided to go after the OSCP certification and I decided to start a thread to journal my progress, efforts, frustrations, failures and ultimate success. I started this for the CISSP but never completed it (I wish I had stuck with it now in hindsight).
This was not a decision I made lightly and it only came after a few months of consideration and pondering during my wife’s imposed "summer vacation of NO STUDYING". Because I am goal driven, I tend to need a “big goal” to work towards in order to move forward. Without an overall goal or purpose, I tend to start lots of projects and then move on to something else without ever completing anything.
My overall plan is this:
1 – general focused study on “the basics” for 2017 Q4
2 – focused study on eCCPT during 2018 Q1
3 – focused study on OSCP during 2018 Q2
I’ve combed the forums and read the majority of OSCP threads for help in developing a plan. I’ve also read many blogs and articles from people who passed the exam (as well as those who have unsuccessfully attempted it and stopped). Below are the steps and progress I have made since October 1 (almost one month in). I’m not publishing the resources I have not started yet because that list is quite long…
Courses
Cybrary.it Course: Penetration Testing and Ethical Hacking by Leo Dregier
Source:
https://www.cybrary.it/course/ethical-hacking/
Status: COMPLETED
Cybrary.it Course: Advanced Penetration Testing by Georgia Weidman
Source:
https://www.cybrary.it/course/advanced-penetration-testing/
Status: COMPLETED
Zercool Wireless Penetration Series
Source:
https://www.youtube.com/channel/UCX-K9aANFs6FLNNFP176nCg
Status: COMPLETED
LearnPython.org
Source:
https://www.learnpython.org/
Status: COMPLETED
CodeAcademy Course: Learn Python
Source:
https://www.codecademy.com/learn/learn-python
Status: COMPLETED
PentesterAcademy: Network Pentesting
Source:
Network Pentesting
Status: IN-PROGRESS, currently on video 13/83
Udemy Course: The Complete Ethical Hacking Course: Beginner to Advanced
Source:
https://www.udemy.com/penetration-testing/
Status: IN-PROGRESS, currently on video 14/113
Books
Nmap: Network Exploration and Security Auditing by Paulino Calderon
Status: COMPLETED (read)
Nmap Network Scanning by Gordon “Fyodor” Lyon
Status: IN-PROGRESS, currently on page 59
Penetration Testing: A Hands-on Introduction to Hacking by Georgia Weidman
Status: IN-PROGRESS, currently on page 180
Lab/Vulnerable VMs
Kali
Metasploitable2 – learning platform for the tools.
Windows XP, Windows 7, Ubuntu – loaded with various vulnerable software from exploit-db as I’ve followed along in courses and books.
VyOS virtual router – test nmap scans behind router configurations