ORIGINAL REDDIT POST

OSCP roadmap for beginners

I just graduated and I feel like my cybersecurity knowledge is still pretty weak I want to get the OSCP but I’m not sure where to start What should I study before going for it Any roadmap or resources you recommend

Original postr/cybersecurity

I just graduated and I feel like my cybersecurity knowledge is still pretty weak I want to get the OSCP but I’m not sure where to start What should I study before going for it Any roadmap or resources you recommend

Collected discussion

13 comments

u/qwikh1t

I would start with the OSCP website?

u/Expert-Explorer-3129

yeah from tryhackme you get such skills. you can also learn linux, active directory, networking, bash skills

u/verter04

Looks like people are doing the OSCP as it is more HR friendly

u/Tired_Pentester

OSCP was my first ever cert. I dislike most "roadmaps" talk because it drags it out endlessly. Don't think "I need xyz cert before I try". You want the OSCP? Keep doing hackthebox, look things up as you go, look up the answer when you get too annoyed to finish, and keep going till you can start finishing boxes without help. When I started, I tried to do one box a day. OSCP is going to be a grind.

u/I-nigma

It is worth it if you want to go into pentesting.

u/Aero077

https://www.offsec.com/ 'CyberCore' is $899/yr. You can use it to judge whether you are ready to move onto serious OSCP certification study. There are other options. Look around before you commit.

u/SlickBackSamurai

Pretty much, as I’ve heard from others experienced in the field that there’s much better training/certs out there (i.e. CPTS) OSCP is just widely recognized

u/rad-saf

Felt the same way. For me I personally started Hack the Box CJCA course. The beginning is alot of relearning alot of what I already learned for my B.S. but I think it's a good overview and refresher. So far 30% done, but I'm looking forward to the enumeration portion and the other half of the course.

u/2timetime

Start with tryhackme, do the rooms, learn the concepts. Do some boxes or do boxes over on hackthebox, once out get solid at those. Start looking at the OSCP, as a large part of it is report based well

u/BackgroundService128

Just do HTB

u/AddendumWorking9756

Honestly the prerequisites are short enough to self check: comfortable in a shell, a TCP handshake you can explain, one scripting language, and enumeration you can do without a hint. Weak on any of those and you just burn the exam fee.

u/OutsideSpot2695

I feel like my cybersecurity knowledge is still pretty weak What does that even mean?

u/ImaginativeWeaver

Are people still doing OSCP? What’s the moat, just clearing the initial screening round?