August 21, 2026
They told me “Try Harder” — My OSCP Exam Experience
My OSCP Exam Experience

By Athiwat Tiprasaharn
12 min read
My OSCP Exam Experience
Hello, pentesters! It has been quite a while since I last wrote anything for Extreme IT. I have been busy with my day job — and quietly preparing for an exam on the side. At long last, I have passed the Offensive Security Certified Professional, or OSCP, from OffSec: a credential that opens doors everywhere for anyone interested in a career in pentesting.
Why I Decided to Take the OSCP
To be honest, I had always told myself that I would never take the OSCP. The reason was simple: I was not planning to pursue cybersecurity as a full-time career. At most, I thought I might take on a little freelance work here and there. That was why I had previously collected certifications from all sorts of providers — nearly every certification offered by TCM Security, CompTIA PenTest+, HTB CWES, TryHackMe PT1 and WEB1, SecOps Group CAPenX, ADPenX and CNPen, plus certifications from Cyberwarfare, KnightSquad Academy, INE, and several others.
Another factor was the price. The OSCP exam voucher alone costs $1,699, or roughly 55,900 baht. That gave me serious pause. If I failed, I would essentially be throwing more than 50,000 baht down the drain.
But in the end, the OSCP is still one of those summits that every pentester wants to conquer at least once — the pentesting equivalent of climbing Mount Everest. And, if we are being honest, once you have the OSCP on your profile, HR departments are practically lining up to respond to your applications.
Preparing for the Exam
There was nothing especially unusual about the way I prepared. I mainly relied on the knowledge I had accumulated since buying my first certification voucher from TCM Security. Each voucher comes with a course — or perhaps I should say that you buy the course and get the voucher thrown in. I worked through TCM Security's video courses and gained additional practice while preparing for the many other certifications I mentioned earlier.
That said, I would like to recommend a few useful courses and resources for anyone looking for additional material.
TCM Security PNPT
The PNPT is TCM Security's most popular certification. When you purchase it, you also receive the Practical Ethical Hacking, Windows Privilege Escalation, and Linux Privilege Escalation courses. Study all of them thoroughly. They provide a solid foundation that you can build on when preparing for the OSCP.
HTB Penetration Tester Job Role Path
This Job Role Path is primarily intended as preparation for the HTB CPTS exam. I have not actually finished it myself, but from the substantial portion I have completed, I think the material should be more than enough to help prepare you for the OSCP. I have also heard from some younger colleagues that if you complete the path and pass the CPTS, the OSCP feels like a walk in the park.
Penetration Testing with Kali Linux (PEN-200)
This is OffSec's own course, so there is not much more to say. Its content is naturally designed to align with the OSCP exam. As I understand it, PEN-200 has to be purchased as a bundle with an OSCP exam voucher. The bundle costs $1,749, or about 57,000 baht. This is the option I bought.
Proving Grounds
Proving Grounds is OffSec's own lab platform. I mainly used the Practice machines because they are created by OffSec itself, unlike the Play machines, which are community-made. After all, who knows the style of the exam better than OffSec? You might as well practice in their own labs.
Challenge Labs
These labs come with the PEN-200 course and closely simulate the experience of working through OSCP exam machines. I recommend focusing on OSCP A, B, and C. The other labs I completed were Poseidon, Zeus, Relia, and Secura.
HTB Labs
This is an additional option for anyone who already has an HTB subscription but does not yet have the budget for PEN-200. You can work through the HTB machines on TJ Null's list here: https://docs.google.com/spreadsheets/u/1/d/1dwSMIAPIam0PuRBkCiDI88pU3yzrqqHkDtBngUHNCw8/htmlview
If you ask how long I studied, counting from the first time I learned pentesting through a TCM Security course until the OSCP exam, the answer would be one year. However, I spent only about three to four months seriously preparing specifically for the OSCP. Whenever I had some free time outside work, I would practice in the HTB labs. It was not until two months before the exam that I finally had enough money to buy PEN-200, after which I added Proving Grounds and the Challenge Labs to my practice routine.
Exam Format
For the full details of the OSCP exam, I would rather let everyone read the official guide themselves — honestly, I am just too lazy to type it all out. You can find it here: https://help.offsec.com/hc/en-us/articles/360040165632-OSCP-Exam-Guide
In short, to pass, you need a total score of at least 70 out of 100 and you must submit a report. The exam gives you six machines to test: three in an Active Directory set and three standalone machines. They are scored as follows.
Active Directory Group
The AD set consists of an external client, an internal client, and a Domain Controller (DC). You only need to retrieve proof.txt from each machine. Because proof.txt is accessible only with administrator privileges, you must escalate your privileges on every machine.
For scoring, proof.txt from the external client is worth 10 points, the one from the internal client is worth another 10, and the DC is worth 20, for a total of 40 points.
Standalone Group
This group consists of three separate machines. Each has its own IP address and is unrelated to the others. On each machine, you first need to retrieve local.txt, which becomes accessible after compromising a user account. You then escalate your privileges to retrieve proof.txt.
local.txt and proof.txt are each worth 10 points, so every standalone machine is worth up to 20 points. Compromising all three gives you a total of 60 points.
Note-Taking
An important part of preparing for the OSCP is keeping notes of the commands you may need. The exam is open book: you can search for information online and consult your own notes during the exam. However, all forms of AI are prohibited during the exam — do not forget that little detail!
I used Obsidian because my brother recommended it to me. Personally, I think the particular app is entirely up to you; just use whichever one you are comfortable with. My process was very simple. No matter which lab I was working on, whenever I found something that I would probably use often — and almost certainly forget — I recorded it under the appropriate topic.
You could also ask AI to help you create useful commands or cheat sheets for the exam. We live in the age of AI, after all. OffSec prohibits its use during the exam, but not while you are preparing beforehand, so feel free to make the most of it!
One Day Before the Exam
I had actually taken leave from work from August 13 to 16, with my exam scheduled for August 14. On the 13th, I was initially torn between pushing myself through one final day of intensive practice and simply taking it easy. In the end, I chose option two and gave myself permission to relax.
I booked a traditional Thai massage at the Faculty of Associated Medical Sciences, Khon Kaen University. Around lunchtime, some younger students from KKU's cybersecurity program invited me to Swensen's. When I got home, I took a short nap before starting one final review.
There was nothing elaborate about the review. I focused on the OSCP A, B, and C labs, along with Zeus, Relia, and Poseidon. I tried to simulate the actual exam as closely as possible, relying only on internet searches and the notes I had prepared. Did everything go smoothly? Absolutely not! There were still a few things I had forgotten and others that I had neglected to put in my notes, so I went back and filled in the gaps.
Once everything was in order, I went to bed and waited for August 14 to arrive.
Part 1: Exam Day
My exam was scheduled for 7:00 a.m., but I woke up at 6:00 to prepare the exam area. I did not even take a shower. I just dunked my face in ice water to wake myself up, made a cup of coffee, and settled in at my exam desk in the living room.
The setup was fairly straightforward. OffSec had me download and install an application, connect to the VPN, share my entire screen, and keep my webcam on throughout the exam so that the proctor could monitor me.
I started with the Active Directory set. If you clear it, you immediately secure 40 points, and, generally speaking, AD sets are not usually impossibly difficult.
During the exam, you can tell the proctor that you need to use the bathroom, step outside for some air, or grab a snack. I mostly asked for bathroom breaks. As for food, I brought it to my desk so I could eat and work on the exam at the same time.
The AD portion was quite demanding. In my opinion, neither the machines nor the vulnerabilities involved were especially difficult, but I cannot stress this enough: enumeration is key. With the set I received, good enumeration meant that half the battle was already won. If you encounter a vulnerability whose exploitation process you do not know, you are free to search the internet as much as necessary — as long as you do not use AI.
Although I say the AD set was not particularly difficult, my enumeration was not very good. As a result, I did not reach the DC until 5:30 p.m. The moment I retrieved its proof.txt, I told the proctor, "Can I step away for a moment to celebrate?" And yes, the proctor let me. Hahaha! Once I had finished celebrating, I came back and asked if I could take a shower. I still had not showered since waking up that morning, and I wanted to reset my brain before tackling the standalone machines.
Then came the three standalone machines — and this was where the real nightmare began.
I could not make any progress at all on the first machine. I enumerated everything I could think of and even tried some unconventional approaches, but I still could not solve it. After almost three hours, I finally gave up and moved on.
On the second machine, I obtained user access with ease and retrieved local.txt very quickly. However, I could not escalate to administrator, no matter what I tried. I spent almost four hours on that machine and ultimately walked away with only local.txt.
By then, it was already midnight. My score stood at 50 out of 100: the complete AD set plus local.txt from the second standalone machine. Without wasting any more time, I immediately started working on the third machine.
I put everything I had into this one. If I could fully compromise it, I would reach the passing score of 70 out of 100.
If I remember correctly, I retrieved local.txt from the third machine within the first hour, perhaps even faster. But then the same obstacle came back to haunt me: privilege escalation to obtain proof.txt.
The hero of this story was none other than WinPEAS. I had run it and saved its output shortly after gaining user access, but I spent nearly an hour trying to figure out how to read the output while preserving the colors and stopping it from overflowing the terminal window. Eventually, I discovered that all I needed was more winpeas.txt. That was it! I had saved the WinPEAS output as winpeas.txt and transferred it back to my Kali machine to read it.
But my problems were not over. A quick read-through gave me no useful clues at all. By then, it was 3:30 a.m. and my brain was starting to shut down. I decided I should sleep for a little while before continuing, so I told the proctor that I wanted to take a short nap and planned to wake up again at 4:30.
I carried my things over and lay down on the sofa, which happened to be directly behind the table holding my computer. So there I was, sleeping face-to-face with the proctor. I dozed on and off for a while, but at 4:00 a.m. a thought hit me: I might as well make every remaining minute count. Whether I passed or failed, I wanted to know that I had given it everything I had. The proctor even suggested that I get some more rest, but I told them, "It's okay. I'd rather give it my best shot." With that, I asked to step away for a moment, walked over to the fridge, grabbed a face mask, and put it on for a little late-night skincare before getting back to work on the third machine.
This time, I reviewed winpeas.txt in as much detail as humanly possible until I found one single clue — the only thing that looked like it could be the answer. I told myself that if I committed to testing this vulnerability and still could not escalate my privileges, I could kiss that 57,000 baht goodbye!
At last, fortune smiled on me. I exploited that weakness, gained administrator privileges on the third machine, and retrieved the final proof.txt I needed to reach a passing score. It was 5:30 a.m. I spent the remaining time double-checking everything and making sure I had captured all the necessary screenshots. At around 6:30 a.m., I asked the proctor to end my exam and went straight to bed.
One more thing: in my opinion, taking the exam early in the morning is much more effective. You can make the most of the entire day, leaving only a few loose ends to clean up late at night before going to bed. If you start in the late morning or afternoon, you have only a small portion of the day left and then face the prospect of working through the entire night. Sleeping for only a few hours before getting up to continue would leave you exhausted. I think the best strategy is to start early and try to finish most of the work during the day. If you genuinely need every last minute, the deadline will not arrive until the following morning — by which time you can finally sleep without a care in the world.
Part 2: Writing the Report
After finishing the exam on August 14, I had another 24 hours on August 15 to complete a report covering all the vulnerabilities I had found. My plan was to wake up around noon and start writing. However, August 15 was also the day of the Thailand Cyber Top Talent competition, and I was one of the challenge authors. I had to remain on standby in case anything went wrong with my challenge.
And, of course, the challenge that caused trouble was mine: Crazy OTP. The backend was not robust enough to withstand competitors hammering it with AI, so it went down around noon. I woke up and worked on fixing it until the system finally became stable at nearly 3:00 p.m. In the end, one team managed to solve my challenge — the only team to do so — and they went on to take first place in the qualifying round.
But that also meant I did not start writing my report until 5:00 p.m. I worked steadily until 9:00, took a short dinner break, and finally completed it at 11:56 p.m. on August 15. By the way, the entire report has to be written in English.
Waiting for the Result — and the Day It Arrived
This was probably the most agonizing part of the whole experience. Waiting for the result was incredibly nerve-racking. One reason was that I had scraped through with exactly 70 out of 100, which made me even more anxious. I slept fitfully. Sometimes I dreamed that the result had arrived and immediately grabbed my phone to check, even though there was still no email notification.
Then, today at around 10:00 a.m., I logged into my OffSec portal and suddenly saw a post-exam survey waiting for me. At that moment, I knew the result was probably out even though the email had not arrived yet. I rushed to the Achievements page — and there it was: the OSCP badge had appeared.
At long last, I had finally earned both the OSCP and OSCP+. The OSCP itself stays with you permanently, while the OSCP+ is valid for three years and must be renewed after that.
I hope this article will be helpful to everyone preparing for the OSCP. See you next time!