OSCP+ Roadmap 2026: Prep Guide to Pass on Your First Try

Certifications & Careers
19 min read
OSCP+ Roadmap 2026: Prep Guide to Pass on Your First Try
On this page
  1. What Changed: OSCP vs OSCP+
    1. Bonus Points Are Gone, So Active Directory Is Effectively Mandatory
    2. An Assumed-Breach Start and Partial AD Points
    3. Three-Year Expiration for OSCP+
    4. Updated PEN-200 Course
  2. OSCP+ Prerequisites
    1. Essential Technical Skills
    2. Time Commitment
    3. Self-Assessment Checklist
  3. OSCP+ Cost Breakdown 2026
    1. Which Option Should You Choose?
    2. Hidden Costs to Consider
  4. Study Timeline Options
    1. 3-Month Intensive (Full-Time Focus)
    2. 6-Month Standard (Working Professionals)
    3. 9-12 Month Extended (Beginners)
  5. Essential Skills for OSCP+
    1. Linux Privilege Escalation
    2. Windows Privilege Escalation
    3. Active Directory Exploitation (Critical for OSCP+)
    4. Web Application Attacks
    5. Password Cracking
  6. Best Practice Resources
    1. TJ Null's OSCP List
    2. Practice Strategy
  7. Exam Day Strategy
    1. Point Distribution
    2. Time Management
    3. Screenshot Requirements
    4. Report Requirements
  8. Common Mistakes to Avoid
    1. 1. Starting Without Prerequisites
    2. 2. Over-Relying on Automated Tools
    3. 3. Not Documenting Methodology
    4. 4. Underestimating Active Directory
    5. 5. Skipping Report Practice
    6. 6. Poor Time Management on Exam Day
  9. Building Your Methodology
    1. Sample Methodology Framework
  10. After OSCP+: What's Next?
    1. Career Paths
    2. Advanced Certifications
  11. Frequently Asked Questions
    1. How long does it take to prepare for OSCP+?
    2. Is OSCP+ worth it in 2026?
    3. Can I pass OSCP+ without prior security experience?
    4. What percentage of people pass OSCP?
    5. Is OSCP+ harder than the original OSCP?
  12. Ethical Considerations
  13. Your OSCP+ Action Plan
    1. Start Here

The OSCP isn't just another cert for your LinkedIn. It proves you can break into systems against a 24-hour clock, and that's why employers trust it. If you're preparing for the OSCP+ certification in 2026, you need to know exactly what changed, what to study, and how to structure your preparation to pass on your first attempt.

This roadmap covers the November 2024 exam changes, realistic study timelines, current costs, the technical skills that decide the exam, and the practice resources that actually help. Active Directory is where most candidates are weakest, so start early: our AD enumeration chapter walks through the domain mapping every OSCP+ attack path begins with.

This guide is part of our pillar resource on cybersecurity certifications, where we compare every credential worth your time and money.

What Changed: OSCP vs OSCP+

On November 1, 2024, OffSec changed the exam and introduced OSCP+. Pass it today and you receive two credentials: the original OSCP, which never expires, and OSCP+, which is valid for three years. The exam itself changed in three ways that matter for your preparation.

Bonus Points Are Gone, So Active Directory Is Effectively Mandatory

The exam is still scored out of 100 with 70 to pass: three standalone machines worth 20 points each (10 for a low-privilege foothold, 10 for privilege escalation) and an Active Directory set of three machines worth 40. Before November 2024, up to 10 bonus points for course exercises let some candidates pass without touching AD. Those bonus points no longer exist. The standalones max out at 60, so you cannot pass without AD points.

An Assumed-Breach Start and Partial AD Points

The AD set now opens the way many real internal tests do: you receive the credentials of a standard domain user and work toward domain compromise. Points are awarded per machine in the set (10, 10 and 20), so a chain that stalls halfway still scores, unlike the old all-or-nothing AD set.

Three-Year Expiration for OSCP+

OSCP+ expires three years after issue. You keep it current by passing a recertification exam, earning another qualifying OffSec certification (OSEP, OSWE or OSED, for example), or completing OffSec's CPE program. Your plain OSCP stays valid for life either way, but some employers and government contracts now ask for the "+".

Updated PEN-200 Course

PEN-200, the course behind the exam, has been updated alongside these changes, with expanded Active Directory material and challenge labs that mirror the exam format. If you have older PEN-200 notes, check them against the current syllabus before relying on them.

Key insight: With no bonus points, every one of the 70 points has to come from exam day. Candidates who can enumerate and escalate inside an AD environment reliably have a clear advantage. Treat AD as a core competency, not "just another topic."

OSCP+ Prerequisites

Before diving into OSCP-specific content, honestly assess your current skill level. Starting OSCP preparation without proper prerequisites is the number one reason candidates fail or burn out. The course assumes foundational knowledge that takes months to build from scratch.

Essential Technical Skills

You should be comfortable with these areas before starting PEN-200:

  • Linux command line proficiency Navigate filesystems, manage processes, use pipes/redirects, write basic bash scripts, and troubleshoot permissions issues without constantly googling
  • Networking fundamentals Understand TCP/IP, common ports and protocols, subnetting, DNS, routing basics, and how to analyze traffic with Wireshark
  • Basic scripting ability Read and modify Python/Bash scripts, automate repetitive tasks, and understand enough code to troubleshoot exploit scripts when they fail
  • Web application basics HTTP methods, cookies, sessions, basic HTML/JavaScript, and how web servers handle requests
  • Windows fundamentals PowerShell basics, Windows services, registry, user/group management, and Active Directory concepts

Time Commitment

Realistic OSCP preparation requires 10-20 hours per week for 3-6 months. Less than 10 hours weekly makes progress painfully slow; you'll forget material between sessions. More than 20 hours weekly is sustainable only if you're not working full-time. Be honest about your available time when planning your timeline.

Self-Assessment Checklist

Answer honestly - if you can't check most of these, spend 1-3 months on prerequisites first:

  • I can SSH into a remote Linux server and navigate without a GUI
  • I understand what happens when I type a URL into a browser
  • I can write a basic for loop in Python or Bash
  • I know the difference between TCP and UDP
  • I've used nmap to scan a network before
  • I understand what a reverse shell is conceptually
  • I can explain what Active Directory does at a high level

If you're missing prerequisites, don't skip ahead. Build your foundation first with reconnaissance techniques and network scanning fundamentals on HackerDNA. Some candidates pursue CompTIA PenTest+ first as a stepping stone. Solid foundations make everything else easier.

💻
Practice this now: Hack the Box - chain a web foothold into full root on a multi-stage target, the same enumerate, exploit, escalate loop as an OSCP+ standalone machine. Runs in your browser, no VPN needed.

OSCP+ Cost Breakdown 2026

OSCP+ is not cheap, and OffSec's packaging has changed over the years, so many older guides quote plans that no longer exist. These are the options on OffSec's PEN-200 page in September 2026:

OptionPriceWhat you get
Course & Cert Exam Bundle$1,749PEN-200, 90 days of lab access, one exam attempt
Learn One$2,749/yearOne year of one 200- or 300-level course with labs, two exam attempts
OSCP+ exam only$1,699One exam attempt, no course material
Exam retake$249An extra attempt once included attempts are used

Which Option Should You Choose?

The $1,749 bundle works if you already have penetration testing experience, can put in serious weekly hours, and have done substantial practice elsewhere first. Ninety days of lab time goes fast.

Learn One suits most people. The extra $1,000 buys a full year of lab access and a second exam attempt, which on its own is worth $249 and a lot of stress.

The exam-only option is for people who prepared entirely outside OffSec's material and just want the attempt. At $1,699 it is barely cheaper than the bundle, so most candidates are better off with the course.

Hidden Costs to Consider

  • Supplementary practice platforms ($17-25/month for 3-6 months)
  • An exam retake if needed ($249, unless your plan includes a second attempt)
  • Reference books and additional resources ($50-150)
  • Virtualization software for your attack VM (VirtualBox is free, VMware Workstation Pro is now free for personal use)

Budget roughly $1,900-3,200 in total including supplementary resources. Some employers cover certification costs, so ask about a professional development budget before paying out of pocket.

Study Timeline Options

Your timeline depends on your background, available hours, and how quickly you absorb new material. Here are three realistic paths based on different situations:

3-Month Intensive (Full-Time Focus)

Best for: Career changers, people between jobs, or those with flexible schedules.
Hours required: 30-40 hours per week

  • Month 1: Complete PEN-200 course modules, take detailed notes, build your methodology document
  • Month 2: Focus on OffSec labs - aim for 40+ machines. Supplement with external practice
  • Month 3: Exam simulations, weak area review, report writing practice, schedule exam for end of month

6-Month Standard (Working Professionals)

Best for: Full-time employees with consistent evening/weekend availability.
Hours required: 15-20 hours per week

  • Months 1-2: Complete course modules methodically, one section per week
  • Months 3-4: Lab work - complete 30-40 machines from OffSec labs and TJ Null's list
  • Month 5: Focus on weak areas (usually AD and privilege escalation), exam simulations
  • Month 6: Final review, report practice, exam attempt

This is the most common successful timeline for people balancing work and study.

9-12 Month Extended (Beginners)

Best for: Career changers without IT background, limited weekly availability, or those building prerequisites simultaneously.
Hours required: 10-15 hours per week

  • Months 1-3: Prerequisites and fundamentals while beginning PEN-200 modules
  • Months 4-6: Complete course materials, begin basic lab machines
  • Months 7-9: Intensive lab practice, 50+ machines across multiple platforms
  • Months 10-12: Exam preparation, simulations, weak area focus, exam attempt

⚠️ Timeline reality check: Most candidates underestimate preparation time. If you're frequently skipping study sessions or struggling with basic concepts after month two, extend your timeline rather than rushing to the exam unprepared. A failed attempt costs money and morale.

Essential Skills for OSCP+

The OSCP+ exam tests practical exploitation across several domains. You need working proficiency, not theoretical knowledge, in each area. Here's what to master and which tools to learn.

Linux Privilege Escalation

You'll encounter Linux boxes where initial access gives you a low-privilege shell. Escalating to root requires systematic enumeration and understanding of common misconfigurations.

  • SUID/SGID binaries: Find binaries with elevated permissions and abuse them via GTFOBins techniques
  • Sudo misconfigurations: Check sudo -l output for exploitable entries, including NOPASSWD and wildcards
  • Cron jobs: Identify scheduled tasks running as root with writable scripts or path hijacking opportunities
  • Kernel exploits: Last resort - identify kernel version and check for known privilege escalation CVEs
  • Capabilities: Find binaries with dangerous capabilities like cap_setuid

Essential tools: LinPEAS, linux-exploit-suggester, pspy (for process monitoring), and manual enumeration scripts you understand deeply.

Windows Privilege Escalation

Windows privilege escalation has more vectors than Linux. Service misconfigurations, registry permissions, and token manipulation are your bread and butter.

  • Service misconfigurations: Unquoted paths, weak service permissions, writable service binaries
  • Token impersonation: SeImpersonatePrivilege, SeAssignPrimaryTokenPrivilege (Potato attacks)
  • Registry exploits: AlwaysInstallElevated, autorun locations, service registry permissions
  • Scheduled tasks: Writable task scripts, missing binaries in scheduled tasks
  • Credential harvesting: SAM/SYSTEM extraction, cached credentials, saved passwords

Essential tools: WinPEAS, PowerUp, Seatbelt, accesschk.exe, and manual PowerShell enumeration.

Active Directory Exploitation (Critical for OSCP+)

This is the biggest gap for most candidates. AD wasn't emphasized in older OSCP versions, so many study resources underweight it. For OSCP+, AD is non-negotiable. You must understand domain enumeration, common attack paths, and lateral movement techniques.

  • Kerberoasting: Request service tickets for SPNs and crack them offline to reveal service account passwords
  • AS-REP Roasting: Target accounts without Kerberos pre-authentication for offline cracking
  • Pass-the-Hash: Authenticate using NTLM hashes without knowing plaintext passwords
  • Pass-the-Ticket: Use stolen Kerberos tickets for authentication and lateral movement
  • DCSync: Replicate domain controller data to extract all password hashes
  • BloodHound analysis: Map AD relationships to find attack paths to Domain Admin

Essential tools: BloodHound, Mimikatz, NetExec (nxc, the maintained successor to CrackMapExec), Impacket suite (secretsdump.py, GetUserSPNs.py, psexec.py), Rubeus, and PowerView for enumeration.

💡 AD priority: Spend at least 25-30% of your study time on Active Directory. Most failed attempts cite AD as the weakest area. Don't just learn the attacks - understand why they work and how to enumerate AD environments systematically.

Web Application Attacks

Web vulnerabilities provide initial access on many exam machines. You need practical exploitation skills, not just theoretical understanding.

  • SQL injection: Manual exploitation, authentication bypasses, data extraction, and command execution
  • File upload vulnerabilities: Bypass filters, webshells, extension manipulation
  • Local/Remote File Inclusion: LFI to RCE via log poisoning, PHP wrappers, and filter chains
  • Command injection: Identify injection points, bypass filters, establish reverse shells
  • Authentication bypasses: Default credentials, logic flaws, session manipulation

Practice these attacks hands-on in HackerDNA's web security modules, which cover exploitation techniques with practical exercises.

Password Cracking

You'll extract hashes from various sources and need to crack them efficiently. Understanding hash types, wordlist strategies, and rule-based attacks is essential.

  • Identify hash types (hashid, hash-identifier)
  • Use appropriate wordlists (rockyou.txt, SecLists)
  • Apply effective rules for hashcat/john
  • Crack NTLMv2, Kerberos tickets, Linux shadow hashes

Build your password cracking skills with dictionary attack techniques and the rest of our password cracking course.

Best Practice Resources

OffSec labs alone aren't enough. Successful candidates supplement with external platforms that provide diverse challenges and different machine styles. Here's what works:

Resource Cost OSCP Relevance
PEN-200 Labs Included with course 10/10 - Direct exam preparation
Proving Grounds Practice $19/month 9/10 - OffSec-created, exam-like
HackerDNA Labs Free to start 9/10 - Guided learning, skill building
Hack The Box $25/month 8/10 - Excellent variety
TryHackMe $16.99/month 7/10 - Great for prerequisites

TJ Null's OSCP List

TJ Null maintains a curated list of Hack The Box and Proving Grounds machines that closely mirror OSCP difficulty and style. This list is considered essential preparation by the community. Aim to complete 30-40 machines minimum from this list before your exam attempt.

Find the current list on r/oscp or NetSecFocus. The list gets updated as new relevant machines are released.

Practice Strategy

  • Start with easier boxes to build confidence and methodology
  • Track your time per machine - aim for 2-4 hours on medium boxes
  • Take detailed notes on every machine, even easy ones
  • Review walkthroughs after attempting (not before) to learn what you missed
  • Redo machines you struggled with after a few weeks

Exam Day Strategy

The OSCP+ exam is a 23-hour and 45-minute practical test followed by 24 hours to write and submit your report. You need 70 points to pass. Proper exam strategy is as important as technical skills - many technically capable candidates fail due to poor time management.

Point Distribution

The exam typically includes standalone machines worth varying points and an Active Directory set. Understanding point distribution helps prioritize your time:

  • Three standalone machines: 20 points each (10 for local.txt as a low-privilege user, 10 for proof.txt as root/SYSTEM)
  • AD set: 40 points across three machines (10, 10 and 20), starting from supplied domain user credentials
  • Bonus points: none since November 2024
  • Tool limits: Metasploit (and Meterpreter) may be used against one target only, and automated exploitation tools such as sqlmap are banned. Read OffSec's current exam guide before exam day.

Strategy: The full AD set (40) plus one full standalone (20) and one foothold (10) is exactly 70. Secure AD first, then focus on machines where you can at least get low-privilege access for partial points. Don't spend 5 hours on one stubborn machine when others might be faster wins.

Time Management

  • First 30 minutes: Run initial scans on all machines, review results while they complete
  • Hours 1-4: Tackle the AD set first while fresh - it's worth the most points
  • Hours 5-12: Work through standalone machines, spend max 2 hours stuck before moving on
  • Hours 13-20: Return to machines with partial progress, try alternative approaches
  • Hours 21-24: Ensure all screenshots are captured, begin organizing notes for report

Take breaks. Seriously. Step away every 2-3 hours for 10-15 minutes. Eat real meals. Get a few hours of sleep if you need it. Fresh eyes solve problems faster than exhausted grinding.

Screenshot Requirements

Missing screenshots can cost you points you legitimately earned. Document obsessively:

  • Screenshot the proof.txt or local.txt content with type proof.txt or cat local.txt
  • Include ipconfig or ifconfig output in the same screenshot
  • Show the whoami command to prove privilege level
  • Capture every significant step in your exploitation chain

⚠️ Critical: Screenshot immediately after getting each flag. Don't wait. Machines can reset, connections can drop, and you may not remember exact reproduction steps later. A screenshot takes 2 seconds and can save your entire point allocation for that machine.

Report Requirements

Your report must clearly demonstrate the exploitation path for each machine. Include:

  • Enumeration steps that led to vulnerability discovery
  • Proof of exploitation with command output and screenshots
  • Clear step-by-step reproduction instructions
  • Remediation recommendations (shows professional mindset)

Write your report as if someone else needs to reproduce your work. OffSec reviewers follow your instructions - if they can't reproduce your exploitation, you don't get the points.

Common Mistakes to Avoid

Learn from others' failures. These mistakes derail more OSCP attempts than technical skill gaps:

1. Starting Without Prerequisites

Jumping into PEN-200 without solid Linux, networking, and scripting fundamentals wastes your lab time. You'll spend hours learning basics instead of practicing exploitation. Build prerequisites first.

2. Over-Relying on Automated Tools

Running autorecon and waiting for vulnerabilities to appear doesn't build exam-ready skills. Automated tools miss things, produce false positives, and can't adapt to unusual configurations. Learn manual enumeration first, then use automation to speed up what you already understand.

3. Not Documenting Methodology

Every successful candidate has a written methodology they follow. Without documentation, you'll forget steps under exam pressure and miss obvious vectors. Create checklists for enumeration, privilege escalation, and common services.

4. Underestimating Active Directory

AD is now mandatory for OSCP+. Candidates who treat it as "just another topic" fail. Dedicate significant time to understanding AD environments, attack paths, and tooling. Practice full AD chains repeatedly until they're second nature.

5. Skipping Report Practice

Many candidates never write a practice report until exam day. Then they spend 8 hours struggling with formatting instead of sleeping. Write at least 2-3 full practice reports on lab machines before your exam. Develop a template and practice using it under time pressure.

6. Poor Time Management on Exam Day

Spending 6 hours on one machine while ignoring others is a common failure mode. Set time limits per machine, move on when stuck, and return with fresh perspective. Partial points on multiple machines beat zero points on a machine you couldn't fully exploit.

🚨 Reality check: If you recognize yourself in several of these mistakes, you're not exam-ready yet. That's okay - recognizing the problem is the first step to fixing it. Adjust your preparation plan before attempting the exam.

Building Your Methodology

A repeatable methodology is your most valuable asset on exam day. When stress hits and your mind goes blank, your methodology guides you through systematic enumeration and exploitation. Here's a framework to adapt:

Sample Methodology Framework

  1. Reconnaissance Initial port scanning, service enumeration, version detection

    Run comprehensive nmap scans (-sC -sV -p-) on all targets. Identify services, versions, and potential attack surfaces. Don't skip full port scans - important services often run on non-standard ports.

  2. Enumeration Deep-dive into discovered services using service-specific tools

    HTTP: Directory brute-forcing, technology identification, source code review. SMB: Share enumeration, null sessions, user listing. FTP: Anonymous access, version exploits. Each service has specific enumeration checklists.

  3. Vulnerability Identification Map findings to potential exploits and attack vectors

    Research service versions for known CVEs. Identify misconfigurations. Note potential credentials, usernames, or sensitive information found during enumeration.

  4. Exploitation Gain initial access through identified vulnerabilities

    Test exploitation hypotheses. Start with most likely vectors. Document failed attempts - knowing what doesn't work helps narrow possibilities. Establish stable shell access.

  5. Post-Exploitation Enumerate the compromised system thoroughly

    Run enumeration scripts (LinPEAS/WinPEAS). Check current privileges, local users, running processes, network connections, installed software. Look for credentials, SSH keys, configuration files with sensitive data.

  6. Privilege Escalation Escalate to root/SYSTEM/Domain Admin

    Work through your privilege escalation checklist systematically. Don't jump to kernel exploits first - misconfigurations are more reliable. Document your path for the report.

  7. Documentation Capture all evidence and write reproducible steps

    Screenshot proofs immediately. Note exact commands used. Organize findings in report template. This happens throughout, not just at the end.

Key insight: Your methodology should fit on one page for quick reference. Detailed checklists for specific services (HTTP, SMB, AD, etc.) are separate documents you reference when needed. The core methodology keeps you oriented; the checklists ensure thoroughness.

After OSCP+: What's Next?

OSCP+ opens doors, but it's not the end of your journey. Here's what successful OSCP holders typically pursue:

Career Paths

  • Penetration Tester Client-facing assessments, variety of targets, consulting lifestyle
  • Red Team Operator Adversary emulation over longer engagements against mature defenses, requires additional skills
  • Security Consultant Broader scope including policy, architecture review, and technical testing
  • Bug Bounty Hunter Independent researcher, flexible schedule, variable income

Advanced Certifications

After OSCP+, many professionals pursue specialized certifications:

  • OSEP (Experienced Penetration Tester): Testing hardened environments, custom tooling, advanced techniques
  • OSED (Exploit Development): Windows exploit development, reverse engineering
  • CRTP/CRTE: Advanced Active Directory attacks, red team operations
  • OSWE: Advanced web application exploitation, code review

Choose certifications aligned with your career interests. Red teamers often pursue OSEP; web specialists go for OSWE; those interested in exploit development choose OSED.

Frequently Asked Questions

How long does it take to prepare for OSCP+?

Most successful candidates spend 3-6 months preparing with 15-20 hours weekly. Beginners without IT background may need 9-12 months. Prior penetration testing experience can shorten this to 2-3 months. The key variable is consistent, focused practice rather than total calendar time.

Is OSCP+ worth it in 2026?

Yes, if you're pursuing a career in penetration testing or red teaming. OSCP remains the most recognized practical certification. The + updates make it more relevant to current real-world assessments. However, it's expensive - ensure it aligns with your career goals before investing.

Can I pass OSCP+ without prior security experience?

Yes, but it requires more preparation time. You'll need strong IT fundamentals (networking, Linux, scripting) before starting. Many successful candidates come from sysadmin, network engineering, or development backgrounds. Complete beginners should budget 9-12 months.

What percentage of people pass OSCP?

OffSec doesn't publish official pass rates. Community surveys suggest first-attempt pass rates around 40-50%, but this varies widely based on preparation quality. Candidates who complete 40+ practice machines and develop solid methodologies pass at higher rates.

Is OSCP+ harder than the original OSCP?

Losing the 10 bonus points makes it harder to scrape a pass, and AD is now effectively mandatory. On the other hand, the assumed-breach start and per-machine AD points make the AD set more forgiving than the old all-or-nothing version. Overall difficulty is similar; the skills you must bring are different.

Ethical Considerations

The skills you develop for OSCP+ are powerful. With exploitation capabilities comes responsibility. Throughout your preparation and career, maintain strict ethical boundaries.

⚠️ Critical reminder: Always get explicit written authorization before testing any system. Use only legal practice environments for study. Unauthorized access is illegal regardless of intent, and can result in criminal prosecution, fines, and permanent career damage.

  • Practice only on authorized systems: OffSec labs, Proving Grounds, HackerDNA Labs, and personal lab environments are legal. Random internet targets are not.
  • Protect client data: During professional engagements, handle discovered data with care. Report findings responsibly and never retain or exploit client information.
  • Follow responsible disclosure: If you discover vulnerabilities outside authorized testing, report them through proper channels without exploitation.
  • Stay within scope: During engagements, respect defined boundaries. Just because you can pivot doesn't mean you should.

Last verified: September 2026. Prices and exam rules confirmed on OffSec's PEN-200 page and exam guide.

Your OSCP+ Action Plan

OSCP+ certification is achievable with proper preparation, consistent practice, and realistic expectations. The exam tests practical skills that take months to develop, not memorized facts you can cram in a weekend.

Your roadmap: Build prerequisites, complete PEN-200 methodically, practice 40+ machines across multiple platforms, develop your methodology, and master Active Directory. Combine structured learning with hands-on lab practice to build the practical skills employers demand.

Start Here

Ready to begin your OSCP+ journey? Build foundational skills first:

Everything above runs in your browser on HackerDNA's free tier, no credit card required. Pick one weak area from this guide, practice it this week, and write it up as if it were an exam report.

HackerDNA Team

HackerDNA Team

Written by the HackerDNA team - cybersecurity professionals building hands-on hacking labs and educational content to help you develop real-world security skills.

Meet the Team

Ready to put this into practice?

Stop reading, start hacking. Real machines, in your browser, free.

Start Hacking Free
30,000+ Hackers Real labs Free
Start Hacking Free or solve today's hack, no account needed