Strategy recommendations, pitfalls to avoid, and why you should just write the lab report for crying out loud. There’s a reason why this certification has a reputation. The material covers a wide array of topics, the time required is substantial, and the exam is difficult. For those looking to take the PWKv2 course or are close to taking the OSCP exam, my goal in this post is to help you avoid some of the traps I almost fell in along the way. It won't contain tools I used, tips and tricks, etc. There are plenty of places to find that stuff already if you Google around a bit and gathering them together is part of learning!
How to Spend Your Lab Time
"dont skip the lab exercises, srsly" - Confucius One of the first things you might notice about PWKv2 is that there's a lot more material than in PWKv1. And I mean over twice the amount. Since you can only buy a maximum of 90 days of lab time, there are some things you should think about before starting:Trap 0: Not Studying the Course Content
When I started the course, I immediately went for the actual course content to get it out of the way and get to the labs as soon as possible. Doing this pointed out gaps in my knowledge and forced me to think in ways I hadn't before. Going through the course content, doing what was effectively an expertise audit, was invaluable. As I read about others' experiences with the exam, I noticed that a significant number of the people who failed their first or second attempt spent little to no time on the course content. They also often added that if they had, they probably would have passed sooner. Not going through the content absolutely defies logic. You can't be certain you're prepared for the exam if you don't, which leads me to my next point:Trap 1: Not Doing The Bonus Lab Report
OffSec lets you submit an optional report on all of the exercises in the book and 10 lab machines for a chance at five (5) extra points on your exam. You should decide if you're going to do this before even starting (you definitely should) and spend your lab time accordingly (seriously, do the bonus report). Assuming you've decided to go for the bonus points, I highly recommend writing your lab report as you go as if you were going to submit it without revisions. You'll need the lab time to complete all of the exercises and you don't want to end up buying extra lab time (like me) just to get your bonus points. The lab report will take you a long time. It took me about a month (one-third of my lab time) to get through the book and videos because of all the additional material. This left me with only 60 days to attack the lab machines. The final draft was just under 400 pages. When all is said and done, you will have struggled through every book exercise and learned a lot along the way that will help you build your methodology (which I'll talk about in the next sections) and build a deep understanding of the concepts that OffSec has included.Trap 2: Using Metasploit/Sqlmap (Too Much)
Whether or not you should use these in the lab environment is hotly debated and both sides make good points. The pros and cons of using these two tools, in particular are, to me, as follows: Pros- Practice with tools you'll probably use in the real world
- Faster compromise of machines (less time being stuck and not moving on to others)
- Easier lab report writing
- Less experience with using non-Metasploit exploits
- Shallower understanding of how exploits you use work
- A false sense of preparedness come exam time
Trap 3: Not Building a Methodology
Use your time in the labs to establish your own way of attacking boxes. Repeat it, improve it, and document it. This will help you recognize when a situation is something you have dealt with before and when you're out of your element and need to do some research. This process should help you curate a toolset you like (in addition to tools the book teaches you about) and a collection of payloads that are good to have on-hand. Don't get caught up in how many different tools you can use to do automatic enumeration or scanning. Find the tools that work and stick to them.The Exam
No matter how prepared you are for it, 24 hours to hack as much as possible isn't much. This, according to OffSec, is on purpose. The true adversary for those 24 hours isn't OffSec and it isn't your target range. It's your mind. Everything else is secondary. Here's what I mean by that:- Time is a safety net. Your brain sees things differently when the clock is ticking down.
- Sleep is a gamble. You're going to get tired. If you're like me, after about 15 hours, you'll start typing slower, thinking less clearly, and obsessively calculating your points to see how close you are.
- Not making progress feels like doom. Every minute that goes by without some measure of success feels like failure.
Ryan Basden
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)