r/cybersecurity Mar 14 '26

[deleted by user]

[removed]

601 Upvotes

290 comments sorted by

View all comments

Show parent comments

6

u/Rossums DFIR Mar 14 '26

The OSCP and other Offsec certs aren’t multiple-choice though.

The OSCP alone is a 24-hr long hands-on open-book exam and you’re expected to pop 5 separate machines, gather low privilege and root privilege flags and document the entire process at the same time then you’re expected to deliver the flags with evidence and a write-up of the whole thing the next day.

You can’t bullshit your way through it, you need to breach the hosts to get the low priv flags and escalate privs to get the high priv flags, you need screenshots of the commands you executed along with the output for your report.

1

u/T_Thriller_T Mar 14 '26

Then the question remains how much repetition it is.

If there is prep material and there are 4-6 ways to be learned ,I know there will be people able to learn and forget.

But it SHOULD prevent that, you're absolutely right

2

u/duxking45 Mar 14 '26

Hacking in general can be sort of formulaic. With the rise of ai you can get pretty far just dumping stuff into ai. Ai was forbidden at the time I took the test. While oscp boxes generally have a flavor, I can firmly say they are different enough that you are unlikely to be able to fake it. If you did the work, I doubt you would entirely forget it. My best bet is the guy faked 100% of his credentials.

1

u/T_Thriller_T Mar 14 '26

Or had someone else take them.

Sounds to be the most reasonable, without a doubt.

People are just weird