Skip to main content
Cybersecurity

OSEP

OffSec's evasion / advanced AD cert, only meaningful after OSCP and red-team exposure.

DifficultyAdvanced
Study6–9 months
Exam~£1,400
Valid3 years
Compare
POST verdict
WorkableMarket-level call. Not personal advice.

OSCP's harder, narrower successor. A real signal for red team and adversary-simulation roles, near-invisible to general pentest hiring.

Confidence: High Signal strength: Medium
UK red team and adversary-simulation practices recognise the AV-evasion and lateral-movement scope directly. CREST CCT INF and OSEP appear together in senior red-team JDs at named consultancies.
Heavily weighted at red-team consultancies and at CBEST-aligned firms running adversary-simulation engagements. Largely irrelevant to web app or general internal pentest hiring, where OSCP plus reps is the screened combination. The AV-evasion-as-portfolio trap traps candidates without documented engagement output above the cert weight.
Who this pays off for
  • Red team operators at named UK consultancies running CBEST, STAR-FS or TBEST-aligned adversary-simulation engagements
  • Pentesters with OSCP plus two to four years of internal infrastructure reps wanting to move into evasion-shaped engagement work
  • Specialists targeting financial services purple-team roles where AV and EDR evasion is part of the scoped objective rather than out of scope
Who walks away with nothing
  • A general pentest credential. OSEP is evasion and process-injection focused; broad pentest hiring screens for OSCP plus engagement reps instead
  • A web app credential. OSWE is OffSec's web track; OSEP scope is internal infrastructure and evasion, not source-code review or chained web exploitation
  • An OSCP substitute. Hiring managers expect OSCP first; OSEP without it reads as an unusual entry path rather than a senior signal
The named failure mode

The OSEP-after-OSCP escalation pattern stalling without engagement output. Candidates pass both exams without three to six months of documented evasion-shaped engagement reps, and red-team consultancies screen for that operational record before the cert weight begins to count.

Recruiter signal, not marketing

Direct credibility in UK red team and adversary-simulation hiring at named consultancies, particularly where CBEST or TBEST scope demands documented evasion competency. Does not substitute for OSCP in general pentest hiring, does not displace OSWE for web-app roles, and adds limited weight outside adversary-simulation specialist tracks.

Falsifiability
  • OffSec restructures the OSCP-OSEP-OSWE certification path in a way that elevates OSEP to a more visible mid-tier credential outside red-team specialist hiring
  • Bank of England CBEST or PRA TBEST framework guidance explicitly references OSEP-style evasion competencies as a named requirement for accredited providers
  • EDR market consolidation reduces the diversity of evasion targets to a point where the cert's scope narrows in operational relevance

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Senior pentest / red-team interviews
  • EDR evasion / C2 tradecraft credibility
Practitioner take

OSEP is OffSec's evasion and lateral movement cert and it's the credential that genuinely matters when red team hiring stops asking about OSCP and starts asking what you can do once EDR is in the way. The PEN-300 syllabus is AV bypass, custom tooling, AppLocker and constrained language mode, kerberos abuse, and persistence in mature AD estates. The exam is 48 hours and assumes you can write your own loaders. Take it when you've spent at least a year in a red team or senior pentest seat and the next move is internal red team lead or specialist consultancy work. Skip it straight off OSCP. The gap between the two exams is the gap between knowing exploitation and operating against a defender, and skipping it shows on day one of the engagement.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • OSCP or equivalent

Common misconceptions

  • OSEP alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Red-team lead roles on its own

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.