BBLABS v2BBLABSv2
>Home>Labs
>New labs

Latest 3 labs

Loading…

View all labs →
>Creators>Ranking
>Learn

Learn bug bounty

AcademyGuides, cheatsheets and glossaryVulnerabilitiesXSS, SQLi, IDOR, SSRF and moreHunter RoadmapYour step-by-step bug bounty pathBlogBug bounty guides and news
>Business>Pricing
ES
Log inLog in
>Home>Labs>New labs>Creators>Ranking>Learn>Business>Pricing
ES
Sign inCreate account

Contact

Practice, learn and hack

Bug bounty practice platform with labs based on real reports. Learn ethical hacking in safe environments.

contact→

Follow us

YouTube
@0xGorka
X
@gorkaelbochi
LinkedIn
gorka-el-bochi-morillo
Instagram
@_.gorkaaa.b
Email
team@bblabs.es

Access every lab from €7.99/mo

New labs every week. Cancel anytime.

Create account

BBLabs is the bug bounty labs platform where you learn bug bounty with real vulnerabilities extracted from paid reports on HackerOne, Bugcrowd and Intigriti. Here you practice web hacking —XSS, SQLi, IDOR, SSRF, CSRF and more— in downloadable environments, capture the flag, read the writeup and apply the technique on active bug bounty programs.

BBLabs is the alternative to HackTheBox, TryHackMe and PentesterLab for those who want to practice bug bounty with real reports instead of artificial CTFs. From €7.99/mo, no commitment.

→ Learn bug bounty from scratch→ How to do bug bounty step by step→ Real bug bounty reports→ BBLabs for companies and academiesLabsAcademyVulnerabilitiesToolsHunter rankingXSS labsIDOR labsSSRF labsCSRF labsHackTheBox alternativeHack4u alternativeTryHackMe alternativePortSwigger alternativePentesterLab alternativeBug Bounty Labs comparisonHackerOne to practiceOffSec / OSCP alternativeINE / eWPT alternativeHTB Academy alternativeDVWA alternativeJuice Shop alternativeVulnHub alternativePentesterAcademy alternativeRoot-Me alternativeHackTheBox vs TryHackMeBest bug bounty platforms 2026BlogSpoilersWhat is bug bounty?How much do you earn in bug bounty?OWASP Top 10 explainedBest sites to practice web hackingHow to become an ethical hacker from scratchBurp Suite tutorial (Spanish)OSCP guide and prepGoogle Dorks for bug bountyHow much an ethical hacker earns in SpainBug bounty tools 2026Best cybersecurity certifications 2026Burp Suite tutorialsqlmap tutorialffuf web fuzzingnuclei tutorialHTTP Request SmugglingWAF bypassPrompt injection (LLM)Google Dorks
Made withand code
TermsPrivacyComparisonES

© 2026 BBLABS v2 — All rights reserved

back to blog
guides

OSCP guide: what it is, how to prepare and whether it's worth it (2026)

OSCP guide: what it is, what the exam evaluates (infrastructure pentest, Active Directory, 24h + report), who it's for, how to prepare, OSCP vs eJPT vs eWPT and why it's infrastructure pentesting, not web bug bounty (complementary).

GEB

Gorka El Bochi

Founder of BBLABS

2026-07-2113 min read
#oscp#certifications#pentesting#career#offsec

Quick answer: The OSCP (Offensive Security Certified Professional) is the most recognized hands-on pentesting certification in the world. You pass it with a 24-hour exam in which you compromise real machines in a lab, followed by another 24 hours to deliver a professional report. It evaluates infrastructure pentesting (including Active Directory), not web bug bounty: they're complementary.

What is the OSCP?

The OSCP is OffSec's flagship certification (formerly Offensive Security). Unlike almost every security cert, it's not a multiple-choice test: it's completely hands-on. To pass it you have to hack real machines and prove you did it.

Its reputation comes from that toughness. OffSec's unofficial motto —"Try Harder"— sums up the philosophy: they don't give you the answer, they give you a lab and you have to figure it out. That's why the OSCP carries so much weight in the pentesting job market: whoever holds it has proven they can actually compromise systems, not just pass a theoretical exam.

You earn it by taking the associated material (the PEN-200 course) and passing the exam. OffSec periodically changes the price and subscription formats, so always check the up-to-date official figures on their website rather than trusting a number you read somewhere.

What does the OSCP exam evaluate?

The exam is the legendary part. Broadly:

  • 24 hours of hands-on exam. You connect via VPN to a lab with several machines and you have to compromise them, obtaining proofs (flags) for each access level.
  • It includes an Active Directory environment. It's no longer just "isolated machines": part of it evaluates that you know how to move and escalate privileges inside a Windows domain, which is how real companies work.
  • Points system. You need to reach a minimum score by combining the compromised machines and their different access levels (user and root/admin).
  • Another 24 hours for the report. Once the exam is over, you write a professional pentest report with findings, exploitation steps and evidence. If the report is weak, you fail even if you hacked everything.

That second part is key and many people underestimate it: the OSCP doesn't only evaluate whether you can hack, but whether you can communicate it the way a consultant would. Documenting well is half the job, just as in bug bounty a weak report tears down a good finding.

Who is the OSCP for?

The OSCP makes sense if:

  • You want to work as a pentester in a consultancy or an offensive security team. Here the OSCP is almost a standard: many job postings explicitly ask for it or value it highly.
  • You need a recognizable badge that opens job doors and HR filters.
  • You're looking for a structured path to learn infrastructure pentesting with a clear goal.

It may not be your priority if:

  • Your goal is web bug bounty and making money reporting flaws. There, the OSCP helps with the foundations, but it's not what will make you find an IDOR or an SSRF in an application (for that, specific web practice).
  • You're starting from absolute zero. The OSCP assumes prior knowledge; it's best to arrive with foundations already in place. If that's your case, start with becoming an ethical hacker from scratch.

How to prepare for the OSCP?

Don't dive into the exam cold. Sensible path:

  1. Solid fundamentals: networking, Linux, basic Windows and scripting (Bash and some Python). Without these, the course will be an uphill battle.
  2. Web base: even though the OSCP is infra-focused, there's a web portion. Understanding the classic vulnerabilities and practicing them in the Academy saves you pain.
  3. The official material (PEN-200) and, above all, lots of lab machines. Real preparation is hacking dozens of machines until the methodology (enumerate → find the vector → exploit → escalate) is a reflex.
  4. Practice Active Directory separately: it's where most people fail. Set up or use specific AD labs.
  5. Train the report. Write reports for the machines you practice as if they were exam ones. Arriving with a template and fluency gives you hours of advantage.

Enumeration is 80% of success. Most people who fail don't do so because they can't exploit, but because they didn't find the vector by enumerating superficially.

OSCP vs eJPT vs eWPT (brief)

Three certs that get confused a lot:

  • eJPT (INE/eLearnSecurity): entry level, far more affordable than the OSCP. Ideal as a first step to validate pentesting fundamentals before tackling the OSCP.
  • OSCP (OffSec): intermediate-advanced level, infrastructure pentesting + AD. The industry standard.
  • eWPT (INE): focused specifically on web application pentesting. If your goal is the web, it fits better than the OSCP in that specific respect.

The usual order for someone going into infra pentesting: eJPT → OSCP. For someone going into web, the eWPT is more relevant, and if you also want to get paid for web flaws, bug bounty provides what no cert gives: real results and a public profile.

OSCP vs web bug bounty: complementary, not substitutes

Here's the honest part, because it's constantly misunderstood:

The OSCP trains infrastructure pentesting. BBLABS trains web bug bounty. They're different, complementary things.

  • The OSCP teaches you to compromise machines, escalate privileges and move through an Active Directory. It's the world of the systems pentester and the red team.
  • Web bug bounty —what you train in the BBLABS labs— is about finding flaws in applications: IDOR, XSS, SQLi, SSRF, business logic flaws. It's what you get paid for by reporting on HackerOne, Bugcrowd or Intigriti.

A pentester with an OSCP who wants to hunt web bugs also needs to train the pattern of application flaws. And a web hunter who wants to apply for an infra pentester role will lean on the OSCP. They don't compete: they add up. If your goal is to make money reporting web flaws, start with web practice (Learn bug bounty + labs); if your goal is a generalist pentester job, the OSCP is a great investment.

Is the OSCP worth it?

It depends on your goal:

  • If you want a job in pentest/red team: yes, it's among the certs with the best employability return in the sector.
  • If your goal is exclusively web bug bounty: it's a good reinforcement of fundamentals, but it's not what gets you closest to your first bounty. There, specific web practice yields more.
  • If you're at absolute zero: foundations first (and maybe an eJPT); the OSCP comes later.

What no one disputes is that preparing the OSCP makes you better, pass or fail: the enumeration and persistence methodology you internalize is transferable to everything, including bug bounty.

Tips for OSCP exam day

When you reach the exam, technique matters, but management matters more. What separates passing from falling one point short:

  • Enumerate to exhaustion. Most blocks get resolved by re-enumerating a service you dismissed too quickly. If you're not making progress, you're almost never missing a magic exploit: you're missing information.
  • Manage time by machines, not by pride. If a machine stumps you, switch to another and come back later. Score what you can before obsessing over a single one.
  • Document while you hack, not at the end. Take screenshots of every step and every flag in the moment. Reconstructing the report from memory at 3 a.m. is the best way to lose points you already earned.
  • Rest. It's 24 hours, not a sprint. Sleeping a few hours yields more than forcing your eyes in a loop over the same prompt.
  • Have your templates ready. An enumeration methodology, frequent commands and a report template prepared in advance save you hours of clock time.

And if you fail the OSCP?

Failing the OSCP is completely normal: many people pass it on the second or third attempt. It's not a verdict on your worth, it's information. If you don't pass the first time:

  • Analyze where your time went. It's almost always superficial enumeration or clock management, not a lack of knowledge.
  • Practice more exam-style machines, especially Active Directory and privilege escalation, which is where most people slip.
  • Refine your methodology so that enumerating is systematic and doesn't depend on the inspiration of the moment.

The very process of retrying makes you a better pentester. No one who has seriously prepared the OSCP has come out worse than they went in.

OSCP and bug bounty: how they reinforce each other

Even though they're different disciplines, the OSCP methodology —enumerate thoroughly, don't give up, document— is exactly the mindset that makes you good at bug bounty. And vice versa: the eye you train hunting web flaws in real-case labs helps you with the web part of the exam. Many complete professionals prepare the OSCP for employment and do bug bounty for the results and the public profile. Don't choose between the two if your goal is to be a complete offensive hacker: order them according to your current priority.

Frequently asked questions (FAQ)

How much does the OSCP cost?
OffSec changes its prices and subscription models frequently, so check the official figure on their website. Don't trust specific amounts you read in forums: they're usually outdated.

How long does it take to prepare?
Very variable depending on your base: from a few months with intense dedication and prior experience, to much longer if you start with little base. Preparation is measured in machines hacked, not hours of video.

Is the OSCP useful for bug bounty?
It helps with the foundations and methodology, but web bug bounty demands practice with specific application flaws. Complement the OSCP with real web labs.

Do I need to know how to program for the OSCP?
You need functional scripting (Bash and some Python) to adapt exploits and automate tasks. You don't need to be a developer, but you do need to hold your own with code.

Conclusion

The OSCP is the reference certification for anyone who wants to work in infrastructure pentesting and is looking for a recognized badge in the job market. It's tough, hands-on and makes you better just by preparing it. But be clear on the boundaries: the OSCP is systems and Active Directory pentesting; web bug bounty is another, complementary discipline, trained separately with real application flaws and an ordered path. Choose according to your goal —employment or bounties— and, if you can, add them together: the most complete pentester is the one who masters both.

share
share:
hunters training
650

hunters training

labs from real reports
50

labs from real reports

completions
380

completions

in bounties practiced
$200,000

in bounties practiced

40 flags captured this week·Real reports from HackerOne · Bugcrowd · Intigriti·No commitment·Free Academy
BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.

Create free accountSee the labs

No card · free Academy · cancel anytime

[RELATED_POSTS]

Continue Reading

guides

What is bug bounty: the complete 2026 guide (how it works, how much it pays, is it legal)

What bug bounty is, how a program works step by step, which platforms it runs on (HackerOne, Bugcrowd, Intigriti, YesWeHack), how much you earn, whether it's legal and where to start from scratch.

2026-06-25•13 min read
guides

How much you earn in bug bounty (real figures 2026)

What bug bounty really pays: average rewards by vulnerability type and severity, what top hunters earn, the reality for beginners and why most people don't make a living from it.

2026-06-25•12 min read
guides

OWASP Top 10 (2021/2025) explained with real examples

The OWASP Top 10 explained category by category, with real examples: broken access control, injections, SSRF, cryptographic failures and more. With links to the theory and hands-on labs for each flaw.

2026-06-25•16 min read