OSCP guide: what it is, what the exam evaluates (infrastructure pentest, Active Directory, 24h + report), who it's for, how to prepare, OSCP vs eJPT vs eWPT and why it's infrastructure pentesting, not web bug bounty (complementary).
Gorka El Bochi
Founder of BBLABS
Quick answer: The OSCP (Offensive Security Certified Professional) is the most recognized hands-on pentesting certification in the world. You pass it with a 24-hour exam in which you compromise real machines in a lab, followed by another 24 hours to deliver a professional report. It evaluates infrastructure pentesting (including Active Directory), not web bug bounty: they're complementary.
The OSCP is OffSec's flagship certification (formerly Offensive Security). Unlike almost every security cert, it's not a multiple-choice test: it's completely hands-on. To pass it you have to hack real machines and prove you did it.
Its reputation comes from that toughness. OffSec's unofficial motto —"Try Harder"— sums up the philosophy: they don't give you the answer, they give you a lab and you have to figure it out. That's why the OSCP carries so much weight in the pentesting job market: whoever holds it has proven they can actually compromise systems, not just pass a theoretical exam.
You earn it by taking the associated material (the PEN-200 course) and passing the exam. OffSec periodically changes the price and subscription formats, so always check the up-to-date official figures on their website rather than trusting a number you read somewhere.
The exam is the legendary part. Broadly:
That second part is key and many people underestimate it: the OSCP doesn't only evaluate whether you can hack, but whether you can communicate it the way a consultant would. Documenting well is half the job, just as in bug bounty a weak report tears down a good finding.
The OSCP makes sense if:
It may not be your priority if:
Don't dive into the exam cold. Sensible path:
Enumeration is 80% of success. Most people who fail don't do so because they can't exploit, but because they didn't find the vector by enumerating superficially.
Three certs that get confused a lot:
The usual order for someone going into infra pentesting: eJPT → OSCP. For someone going into web, the eWPT is more relevant, and if you also want to get paid for web flaws, bug bounty provides what no cert gives: real results and a public profile.
Here's the honest part, because it's constantly misunderstood:
The OSCP trains infrastructure pentesting. BBLABS trains web bug bounty. They're different, complementary things.
A pentester with an OSCP who wants to hunt web bugs also needs to train the pattern of application flaws. And a web hunter who wants to apply for an infra pentester role will lean on the OSCP. They don't compete: they add up. If your goal is to make money reporting web flaws, start with web practice (Learn bug bounty + labs); if your goal is a generalist pentester job, the OSCP is a great investment.
It depends on your goal:
What no one disputes is that preparing the OSCP makes you better, pass or fail: the enumeration and persistence methodology you internalize is transferable to everything, including bug bounty.
When you reach the exam, technique matters, but management matters more. What separates passing from falling one point short:
Failing the OSCP is completely normal: many people pass it on the second or third attempt. It's not a verdict on your worth, it's information. If you don't pass the first time:
The very process of retrying makes you a better pentester. No one who has seriously prepared the OSCP has come out worse than they went in.
Even though they're different disciplines, the OSCP methodology —enumerate thoroughly, don't give up, document— is exactly the mindset that makes you good at bug bounty. And vice versa: the eye you train hunting web flaws in real-case labs helps you with the web part of the exam. Many complete professionals prepare the OSCP for employment and do bug bounty for the results and the public profile. Don't choose between the two if your goal is to be a complete offensive hacker: order them according to your current priority.
How much does the OSCP cost?
OffSec changes its prices and subscription models frequently, so check the official figure on their website. Don't trust specific amounts you read in forums: they're usually outdated.
How long does it take to prepare?
Very variable depending on your base: from a few months with intense dedication and prior experience, to much longer if you start with little base. Preparation is measured in machines hacked, not hours of video.
Is the OSCP useful for bug bounty?
It helps with the foundations and methodology, but web bug bounty demands practice with specific application flaws. Complement the OSCP with real web labs.
Do I need to know how to program for the OSCP?
You need functional scripting (Bash and some Python) to adapt exploits and automate tasks. You don't need to be a developer, but you do need to hold your own with code.
The OSCP is the reference certification for anyone who wants to work in infrastructure pentesting and is looking for a recognized badge in the job market. It's tough, hands-on and makes you better just by preparing it. But be clear on the boundaries: the OSCP is systems and Active Directory pentesting; web bug bounty is another, complementary discipline, trained separately with real application flaws and an ordered path. Choose according to your goal —employment or bounties— and, if you can, add them together: the most complete pentester is the one who masters both.
hunters training
labs from real reports
completions
in bounties practiced
Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime
What bug bounty is, how a program works step by step, which platforms it runs on (HackerOne, Bugcrowd, Intigriti, YesWeHack), how much you earn, whether it's legal and where to start from scratch.
What bug bounty really pays: average rewards by vulnerability type and severity, what top hunters earn, the reality for beginners and why most people don't make a living from it.
The OWASP Top 10 explained category by category, with real examples: broken access control, injections, SSRF, cryptographic failures and more. With links to the theory and hands-on labs for each flaw.