Certification Path
The path doesn't start at OSCP. It starts at the fundamentals — building the mental model, the Linux fluency, the networking baseline — before touching a single exploit. Four milestones. One goal.
PHASE 0
Fundamentals
PHASE 1
eJPT
PHASE 2
TCM PEH
PHASE 3
HTB WebApp
GOAL
OSCP
Phase 00 — Foundation
Before touching real tools, the fundamentals have to be solid. Linux command line, basic networking (TCP/IP, DNS, HTTP), how web applications work, and the mindset shift from user to attacker. TryHackMe's learning paths cover this ground in a structured way. HackTheBox Starting Point machines provide the first live targets. This phase is not skippable — it's the reason OSCP candidates fail when they rush the cert.
Phase 01 — First Certification
The eJPT is the first real exam — a hands-on, practical assessment that validates the fundamentals. No multiple choice. You get a network, you get objectives, you have 72 hours. It's cheap (~$200), beginner-friendly, and creates the first line on the résumé. TCM Security's free PEH course is the recommended prep. Passing eJPT means the foundation is solid enough to move into more aggressive territory.
Phase 02 — Intermediate
TCM Security's Practical Ethical Hacking course is where the methodology locks in. Active Directory attacks, privilege escalation, post-exploitation, pivoting, and report writing. Heath Adams (The Cyber Mentor) built this course specifically for people heading to OSCP — it bridges the gap between "I can hack CTF boxes" and "I understand how real internal networks fall." The PNPT certification that comes with it is one of the best practical certs in the field.
Phase 03 — Web Application
OSCP now includes web application attacks as a significant component of its exam. The HTB Bug Bounty Hunter certification covers the web attack surface systematically — SQLi, XSS, SSRF, XXE, authentication bypasses, and the methodology real bug bounty hunters use. This phase runs parallel to or after TCM PEH depending on comfort level. The PortSwigger Web Security Academy is the free supplement that goes deeper on individual vulnerability classes.
The Goal
Offensive Security Certified Professional. The industry benchmark. 24-hour hands-on exam. You either pop the boxes or you don't. No partial credit. No multiple choice. Everything on this path exists to make that 24 hours survivable.