OSCP Coaching — One-to-One Mentorship From Someone Who Tests for a Living
Most OSCP mentors passed the exam once and now teach full time. I test production Active Directory environments and web applications for paying clients every month, then bring the same attack paths and methodology into your sessions — coaching from someone still doing the work, not someone who used to.
What we work on
- Enumeration methodology that scales to any box
- Active Directory attack paths — Kerberoasting, ACL abuse, ADCS, delegation
- Linux privilege escalation
- Windows privilege escalation
- Web exploitation fundamentals
- Pivoting and tunneling through multi-layer networks
- Exam strategy and time management
- Report writing that would pass a real client review
How sessions work
One-to-one video calls, scheduled around your pace — weekly or biweekly, whichever keeps momentum without burning you out. Every session starts from where you're actually stuck, not a fixed curriculum you already half-know. Between sessions you get a short written plan: what to redo, what to read, what to attempt before we talk again.
Pricing
OSCP prep time varies enormously by starting point — Linux/networking background, hours available per week, and how much of PWK or HTB you've already worked through. There's no flat public rate for that reason. The free readiness call ends with a clear plan and a fixed price in writing, the same way every engagement on this site is scoped.
Why 1:1 mentorship beats a course or a Discord server
Courses and community servers are good at explaining concepts. They're bad at telling you why your enumeration missed the pivot point, or why your privilege escalation attempt is technically correct but pointed at the wrong service. That kind of feedback needs someone watching your actual process — your terminal, your notes, your reasoning — and pointing at the specific habit that's costing you time. That's what a session is for.
Sessions are built around the same four areas most candidates get stuck on: Active Directory attack chaining under time pressure, the jump from "found a vulnerability" to reliable privilege escalation, exam-day time management across multiple targets, and writing a report that actually documents what you did — which is also tested on the OSCP exam itself and is the exact skill I deliver commercially in every paid engagement.
Where this comes from
Every technique used in these sessions is published for free in the Arsenal before it's ever discussed on a call — the BloodHound attack reference, the ADCS attack reference (ESC1–ESC16), the privilege escalation toolkit, the Windows token privileges reference, and the web exploitation arsenal. You can read the actual methodology before you book a call, not just take a sales page's word for it.
HTB Penetration Tester → CPTS → OSCP, and other starting points
If you're coming from HTB's Penetration Tester path or CPTS, most of the enumeration and web exploitation methodology carries over directly — the gap is usually Active Directory chaining and exam-specific time pressure, which is exactly where sessions focus first. If you're starting from zero, the readiness call gives you an honest answer on whether OSCP is the right next step yet or whether foundational Linux and networking work comes first.
What coaching does not include
No sharing of live exam content, and no encouraging you to violate OffSec's exam agreement — if you've attempted the exam before, sessions work from what you're allowed to discuss, not a walkthrough of confidential material. No pass guarantees. No pre-recorded course — every session is live and specific to where you actually are.
Questions about OSCP coaching
Most marketplace mentors are judged on price per hour, and many haven't tested a real environment since their own OSCP exam. Sessions here are run by an OSCP+ certified penetration tester who is currently doing paid Active Directory and web application engagements, using the same methodology published openly in the Arsenal — so you can check the depth before you book anything.
No — and any mentor who guarantees a certification outcome isn't being straight with you. Exam results depend on your own preparation and performance under time pressure. What coaching delivers is a personalized plan, direct feedback on your specific weak areas, and methodology drawn from live client engagements.
Yes, that's exactly what the free readiness call is for. Bring what you've already done — HTB, TryHackMe, CTFs, prior certifications — and get an honest read on whether now is the right time or what to shore up first.
We work from your own recollection of where you got stuck, without discussing confidential exam content covered by OffSec's exam agreement. Most repeat attempts fail on the same handful of things — Active Directory chaining under time pressure, privilege escalation tunnel vision, or running out of time to write the report — and sessions target whichever of those cost you the most.
They test similar skills in different formats. CPTS is closer to a guided consulting engagement; OSCP adds exam-style time pressure and more self-directed enumeration. If you've already done CPTS, most of that work carries over — coaching sessions focus on the delta, mainly Active Directory chaining and exam time management.
Whatever you're stuck on, worked through live — your enumeration process, your privilege escalation attempts, your Active Directory attack chain — with feedback on the actual mistake instead of a generic lecture. Every session ends with a short written plan for what to do before the next one.
There's no flat public rate, because prep time varies enormously by starting point — Linux and networking background, hours available per week, and how much of PWK or HTB you've already worked through. The free readiness call ends with a clear plan and a fixed price for it, in writing, the same way every engagement on this site is scoped.
Stuck somewhere in PWK or HTB and not sure why?
Free 30-minute readiness call. No pitch, no pressure — just an honest read on where you are.