Preview·This page is live at its real address and is not collecting email addresses yet.
Claim my page →Elliot
Free guide
A written course
OffSec Mastery: The Written Course

A written course
OffSec Mastery: The Written Course
For pentesters who know the basics; you finish with a tested methodology
Elliot
For pentesters who know the basics; you finish with a tested methodology
158 pages · about 129 minutes to read · PDF
Inside the guide
24 chapters, and what each one leaves you able to do.
- 01
Map Your Course to OffSec Mastery
Set expectations, prerequisites, and a study plan for the journey ahead.
- 02
Build a Lab That Mirrors Reality
Design a virtual lab with targets, networks, and tools for safe practice.
- 03
Recon with Purpose, Not Noise
Define your scope and gather target details using passive and active methods.
- 04
Scan Ports and Services Methodically
Use Nmap to discover open ports, services, and versions for attack planning.
- 05
Fingerprint Services and Uncover Banners
Identify software versions and banners to match known vulnerabilities.
- 06
Exploit Weak Credentials through Password Attacks
Perform dictionary and brute-force attacks against services with common tools.
- 07
Gain a Foothold via Web Vulnerabilities
Exploit common web flaws like SQLi, XSS, and file upload to get initial access.
- 08
Stabilize Your Shell and Upgrade It
Convert a basic reverse shell into a stable and interactive TTY session.
- 09
Privilege Escalation on Linux Systems
Enumerate a Linux system to find misconfigurations and escalate to root.
- 10
Privilege Escalation on Windows Systems
Leverage Windows services, permissions, and credentials to gain admin rights.
- 11
Pivot through Networks Using SSH and Proxies
Use SSH tunnels and dynamic proxies to reach internal network segments.
- 12
Maintain Access with Persistence Mechanisms
Install backdoors or services to regain access after a reboot or cleanup.
- 13
Collect and Exfiltrate Data Stealthily
Locate sensitive data, compress it, and transfer it out without detection.
- 14
Cover Your Tracks and Clear Logs
Delete or modify logs and remove artifacts to evade forensic analysis.
- 15
Stage Your Attack with Metasploit Modules
Plan and execute a multi-step attack using Metasploit's framework and payloads.
- 16
Write Simple Exploits in Python
Develop custom scripts to exploit buffer overflows or basic web vulnerabilities.
- 17
Assess Web Applications Systematically
Perform a structured web app test covering auth, session, and business logic.
- 18
Hunt Vulnerabilities in Wireless Networks
Capture handshakes, crack WPA/WPA2, and assess rogue access points.
- 19
Social Engineer Your Way into Systems
Craft phishing emails and pretexts to trick users into granting access.
- 20
Integrate Tools into a Custom Workflow
Combine Nmap, Burp, Metasploit, and custom scripts into a repeatable process.
- 21
Execute a Full External Penetration Test
Plan and run a complete engagement from recon to report against an external IP.
- 22
Execute a Full Internal Penetration Test
Simulate an attacker inside the network, moving from entry to domain admin.
- 23
Write a Clear and Actionable Pentest Report
Structure findings, risks, and remediation steps for a technical audience.
- 24
Refine Your Methodology and Keep Learning
Turn lessons into a personal playbook and practice on legal, varied targets.
Look inside
Two real pages, set exactly as they print.
01
Map Your Course to OffSec Mastery
Set expectations, prerequisites, and a study plan for the journey ahead.
By the end of this lesson, you can lay out a realistic study plan for OffSec Mastery, identify what you need before you start, and know how to pace yourself through the whole course. You should already have a working grasp of TCP/IP, common Linux and Windows command lines, and basic scripting in Python or Bash, because I will not revisit those foundations. The course runs about 120 to 150 hours of focused work, which lands at eight to ten weeks if you put in three evenings a week and a weekend morning. You work through the lessons in order, because each one builds on the previous, and you do every practice exercise on your own lab before you move on. Skipping a practice means you miss the part where the idea becomes a reflex, so treat the exercises as the actual content and the reading as preparation for them.
The first idea to fix in your head is the difference between coverage and capability. Coverage means you have read about a technique, seen a tool name, or watched a demo; capability means you can reproduce that technique from memory on a target you have never seen, adapt it when something goes wrong, and explain why it worked. Most courses sell coverage, because it feels productive to tick boxes, but OffSec Mastery is built for capability. You will know you are building capability when you can start a task without looking at the notes, hit an error, and recover by reasoning about what the error means rather than by searching for the exact phrase. The whole course is a sequence of small capabilities that stack into a methodology, and the methodology is the product you carry into a real engagement.