OSCP & Offensive Security Cert Prep Tutor
Learn the offensive-security exam curriculum and practice it hands-on in authorized labs, OSCP, PNPT, CPTS, and friends.
$12
Works with the AI tools you already use
OSCP & Offensive Security Cert Prep Tutor
Example session with this skill installed
I'm in my OffSec Proving Grounds lab and found a Windows machine with port 445 open and an unusual service on 8080. How should I proceed with enumeration?
- Read your context and instructions
- Compiled the oscp & offensive
- Generated the document
I have noted you are working within your authorized OffSec Proving Grounds environment. Since you have identified SMB (445) and an unknown service on 8080, we will follow a structured enumeration methodology to identify potential entry points.
Enumeration Workflow: Windows Target
| Phase | Action | Tool / Command |
|---|---|---|
| SMB Enumeration | Check for anonymous login and list shares. | smbclient -L //TARGET_IP/ -N |
| SMB Vulnerability | Scan for common vulnerabilities like MS17-010. | nmap --script smb-vuln* -p 445 TARGET_IP |
| Service Discovery | Identify the service banner and version on 8080. | curl -I http://TARGET_IP:8080 |
| Web Crawling | Directory brute-force to find hidden files or consoles. | gobuster dir -u http://TARGET_IP:8080 -w /usr/share/wordlists/dirb/common.txt |
| RPC Check | Query for user information if null sessions are enabled. | rpcclient -U "" TARGET_IP |
Detailed Steps
Investigate Port 8080: High ports often host management consoles (Jenkins, Tomcat, etc.) or custom API documentation. Use nmap -sV -sC -p 8080 to get the specific version string.
2.
SMB Mapping: If smbclient fails, use enum4linux-ng to look for user SIDs or password policies that might assist in a later spray.
3.
Documentation: Capture the output of your nmap scans immediately. If you find a web portal on 8080, take a screenshot of the landing page for your report.
Next steps
- Run the version scan on port 8080 and check SearchSploit for the service name.
- Attempt to map the IPC$ share on SMB to see if you can pull a user list.
- If a web application is present, check the source code for hardcoded comments or version numbers.
oscp-offensive-security-cert-prep-tutor.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
A hands-on study partner for the major hands-on offensive-security certifications. It teaches the shared curriculum these exams test, enumeration, web exploitation, Active Directory attacks, privilege escalation on Windows and Linux, pivoting and tunneling, password attacks, buffer overflow, and the exam report, and coaches you through actually doing each technique against targets you control. Built for anyone preparing for OSCP, PNPT, CPTS, eJPT, PenTest+, CEH, OSEP, CRTP, or CRTO who wants methodology mastery, not memorized answers.
It maps every topic to the certs that test it and at what depth, so you know where to focus, then helps you build a study plan and work through technique in your own lab. Reach for it when you're studying for an offensive cert, want to shore up a weak area like AD or privilege escalation, or need to practice writing the exam report under time pressure. Think of it as the deep companion to a cert-chooser: that tells you which cert to sit; this helps you pass it.
Honest limits: it teaches the method, it does not run tools or attack anything for you, and it will not hand you leaked exam questions, flags, or solutions to a cert's live exam machines. It confirms an authorized context before giving hands-on steps and won't help against unauthorized targets or with proctor evasion. Exam details (cost, format, passing score, time limits) change, so verify them on the official page. It's a tutor, not a shortcut: passing depends on your practice, and there's no guarantee.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 9 days ago
- Passed all security checks, Safe to install
Needs access to