Why the Report Still Decides Your Fate
OffSec’s new OSCP⁺ exam awards up to 10 of the 100 points for a clear, evidence‑rich report. Miss a required screenshot or botch a step‑by‑step exploit narrative and you can fail—even with 70 lab points. Treat the report as a second exam, not an afterthought.
1 | Battle‑Tested Template Structure
-
Executive Summary – ½ page; risk language a manager can quote.
-
Methodology & Scope – tools, ethical constraints, network map.
-
Vulnerability #1 (AD chain)
-
Intro sentence
-
Step‑by‑step exploit bullets
-
Screenshot 1: foothold shell & hostname
-
Screenshot 2: privilege‑escalation proof
-
-
Vulnerability #2 (Standalone box)
-
Mitigation Recommendations – one actionable line per vuln.
-
Appendix – full command output, hashes, screenshots in numbered order.
Time‑Saver: Use our free Markdown template and export to PDF—headings auto‑populate the table of contents.
2 | Screenshot Must‑Haves
-
Include timestamp + hostname in every shell shot (
whoami && hostname
). -
For AD points, capture the NTLM hash or ticket you abused.
-
Name files logically:
Vuln1_shell.png
,Vuln1_hash.png
.
3 | Proof‑of‑Concept (PoC) Etiquette
-
Annotated code—comment the one‑liner that triggers RCE; leave out recon noise.
-
Highlight creds—underline stolen passwords so graders see them instantly.
-
Reverse shells? Mask internal IPs if asked; OffSec likes clean, redacted outputs.
4 | Common Mistakes That Cost Points
Mistake | Point Loss |
---|---|
Missing “root” or “NT AUTHORITY\SYSTEM” screenshot | –5 |
Steps out of chronological order | –3 |
No mitigation or CWE mapping | –2 |
Over‑compressed images (blurry text) | –1 |
5 | First‑Attempt Pass with Cert Fast Pass
-
2025‑aligned report template—auto‑checks headings, page numbers, and appendix order.
-
Screenshot checklist integrated into our timed mocks—never forget a proof.
-
One‑to‑one mentor review—we mark up your draft PDF before you ever schedule the real exam.
-
Pay‑Only‑After‑You‑Pass guarantee—tuition due only when OffSec emails “PASS.”
Comparing cert paths? See OSCP⁺ vs. OSEP—Which Red‑Team Cert Pays Off Faster? for salary data and skill overlap.
Ready to Ship a Perfect OSCP⁺ Report?
📲 Grab the free Markdown template or book a 15‑minute mentor call: https://certfastpass.net/contact/
Upskill smarter. Pass faster. Negotiate higher—with Cert Fast Pass.
Leave a Reply