PEN-300: Advanced Evasion Techniques and Breaching Defenses

PEN-300: Advanced Evasion Techniques and Breaching Defenses

Building on the skills acquired in PEN-200, OffSec’s PEN-300 course explores advanced penetration testing techniques against hardened targets. Learners gain hands-on experience bypassing security defenses and crafting custom exploits in real-world scenarios, enhancing their expertise in ethical hacking and vulnerability assessment.

This self-paced course culminates in a challenging exam, leading to the OffSec Experienced Penetration Tester (OSEP) certification. Achieving the OSEP certification distinguishes professionals with advanced penetration testing skills, making them highly sought-after experts in securing organizations from sophisticated threats.

OSEP Certification Badge

Starting at $1,749

Advance your penetration testing skills

PEN-300 takes OSCPs and experienced offensive security professionals to the next level. Learn how to launch attacks against mature organizations with an established security function. Develop your skills against hardened systems in real-time.

Advanced Evasion Techniques and Breaching Defenses Syllabus

  • Operating System and Programming Theory

    This comprehensive module provides a deep understanding of the inner workings of operating systems and fundamental programming concepts. You’ll study memory management, process scheduling, file systems, and other essential OS components, gaining a solid foundation for understanding and exploiting vulnerabilities.

  • Client-Side Code Execution with Office

    This module focuses on leveraging known vulnerabilities in Microsoft Office applications (Word, Excel, PowerPoint) to craft malicious documents that trigger code execution on a victim’s machine, gaining unauthorized access and control.

  • Client-Side Code Execution with Jscript

    Learn how to exploit Jscript, a scripting language used in Windows environments, for code execution attacks, gaining unauthorized access and control on a victim’s machine.

  • Process Injection and Migration

    In this module, you’ll master the art of stealth and persistence by injecting your malicious code into legitimate running processes. You’ll also learn how to migrate between processes to evade detection and maintain control even if one process is terminated.

  • Introduction to Antivirus Evasion

    This module introduces basic techniques to bypass or evade antivirus software, such as obfuscation and packing, allowing you to create malware that goes undetected.

  • Advanced Antivirus Evasion

    Learn more sophisticated methods like signature-based and heuristic-based evasion, enabling you to create malware that goes undetected by even the most sophisticated antivirus solutions.

  • Application Whitelisting

    Learn how to circumvent application whitelisting, a security measure that restricts the execution of unauthorized software.

  • Bypassing Network Filters

    Discover various advanced techniques to bypass network filters and firewalls, gaining access to restricted resources and networks.

  • Linux Post-Exploitation

    This module covers a wide range of techniques for maintaining access and escalating privileges on compromised Linux systems. You’ll learn how to navigate file systems, manipulate user accounts, extract sensitive information, and establish persistent backdoors for future access.

  • Windows Post-Exploitation

    Learn various advanced techniques for maintaining access and escalating privileges on compromised Windows systems, including navigating file systems, manipulating user accounts, extracting sensitive information, and establishing persistent backdoors.

Start learning with OffSec

Most
popular

Course + Cert
Exam Bundle

$1,749/once

The bundle includes 90 days of access to a single course, the associated labs and a single exam attempt.

Buy now
Best
value

Learn
One

$2,749/year*

One year of lab access alongside a single course plus two exam attempts.

Buy now
All
access

Learn
Unlimited

$6,099/year*

Unlimited OffSec Learning Library access plus unlimited exam attempts for one year.

Contact us
Large
teams

Learn
Enterprise

Get a quote

Flexible terms and volume discounts available.

Book a meeting
*Subscription auto-renews unless canceled.

What our community is saying

Luca Demers

Luca Demers

Offensive Security Engineer

The long hours, the challenges, and the relentless pursuit of excellence have sharpened my skills and expanded my ability to innovate and solve problems.

Nullg0re

Nullg0re

Penetration Tester

...I can take the skills taught in this course and immediately apply it to my day job....This course does a very impressive and consistent job of starting with theory and then diving into practical application of that theory.

Randy Becker

Randy Becker

CISSP | OSCP | OSEP

This course not only provided me with valuable knowledge but also encouraged me to explore more advanced techniques that can be applied to my job on a day-to-day basis...

Read more

PEN-300 FAQ

Upcoming PEN-300 Live Training

Sep 22 - Sep 26, 2025

Location: Virtual

Languages: English

Hosted by:

OffSec + TSTC
Register now
See all live training events

OffSec Penetration Testing Courses & Certifications