PEN-300: Advanced Evasion Techniques and Breaching Defenses
Building on the skills acquired in PEN-200, OffSec’s PEN-300 course explores advanced penetration testing techniques against hardened targets. Learners gain hands-on experience bypassing security defenses and crafting custom exploits in real-world scenarios, enhancing their expertise in ethical hacking and vulnerability assessment.
This self-paced course culminates in a challenging exam, leading to the OffSec Experienced Penetration Tester (OSEP) certification. Achieving the OSEP certification distinguishes professionals with advanced penetration testing skills, making them highly sought-after experts in securing organizations from sophisticated threats.
Starting at $1,749
Advance your penetration testing skills
Advanced Evasion Techniques and Breaching Defenses Syllabus
-
Operating System and Programming Theory
This comprehensive module provides a deep understanding of the inner workings of operating systems and fundamental programming concepts. You’ll study memory management, process scheduling, file systems, and other essential OS components, gaining a solid foundation for understanding and exploiting vulnerabilities.
-
Client-Side Code Execution with Office
This module focuses on leveraging known vulnerabilities in Microsoft Office applications (Word, Excel, PowerPoint) to craft malicious documents that trigger code execution on a victim’s machine, gaining unauthorized access and control.
-
Client-Side Code Execution with Jscript
Learn how to exploit Jscript, a scripting language used in Windows environments, for code execution attacks, gaining unauthorized access and control on a victim’s machine.
-
Process Injection and Migration
In this module, you’ll master the art of stealth and persistence by injecting your malicious code into legitimate running processes. You’ll also learn how to migrate between processes to evade detection and maintain control even if one process is terminated.
-
Introduction to Antivirus Evasion
This module introduces basic techniques to bypass or evade antivirus software, such as obfuscation and packing, allowing you to create malware that goes undetected.
-
Advanced Antivirus Evasion
Learn more sophisticated methods like signature-based and heuristic-based evasion, enabling you to create malware that goes undetected by even the most sophisticated antivirus solutions.
-
Application Whitelisting
Learn how to circumvent application whitelisting, a security measure that restricts the execution of unauthorized software.
-
Bypassing Network Filters
Discover various advanced techniques to bypass network filters and firewalls, gaining access to restricted resources and networks.
-
Linux Post-Exploitation
This module covers a wide range of techniques for maintaining access and escalating privileges on compromised Linux systems. You’ll learn how to navigate file systems, manipulate user accounts, extract sensitive information, and establish persistent backdoors for future access.
-
Windows Post-Exploitation
Learn various advanced techniques for maintaining access and escalating privileges on compromised Windows systems, including navigating file systems, manipulating user accounts, extracting sensitive information, and establishing persistent backdoors.
Start learning with OffSec
popular
Course + Cert
Exam Bundle
$1,749/once
The bundle includes 90 days of access to a single course, the associated labs and a single exam attempt.
value
access
Learn
Unlimited
$6,099/year*
Unlimited OffSec Learning Library access plus unlimited exam attempts for one year.
teams
Learn
Enterprise
Get a quote
Flexible terms and volume discounts available.
What our community is saying
Luca Demers
Offensive Security Engineer
The long hours, the challenges, and the relentless pursuit of excellence have sharpened my skills and expanded my ability to innovate and solve problems.
Nullg0re
Penetration Tester
...I can take the skills taught in this course and immediately apply it to my day job....This course does a very impressive and consistent job of starting with theory and then diving into practical application of that theory.
Randy Becker
CISSP | OSCP | OSEP
This course not only provided me with valuable knowledge but also encouraged me to explore more advanced techniques that can be applied to my job on a day-to-day basis...
PEN-300 FAQ
Upcoming PEN-300 Live Training
Sep 22 - Sep 26, 2025