Skip to content
Exploit Labs
OffSec Official Learning & Channel Partner - DACH · MENA · GCC

Pass OSCP, OSEP & OSWE - with 1:1 mentoring and EUR invoicing from a German entity.

Official OffSec licences, live bootcamps and Learn Enterprise rollouts - supported by active pentesters rather than career trainers. For individual learners and entire security teams.

  • OffSec Official Partner
  • EUR invoicing · DE bank account
  • 1:1 mentoring in your language
  • TIBER-EU & DORA-aligned vendor DD
OSCPOSEPOSWEOSWAOSDAOSIROSTHOSEDOSWPOSCC-SECOSCC-SJDOSAI
For individual learners

Certify what you already know - or build a new specialisation.

From entry-level to senior consultant: we guide you through OSCP, OSEP, OSWE, OSDA and the rest of the OffSec catalog - with 1:1 mentoring, exam prep, and access to real attack scenarios from our live engagements.

  • OSCP bootcamps led by active pentesters.
  • EUR invoicing via German bank account - no credit card required.
  • 1:1 mentoring and exam prep.
  • Career paths: pentester, red teamer, SOC analyst, threat hunter.
For enterprise teams

Audit-ready skill evidence for your security team - at OffSec standard.

Learn Enterprise is the platform solution for whole teams: reassignable licences, progress reporting, LMS integration and onboarding paths that make new hires productive in weeks rather than months. We deliver the full OffSec catalog plus DACH-localised support, TIBER-/DORA-aligned vendor processes, and trainers who actually pentest between courses.

  • Reassignable licences when staff move on.
  • Progress and certification reporting for audit evidence.
  • LMS integration and structured onboarding paths.
  • Cyber ranges: live attack scenarios instead of slide decks.
  • Vendor onboarding aligned with ISO 27001, BSI IT-Grundschutz, TIBER-EU and DORA.
Why Exploit Labs - instead of OffSec direct

Original OffSec curriculum. Local support, EUR billing, regulatory clarity.

Local expertise, in your language

Original OffSec courses combined with local-language support and 1:1 mentoring - so your team applies what they learn.

Regulatory safety

Based in Germany. Meets ISO 27001, BSI IT-Grundschutz, TIBER-EU and DORA requirements. Vendor due diligence and third-party risk assessments without friction.

Billing in EUR

Payment via German bank account in Euro. No cross-border transactions, no FX risk, no credit-card requirement.

Exclusive extras

Beyond standard OffSec bootcamps: extra trainings, 1:1 mentoring, and access to attack scenarios from our live engagements.

Trainers with a dual role

Our trainers are active red team consultants and pentesters - with real project experience from banks, insurers and critical infrastructure.

Strategic partner

From first enquiry to sustained capability - including career guidance, exam prep, and follow-on engagements.

The full OffSec catalog

From foundational level to senior exploit development.

Filter by discipline or level. Every course page shows prerequisites, exam, learning path and which packages include the course.

SEC-100OSCC-SEC

CyberCore - Cybersecurity Essentials

Build · Foundational

SEC-100 is OffSec's entry course and covers attack, defend and build in one: 40 modules and roughly 138 hours of content on network and system fundamentals, scripting, cloud, secure coding and defensive analysis. The exam has an Attack, a Defend and a Build section.

See the course page
PEN-103KLCP

Kali Linux Revealed

Build · Foundational

PEN-103 (Kali Linux Revealed) covers the distribution itself: installation, configuration, Debian package management, custom images and running Kali cleanly in test environments - around 181 hours of content. It is free with every OffSec account and leads to the KLCP certification.

See the course page
PEN-200OSCP

Penetration Testing with Kali Linux

Attack · Intermediate

PEN-200 is OffSec's foundational course leading to the OSCP certification: enumeration, web and service exploitation, privilege escalation on Linux and Windows and Active Directory fundamentals, ending in a 24-hour practical exam.

See the course page
PEN-210OSWP

Foundational Wireless Network Attacks

Attack · Foundational

PEN-210 covers attacks against wireless networks: reconnaissance, authentication mechanisms, WPA variants, enterprise WLAN with RADIUS, and the usual misconfigurations. It leads to the OSWP certification.

See the course page
WEB-200OSWA

Foundational Web Application Assessments

Attack · Intermediate

WEB-200 is OffSec's black-box web course leading to OSWA: injection classes, authentication and session flaws, access control, SSRF, deserialisation and chaining multiple weaknesses.

See the course page
SOC-200OSDA

Foundational Security Operations and Defensive Analysis

Defend · Intermediate

SOC-200 (OSDA) shows attacks from the defender's seat: what traces common techniques leave, how they surface in SIEM data, and how to separate real attacks from noise.

See the course page
IR-200OSIR

Foundational Incident Response

Defend · Intermediate

IR-200 (OSIR) covers the incident response lifecycle: preparation, detection, containment, evidence preservation, recovery and lessons learned - including communications and case management.

See the course page
TH-200OSTH

Foundational Threat Hunting

Defend · Intermediate

TH-200 (OSTH) covers threat hunting: forming hypotheses, data sources and coverage, hunting attacker behaviour rather than signatures, and turning findings into durable detections.

See the course page
SJD-100OSCC-SJD

Secure Java Development Essentials

Build · Foundational

SJD-100 covers secure Java development from a developer's perspective: ten modules and roughly 41 hours on input validation, output encoding, cookie and session security, logging and error handling, misconfiguration and secure database access, each with hands-on labs. Not an attack course.

See the course page
PEN-300OSEP

Advanced Evasion Techniques and Breaching Defenses

Attack · Advanced

PEN-300 (OSEP) is the advanced evasion and breaching course: antivirus and EDR evasion, application whitelisting, advanced Active Directory attacks and lateral movement in monitored networks.

See the course page
WEB-300OSWE

Advanced Web Attacks and Exploitation

Attack · Advanced

WEB-300 is the whitebox advanced course (OSWE): source review with an attacker mindset, authentication bypasses, and building your own exploit chains up to remote code execution in real applications.

See the course page
EXP-301OSED

Windows User Mode Exploit Development

Attack · Advanced

EXP-301 (OSED) covers Windows exploit development: assembly, debugging with WinDbg, reverse engineering, stack overflows, SEH, ROP and bypassing modern protections such as DEP and ASLR.

See the course page
EXP-401OSEE

Advanced Windows Exploitation

Attack · Expert

EXP-401 (OSEE) is the most demanding course in the OffSec catalogue: exploiting modern Windows targets, complex memory corruption, browser and kernel surfaces, and bypassing current mitigations.

See the course page
AI-300OSAI

Offensive Security for AI Systems

Attack · Advanced

AI-300 (OSAI) covers attacks against AI systems: prompt injection, manipulating agents and tool calls, attacks on data pipelines and model supply chain, and hardening LLM applications.

See the course page
Plans & pricing

From CyberCore to Learn Enterprise.

Course + Cert Bundle and Learn One are single-course packages: at checkout you pick one course from the OffSec catalog (OSCP, OSEP, OSWE, OSDA …). Learn Enterprise gives your team access to the entire catalog - see the table below for the exact differences.

Already know what you need? Head straight to checkout. Still weighing options? Get in touch - we'll help you pick. Prices in EUR, net, plus statutory VAT.

→ Only after OSCP? See the OSCP certification overview
FeatureCyberCore™Course + Cert BundleLearn OneLearn Enterprise
Lab access (days)36590365365
Exam attempts212 + 1× KLCP + 1× OSWP6 per seat/year · KLCP/OSWP unlimited
100-level courses
200- & 300-level courses
Fundamentals learning paths
Proving Grounds Play
Proving Grounds Practice
PEN-103 access
PEN-210 accessoptional
Reassignable licence5+ seats
Price (net, +VAT)€800€1,545€2,425€5,500+
CyberCore™
€800 + VAT

One-time · EUR invoice · VAT calculated at checkout.

Course + Cert Bundle
€1,545 + VAT

One-time · EUR invoice · VAT calculated at checkout.

Learn One
€2,425 + VAT

One-time · EUR invoice · VAT calculated at checkout.

Learn Enterprise
€5,500 / seat / year · + VAT
Subtotal: 27,500
Exploit Bootcamps

Game of Active Directory - 2-day Windows AD hacking with Kali Linux.

Our own bootcamps - on-site in Reykjavík and Dubai or fully remote in German. Hands-on attack paths: enumeration, Kerberos attacks, lateral movement, domain dominance. Prices per format below (net, plus VAT).

What is Game of Active Directory (GOAD v3)?

GOAD is Orange Cyberdefense's open-source Active Directory lab - now the de-facto standard for practising real-world Windows AD attack techniques. Version 3 uses Ansible to spin up a full multi-forest with two domains (sevenkingdoms.local and north.sevenkingdoms.local) plus a trust-linked essos.local - five Windows servers, an IIS web host and an MSSQL host, intentionally misconfigured.

In the bootcamp you work the full chain: unauthenticated recon and AS-REP roasting, LLMNR/NBT-NS poisoning with Responder, SMB relay against unhardened hosts, Kerberoasting and silver/golden tickets, ACL abuse (GenericAll, WriteDACL) via BloodHound, delegation attacks (unconstrained, constrained, RBCD), coercion via PetitPotam, MSSQL linked-server abuse, ADCS abuse (ESC1/ESC8), and cross-domain / cross-forest movement using SID history and trust tickets - all the way to enterprise admin.

All you need is a laptop with Kali Linux (VM or native). Everything else - toolchain, cheat-sheets, attack paths - is provided.

Exploit Online (DE)
€129 + VAT

Game of Active Directory · 2 days

  • Online · German
  • 1-2 Dec 2026 · Remote
Or request invoice / group booking
Join the waiting list
Exploit Iceland - live bootcamp logoExploit Iceland
€999 + VAT

Game of Active Directory · 2 days

  • Reykjavík
  • 15-16 Oct 2026 · Venue: TBA
Or request invoice / group booking
Join the waiting list
Exploit Dubai - live bootcamp logoExploit Dubai
€999 + VAT

Game of Active Directory · 2 days

  • Dubai
  • 5-6 Nov 2026 · Venue: TBA
Or request invoice / group booking
Join the waiting list
New · Online (DE)
Game of Active Directory - the €129 hands-on workshop

Detail page with curriculum, audience, hard facts and single/company booking.

Open the GOAD page
Dragon Drop · Monthly mini-training
A live glimpse of Learn Enterprise - free, hands-on.

New OffSec content, curated and practised. Currently hibernating for summer - back end of September. Stay tuned.

Open Dragon Drop
Red Blue Alliance · Partner Trainings

OffSec live trainings with our partner Red Blue Alliance.

We co-deliver selected OffSec courses with Red Blue Alliance. Registration and pricing directly at redbluealliance.com.

PEN-200 · OSCP+

Penetration Testing with Kali Linux

  • 31 Aug - 04 Sep 2026 · Frankfurt · 5-day intensive · Guaranteed
  • 27 Oct - 19 Nov 2026 · Online · 4 Tuesdays 9-17 CET · from 5 attendees
Dates & pricing on Red Blue Alliance
AI-300 · OSAI+ (Neu)

Advanced AI Red Teaming

  • Coming soon · 8×4 h online (14-18 CET) · Waiting list
Dates & pricing on Red Blue Alliance
The difference

A decade of live-earned exploits

Supplementary material from ten years of live operations - techniques you won't find in a slide deck.

Trainers who run live engagements

Not full-time trainers - practitioners who actually pentest and run red team engagements between courses.

Training updates

New OffSec courses, bootcamp dates and license discounts - straight to your inbox.

We only write when there's something worth reading: new Learn Enterprise content, open Iceland and Dubai bootcamps, OSCP/OSEP/OSWE promos. No marketing filler.

Subscribe to OffSec updates

1-2 emails a month, opt out any time.