Click Study Flashcards above to open the flashcard hub — over a hundred OSCP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the OffSec PEN-200 methodology, so you study exactly what the hands-on penetration-testing exam tests.[1] Pair them with our free practice questions and study guide — and with real lab machines.
OSCP Flashcard Study Modes
Flip mode lets you study each card front and back at your own pace, Match turns term-to-definition pairing into a timed game, Type shows the definition and asks you to spell the term back — DCSync, for example — and Quiz builds multiple-choice questions from the same 128 cards. Rotate through all four so recognition turns into recall.

Why Flashcards Work for the OSCP
Active Directory & Pivoting is the largest section at 42 cards, and it drills the vocabulary you need once a foothold turns into a domain problem. You get structural terms like Domain and Forest alongside the tooling and technique names that show up in lateral movement, including WMI, PsExec, and Mimikatz. Credential-material cards such as NTDS.dit and DCSync sit next to tunneling entries like Chisel, so pivoting language and directory language get reinforced together.
Shells & Privilege Escalation carries 32 cards covering what happens between initial code execution and root or SYSTEM. Payload and listener terms such as msfvenom and socat are here, as are the enumeration helpers linPEAS and winPEAS that feed escalation decisions. Cards like sudo -l and bash -p drill specific Linux misconfiguration checks, while Hydra and Hashcat keep the online and offline credential-attack distinction sharp in your head.
Enumeration & Exploit Research holds 27 cards on the scanning and discovery language that starts every box. Nmap anchors the section, and the flag cards force precision: -Pn, -sV, -sC, and -sU each mean something different under time pressure. Content discovery gets its own vocabulary through ffuf and gobuster, with Wordlist tying the brute-force side of enumeration back to the tooling you point at a target.
Web Application Attacks also has 27 cards, covering the input-handling flaws that often supply the first shell. Injection and interception terms include sqlmap and Burp Suite, while Reflected XSS and Stored XSS force you to separate two outcomes that share a name. File-handling and payload-delivery cards such as php://filter, Log poisoning, Web shell, and Malicious macro round out the routes from a browser request to command execution.
The OSCP exam is hands-on, so the cards play a specific role: they make the tools, flags, and techniques automatic so you spend exam time exploiting rather than recalling syntax.[2] Used alongside our practice questions, our study guide, and real lab practice, they turn review time into measurable progress.
OSCP Flashcards by Domain
The cards are organized by the OffSec PEN-200 methodology. Drill them in the order a penetration test flows — enumerate, exploit, escalate, then attack Active Directory and pivot:[1]
| Domain | What it covers |
|---|---|
| Enumeration & Exploit Research | Nmap flags, SMB/web/FTP enumeration, searchsploit, vulnerability scanning |
| Web Application Attacks | SQL injection, XSS, command injection, LFI/traversal, file upload |
| Shells & Privilege Escalation | Reverse/bind shells, msfvenom, Linux SUID/sudo/cron, Windows tokens/services |
| Active Directory & Pivoting | Kerberoasting, AS-REP roasting, Pass-the-Hash, tickets, SSH tunnels, proxychains, Chisel |
How to Get the Most Out of These Flashcards
- Start with Active Directory & Pivoting. At 42 cards it is the biggest block in the deck, and domain vocabulary is the part most people fumble when a foothold suddenly becomes a directory problem.
- Type-drill the exact strings. Cards like sudo -l and -sV punish approximate memory, so typing them forces the precision you need when syntax matters more than the general idea.
- Use Match for tool names. Pairing entries such as linPEAS, winPEAS, ffuf, and gobuster against their descriptions quickly exposes which tools you only half-recognize from reading walkthroughs.
- Switch to the practice test once Quiz gets easy. When multiple choice across all four domains stops surprising you, move to timed questions and use the study guide to repair whatever breaks.
- Keep the cadence small and repeated. Work one domain per session, finish with a mixed Quiz over all 128 cards, and revisit missed terms the next day rather than cramming a full pass.
OSCP Flashcards FAQ
Over a hundred free OSCP flashcards, organized across the OffSec PEN-200 methodology — Enumeration & Exploit Research, Web Application Attacks, Shells & Privilege Escalation, and Active Directory & Pivoting. They're free with no account required.
Yes, as a complement to hands-on practice. The OSCP exam is a 24-hour practical, so the real skill is doing the work in a lab — but flashcards use active recall to make the underlying tools, flags, and techniques automatic, so you spend exam time exploiting rather than recalling syntax. Pair the cards with real lab machines (PEN-200, Proving Grounds, or similar).
The whole penetration-testing methodology: enumeration (Nmap flags, SMB/web/FTP enumeration, searchsploit), web application attacks (SQL injection, XSS, command injection, LFI, file upload), shells and privilege escalation (reverse/bind shells, msfvenom, SUID/sudo/cron on Linux, tokens/services on Windows), and Active Directory and pivoting (Kerberoasting, AS-REP roasting, Pass-the-Hash, golden/silver tickets, SSH tunnels, proxychains, Chisel).
Lead with enumeration — it's the highest-leverage OSCP skill — then drill the attack chain in order. Mix the modes: flip to learn, type to test recall of exact tools and flags, match for speed, and quiz to check yourself. Crucially, use the cards alongside real lab practice; recognizing a technique on a card is not the same as executing it under the clock.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current OffSec PEN-200 methodology and reflect current standards — Active Directory attacks (Kerberoasting, AS-REP roasting, ticket attacks), modern Windows privilege escalation (Potato attacks), and pivoting with proxychains and Chisel.
OSCP flashcard bank
All 128 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Enumeration & Exploit Research (27)
- Enumeration
Show answerHide answer
The systematic discovery of hosts, ports, services, versions, and configurations — the most important OSCP skill; when stuck, enumerate more.
- Nmap
Show answerHide answer
The primary port scanner: discovers live hosts, open ports, and service versions that drive exploit research.
- Ping sweep (nmap -sn)
Show answerHide answer
Host discovery only — lists which hosts are alive across a range without scanning any ports.
- -Pn
Show answerHide answer
Nmap option that skips host discovery and scans a host even if it does not respond to ICMP (treats it as up).
- -p- (full port scan)
Show answerHide answer
Scans all 65,535 TCP ports — slow but catches a foothold service hidden on an uncommon high port.
- -sV
Show answerHide answer
Nmap service/version detection — reports each service's product name and version, the input for exploit research.
- -sC
Show answerHide answer
Runs Nmap's default category of NSE scripts during a scan to gather extra information and catch common issues.
- -sU
Show answerHide answer
Nmap UDP scan — reveals UDP services such as DNS and SNMP that a TCP scan will never show.
- Closed port
Show answerHide answer
An Nmap state meaning the port is reachable but no service is listening on it — it actively refuses connections.
- NSE (Nmap Scripting Engine)
Show answerHide answer
Nmap's scripting framework; run script categories like 'vuln' or 'smb-enum-shares' for deeper enumeration.
- Banner grabbing
Show answerHide answer
Reading a service's identifying banner (e.g. via Netcat) to learn its software and version for exploit research.
- gobuster
Show answerHide answer
A directory and file brute-forcer for web servers; in dir mode it appends extensions to each wordlist entry.
- ffuf
Show answerHide answer
A fast web fuzzer; filter results by status code, size, or words to discard noise like soft-404 responses.
- robots.txt
Show answerHide answer
A file that may reveal hidden or sensitive paths the site owner did not want indexed — useful for enumeration.
- enum4linux
Show answerHide answer
A wrapper tool that enumerates Windows/Samba hosts over SMB — domain, users, groups, shares, and policy.
- SMB null session
Show answerHide answer
An anonymous SMB connection with empty credentials that can reveal users, groups, and shares.
- smbclient
Show answerHide answer
A command-line SMB client to list and access shares; writable shares may allow uploading a payload.
- Anonymous FTP
Show answerHide answer
An FTP service allowing login with the 'anonymous' user; first step is to log in and list directories for readable files.
- Virtual host (vhost) enumeration
Show answerHide answer
Discovering name-based virtual hosts by varying the Host header; a wordlist may reveal internal-only sites on one IP.
- searchsploit
Show answerHide answer
A command-line search of the offline Exploit-DB archive bundled with Kali — works without internet.
- Exploit-DB
Show answerHide answer
A public archive of exploits and proof-of-concept code; match the exact product and version, then read and adapt the code.
- Proof-of-concept (PoC)
Show answerHide answer
Public exploit code that usually needs adapting — set the attacker IP/port, fix offsets, and replace shellcode before use.
- Vulnerability scanner
Show answerHide answer
A tool (e.g. Nessus, OpenVAS) that enumerates known weaknesses; authenticated scans (valid credentials) are most accurate.
- False positive
Show answerHide answer
A scanner finding that is not actually exploitable; always manually verify before relying on a reported vulnerability.
- Wordlist
Show answerHide answer
A list of candidate names/passwords (e.g. SecLists, rockyou.txt) chosen to fit the target's technology and language.
- Service principal name (SPN)
Show answerHide answer
An identifier that maps a service instance to a domain account; SPN-enabled accounts are the targets of Kerberoasting.
- DNS enumeration
Show answerHide answer
Collecting hostnames from DNS and certificates that point to a box, revealing additional virtual hosts and services.
Web Application Attacks (27)
- SQL injection (SQLi)
Show answerHide answer
Untrusted input alters a SQL query; can extract data, bypass authentication, or reach code execution.
- UNION-based SQLi
Show answerHide answer
Appends a UNION SELECT to exfiltrate data; first determine the column count with ORDER BY n.
- Blind / time-based SQLi
Show answerHide answer
No data is returned, so inject a payload that pauses (e.g. SLEEP) and infer values from the response delay.
- Error-based SQLi
Show answerHide answer
Forces the database to leak data inside its error messages, which the application displays on the page.
- Authentication bypass (SQLi)
Show answerHide answer
Submitting a value that closes the string and adds an always-true condition to log in without valid credentials.
- Second-order SQLi
Show answerHide answer
Input stored by one feature is later used unsafely in a query by a different, often more privileged feature.
- sqlmap
Show answerHide answer
Automates SQL injection: detect, then enumerate databases (--dbs), tables, and dump data; supports auth and request files.
- xp_cmdshell / FILE privilege
Show answerHide answer
MSSQL stored procedure (or MySQL FILE) that turns SQL injection into OS command execution or web-shell writing.
- Cross-site scripting (XSS)
Show answerHide answer
Injected script runs in a victim's browser — steal sessions and keystrokes or force state-changing requests.
- Reflected XSS
Show answerHide answer
A payload bounced straight back from a single request and executed in the victim's browser.
- Stored XSS
Show answerHide answer
A payload persisted by the app (e.g. a comment) that fires for every visitor — usually the most impactful XSS.
- Content Security Policy (CSP)
Show answerHide answer
A header restricting script sources; a strict CSP blocks inline payloads and must be bypassed for XSS.
- Session hijacking
Show answerHide answer
Stealing a victim's session cookie (often via XSS) to impersonate their authenticated session.
- Command injection
Show answerHide answer
User input reaches an OS shell; chain a separator (; | && ) and a command to execute arbitrary commands.
- Blind command injection
Show answerHide answer
No command output is returned, so confirm execution out of band — a time delay or a DNS/HTTP callback.
- Command substitution
Show answerHide answer
Using backticks or $(…) to run a command inside another; often slips past filters that strip other separators.
- Directory traversal
Show answerHide answer
Abusing ../ sequences to read files outside the web root, such as /etc/passwd or a Windows web.config.
- Local file inclusion (LFI)
Show answerHide answer
The app includes a referenced file in execution; can escalate to code execution via log poisoning or PHP wrappers.
- Log poisoning
Show answerHide answer
Injecting PHP into a log the application reads via LFI, then including the log to execute the injected code.
- php://filter
Show answerHide answer
A PHP wrapper that reads a file as a stream (often base64-encoded) to disclose source code safely via LFI.
- File upload bypass
Show answerHide answer
Defeating signature, extension allow-list, or MIME checks to upload an executable web shell the server runs.
- Web shell
Show answerHide answer
A script placed on a server that the server executes, giving remote command execution through the browser.
- Magic-byte (signature) check
Show answerHide answer
An upload filter validating leading file bytes; bypass by prepending a valid image signature to a script.
- Double-extension / case bypass
Show answerHide answer
Tricks like shell.php.jpg or shell.PHP that defeat naive or case-sensitive extension allow-lists on uploads.
- Client-side attack
Show answerHide answer
Delivering a payload a staff user opens — a malicious Office macro or a link using a custom URI handler.
- Malicious macro
Show answerHide answer
An embedded macro in an Office document that runs attacker code when the victim enables content.
- Burp Suite
Show answerHide answer
An intercepting web proxy used to view, modify, and replay HTTP requests during web application testing.
Shells & Privilege Escalation (32)
- Reverse shell
Show answerHide answer
The target connects back to a listener on the attacker — preferred when the target blocks inbound connections (NAT/firewall).
- Bind shell
Show answerHide answer
A listener opened on the target that the attacker connects to; exposed to anyone who scans the port.
- Netcat (nc)
Show answerHide answer
A networking utility used as a listener for reverse shells or to grab banners; a plain listener offers no encryption.
- socat
Show answerHide answer
A flexible relay tool used to create encrypted, more stable reverse shells than a plain netcat listener.
- TTY upgrade
Show answerHide answer
Turning a dumb shell into an interactive terminal — python3 pty.spawn /bin/bash, then stty raw -echo and export TERM/PATH.
- msfvenom
Show answerHide answer
Metasploit's standalone payload generator — builds EXE, raw shellcode, or web payloads with LHOST/LPORT set.
- Bad characters
Show answerHide answer
Bytes that break an exploit or are filtered by the target; specify them (msfvenom -b) so shellcode survives the parser.
- Privilege escalation
Show answerHide answer
Moving from a low-privileged user/service account to root or SYSTEM — the second 10 points on each OSCP machine.
- SUID binary
Show answerHide answer
A file that runs with its owner's privileges; a SUID-root program that spawns a shell is a path to root.
- bash -p
Show answerHide answer
Runs bash without dropping elevated privileges; the invocation that turns a SUID-root bash copy into a root shell.
- sudo -l
Show answerHide answer
Lists the commands the current user may run via sudo; many such binaries have a documented root-shell escape.
- GTFOBins
Show answerHide answer
A reference of Unix binaries that can be abused (via SUID, sudo, or capabilities) to escape restrictions and escalate.
- Linux capabilities (getcap)
Show answerHide answer
Fine-grained root powers on a binary; cap_setuid on an interpreter like python allows escalating to root.
- Cron job abuse
Show answerHide answer
A root-run scheduled job that is writable, uses a wildcard (tar *), or calls a command without a full path — exploit for root.
- Kernel exploit
Show answerHide answer
A local-root exploit against the running kernel version; a last resort — match the exact version and prefer a misconfiguration.
- SeImpersonatePrivilege
Show answerHide answer
A Windows privilege (common on service accounts) abused by 'Potato' attacks to impersonate a SYSTEM token.
- Potato attacks
Show answerHide answer
PrintSpoofer, RoguePotato, GodPotato and similar tools that escalate a SeImpersonate-holding service account to SYSTEM.
- SeBackupPrivilege
Show answerHide answer
A Windows privilege that lets the holder read protected files such as the SAM and SYSTEM registry hives.
- Unquoted service path
Show answerHide answer
A service path with spaces and no quotes; writing a binary to an earlier directory lets it run at the service's privilege.
- Writable service binary
Show answerHide answer
A service whose executable the current user can overwrite; replace it to run code as the service account on restart.
- DLL hijacking
Show answerHide answer
Placing a malicious DLL where an elevated app loads it; use Process Monitor to find a missing or writable DLL path.
- AlwaysInstallElevated
Show answerHide answer
A Windows policy that runs MSI installers as SYSTEM; if set, a malicious MSI yields SYSTEM privileges.
- Stored credentials (Windows)
Show answerHide answer
Passwords left in autologon registry values, Unattend.xml, or config files — recoverable for escalation or reuse.
- whoami /priv
Show answerHide answer
Lists the current Windows token's privileges; checking for SeImpersonate/SeBackup is a standard early escalation step.
- linPEAS
Show answerHide answer
An automated Linux enumeration script that highlights privilege-escalation findings by likelihood.
- winPEAS
Show answerHide answer
The Windows counterpart to linPEAS; may be quarantined by antivirus, so an obfuscated/in-memory run helps evade it.
- Hashcat
Show answerHide answer
A GPU password cracker; select the correct mode per hash type (e.g. 13100 Kerberoast, 18200 AS-REP) and use rules.
- John the Ripper
Show answerHide answer
A password cracker offering dictionary and incremental (brute-force) modes for cracking recovered hashes.
- Hydra
Show answerHide answer
An online brute-force tool against network services; lockout policies may force throttling or a different approach.
- Password spraying
Show answerHide answer
Trying one weak password against many accounts to avoid lockouts — effective early against a domain with no credentials.
- File transfer (target)
Show answerHide answer
Moving tools onto a foothold without outbound internet — a Python/SimpleHTTPServer, SMB share, or certutil download.
- docker group
Show answerHide answer
Membership lets a user mount the host filesystem in a container as root — a direct Linux privilege-escalation path.
Active Directory & Pivoting (42)
- Active Directory (AD)
Show answerHide answer
Microsoft's directory service grouping computers and users into domains that share a database and security policy.
- Domain
Show answerHide answer
The logical boundary in AD that groups users and computers to share a directory database and authentication.
- Forest
Show answerHide answer
One or more AD domains combined into a larger structure that shares a common schema and configuration.
- Domain controller (DC)
Show answerHide answer
The server that hosts the AD database and authenticates the domain — the highest-value target in the AD set.
- Member server
Show answerHide answer
A domain-joined server that is not a domain controller; a lateral-movement stepping stone toward the DC.
- LDAP (port 389)
Show answerHide answer
The directory query protocol used to enumerate and interact with Active Directory objects.
- Kerberos
Show answerHide answer
AD's default authentication protocol using tickets (TGT and TGS) issued by the DC's Key Distribution Center.
- TGT (ticket-granting ticket)
Show answerHide answer
Issued after initial authentication; presented to obtain service tickets. Signed by the krbtgt key.
- TGS (service ticket)
Show answerHide answer
A ticket for a specific service, encrypted with that service account's key — the material Kerberoasting cracks.
- BloodHound
Show answerHide answer
A tool that graphs AD attack paths from a controlled account to high-value targets like Domain Admins.
- PowerView
Show answerHide answer
A PowerShell AD enumeration toolkit; functions reveal sessions, SPNs, group memberships, and rights.
- Kerberoasting
Show answerHide answer
Request TGS tickets for SPN-enabled accounts and crack them offline; needs only one valid domain credential.
- AS-REP Roasting
Show answerHide answer
Capture and crack the AS-REP of accounts with pre-authentication disabled; needs no credential, only usernames.
- Kerberos pre-authentication
Show answerHide answer
A control that, when disabled on an account, exposes it to AS-REP Roasting.
- NTLM hash
Show answerHide answer
A one-way representation of an account password used for NTLM authentication and reused in Pass-the-Hash.
- Pass-the-Hash (PtH)
Show answerHide answer
Authenticate with a captured NT hash without cracking it; defeats strong passwords, blunted by unique local passwords (LAPS).
- Pass-the-Ticket (PtT)
Show answerHide answer
Inject a stolen Kerberos TGT or TGS to impersonate a user; tickets expire, so they must be reasonably fresh.
- Golden ticket
Show answerHide answer
A forged TGT made from the krbtgt hash and domain SID — any user, any groups, domain-wide; reset krbtgt twice to kill it.
- Silver ticket
Show answerHide answer
A forged TGS made from one service account's hash — narrower scope and stealthier (no DC contact) than a golden ticket.
- krbtgt account
Show answerHide answer
The account whose key signs all Kerberos tickets; capturing its hash enables forging golden tickets.
- Mimikatz
Show answerHide answer
A tool that dumps credentials and Kerberos tickets from memory; needs elevated privileges to access LSASS.
- DCSync
Show answerHide answer
Abuses the replication protocol to request domain account hashes from a DC without touching NTDS.dit on disk.
- NTDS.dit
Show answerHide answer
The Active Directory database file on a domain controller; extracting it yields all domain password hashes.
- NTLM relay
Show answerHide answer
Forwarding captured authentication to another service (e.g. LDAP/SMB) to authenticate as the victim without the hash.
- SMB signing
Show answerHide answer
A control that defeats NTLM relay to SMB targets by ensuring messages are signed and cannot be forwarded.
- PsExec
Show answerHide answer
Remote command execution over SMB using a temporary service; a common but noisy lateral-movement method.
- WMI
Show answerHide answer
Windows Management Instrumentation — executes commands on a remote host with valid credentials or a hash.
- WinRM (5985/5986)
Show answerHide answer
Remote management providing an interactive PowerShell session; often preferred over PsExec for stealthier movement.
- Lateral movement
Show answerHide answer
Moving host-to-host using reused credentials (PtH, PtT, PsExec, WMI, WinRM) — the heart of the AD set's scoring.
- Credential reuse
Show answerHide answer
The same account or hash valid on many hosts; the engine that makes AD compromise fast once one credential is found.
- Pivot host
Show answerHide answer
A compromised, dual-homed host used to route traffic into a network the attacker cannot reach directly.
- SSH local forward (-L)
Show answerHide answer
Exposes one internal service on a local port of the attacker box through a Linux pivot you can SSH to.
- SSH remote forward (-R)
Show answerHide answer
Used when the pivot can reach the attacker but not vice versa; the pivot pushes an internal port out to you.
- SSH dynamic forward (-D)
Show answerHide answer
Opens a SOCKS proxy to route many tools at once into the internal network; pair with proxychains.
- Chisel
Show answerHide answer
A client-server SOCKS tunnel over HTTP for pivoting through a firewalled Windows host that lacks an SSH server.
- proxychains
Show answerHide answer
Forces a command-line tool's TCP connections through a SOCKS proxy; use TCP-connect scans, not ICMP/UDP.
- TCP connect scan (-sT)
Show answerHide answer
A full-handshake scan required through a SOCKS proxy, since half-open SYN, ping, and UDP do not traverse the tunnel.
- Dual-homed host
Show answerHide answer
A host with two interfaces on different subnets; ideal as a pivot to reach an otherwise unreachable network.
- Domain Admins
Show answerHide answer
The built-in group whose membership most directly equates to full control of the domain — the prime target.
- WriteDACL / GenericAll
Show answerHide answer
BloodHound ACL edges granting rights over an object that can be abused to take it over and escalate.
- Domain SID
Show answerHide answer
The domain's security identifier; combined with the krbtgt hash, it is needed to forge a golden ticket.
- AD set scoring
Show answerHide answer
The OSCP Active Directory chain is worth 40 points: 10 client + 10 second host + 20 domain controller.
References
- 1.OffSec (Offensive Security). “PEN-200: Penetration Testing with Kali Linux (OSCP).” offsec.com. ↑
- 2.MITRE. “MITRE ATT&CK — Enterprise Tactics and Techniques.” attack.mitre.org. ↑
- 3.OWASP. “OWASP Top Ten and Attack Reference.” owasp.org. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
