Career Employer

Your FREE OSCP Flashcards 2026 – 100+ Cards

Realistic, OSCP exam-style flashcards across the OffSec PEN-200 methodology — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer OSCP”

By

Click Study Flashcards above to open the flashcard hub — over a hundred OSCP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the OffSec PEN-200 methodology, so you study exactly what the hands-on penetration-testing exam tests.[1] Pair them with our free practice questions and study guide — and with real lab machines.

OSCP Flashcard Study Modes

Flip mode lets you study each card front and back at your own pace, Match turns term-to-definition pairing into a timed game, Type shows the definition and asks you to spell the term back — DCSync, for example — and Quiz builds multiple-choice questions from the same 128 cards. Rotate through all four so recognition turns into recall.

Free OSCP flashcards from Career Employer — active recall for the OffSec PEN-200 penetration-testing exam

Why Flashcards Work for the OSCP

Active Directory & Pivoting is the largest section at 42 cards, and it drills the vocabulary you need once a foothold turns into a domain problem. You get structural terms like Domain and Forest alongside the tooling and technique names that show up in lateral movement, including WMI, PsExec, and Mimikatz. Credential-material cards such as NTDS.dit and DCSync sit next to tunneling entries like Chisel, so pivoting language and directory language get reinforced together.

Shells & Privilege Escalation carries 32 cards covering what happens between initial code execution and root or SYSTEM. Payload and listener terms such as msfvenom and socat are here, as are the enumeration helpers linPEAS and winPEAS that feed escalation decisions. Cards like sudo -l and bash -p drill specific Linux misconfiguration checks, while Hydra and Hashcat keep the online and offline credential-attack distinction sharp in your head.

Enumeration & Exploit Research holds 27 cards on the scanning and discovery language that starts every box. Nmap anchors the section, and the flag cards force precision: -Pn, -sV, -sC, and -sU each mean something different under time pressure. Content discovery gets its own vocabulary through ffuf and gobuster, with Wordlist tying the brute-force side of enumeration back to the tooling you point at a target.

Web Application Attacks also has 27 cards, covering the input-handling flaws that often supply the first shell. Injection and interception terms include sqlmap and Burp Suite, while Reflected XSS and Stored XSS force you to separate two outcomes that share a name. File-handling and payload-delivery cards such as php://filter, Log poisoning, Web shell, and Malicious macro round out the routes from a browser request to command execution.

The OSCP exam is hands-on, so the cards play a specific role: they make the tools, flags, and techniques automatic so you spend exam time exploiting rather than recalling syntax.[2] Used alongside our practice questions, our study guide, and real lab practice, they turn review time into measurable progress.

OSCP Flashcards by Domain

The cards are organized by the OffSec PEN-200 methodology. Drill them in the order a penetration test flows — enumerate, exploit, escalate, then attack Active Directory and pivot:[1]

OSCP flashcards by methodology domain
DomainWhat it covers
Enumeration & Exploit ResearchNmap flags, SMB/web/FTP enumeration, searchsploit, vulnerability scanning
Web Application AttacksSQL injection, XSS, command injection, LFI/traversal, file upload
Shells & Privilege EscalationReverse/bind shells, msfvenom, Linux SUID/sudo/cron, Windows tokens/services
Active Directory & PivotingKerberoasting, AS-REP roasting, Pass-the-Hash, tickets, SSH tunnels, proxychains, Chisel

How to Get the Most Out of These Flashcards

  • Start with Active Directory & Pivoting. At 42 cards it is the biggest block in the deck, and domain vocabulary is the part most people fumble when a foothold suddenly becomes a directory problem.
  • Type-drill the exact strings. Cards like sudo -l and -sV punish approximate memory, so typing them forces the precision you need when syntax matters more than the general idea.
  • Use Match for tool names. Pairing entries such as linPEAS, winPEAS, ffuf, and gobuster against their descriptions quickly exposes which tools you only half-recognize from reading walkthroughs.
  • Switch to the practice test once Quiz gets easy. When multiple choice across all four domains stops surprising you, move to timed questions and use the study guide to repair whatever breaks.
  • Keep the cadence small and repeated. Work one domain per session, finish with a mixed Quiz over all 128 cards, and revisit missed terms the next day rather than cramming a full pass.

OSCP Flashcards FAQ

Over a hundred free OSCP flashcards, organized across the OffSec PEN-200 methodology — Enumeration & Exploit Research, Web Application Attacks, Shells & Privilege Escalation, and Active Directory & Pivoting. They're free with no account required.

OSCP flashcard bank

All 128 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Enumeration & Exploit Research (27)

Enumeration
Show answer

The systematic discovery of hosts, ports, services, versions, and configurations — the most important OSCP skill; when stuck, enumerate more.

Nmap
Show answer

The primary port scanner: discovers live hosts, open ports, and service versions that drive exploit research.

Ping sweep (nmap -sn)
Show answer

Host discovery only — lists which hosts are alive across a range without scanning any ports.

-Pn
Show answer

Nmap option that skips host discovery and scans a host even if it does not respond to ICMP (treats it as up).

-p- (full port scan)
Show answer

Scans all 65,535 TCP ports — slow but catches a foothold service hidden on an uncommon high port.

-sV
Show answer

Nmap service/version detection — reports each service's product name and version, the input for exploit research.

-sC
Show answer

Runs Nmap's default category of NSE scripts during a scan to gather extra information and catch common issues.

-sU
Show answer

Nmap UDP scan — reveals UDP services such as DNS and SNMP that a TCP scan will never show.

Closed port
Show answer

An Nmap state meaning the port is reachable but no service is listening on it — it actively refuses connections.

NSE (Nmap Scripting Engine)
Show answer

Nmap's scripting framework; run script categories like 'vuln' or 'smb-enum-shares' for deeper enumeration.

Banner grabbing
Show answer

Reading a service's identifying banner (e.g. via Netcat) to learn its software and version for exploit research.

gobuster
Show answer

A directory and file brute-forcer for web servers; in dir mode it appends extensions to each wordlist entry.

ffuf
Show answer

A fast web fuzzer; filter results by status code, size, or words to discard noise like soft-404 responses.

robots.txt
Show answer

A file that may reveal hidden or sensitive paths the site owner did not want indexed — useful for enumeration.

enum4linux
Show answer

A wrapper tool that enumerates Windows/Samba hosts over SMB — domain, users, groups, shares, and policy.

SMB null session
Show answer

An anonymous SMB connection with empty credentials that can reveal users, groups, and shares.

smbclient
Show answer

A command-line SMB client to list and access shares; writable shares may allow uploading a payload.

Anonymous FTP
Show answer

An FTP service allowing login with the 'anonymous' user; first step is to log in and list directories for readable files.

Virtual host (vhost) enumeration
Show answer

Discovering name-based virtual hosts by varying the Host header; a wordlist may reveal internal-only sites on one IP.

searchsploit
Show answer

A command-line search of the offline Exploit-DB archive bundled with Kali — works without internet.

Exploit-DB
Show answer

A public archive of exploits and proof-of-concept code; match the exact product and version, then read and adapt the code.

Proof-of-concept (PoC)
Show answer

Public exploit code that usually needs adapting — set the attacker IP/port, fix offsets, and replace shellcode before use.

Vulnerability scanner
Show answer

A tool (e.g. Nessus, OpenVAS) that enumerates known weaknesses; authenticated scans (valid credentials) are most accurate.

False positive
Show answer

A scanner finding that is not actually exploitable; always manually verify before relying on a reported vulnerability.

Wordlist
Show answer

A list of candidate names/passwords (e.g. SecLists, rockyou.txt) chosen to fit the target's technology and language.

Service principal name (SPN)
Show answer

An identifier that maps a service instance to a domain account; SPN-enabled accounts are the targets of Kerberoasting.

DNS enumeration
Show answer

Collecting hostnames from DNS and certificates that point to a box, revealing additional virtual hosts and services.

Web Application Attacks (27)

SQL injection (SQLi)
Show answer

Untrusted input alters a SQL query; can extract data, bypass authentication, or reach code execution.

UNION-based SQLi
Show answer

Appends a UNION SELECT to exfiltrate data; first determine the column count with ORDER BY n.

Blind / time-based SQLi
Show answer

No data is returned, so inject a payload that pauses (e.g. SLEEP) and infer values from the response delay.

Error-based SQLi
Show answer

Forces the database to leak data inside its error messages, which the application displays on the page.

Authentication bypass (SQLi)
Show answer

Submitting a value that closes the string and adds an always-true condition to log in without valid credentials.

Second-order SQLi
Show answer

Input stored by one feature is later used unsafely in a query by a different, often more privileged feature.

sqlmap
Show answer

Automates SQL injection: detect, then enumerate databases (--dbs), tables, and dump data; supports auth and request files.

xp_cmdshell / FILE privilege
Show answer

MSSQL stored procedure (or MySQL FILE) that turns SQL injection into OS command execution or web-shell writing.

Cross-site scripting (XSS)
Show answer

Injected script runs in a victim's browser — steal sessions and keystrokes or force state-changing requests.

Reflected XSS
Show answer

A payload bounced straight back from a single request and executed in the victim's browser.

Stored XSS
Show answer

A payload persisted by the app (e.g. a comment) that fires for every visitor — usually the most impactful XSS.

Content Security Policy (CSP)
Show answer

A header restricting script sources; a strict CSP blocks inline payloads and must be bypassed for XSS.

Session hijacking
Show answer

Stealing a victim's session cookie (often via XSS) to impersonate their authenticated session.

Command injection
Show answer

User input reaches an OS shell; chain a separator (; | && ) and a command to execute arbitrary commands.

Blind command injection
Show answer

No command output is returned, so confirm execution out of band — a time delay or a DNS/HTTP callback.

Command substitution
Show answer

Using backticks or $(…) to run a command inside another; often slips past filters that strip other separators.

Directory traversal
Show answer

Abusing ../ sequences to read files outside the web root, such as /etc/passwd or a Windows web.config.

Local file inclusion (LFI)
Show answer

The app includes a referenced file in execution; can escalate to code execution via log poisoning or PHP wrappers.

Log poisoning
Show answer

Injecting PHP into a log the application reads via LFI, then including the log to execute the injected code.

php://filter
Show answer

A PHP wrapper that reads a file as a stream (often base64-encoded) to disclose source code safely via LFI.

File upload bypass
Show answer

Defeating signature, extension allow-list, or MIME checks to upload an executable web shell the server runs.

Web shell
Show answer

A script placed on a server that the server executes, giving remote command execution through the browser.

Magic-byte (signature) check
Show answer

An upload filter validating leading file bytes; bypass by prepending a valid image signature to a script.

Double-extension / case bypass
Show answer

Tricks like shell.php.jpg or shell.PHP that defeat naive or case-sensitive extension allow-lists on uploads.

Client-side attack
Show answer

Delivering a payload a staff user opens — a malicious Office macro or a link using a custom URI handler.

Malicious macro
Show answer

An embedded macro in an Office document that runs attacker code when the victim enables content.

Burp Suite
Show answer

An intercepting web proxy used to view, modify, and replay HTTP requests during web application testing.

Shells & Privilege Escalation (32)

Reverse shell
Show answer

The target connects back to a listener on the attacker — preferred when the target blocks inbound connections (NAT/firewall).

Bind shell
Show answer

A listener opened on the target that the attacker connects to; exposed to anyone who scans the port.

Netcat (nc)
Show answer

A networking utility used as a listener for reverse shells or to grab banners; a plain listener offers no encryption.

socat
Show answer

A flexible relay tool used to create encrypted, more stable reverse shells than a plain netcat listener.

TTY upgrade
Show answer

Turning a dumb shell into an interactive terminal — python3 pty.spawn /bin/bash, then stty raw -echo and export TERM/PATH.

msfvenom
Show answer

Metasploit's standalone payload generator — builds EXE, raw shellcode, or web payloads with LHOST/LPORT set.

Bad characters
Show answer

Bytes that break an exploit or are filtered by the target; specify them (msfvenom -b) so shellcode survives the parser.

Privilege escalation
Show answer

Moving from a low-privileged user/service account to root or SYSTEM — the second 10 points on each OSCP machine.

SUID binary
Show answer

A file that runs with its owner's privileges; a SUID-root program that spawns a shell is a path to root.

bash -p
Show answer

Runs bash without dropping elevated privileges; the invocation that turns a SUID-root bash copy into a root shell.

sudo -l
Show answer

Lists the commands the current user may run via sudo; many such binaries have a documented root-shell escape.

GTFOBins
Show answer

A reference of Unix binaries that can be abused (via SUID, sudo, or capabilities) to escape restrictions and escalate.

Linux capabilities (getcap)
Show answer

Fine-grained root powers on a binary; cap_setuid on an interpreter like python allows escalating to root.

Cron job abuse
Show answer

A root-run scheduled job that is writable, uses a wildcard (tar *), or calls a command without a full path — exploit for root.

Kernel exploit
Show answer

A local-root exploit against the running kernel version; a last resort — match the exact version and prefer a misconfiguration.

SeImpersonatePrivilege
Show answer

A Windows privilege (common on service accounts) abused by 'Potato' attacks to impersonate a SYSTEM token.

Potato attacks
Show answer

PrintSpoofer, RoguePotato, GodPotato and similar tools that escalate a SeImpersonate-holding service account to SYSTEM.

SeBackupPrivilege
Show answer

A Windows privilege that lets the holder read protected files such as the SAM and SYSTEM registry hives.

Unquoted service path
Show answer

A service path with spaces and no quotes; writing a binary to an earlier directory lets it run at the service's privilege.

Writable service binary
Show answer

A service whose executable the current user can overwrite; replace it to run code as the service account on restart.

DLL hijacking
Show answer

Placing a malicious DLL where an elevated app loads it; use Process Monitor to find a missing or writable DLL path.

AlwaysInstallElevated
Show answer

A Windows policy that runs MSI installers as SYSTEM; if set, a malicious MSI yields SYSTEM privileges.

Stored credentials (Windows)
Show answer

Passwords left in autologon registry values, Unattend.xml, or config files — recoverable for escalation or reuse.

whoami /priv
Show answer

Lists the current Windows token's privileges; checking for SeImpersonate/SeBackup is a standard early escalation step.

linPEAS
Show answer

An automated Linux enumeration script that highlights privilege-escalation findings by likelihood.

winPEAS
Show answer

The Windows counterpart to linPEAS; may be quarantined by antivirus, so an obfuscated/in-memory run helps evade it.

Hashcat
Show answer

A GPU password cracker; select the correct mode per hash type (e.g. 13100 Kerberoast, 18200 AS-REP) and use rules.

John the Ripper
Show answer

A password cracker offering dictionary and incremental (brute-force) modes for cracking recovered hashes.

Hydra
Show answer

An online brute-force tool against network services; lockout policies may force throttling or a different approach.

Password spraying
Show answer

Trying one weak password against many accounts to avoid lockouts — effective early against a domain with no credentials.

File transfer (target)
Show answer

Moving tools onto a foothold without outbound internet — a Python/SimpleHTTPServer, SMB share, or certutil download.

docker group
Show answer

Membership lets a user mount the host filesystem in a container as root — a direct Linux privilege-escalation path.

Active Directory & Pivoting (42)

Active Directory (AD)
Show answer

Microsoft's directory service grouping computers and users into domains that share a database and security policy.

Domain
Show answer

The logical boundary in AD that groups users and computers to share a directory database and authentication.

Forest
Show answer

One or more AD domains combined into a larger structure that shares a common schema and configuration.

Domain controller (DC)
Show answer

The server that hosts the AD database and authenticates the domain — the highest-value target in the AD set.

Member server
Show answer

A domain-joined server that is not a domain controller; a lateral-movement stepping stone toward the DC.

LDAP (port 389)
Show answer

The directory query protocol used to enumerate and interact with Active Directory objects.

Kerberos
Show answer

AD's default authentication protocol using tickets (TGT and TGS) issued by the DC's Key Distribution Center.

TGT (ticket-granting ticket)
Show answer

Issued after initial authentication; presented to obtain service tickets. Signed by the krbtgt key.

TGS (service ticket)
Show answer

A ticket for a specific service, encrypted with that service account's key — the material Kerberoasting cracks.

BloodHound
Show answer

A tool that graphs AD attack paths from a controlled account to high-value targets like Domain Admins.

PowerView
Show answer

A PowerShell AD enumeration toolkit; functions reveal sessions, SPNs, group memberships, and rights.

Kerberoasting
Show answer

Request TGS tickets for SPN-enabled accounts and crack them offline; needs only one valid domain credential.

AS-REP Roasting
Show answer

Capture and crack the AS-REP of accounts with pre-authentication disabled; needs no credential, only usernames.

Kerberos pre-authentication
Show answer

A control that, when disabled on an account, exposes it to AS-REP Roasting.

NTLM hash
Show answer

A one-way representation of an account password used for NTLM authentication and reused in Pass-the-Hash.

Pass-the-Hash (PtH)
Show answer

Authenticate with a captured NT hash without cracking it; defeats strong passwords, blunted by unique local passwords (LAPS).

Pass-the-Ticket (PtT)
Show answer

Inject a stolen Kerberos TGT or TGS to impersonate a user; tickets expire, so they must be reasonably fresh.

Golden ticket
Show answer

A forged TGT made from the krbtgt hash and domain SID — any user, any groups, domain-wide; reset krbtgt twice to kill it.

Silver ticket
Show answer

A forged TGS made from one service account's hash — narrower scope and stealthier (no DC contact) than a golden ticket.

krbtgt account
Show answer

The account whose key signs all Kerberos tickets; capturing its hash enables forging golden tickets.

Mimikatz
Show answer

A tool that dumps credentials and Kerberos tickets from memory; needs elevated privileges to access LSASS.

DCSync
Show answer

Abuses the replication protocol to request domain account hashes from a DC without touching NTDS.dit on disk.

NTDS.dit
Show answer

The Active Directory database file on a domain controller; extracting it yields all domain password hashes.

NTLM relay
Show answer

Forwarding captured authentication to another service (e.g. LDAP/SMB) to authenticate as the victim without the hash.

SMB signing
Show answer

A control that defeats NTLM relay to SMB targets by ensuring messages are signed and cannot be forwarded.

PsExec
Show answer

Remote command execution over SMB using a temporary service; a common but noisy lateral-movement method.

WMI
Show answer

Windows Management Instrumentation — executes commands on a remote host with valid credentials or a hash.

WinRM (5985/5986)
Show answer

Remote management providing an interactive PowerShell session; often preferred over PsExec for stealthier movement.

Lateral movement
Show answer

Moving host-to-host using reused credentials (PtH, PtT, PsExec, WMI, WinRM) — the heart of the AD set's scoring.

Credential reuse
Show answer

The same account or hash valid on many hosts; the engine that makes AD compromise fast once one credential is found.

Pivot host
Show answer

A compromised, dual-homed host used to route traffic into a network the attacker cannot reach directly.

SSH local forward (-L)
Show answer

Exposes one internal service on a local port of the attacker box through a Linux pivot you can SSH to.

SSH remote forward (-R)
Show answer

Used when the pivot can reach the attacker but not vice versa; the pivot pushes an internal port out to you.

SSH dynamic forward (-D)
Show answer

Opens a SOCKS proxy to route many tools at once into the internal network; pair with proxychains.

Chisel
Show answer

A client-server SOCKS tunnel over HTTP for pivoting through a firewalled Windows host that lacks an SSH server.

proxychains
Show answer

Forces a command-line tool's TCP connections through a SOCKS proxy; use TCP-connect scans, not ICMP/UDP.

TCP connect scan (-sT)
Show answer

A full-handshake scan required through a SOCKS proxy, since half-open SYN, ping, and UDP do not traverse the tunnel.

Dual-homed host
Show answer

A host with two interfaces on different subnets; ideal as a pivot to reach an otherwise unreachable network.

Domain Admins
Show answer

The built-in group whose membership most directly equates to full control of the domain — the prime target.

WriteDACL / GenericAll
Show answer

BloodHound ACL edges granting rights over an object that can be abused to take it over and escalate.

Domain SID
Show answer

The domain's security identifier; combined with the krbtgt hash, it is needed to forge a golden ticket.

AD set scoring
Show answer

The OSCP Active Directory chain is worth 40 points: 10 client + 10 second host + 20 domain controller.

References

  1. 1.OffSec (Offensive Security). “PEN-200: Penetration Testing with Kali Linux (OSCP).” offsec.com. ↑
  2. 2.MITRE. “MITRE ATT&CK — Enterprise Tactics and Techniques.” attack.mitre.org. ↑
  3. 3.OWASP. “OWASP Top Ten and Attack Reference.” owasp.org. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.