Career Employer

Your FREE OSCP Flashcards 2026 – 100+ Cards

Realistic, OSCP exam-style flashcards across the OffSec PEN-200 methodology — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer OSCP

By

Click Study Flashcards above to open the flashcard hub — over a hundred OSCP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the OffSec PEN-200 methodology, so you study exactly what the hands-on penetration-testing exam tests.[1] Pair them with our free practice questions and study guide — and with real lab machines.

OSCP Flashcard Study Modes

Flip mode lets you study each card front and back at your own pace, Match turns term-to-definition pairing into a timed game, Type shows the definition and asks you to spell the term back — DCSync, for example — and Quiz builds multiple-choice questions from the same 128 cards. Rotate through all four so recognition turns into recall.

Free OSCP flashcards from Career Employer — active recall for the OffSec PEN-200 penetration-testing exam

Why Flashcards Work for the OSCP

Active Directory & Pivoting is the largest section at 42 cards, and it drills the vocabulary you need once a foothold turns into a domain problem. You get structural terms like Domain and Forest alongside the tooling and technique names that show up in lateral movement, including WMI, PsExec, and Mimikatz. Credential-material cards such as NTDS.dit and DCSync sit next to tunneling entries like Chisel, so pivoting language and directory language get reinforced together.

Shells & Privilege Escalation carries 32 cards covering what happens between initial code execution and root or SYSTEM. Payload and listener terms such as msfvenom and socat are here, as are the enumeration helpers linPEAS and winPEAS that feed escalation decisions. Cards like sudo -l and bash -p drill specific Linux misconfiguration checks, while Hydra and Hashcat keep the online and offline credential-attack distinction sharp in your head.

Enumeration & Exploit Research holds 27 cards on the scanning and discovery language that starts every box. Nmap anchors the section, and the flag cards force precision: -Pn, -sV, -sC, and -sU each mean something different under time pressure. Content discovery gets its own vocabulary through ffuf and gobuster, with Wordlist tying the brute-force side of enumeration back to the tooling you point at a target.

Web Application Attacks also has 27 cards, covering the input-handling flaws that often supply the first shell. Injection and interception terms include sqlmap and Burp Suite, while Reflected XSS and Stored XSS force you to separate two outcomes that share a name. File-handling and payload-delivery cards such as php://filter, Log poisoning, Web shell, and Malicious macro round out the routes from a browser request to command execution.

The OSCP exam is hands-on, so the cards play a specific role: they make the tools, flags, and techniques automatic so you spend exam time exploiting rather than recalling syntax.[2] Used alongside our practice questions, our study guide, and real lab practice, they turn review time into measurable progress.

OSCP Flashcards by Domain

The cards are organized by the OffSec PEN-200 methodology. Drill them in the order a penetration test flows — enumerate, exploit, escalate, then attack Active Directory and pivot:[1]

OSCP flashcards by methodology domain
DomainWhat it covers
Enumeration & Exploit ResearchNmap flags, SMB/web/FTP enumeration, searchsploit, vulnerability scanning
Web Application AttacksSQL injection, XSS, command injection, LFI/traversal, file upload
Shells & Privilege EscalationReverse/bind shells, msfvenom, Linux SUID/sudo/cron, Windows tokens/services
Active Directory & PivotingKerberoasting, AS-REP roasting, Pass-the-Hash, tickets, SSH tunnels, proxychains, Chisel

How to Get the Most Out of These Flashcards

  • Start with Active Directory & Pivoting. At 42 cards it is the biggest block in the deck, and domain vocabulary is the part most people fumble when a foothold suddenly becomes a directory problem.
  • Type-drill the exact strings. Cards like sudo -l and -sV punish approximate memory, so typing them forces the precision you need when syntax matters more than the general idea.
  • Use Match for tool names. Pairing entries such as linPEAS, winPEAS, ffuf, and gobuster against their descriptions quickly exposes which tools you only half-recognize from reading walkthroughs.
  • Switch to the practice test once Quiz gets easy. When multiple choice across all four domains stops surprising you, move to timed questions and use the study guide to repair whatever breaks.
  • Keep the cadence small and repeated. Work one domain per session, finish with a mixed Quiz over all 128 cards, and revisit missed terms the next day rather than cramming a full pass.

OSCP Flashcards FAQ

Over a hundred free OSCP flashcards, organized across the OffSec PEN-200 methodology — Enumeration & Exploit Research, Web Application Attacks, Shells & Privilege Escalation, and Active Directory & Pivoting. They're free with no account required.

References

  1. 1.OffSec (Offensive Security). “PEN-200: Penetration Testing with Kali Linux (OSCP).” offsec.com.
  2. 2.MITRE. “MITRE ATT&CK — Enterprise Tactics and Techniques.” attack.mitre.org.
  3. 3.OWASP. “OWASP Top Ten and Attack Reference.” owasp.org.
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.