The OSED (OffSec Exploit Developer) Certification training by kodestree is built around OffSec’s EXP-301: Windows User Mode Exploit Development course. This training program equips you with practical skills in x86 assembly, WinDbg debugging, stack and SEH overflow exploitation, egghunters, custom shellcoding, and DEP/ASLR bypass. Guided by experienced exploit development trainers, this program prepares you for the demanding OSED certification exam and real-world offensive security roles across red-teaming, vulnerability research, and malware analysis.
Prerequisites
OffSec does not enforce a formal prerequisite for EXP-301, but candidates get the most value when they arrive with:
- Familiarity with debuggers such as WinDbg, Immunity Debugger, or OllyDbg
- A basic understanding of 32-bit exploitation concepts, particularly stack overflows
- Working knowledge of Python 3 scripting
- Ability to read C code at a basic level
- Ability to read 32-bit x86 Assembly at a basic level
- A prior foundation from OSCP (Penetration Testing with Kali Linux / PEN-200) is recommended, though not mandatory
Why Learn OSED?
Most security certifications teach candidates to run existing exploits. OSED teaches you to build them. It moves you past Metasploit modules and pre-written payloads into the mechanics that make an exploit work, corrupting memory precisely, writing shellcode that fits in a constrained buffer, and getting code execution past DEP and ASLR without any public tool doing the heavy lifting for you.
Because it demands genuine skill rather than checklist knowledge, OSED is recognized across the offensive security industry as a credible signal of exploit-development ability. It also forms one-third of the OSCE³ credential alongside OSEP and OSWE, making it a natural next step for OSCP holders who want to specialize in binary exploitation, vulnerability research, or malware reverse engineering rather than general penetration testing.
Course Objectives
This training is designed to help you:
- Build a strong working foundation in x86 architecture and WinDbg-based debugging
- Exploit stack-based and SEH-based buffer overflows on Windows
- Use IDA Pro for static reverse engineering of unfamiliar binaries
- Write custom, null-free, position-independent shellcode from scratch
- Develop and adapt egghunters to work around limited buffer space
- Bypass DEP using Return-Oriented Programming (ROP)
- Bypass ASLR and exploit format string vulnerabilities for read/write primitives
- Build the practical stamina and methodology needed for the 47-hour-45-minute OSED exam
What You Will Learn
Across the program, you will work through:
- x86 architecture fundamentals and effective use of WinDbg
- Exploiting vanilla stack overflows and SEH overflows on Windows targets
- Reverse engineering closed-source binaries with IDA Pro to uncover vulnerabilities
- Writing egghunters and custom shellcode without relying on public payload generators
- Constructing ROP chains to defeat Data Execution Prevention (DEP)
- Practical techniques to bypass Address Space Layout Randomization (ASLR)
- Reading and writing memory through format string specifier attacks
- Structuring clear, professional exploit-development documentation for the exam and the field
Who Is This Course For?
This training fits professionals such as:
- Penetration testers and red teamers who want to move past scripted exploits
- Security researchers and vulnerability analysts
- Malware analysts looking to strengthen their grip on Windows internals
- Software developers building or auditing security-sensitive products
- OSCP holders progressing toward the OSCE³ credential
- Blue team and SOC professionals who want a deeper understanding of attacker tradecraft
Tools You Will Work With
- WinDbg
- Immunity Debugger / OllyDbg
- IDA Pro
- Python 3
- Mona.py
- Kali Linux
- x86 Assembly tooling (e.g., NASM)
- Metasploit (for payload comparison and reference only)
Skills You Will Gain
By the end of this course, you will be able to:
- Debug and analyze Windows applications at the assembly level
- Identify and exploit stack-based and SEH-based buffer overflows
- Reverse engineer closed-source binaries to discover exploitable vulnerabilities
- Write custom shellcode and egghunters independent of public tooling
- Defeat modern mitigations, including DEP and ASLR
- Exploit format string vulnerabilities to build read/write primitives
- Approach unfamiliar Windows exploitation challenges with a repeatable methodology
Career Outcomes
OSED-certified professionals are well positioned for roles such as:
- Exploit Developer
- Vulnerability Researcher
- Senior Penetration Tester / Red Teamer
- Malware Reverse Engineer
- Security Research Engineer
- Offensive Security Consultant
Why Choose kodestree for This Training?
kodestree supports your OSED journey with:
- Instructor-led sessions guided by trainers experienced in offensive security and exploit development
- 100% hands-on labs mirroring real Windows exploitation scenarios
- Structured coverage mapped to the official EXP-301 syllabus
- Doubt-resolution support and mentorship throughout the course
- Flexible batch timings for working professionals
- Certification guidance and career support after course completion
- Access to recorded sessions for revision and exam preparation