OffSec Authorized Training

OffSec Advanced MacOS Control Bypasses EXP-312 (OSMR) Training

Advanced macOS Control Bypasses (EXP-312) is an advanced course that teaches the skills necessary to bypass security controls implemented by macOS, and exploit logic vulnerabilities to perform privilege escalation on macOS systems. Learners who complete the course and pass the exam earn the OffSec macOS Researcher (OSMR) certification.

LevelAdvanced
Duration5 Days
Experience4 years: macOS
Average Salary$100,000
LabsYes

Advanced macOS Control Bypasses (EXP-312)

Course Overview

EXP-312 (macOS Control Bypasses) is an offensive logical exploit development course for macOS, focusing on local privilege escalation and bypassing the operating system’s defenses. It’s an intermediate course that teaches the skills necessary to bypass security controls implemented by macOS, and exploit logic vulnerabilities to perform privilege escalation on macOS systems.

  • Obtain a strong understanding of macOS internals
  • Learn the basics of Mach messaging
  • Learn how to bypass Transparency, Content and Control (TCC) protections
  • Learn how to escape the Sandbox
  • Perform symbolic link attacks
  • Leverage process injection techniques
  • Exploit XPC for privilege escalation
  • Perform hooking based attacks
  • Write Shellcode for macOS
  • Bypass kernel code-signing protection
  • Course Materials
  • Active Student Forums
  • Access to Home Lab Setup
Course Outline
  • Lesson 1: macOS Control Bypasses: General Course Information
  • Lesson 2: Virtual Machine Setup Guide
  • Lesson 3: Introduction to macOS
  • Lesson 4: macOS Binary Analysis Tools
  • Lesson 5: The Art of Crafting Shellcodes
  • Lesson 6: Dylib Injection Egghunters
  • Lesson 7: The Mach Microkernel
  • Lesson 8: Function Hooking on macOS
  • Lesson 9: XPC Attacks
  • Lesson 10: The macOS Sandbox
  • Lesson 11: Bypassing Transparency, Consent, and Control (Privacy)
  • Lesson 12: GateKeeper Internals
  • Lesson 13: Bypassing GateKeeper
  • Lesson 14: Symlink and Hardlink Attacks
  • Lesson 15: Getting Kernel Code Execution
  • Lesson 16: Injecting Code into Electron Applications
  • Lesson 17: Mount(ain) of Bugs (Archived)
  • Lesson 18: The Art of Crafting Shellcodes (Apple Silicon Edition)
  • Lesson 19: Mach IPC Exploitation
  • Lesson 20: Chaining Exploits on macOS Ventura
  • Lesson 21: macOS Penetration Testing
Intended Audience
  • Anyone who is interested in learning about macOS exploitation
  • Pentesters looking to broaden their skill set to include macOS expertise
  • Anyone committed to the defense or security of macOS systems
  • Job roles like Penetration testers, Exploit developers, Security researcher, macOS defenders, and macOS application developers
Prerequisites

We strongly suggest that students taking PEN-300 have either taken PWK and passed the OSCP certification or have equivalent knowledge and skills in the following areas:

  • Working familiarity with Kali Linux command line
  • Solid ability run enumerating targets to identify vulnerabilities
  • Basic scripting abilities in Bash, Python and PowerShell
  • Identifying and exploiting vulnerabilities like SQL injection, file inclusion and local privilege escalation
  • Foundational understanding of Active Directory and knowledge of basic AD attacks
  • Familiarity with C# programming is a plus
Features

Also available in On-Demand formats below:

  • Offsec Learn One
  • Learn One Package – $2,749
  • 1 year of access to the course of your choice
  • 2 exam attempts during your subscription
  • 365 days of lab access
  • Access to all 100-level content for 1 year
  • 1 year of unlimited access to all fundamental content and OffSec curated Learning Paths
  • PEN-103 + 1 KLCP exam attempt
  • PEN-210 + 1 OSWP exam attempt
  • Proving Grounds Practice labs
  • Learn More
  • OR
  • OffSec Learn Unlimited
  • Learn Unlimited Package – $6,099
  • 1 year of access to unlimited course & content
  • Unlimited exam attempts during your subscription
  • 365 days of lab access
  • 1 year of unlimited access to all fundamental content and OffSec curated Learning Paths
  • Access to all 100-level content for 1 year
  • PEN-103 + unlimited KLCP exam attempts
  • PEN-210 + unlimited OSWP exam attempts
  • Proving Grounds Practice labs
  • 3 downloads of course material
  • Learn More
Follow-On Courses

PROUD OFFSEC PARTNERSHIP

We are proud to be an OffSec Learning, Government, and Channel Partner. We pride

ourselves on providing award winning boot camps and direct mentoring in our classrooms,

Online Live or at your location. The only immersive Authorized Instructor-Led OffSec

training available - join us today!

Related training topics

Get approved to attend

Justify your training

Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.

Sample training request letter

Subject: Request for Penetration Testing & Red Teaming training from Applied Technology Academy

[Decision Maker Name],

I'm writing to request time and budget approval to complete Applied Technology Academy's course, OffSec Advanced MacOS Control Bypasses EXP-312 (OSMR) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.

Course Description
Advanced macOS Control Bypasses (EXP-312) is an advanced course that teaches the skills necessary to bypass security controls implemented by macOS, and exploit logic vulnerabilities to perform privilege escalation on macOS systems. Learners who complete the course and pass the exam earn the OffSec macOS Researcher (OSMR) certification. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.

Course Objectives
Once I've completed the course, I'll have hands-on, job-ready skills in penetration testing & red teaming that I can apply immediately to our work.

Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.

Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.

Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in penetration testing & red teaming. Additional course information is available at https://appliedtechnologyacademy.com/offsec-training/offsec-exp-312-osmr-training/.

Thank you for your consideration,
[Your Name]

Design training around your team, not the other way around.

Talk to a training advisor about private cohorts, funding paths and program management.

Request a Quote Call 800.674.3550