OffSec Authorized Training

OffSec Advanced Windows Exploitation EXP-401 (OSEE) Training

We are a premier provider of EXP-401 Offensive Security OSEE Training. Modern exploits for Windows-based platforms require modern bypass methods to circumvent Microsoft’s defenses. In Advanced Windows Exploitation, our expert instructors will challenge students to develop creative solutions that work in today’s increasingly difficult exploitation environment.

LevelAdvanced
Duration5 Days
Experience4 years: Advanced Windows Exploitation
Average Salary$120,634
LabsYes

Advanced Windows Exploitation OSEE (EXP-401)

Course Overview

The OSEE is the most difficult exploit development certification you can earn. We recommend completing the 300- level certifications before registering for this course.

Students who complete EXP-401 and pass the exam will earn the Offensive Security Exploitation Expert (OSEE) certification. The OSEE exam assesses not only the course content, but also the ability to think laterally and adapt to new challenges.

The virtual lab environment has a limited number of target systems. The software within contains specific, unknown vulnerabilities. Students have 72 hours to develop and document exploits. The exam requires a stable, high-speed internet connection.

You must submit a comprehensive penetration test report as part of the exam. It should contain in-depth notes and screenshots detailing the steps taken and the exploit methods used.

  • Custom Shellcode Creation
  • Writing Exploit Code
  • Shellcode Framework Creation
  • Reverse Shell
  • VMware Workstation Guest-To-Host Escape
  • Data Execution Prevention (DEP)
  • VMware Workstation Guest-To-Host Escape
  • Driver Callback Overwrite
  • Address Space Layout Randomization
  • VMware Workstation Internals
  • The Windows Heap Memory Manager
  • Low Fragmentation Heap
  • Restoring the Execution Flow
  • Windows Defender Exploit Guard
  • ROP Mitigations
  • Unsanitized User-mode Callback
  • Course Materials
  • Active Student Forums
  • Access to Home Lab Setup
Course Outline
  • Lesson 1: Introduction
  • Lesson 2: Custom Shellcode Creation
  • Lesson 3: VMware Workstation Guest-To-Host Escape
  • Lesson 4: Microsoft Edge Type Confusion
  • Lesson 5: Driver Callback Overwrite
  • Lesson 6: Unsanitized User-mode Callback
Intended Audience

Advanced Windows Exploitation is NOT an entry level course. We expect students to have previous exploitation experience in a Windows environment and understand their way around a debugger. This is the hardest course Offensive Security offers.

Prerequisites

All students are required to have:

Experience in developing windows exploits and understand how to operate a debugger. Familiarity with WinDBG, x86_64 assembly, IDA Pro and basic C/C++ programming is highly recommended. A willingness to work and put in real effort will greatly help students succeed in this security training course.

A laptop that is able to run three VMs with ease. Please do not bring netbooks or other low-resolution systems. The only supported host operating system is Windows 10.

  • VMware Workstation 15 or higher
  • 64-bit CPU with a minimum of 4 cores along with support for NX, SMEP, VT-d/IOMMU and VT-x/EPT
  • At least 160 GB HD free
  • At least 16 GB of RAM
Features

Our EXP-401 course includes:

  • Instructor-Led Training with our advanced practitioner instructor team.
  • Comprehensive EXP-401 Courseware Binder with all of the most recent course updates!
  • All of the EXP-401 VMs to help launch you in to execution!
  • An OSEE Exam Voucher
Follow-On Courses

    PROUD OFFSEC PARTNERSHIP

    We are proud to be an OffSec Learning, Government, and Channel Partner. We pride

    ourselves on providing award winning boot camps and direct mentoring in our classrooms,

    Online Live or at your location. The only immersive Authorized Instructor-Led OffSec

    training available - join us today!

    Related training topics

    Get approved to attend

    Justify your training

    Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.

    Sample training request letter

    Subject: Request for Penetration Testing & Red Teaming training from Applied Technology Academy

    [Decision Maker Name],

    I'm writing to request time and budget approval to complete Applied Technology Academy's course, OffSec Advanced Windows Exploitation EXP-401 (OSEE) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.

    Course Description
    We are a premier provider of EXP-401 Offensive Security OSEE Training. Modern exploits for Windows-based platforms require modern bypass methods to circumvent Microsoft’s defenses. In Advanced Windows Exploitation, our expert instructors will challenge students to develop creative solutions that work in today’s increasingly difficult exploitation environment. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.

    Course Objectives
    Once I've completed the course, I'll have hands-on, job-ready skills in penetration testing & red teaming that I can apply immediately to our work.

    Expected Organizational Benefits
    After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.

    Expected Cost & Funding
    Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.

    Conclusion
    This training provides practical, hands-on experience I can apply immediately to strengthen our work in penetration testing & red teaming. Additional course information is available at https://appliedtechnologyacademy.com/offsec-training/offsec-exp-401-osee-training/.

    Thank you for your consideration,
    [Your Name]

    Design training around your team, not the other way around.

    Talk to a training advisor about private cohorts, funding paths and program management.

    Request a Quote Call 800.674.3550