
oscp-notes-2026 — Updated!
OSCP field notebook: merged technique vault and numbered notes. MIT.
OSCP Field Notebook

Port-indexed pentest methodology notebook: decision trees, copy-paste command patterns, and lessons from authorized practice boxes (HTB / PG / personal labs). Merged from the older finalnotes-vault into this single tree.
A workflow you can run under time pressure. Commands and decision trees first.
Public study notes for authorized practice only (your labs, HTB/PG, courses you own). No exam keys, no live engagement dumps, no OffSec course content dump.
Repo: https://gitlab.com/WattoCyber/oscp-notes-2026
At a glance
| What | OSCP-style field notes: decision trees, command patterns, technique cards. |
| Who it is for | OSCP candidates and lab operators who want a workflow they can run under time pressure. |
| What it is not | Not a payload dump, not exam keys, not OffSec course content, and not a substitute for official materials. |
| Size | 512+ markdown notes in numbered engagement order, plus a 2026 bug-bounty library (ALPHA runbook, playbooks, writeup cards). |
Quick start
git clone https://gitlab.com/WattoCyber/oscp-notes-2026.git
cd oscp-notes-2026
# optional: bind placeholders to your lab IPs
# edit 00-Start-Here/Variables.md
python fill-variables.py apply
python fill-variables.py status
python fill-variables.py reset # restore placeholders
Success signal: python fill-variables.py status prints Status: PLACEHOLDERS (before apply) or Status: FILLED (after apply with real IPs in Variables.md). Open Home.md in Obsidian, VS Code, or any markdown reader. Wikilinks work best in Obsidian.
Requires Python 3 only (stdlib). No pip install.
Layout
00-Start-Here/ 31 notes
01-Enumeration/ 139 notes
02-Web-Attacks/ 48 notes
03-Active-Directory/ 55 notes
04-Linux-PrivEsc/ 57 notes
05-Windows-PrivEsc/ 92 notes
06-Pivoting/ 13 notes
07-File-Transfers/ 11 notes
08-Shells/ 8 notes
09-Password-Attacks/ 19 notes
10-Reporting/ 5 notes
11-Tools/ 30 notes
12-CVE-Hunting/ bug-bounty / original-findings library (authorized research; public extract: https://gitlab.com/WattoCyber/bug-bounty-library)
fill-variables.py placeholder IP binder
_attachments/ images linked from notes
Scope (what is / is not here)
In scope
- General offensive methodology aligned with OSCP-style learning
- Public-box lessons (HTB, Proving Grounds, personal labs) with secrets redacted
- Tooling patterns (nmap, nxc, impacket, evil-winrm, ligolo, hashcat)
- Authorized CVE / bug-bounty library (conditional methodology, class playbooks, writeup distillations) - not exploit recipes
Out of scope (deliberately)
- Exam answers, exam host notes, VPN configs, proof flags
- Full machine writeup libraries
- Copyrighted OffSec PDF / course text
- Live client or employer engagement data
Verify current exam rules on OffSec's exam guide. Scoring tables here are study aids and can go stale.
Variable filler
Placeholders used across notes: ATTACKER_IP, TARGET_IP, DC_IP, MS01_IP, MS02_IP, STANDALONE1..3, INTERNAL_IP, INTERNAL_NET, DOMAIN.
python3 fill-variables.py apply # write your IPs into every .md
python3 fill-variables.py reset # restore tokens (uses .variables-backup.json)
Do not commit applied IPs. Keep Variables.md as placeholders in git.
Author
Samson Laird (SamsonCyber / WattoCyber). Built while grinding OSCP-style labs.
The older standalone finalnotes-vault repo is archived. This tree is the living copy.
License
MIT for original structure, scripts, and original prose. Technique knowledge is public security tradecraft. Box names refer to public HTB/PG machines; respect each platform's rules.