$ cat articles/osee-review.md

OSEE Review — Our Journey Around the World to AWE

Exam review

I passed the OSEE (OffSec Exploitation Expert). It's one of the hardest offensive security certifications out there, yet there's barely any content about it online — so here's what it actually is, and exactly how my friends and I studied for it.

This post is a written version of my YouTube video, “AWE OSEE Review — Our Journey Around the World ”.

Out of respect for the exam's NDA, I don't discuss any specific exam content. This post covers only how we studied and my honest thoughts.

A quick intro

I work at an offensive security company. Before OSEE I'd already earned OSCP and OSCE3, so I had some background in exploit development — but to be clear, OSEE is a completely different level.

A lot of what I cover first — the syllabus, the prerequisites, the pricing — you can already find on other blogs and on the official site, so I'll go over it quickly. The part I really want to focus on is my own experience: how I studied and prepared. That's the stuff you can't just Google.

What is OSEE / AWE?

OSEE (OffSec Exploitation Expert) is earned by passing the exam for the course EXP-401, also known as AWE (Advanced Windows Exploitation).

It's OffSec's most advanced certification, focused on modern Windows exploit development: defeating mitigations, kernel-level exploitation, and building working exploits against hardened targets. This isn't a “learn a scanner and get a shell” cert — it's deep, low-level exploit development.

Prerequisites

This is really important, so pay attention. OSEE is not a beginner cert — honestly, it's not even an intermediate one. Before you even think about it, you should be comfortable with:

  • Windows internals
  • Assembly, especially x86 and x64
  • Debugging — you need to be genuinely fluent with tools like WinDbg
  • Exploit development experience — doing OSED first is a very natural stepping stone

If those don't sound familiar, I'd strongly recommend building that foundation first. Jumping straight into OSEE without it is going to be really painful.

The in-person requirement

Here's what makes OSEE really different from other OffSec certs, and it catches a lot of people off guard — including me.

Unlike OSCP or OSED, which you can do completely online at your own pace, AWE has historically been delivered as a live, in-person class. You actually have to attend the training in person, traditionally at events like Black Hat or similar live sessions.

So this isn't something you can buy at 2 a.m. and start grinding from your bedroom. You need to plan around the schedule, the location and, in a lot of cases, travel — not just the money, but the time and logistics.

Cost

This part is not cheap. The course plus the exam runs over $10,000 (prices change, so check the official site for the current number).

And because it's in person, you also have to factor in:

  • Travel and flights
  • Hotel and accommodation
  • Time off work

The real total is quite a bit higher than the sticker price. I'm being upfront about this because I wish someone had spelled it out for me before I started planning.

The exam

The exam is a hands-on, 72-hour exam. You develop working exploits and prove you can actually apply what you learned — not just regurgitate it.

There's no multiple choice. You either produce a working exploit and document it properly, or you don't. It's brutal, but it's fair — a genuine test of skill.

How we studied — traveling the world

This is the part I really wanted to write this for. Everything up to now you can find elsewhere; this is our own experience.

The first thing you should know: I didn't do this alone. I went through this journey with my two best friends, the three of us as a team. To prepare for the exam, we traveled around the world together to take trainings in person. It wasn't cheap and it wasn't easy, but doing it side by side with my best friends is honestly one of the biggest reasons we made it.

Here are the three trainings we took to get ready.

1. Corelan Heap Exploitation Masterclass (Peter Van Eeckhoutte)

This one is legendary in the exploit development world. Heap exploitation is one of the hardest topics to really internalize, and Peter's class forces you to actually understand what's happening under the hood — not just memorize steps.

2. Windows Internals for Security Engineers (Yarden Shafir)

Before you can exploit Windows, you have to understand Windows. This class filled in so many gaps in how the OS actually works internally. For OSEE, that foundation is absolutely critical — you can't exploit what you don't understand. (My log entry: Attended “Windows Internals for Security Engineers” at OffensiveCon 2025)

3. Advanced Windows Exploitation (Morten Schenk, Alexandru Uifalvi, Matteo Memelli)

The AWE course itself — the one that leads directly to OSEE, taught by some of the best in the field. This is where everything came together.

Tips

A few honest tips if you're going for OSEE:

  1. Don't attempt it without solid exploit development experience.
  2. Master WinDbg before the course, not during it.
  3. Build your own notes. Don't rely on memory.
  4. Sleep before the exam. Seriously.

Final thoughts — this is just the first step

Was OSEE worth it for me? Yes. It's expensive, it's demanding, and the in-person requirement makes it a real commitment. But it genuinely made me a better exploit developer, and the title carries real weight.

Passing OSEE isn't the finish line, though. As Windows security researchers, there's still so much left to learn.

If you're serious about advanced Windows exploitation, it's one of the best things you can do for your skills. Got questions about OSEE? Ask me on X (@Yunolay) or in the video comments.

Links

Certificate

OSEE (OffSec Exploitation Expert) certificate
OSEE certificate — earned June 2, 2026

← Back to articles