ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
LainKusanagi list of OSCP like machines
2
>Whoami>What is this list for
3
-Before and while doing PEN 200 course and after failing my first attempt I completed multiple machines in multiple hacking platforms.
-I did all the PEN 200 course along with all the challenge labs that where introduced in the 2023 version of the PEN 200 (including the challenge lab network other people skip).
-I failed my first attempt with 60 points and then passed my second attempt with 90 points. I experienced completely different exam sets in each attempt.
-I also did the challenge labs added on October 2024 before my learn one subscription ended.
-All of this experience gave me a good sense of what is OffSec style of boxes and what is important to know in the exam

Have feedback or suggestions? Let me know here:
https://x.com/unknownseeker99
https://www.reddit.com/user/JosefumiKafka/
https://www.linkedin.com/in/luis-moret-4a42ab246/
-This is a list of machines I consider good for practice before doing the PEN 200 course, challenge labs and OSCP exam however this is not a replacement for the actual course and I recommend you to go through all of the course, exercises and challenges before attempting the exam.
-The machines in this list where selected because either they teach important techniques and concepts found in the course and labs, have similar style to machines made by offsec or where in a way crucial to helping me develop my methodology and help me pass my exam.
-This list overlaps a lot with the famous TJ Null list however it also filters out boxes that may be too outside of the scope of the PEN 200 and OSCP exam and includes boxes from other hacking platforms such as Tryhackme and VirtualHackingLabs, still I added some boxes in this list that may have elements harder than OSCP but I believe are worth doing as they may have some other aspect that is crucial to know and practice


Support me: https://buymeacoffee.com/lainkusanagi
4
>Useful forks made by the community (I do not maintain these forks so they may not reflect latest changes):
-List with difficulty ratings made by Jubba402 https://docs.google.com/spreadsheets/d/13YoNQuY6HC5ot-lZiX2tY9pR5mvwnp3xV6lHs78DlqQ/
-Study tracker combining this list and TJ Null list with difficulty ratings made by Obeyeater https://docs.google.com/spreadsheets/d/1nzEN0G6GzneWCfs6qte6Qqv-i8cV_j6po-tFlZAOx1k/
>Other useful resources for practice and study:
Hacker Blueprint OSCP Practice labs https://www.youtube.com/playlist?list=PLM1644RoigJvm0L7RcK-64aVTp1vZkDv5
Derron C OSCP Practice labs https://www.youtube.com/playlist?list=PLT08J44ErMmb9qaEeTYl5diQW6jWVHCR2
5
HacktheboxTryhackme
6
Start learning to Try harder here. Don’t fully skip hackthebox some boxes have important concepts that are rare even in PG practice like SNMP and Keepass also AD ones are pretty good practice even if harder than OSCP in some ways. At the very least watch ippsec videos and take notesMore guided and friendly approach for some rooms but still great boxes and rooms for prep. Active Directory ones here are very good practice for the OSCP.
7
LinuxWindowsActive Directory and NetworksLinuxWindowsActive Directory and NetworksOther recommended rooms
8
SeaMarkupActiveMr RobotSteel MountainAttacktive DirectorySQL Injection Lab
9
NibblesJerryForestThompsonYear of the OwlAttacking KerberosLinux Privilege Escalation
10
SolidstateNetmonSaunaKenobiRetroWreath NetworkWindows Privilege Escalation
11
PoisonServmonFlightGameZoneAlfredResetGit Happens
12
EditorChatterboxReturnSkynetRelevantVulnnet: ActiveNahamStore
13
SundayJeevesBlackfieldDaily bugleBlueprintEnterprise
14
KeeperSniperCicadaLazy adminHackparkLedger
15
PilgrimageQuerierTheFrizz (harder)TomghostWeaselRecommended paths
16
CozyhostingGiddyRootmeAllSignsPoint2Pwnage Assumed Breach Scenarios:Cyber Security 101
17
CodifyBountyAssumed Breach Scenarios:CMesSAnthemCorpJr Penetration Tester
18
TartarsauceArticAdministratorUltratechHack Smarter Security (harder)Lateral Movement and PivotingOffensive Pentesting
19
JarvisRemoteInternalCyberlensExploiting Active Directory
20
TabbyBuffZeno
21
UsageLoveBoiler CTF
22
MentorSecnotes
Priv Esc not in scope but good practice:
Wonderland
23
DevvortexAccessMonteverdeSilver Platter
24
IrkedMailingEscapeYear of the Jellyfish
25
PopcornHeistEscapeTwo (Assumed breach)
26
BashedCertified (Assumed breach)Update:
27
BrokerPuppy (harder)
12/14/2025 Added Oddysey and sns_secrets to hacksmarter list
28
AnalyticsTimelapse (harder)
1/18/2025 Added Lumon and Static to hacksmarter list
29
NetworkedSigned (Assumed breach)
1/31/2026 Added Facts to Hackthebox list
30
UpDown
2/5/2026 Added Verbose, StellarComms and 404bank to hacksmarter list
31
SwagshopProLabs:
2/8/2026 Added Signed to Hackthebox list and Sams to pg play list
32
NinevehDante
33
PandoraZephyr (harder)
34
OpenAdmin
35
PreciousAWS (Not in the exam)
36
BusquedaEpsilon
37
MonitoredGobox
38
BoardLightBucket
39
MagicFacts
40
Help
41
Editorial
42
Builder
43
Linkvortex
44
UnderPass
45
Dog
46
47
Proving Grounds PracticeHackSmarter
48
The real OSCP like boxes, this is just a list with the ones that are best practice and removing the overly complicated ones that are too out of scope and those that were boxes meant to be mostly for OSEP and OSED (example Kyoto and Nara) that were in TJNull list plus adding some new onesNew platform made by the Hack Smarter community
49
LinuxWindowsActive Directory and NetworksLinuxWindowsActive Directory and Networks
50
ClamAVKevinAccessBankSmarterSlayerShareThePain
51
PelicanInternalNagoyaAscensionSysco
52
PaydayAlgernonHokkaidoTalismanStellarComms
53
SnookumsJackoVaultVerbose (harder)
54
BratarinaCraftAssumed Breach Scenarios:
55
PebblesSquidTreat it like a small networkBuilding Magic
56
NibblesNickelSkillForge (Linux)PivotSmarter (small network)
57
HetemitMedJed
58
ZenPhotoBillyboss
Priv Esc not in scope but good practice:
Networks:
59
NukemShenziHutchOdyssey (harder but good practice)
60
CockpitAuthByResourced
61
ClueSlort
Priv Esc not in scope but good practice:
62
ExtplorerHepetWelcome (Assumed breach)
63
PostfishDVR4Arasaka (Assumed breach)
64
HawatMiceAWS (Not in the exam)Anomaly (harder / network)
65
WallaMonsterPathwayLumon Industries (Assumed breach)
66
PCFish404 bank (Harder)
67
Apex
68
SorcererAWS (Not in the exam)
69
SybarisSns_secrets
70
PeppoStatic
71
Hunit
72
Readys
73
Astronaut
74
Bullybox
75
Marketing
76
Exfiltrated
77
Fanatastic
78
QuackerJack
79
Wombo
80
Flu
81
Roquefort
82
Levram
83
Mzeeav
84
LaVita
85
Xposedapi
86
Zipper
87
Workaholic
88
Fired
89
Scrutiny
90
SPX
91
Vmdak
92
Mantis
93
BitForge
94
WallpaperHub
95
Zab
96
SpiderSociety
97
98
Virtual Hacking LabsVulnLab / Hackthebox
99
Very under rated platform with very OSCP like machines, people that have used it really recommend it for OSCP including me. It has been very crucial help for those that have failed attempts to be able to pass and they are good practice for standalones.VunLab is an amazing platform focused on red teaming, the platform recently joined hackthebox and vulnlab boxes will become available in hackthebox. For simplicity sake VulnLab and Hackthebox will keep being separate lists
100
LinuxWindowsLinuxWindowsActive Directory and Networks