Skip to main content

Certifications & Training

My professional development focuses on offensive security, exploit development, web application security, red-team operations, malware analysis, reverse engineering, and Windows internals.

This page separates completed certifications from current and planned advanced training.


OffSec Certifications #

OSCE³ - Offensive Security Certified Expert 3 #

The OSCE³ designation is awarded after earning all three OffSec 300-level certifications:

  • OSED - Offensive Security Exploit Developer
  • OSEP - Offensive Security Experienced Penetration Tester
  • OSWE - Offensive Security Web Expert

This certification path strengthened my knowledge of Windows exploit development, advanced penetration testing, evasive tradecraft, source-code review, and web application exploitation.


OSED - Offensive Security Exploit Developer #

Primary areas covered:

  • Windows exploit development
  • x86 assembly
  • Stack-based memory corruption
  • DEP and ASLR bypasses
  • Return-oriented programming
  • Shellcode development
  • Reverse engineering
  • WinDbg automation

Many of the exploit-development and Windows-internals articles published on PentestHacks were influenced by the skills developed during this training.


OSEP - Offensive Security Experienced Penetration Tester #

Primary areas covered:

  • Advanced penetration testing
  • Active Directory attacks
  • Network-filtering bypasses
  • Application allow-listing bypasses
  • Lateral movement
  • Credential access
  • Evasion techniques
  • Offensive PowerShell and C#

OSWE - Offensive Security Web Expert #

Primary areas covered:

  • White-box web application testing
  • Source-code review
  • Authentication bypasses
  • Injection vulnerabilities
  • Deserialization
  • Server-side attacks
  • Exploit development and automation

OSCP - Offensive Security Certified Professional #

The OSCP established a practical foundation in:

  • Network penetration testing
  • Enumeration
  • Exploitation
  • Linux and Windows privilege escalation
  • Active Directory fundamentals
  • Technical reporting

Red Teaming #

HTB APTLabs - Red Team Operator Level III #

This certification evaluates practical red-team and adversary-simulation skills in complex enterprise environments.

Primary areas covered:

  • Active Directory exploitation
  • Lateral movement
  • Credential abuse
  • Trust relationships
  • Operational planning
  • Post-exploitation
  • Enterprise attack paths

Malware Development and Reverse Engineering #

MalDev Academy Certified #

Training focused on Windows malware-development concepts and the internal mechanisms used by offensive tooling.

Topics included:

  • Windows API programming
  • Process injection
  • Payload execution
  • API hashing
  • Evasion concepts
  • Windows internals
  • C and C++ development

IMBT - Introduction to Malware Binary Triage #

Completed through InvokeRE.

The training developed practical skills in:

  • Static malware analysis
  • Dynamic analysis
  • Binary triage
  • Reverse engineering
  • Windows API analysis
  • Identifying malware capabilities
  • Writing technical analysis reports

Malware Analyst Professional - Level 1 #

Completed through TrainSec.

The certification covered foundational malware-analysis methodology, including:

  • Static analysis
  • Dynamic analysis
  • Behavioral investigation
  • Indicators of compromise
  • Malware reporting

Current Training #

AMBT - Advanced Malware Binary Triage, Binary Ninja Edition #

Currently progressing through InvokeRE’s advanced malware-analysis training using Binary Ninja.

The course supports my continued development in:

  • Advanced static analysis
  • Binary Ninja workflows
  • Malware capability identification
  • Reverse-engineering methodology
  • Analyst automation
  • Technical reporting

CRTO - Certified Red Team Operator #

The CRTO course material has been completed, and preparation for the practical examination is ongoing.

The training focuses on:

  • Command-and-control operations
  • Active Directory tradecraft
  • Kerberos attacks
  • Credential access
  • Lateral movement
  • Privilege escalation
  • Operational security
  • Adversary emulation

CRTO will be moved to the completed-certifications section after the examination is successfully passed.


Planned Advanced Training #

Zero2Automated - Advanced Malware Analysis #

Zero2Automated has been purchased and is planned after completing AMBT and the CRTO examination.

The course is part of my longer-term development in:

  • Real-world malware analysis
  • Malware loaders
  • Unpacking
  • Process injection
  • Shellcode analysis
  • Anti-analysis techniques
  • Persistence
  • Malware configuration extraction
  • Python-based analyst automation
  • YARA development
  • Malware-family research

It is listed here as planned training and should not be interpreted as completed coursework or certification.


Long-Term Development #

My continued research and training roadmap includes:

  • Malware reverse engineering
  • Binary Ninja
  • Ghidra
  • Windows internals
  • Exploit development
  • Heap exploitation
  • Vulnerability research
  • Red-team operations
  • AI-assisted reverse engineering
  • Private RAG and MCP-assisted research workflows

Certifications represent completed milestones. Continued experimentation, research, and practical application are what turn those milestones into lasting expertise.


Author
mzdaemon
Offensive Security, Penetration Tester, Red Teaming