Get your OSEE certification with EXP-401 | OffSec

Train to become OSEE certified

EXP-401: Advanced Windows Exploitation

Level

400
  • Master advanced Windows exploitation in a hands-on live training class by practicing bypass techniques, vulnerability research, and exploit development
  • EXP-401 is only available in-person
  • Earn our most challenging certification, the OffSec Exploitation Expert (OSEE)

About EXP-401 and the OSEE exam

EXP-401 is OffSec's most challenging and advanced course, designed for experienced penetration testers who are ready to tackle complex exploit development. Through in-depth, hands-on labs, learners explore security mitigation bypasses, complex heap manipulations, and 64-bit kernel exploitation, all applied to large, widely used enterprise applications.

AWE is a particularly demanding penetration testing course, requiring a significant amount of learner-instructor interaction. Therefore, we limit AWE courses to an in-person, hands-on environment.

As the most complex course we offer, the EXP-401 requires a significant time investment. Learners need to commit to reading case studies and reviewing the provided reading material each evening. We recommend completing the 300-level certifications before registering for this course.

Upon completing EXP-401, students may attempt the OffSec Exploitation Expert (OSEE) exam. The 72-hour exam challenges learners to discover and exploit unknown vulnerabilities in a controlled virtual lab, and requires submission of a detailed penetration test report that documents techniques, tools, and results. The OSEE exam assesses not only the course content, but also the ability to think laterally and adapt to new challenges.

The exam requires a stable, high-speed internet connection.

Becoming OSEE certified

  • 72-hour proctored exam

  • In-person learning

  • Develop expert-level exploits

  • Become an exploitation expert

OSEE certification

Topics covered in EXP-401

  • Bypass and evasion of user mode security mitigations
  • Advanced heap manipulations
  • Disarming WDEG mitigations and creating version independence
  • Bypass of kernel mode security mitigations

Get your team OSEE certified

OffSec's in-house training brings our Advanced Windows Exploitation course and certification exam to you. Contact us to learn more!

Train my team

Upcoming EXP-401 live training

Aug 2 - Aug 5, 2025

EXP-401

Advanced Windows Exploitation

Location: Las Vegas, NV

Languages: English

Black Hat Register now

Aug 18 - Aug 22, 2025

EXP-401

Advanced Windows Exploitation

Location: Taiwan

Languages: English

OffSec + DevCore Register now

Nov 3 - Nov 7, 2025

EXP-401

Advanced Windows Exploitation

Location: Veenendaal, Netherlands

Languages: English

OffSec + TSTC Register now