The Offensive Development Practitioner Certification (ODPC) is designed to push beyond traditional offensive security training into the realm of
offensive engineering and real-world evasion. This is not a guided course where tools are handed to you,
it is an environment where you are expected to understand how things work under the hood, adapt new techniques, and build your own custom solutions under pressure.
Me, The Exam & My Experience
A Real Test of Offensive Capability Under Pressure
Why Did I Take the Exam?
From failure to proving ground
It didn’t start with ODPC, OSEP, or even malware development. It started the day I realized I wasn’t as ready as I thought.
After earning my
OSEP, I visited a friend’s office, confident in what I had achieved. That confidence didn’t last long, I was challenged by them to bypass one of their
security solutions and I accepted. Long story short, I failed, completely and multiple times. No partial success, no workaround just a hard stop that exposed the gap between theory and real execution.
I drove back home feeling like I had lost the battle while others were celebrating victory. From that moment, everything changed. I went home, fired up my machine, and started building. Not just running
tools,no more “skiddy” work, but breaking them, fixing them, rewriting them, and understanding why they didn’t work… and why they eventually did.
After hours of trial and failure, I achieved my first real bypass. The next day, I returned back to the battlefield and this time, I didn’t fail, I won I got my callback while the SOC team remained completely
blind, with no alerts triggered on their dashboard
As I continued improving and demonstrating my work, I started hearing the noise: “IronHulk is fake”, “he just exclude his tools”, “he’s a skid chasing attention.”
I never blamed them, cuse most of my work stayed behind the scenes but that noise became fuel. I wasn’t looking for another course, I was looking for a real environment, something that enforces difficulty,
not simulates it and definitely not CFT thing nor pentesting. That’s when I met
KillSwitch, he introduced me to ODPC and told me how difficult it is, and how few people have actually earned the certification.
I started to research about the program, understood what it demanded, how systems are hardened, multiple layers of defense, no shortcuts, no CTF games, and it stood out immediately, exactly what I was looking for.
I didn’t hesitate. I bought the exam voucher and started building my tooling. Here’s what I did:
-
As the creator and developer of my private C2 server, “IronGate”,
I built a new C2 from scratch specifically for the ODPC exam.
-
Since I had to share my tools for validation, I rewrote my tooling and leveraged what I learned from
Maldev Academy, modifying and improving both their material
and selected open-source tools.
I prepared everything independently, and this was no longer about passing, it was about proving to myself that I can bypass hardened environments.
The Exam
Hardened enterprise conditions
The exam environment is deliberately hardened to reflect real-world enterprise conditions. You are placed into multiple RDP sessions across
four machines, each configured with different security controls, policies, and EDR solutions.
Defenses are fully active and enforced: EDR, WDAC, AMSI, Constrained Language Mode (CLM),
Strict Application Control, CIS Benchmark hardening, PowerShell restrictions, and tightly configured
inbound/outbound firewall rules. There is no ability to disable protections, no privilege escalation, and no reliance on execution paths.
You start with nothing, only an RDP session and limited access. Each lab contains
three objectives, and success depends entirely on your ability to operate within these constraints
without breaking policy enforcement.
My Experience
Pressure, failure, adaptation
From the first hour, the difficulty was clear. I was completely lost, no clear starting point, no obvious path forward.
I had internet access from the lab machine, and I can download files, but nothing would execute. Every attempt was blocked, and progress felt nonexistent.
After nearly six hours of trial and failure, the pressure started to build. That was the turning point. Instead of forcing execution,
I shifted perspective, thinking from a defensive mindset. Understanding how controls behave, how they block, and why they trigger
became the key.
As an example, in one of the labs, I began analyzing behavior rather than just running tools. Interestingly, my tooling wasn’t flagged as malware, it was being restricted
by policy, returning messages like "admin restriction".
That distinction changed everything, it meant the problem wasn’t detection, it was security policy enforcement.
From there, I started digging deeper into the environment, understanding the controls, and adapting my approach accordingly.
Once the first path opened, momentum followed. What initially felt impossible became a sequence of controlled, calculated progress
across the remaining labs.
No Spoilers: I won’t reveal the techniques or solutions, it's not a feary tail sotry to tell. The real value of this challenge lies in the process of discovery,
where every failure teaches you something the solution alone never could.
Do not give up early, the first hours are meant to break your assumptions. Progress comes after persistence,
after failure, after stepping back and rethinking your approach.
WKL existed since 2016, and only a handful of individuals have achieved ODPC. When it is described as difficult,
it is not an exaggeration, it is a reflection of the level required to succeed.
My final advice: ODPC is a proving ground battlefield. It’s not about theory; it’s about your ability to bypass hardened systems,
and that is very different from simply buying an AV or deploying an EDR with default settings. This is an entirely different layer of defense.
I also recommend to stop relying on other people’s or ready-made tools, or at least improve them, but building your own tools from custom loaders to your
own C2 and beacon is great vectory. This exam is not for those who depend on GitHub or public tooling; it is for operators who understand, build, and control
every part of their tradecraft.
In the end, I wish the best of luck to everyone preparing to take the exam, and congratulations to those who have successfully passed it.