OSCP report template in Markdown, with CVSS findings

An OSCP report needs an executive summary, methodology, a results table and one repeatable section per target with proof of every flag. Copy the Markdown skeleton and finding template below, then use the CVSS 3.1 example to rate severity consistently.

Required sections

OffSec asks for a professional penetration test report that documents each compromised target well enough for someone else to repeat your steps. At minimum plan for these parts: an executive summary, the scope and methodology, a results summary, and one section per target with the full attack path, proof of the flags, and the code or commands you used. Check the current OSCP+ reporting requirements on the OffSec help center, which are the authority and can change.

Markdown skeleton

Copy this into your notes before the exam and fill it in as you go.

# OSCP Exam Report

- Candidate: <name>
- OSID: OS-XXXXX
- Exam date: YYYY-MM-DD
- Report version: 1.0

## 1. Executive summary
One paragraph: what was tested, how many targets were compromised, and the overall risk.

## 2. Scope and methodology
Targets and IP ranges, tools used, and the phases you followed (recon, enumeration, exploitation, escalation).

## 3. Results summary
| Target | Local flag | Proof flag | Foothold | Escalation |
| --- | --- | --- | --- | --- |
| 10.x.x.x | yes | yes | short name | short name |

## 4. Active Directory set
### 4.1 <host 1>  (repeat the finding template per host)

## 5. Standalone machines
### 5.1 <host>  (repeat the finding template per host)

## Appendix A: scripts and proof of concept code (pasted as text)
## Appendix B: tools and versions

Finding template

Use one block per vulnerability. Keep the steps specific enough that a reader could follow them without you.

### <Host> : <Vulnerability title>

- Severity: Critical
- CVSS 3.1: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Affected: 10.x.x.x:port (service and version)

#### Description
What is wrong and why it matters, in two or three sentences.

#### Steps to reproduce
1. Enumeration command and the result that matters.
2. The exact request or command that gives the foothold.
3. The escalation step.

#### Proof
[screenshot: contents of the proof file with the target IP address visible]

#### Remediation
The specific fix: patch level, configuration change, or control.

CVSS 3.1 worked example

An unauthenticated remote code execution flaw in a network service is the classic maximum. Its vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and the base score is 9.8 (Critical).

MetricMeaningReadingWeight
AV:NAttack Vector: NetworkExploitable remotely0.85
AC:LAttack Complexity: LowNo special conditions0.77
PR:NPrivileges Required: NoneNo account needed0.85
UI:NUser Interaction: NoneNo victim action0.85
S:UScope: UnchangedImpact stays in the vulnerable component-
C:H / I:H / A:HConfidentiality, Integrity, Availability: HighFull compromise0.56 each

With Scope Unchanged, the impact sub score is 6.42 times the ISS, where ISS is 1 minus the product of (1 minus each impact weight). All three at 0.56 gives an ISS of 0.915 and an impact of 5.87. Exploitability is 8.22 times the four exploit weights, which is 3.89. The sum, 9.76, is rounded up to 9.8. The CVSS 3.1 scale rates 9.0 to 10.0 as Critical. If the same flaw needed a low privilege account (PR:L), the score would drop to 8.8 (High).

Proof screenshot rules

OffSec's guidance expects the content of each proof file to be visible in a screenshot together with the target IP address, taken from an interactive shell on the machine rather than a copy pasted into a document. Confirm the exact wording on the live page. In practice:

Packaging and submission

  1. Finish the report and export it as a PDF.
  2. Name it OSCP-OS-XXXXX-Exam-Report.pdf with your own OSID.
  3. Put only that PDF in a .7z archive with the matching name and no password.
  4. Upload before the deadline, which per OffSec is 24 hours after the exam ends.

Generate it in ZeroBox

The ZeroBox exam report generator turns your session into this structure. It records proof screenshots against each flag, takes findings with a CVSS 3.1 vector, sorts them by severity, and exports Markdown or a standalone HTML report. The submission bundle is a .zip holding report.md, report.html, a proofs/ folder, findings.json and a README. OffSec wants a PDF in a .7z, so print report.html to PDF and archive it yourself. Rehearse that whole path in a mock exam from the exam simulator, and see the time budget guide for when to start writing.

Write the report as you hack.

ZeroBox keeps proof screenshots, findings and CVSS vectors per target and exports Markdown, HTML and a zip bundle.

Frequently asked questions

What format does OffSec want for the OSCP report?

Per OffSec's reporting requirements, the report is a PDF inside a .7z archive, named with your OSID, with no password and no other file types. Scripts and proof of concept code go into the PDF as text. Confirm the exact rules on the live OffSec help center page before you submit.

Do I need a CVSS score for every finding?

A CVSS 3.1 vector and score make severity consistent and easy to check, so most good reports include one. Confirm what the current OffSec guidance asks for, then use the vector to justify the rating either way.

Can ZeroBox produce the PDF OffSec asks for?

Not directly. ZeroBox generates the report as Markdown and as a standalone HTML file you can print to PDF from a browser, and its zip bundle holds both with your proof screenshots. You then put the PDF in a .7z yourself.

Related

Sources

Last reviewed: 2026-10-08. ZeroBox is an independent project and is not affiliated with OffSec or Hack The Box.