OSCP report template in Markdown, with CVSS findings
An OSCP report needs an executive summary, methodology, a results table and one repeatable section per target with proof of every flag. Copy the Markdown skeleton and finding template below, then use the CVSS 3.1 example to rate severity consistently.
Required sections
OffSec asks for a professional penetration test report that documents each compromised target well enough for someone else to repeat your steps. At minimum plan for these parts: an executive summary, the scope and methodology, a results summary, and one section per target with the full attack path, proof of the flags, and the code or commands you used. Check the current OSCP+ reporting requirements on the OffSec help center, which are the authority and can change.
Markdown skeleton
Copy this into your notes before the exam and fill it in as you go.
# OSCP Exam Report
- Candidate: <name>
- OSID: OS-XXXXX
- Exam date: YYYY-MM-DD
- Report version: 1.0
## 1. Executive summary
One paragraph: what was tested, how many targets were compromised, and the overall risk.
## 2. Scope and methodology
Targets and IP ranges, tools used, and the phases you followed (recon, enumeration, exploitation, escalation).
## 3. Results summary
| Target | Local flag | Proof flag | Foothold | Escalation |
| --- | --- | --- | --- | --- |
| 10.x.x.x | yes | yes | short name | short name |
## 4. Active Directory set
### 4.1 <host 1> (repeat the finding template per host)
## 5. Standalone machines
### 5.1 <host> (repeat the finding template per host)
## Appendix A: scripts and proof of concept code (pasted as text)
## Appendix B: tools and versions
Finding template
Use one block per vulnerability. Keep the steps specific enough that a reader could follow them without you.
### <Host> : <Vulnerability title>
- Severity: Critical
- CVSS 3.1: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Affected: 10.x.x.x:port (service and version)
#### Description
What is wrong and why it matters, in two or three sentences.
#### Steps to reproduce
1. Enumeration command and the result that matters.
2. The exact request or command that gives the foothold.
3. The escalation step.
#### Proof
[screenshot: contents of the proof file with the target IP address visible]
#### Remediation
The specific fix: patch level, configuration change, or control.
CVSS 3.1 worked example
An unauthenticated remote code execution flaw in a network service is the classic maximum. Its vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and the base score is 9.8 (Critical).
| Metric | Meaning | Reading | Weight |
|---|---|---|---|
AV:N | Attack Vector: Network | Exploitable remotely | 0.85 |
AC:L | Attack Complexity: Low | No special conditions | 0.77 |
PR:N | Privileges Required: None | No account needed | 0.85 |
UI:N | User Interaction: None | No victim action | 0.85 |
S:U | Scope: Unchanged | Impact stays in the vulnerable component | - |
C:H / I:H / A:H | Confidentiality, Integrity, Availability: High | Full compromise | 0.56 each |
With Scope Unchanged, the impact sub score is 6.42 times the ISS, where ISS is 1 minus the product of (1 minus each impact weight). All three at 0.56 gives an ISS of 0.915 and an impact of 5.87. Exploitability is 8.22 times the four exploit weights, which is 3.89. The sum, 9.76, is rounded up to 9.8. The CVSS 3.1 scale rates 9.0 to 10.0 as Critical. If the same flaw needed a low privilege account (PR:L), the score would drop to 8.8 (High).
Proof screenshot rules
OffSec's guidance expects the content of each proof file to be visible in a screenshot together with the target IP address, taken from an interactive shell on the machine rather than a copy pasted into a document. Confirm the exact wording on the live page. In practice:
- Capture the command that prints the flag and the command that shows the IP in one frame.
- Take the screenshot the moment you get the flag, not at the end of the exam.
- Name files by host and flag so you can find them at 3am.
Packaging and submission
- Finish the report and export it as a PDF.
- Name it
OSCP-OS-XXXXX-Exam-Report.pdfwith your own OSID. - Put only that PDF in a
.7zarchive with the matching name and no password. - Upload before the deadline, which per OffSec is 24 hours after the exam ends.
Generate it in ZeroBox
The ZeroBox exam report generator turns your session into this structure. It records proof screenshots against each flag, takes findings with a CVSS 3.1 vector, sorts them by severity, and exports Markdown or a standalone HTML report. The submission bundle is a .zip holding report.md, report.html, a proofs/ folder, findings.json and a README. OffSec wants a PDF in a .7z, so print report.html to PDF and archive it yourself. Rehearse that whole path in a mock exam from the exam simulator, and see the time budget guide for when to start writing.
Write the report as you hack.
ZeroBox keeps proof screenshots, findings and CVSS vectors per target and exports Markdown, HTML and a zip bundle.
Frequently asked questions
What format does OffSec want for the OSCP report?
Per OffSec's reporting requirements, the report is a PDF inside a .7z archive, named with your OSID, with no password and no other file types. Scripts and proof of concept code go into the PDF as text. Confirm the exact rules on the live OffSec help center page before you submit.
Do I need a CVSS score for every finding?
A CVSS 3.1 vector and score make severity consistent and easy to check, so most good reports include one. Confirm what the current OffSec guidance asks for, then use the vector to justify the rating either way.
Can ZeroBox produce the PDF OffSec asks for?
Not directly. ZeroBox generates the report as Markdown and as a standalone HTML file you can print to PDF from a browser, and its zip bundle holds both with your proof screenshots. You then put the PDF in a .7z yourself.
Related
- OSCP exam scoring and 24h time budget
- Exam simulator
- Pentest methodology checklist
- TJ Null OSCP list
- Pentest cheatsheet library
Sources
- OffSec Help Center: OSCP+ Reporting Requirements
- OffSec Help Center: OSCP+ Exam Guide
- FIRST: CVSS v3.1 Specification Document
Last reviewed: 2026-10-08. ZeroBox is an independent project and is not affiliated with OffSec or Hack The Box.