OSIR Study Plan

Find the compromise, collect the evidence and close out the incident. A free, day-by-day OSIR schedule built from the official IR-200: Foundational Incident Response syllabus, scaled to your exam date and weekly hours.

Syllabus last verified Sep 30, 2026 · changelog

Approx. cost
Check vendor
Difficulty
♥♥♥♥♥
Study time
about 112h
Start level
Junior

▶ Build my OSIR plan

> How long does OSIR take?

The plan assumes about 112 study hours. Here is how that stretches across different weekly schedules.

Hours per weekTime to finish
5 hoursabout 23 weeks (5.3 months)
10 hoursabout 12 weeks (2.8 months)
15 hoursabout 8 weeks (1.8 months)
20 hoursabout 6 weeks (1.4 months)
30 hoursabout 4 weeks (0.9 months)

> OSIR exam format

OffSec · IR-200: Foundational Incident Response

  • 8-hour exam proctored by an OffSec employee over a private VPN
  • Identify compromised systems with Splunk, then run forensic analysis on disk images
  • Evaluate the impact of the incident
  • No formal prerequisites; TCP/IP, Linux and Windows familiarity recommended
  • OSIR valid 3 years, renewable through exams or CPE

Official OSIR page ↗

> OSIR syllabus and study hours

Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.

Defender Warm-up

The basics the course assumes: networking, both operating systems and Splunk.

  • TCP/IP networking refresher4h · learn
  • Windows & Linux for responders5h · learn
  • Splunk search fundamentals6h · learn

IR-200: Concepts & Lifecycle

Frameworks, teams and how an incident unfolds.

  • Incident Response Overview2h · learn
  • Fundamentals of Incident Response3h · learn
  • Phases of Incident Response3h · learn
  • Incident Response Communication Plans2h · learn
  • Common Attack Techniques4h · learn

IR-200: Hands-on Response

Detect, investigate, contain, recover and report.

  • Incident Detection and Identification5h · learn
  • Digital Forensics for Incident Responders5h · learn
  • Incident Response Case Management2h · learn
  • Active Incident Containment2h · learn
  • Incident Eradication and Recovery2h · learn
  • Initial Impact Assessment2h · learn
  • Post-Mortem Reporting2h · learn

Training Grounds

Run whole investigations, not just modules.

  • IR-200 Challenge Lab12h · lab
  • Splunk investigation drills15h · lab
  • Disk image forensics practice15h · lab

Final Boss Prep

Turn your notes into a workflow you trust on the day.

  • Build an IR playbook & tool cheat sheet6h · review
  • Practice post-incident write-up5h · review
  • Timed 8-hour mock investigation10h · review

> Where to practise for OSIR

Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:

> OSIR exam-day checklist

General logistics for exam week. The official exam guide always takes priority if it differs.

One to two weeks before

  • Schedule your exam and add the start time, time zone and deadline to your calendar
  • Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
  • Have Splunk search patterns ready for finding compromised systems
  • Practise forensic analysis of disk images and judging the impact of an incident
  • Complete a full-length timed practice run (8 hours if you can) on your exam setup
  • Finalize your note-taking setup and templates (see the notes starter below)
  • Build and review your cheat sheets and command references
  • Arrange time off, tell people you will be unavailable, and plan your meals ahead
  • Check your ID is valid and matches the name on your exam account

Machine and network

  • Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
  • Plug in your laptop and turn off sleep, updates and notifications for the exam
  • Test the VPN or lab connection early and know how to reconnect after a drop
  • Update your attack VM, take a clean snapshot and keep a spare
  • Install and test every tool you plan to use, and check none of them are banned
  • Test your screenshot hotkeys and make sure you have plenty of free disk space

Proctoring and room

  • Test your webcam, microphone and screen sharing on the proctoring platform
  • Clear your desk and room as the rules require, and tell housemates not to interrupt
  • Confirm what is allowed at your desk (second monitor, phone, notes, paper) and follow it exactly
  • Learn the rules for breaks and for leaving the camera view
  • Have your ID ready and know the check-in steps

During the exam

  • Sleep well the night before, and skip last-minute cramming
  • Prepare food and water, and set timers for break reminders
  • Read the brief and scope carefully before you touch anything
  • Write notes and capture proof as you go, not at the end
  • Time-box each target and move on when stuck. You can come back later
  • Stop new attacks with enough time left to verify your evidence

Report and submission (if required)

  • Copy your report template and fill in the easy parts (scope, methodology) while you work
  • Check every finding has reproducible steps and screenshots
  • Proofread: could someone else follow each step?
  • Export in the exact format and naming the exam guide requires
  • Submit with a buffer before the deadline and confirm it was received

Suggested exam-day rhythm

  • Hour 0 to 0:30. Connect, confirm the VPN, read the brief and set up your notes.
  • Hour 0:30 to 2. Enumerate everything first. Rank targets by points and how promising they look.
  • Through the day. Work in blocks of about 90 minutes with a 10-minute break after each. Time-box each target and rotate when stuck.
  • Meals. Eat real meals away from your desk roughly every 5 to 6 hours.
  • Around hour 4. Decide on a sleep window of 4 to 6 hours. A rested brain spots what a tired one misses.
  • Last 1 hours. Stop new attacks unless you are very close. Verify proof, collect screenshots and outline the report.
  • After the hands-on part. Write the report in one focused block, proofread, and submit with a buffer before the deadline.

▶ Open the interactive OSIR exam kit

The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.

> Passed OSIR with PWN PATH

No OSIR debriefs yet

Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.

▶ Share my debrief

Debriefs are self-reported. See all pass stories.

> Recent OSIR changes

  1. Site OSIR, eCPPT, eMAPT, CRTE, BTL1: Added five new certs: OSIR, eCPPT, eMAPT, CRTE and BTL1, with a new Mobile app security track on the roadmap.
  2. Verified OSIR, CRTE: Checked against the official syllabus

Full changelog

> Frequently asked questions

How long does it take to prepare for OSIR?

PWN PATH builds the OSIR plan on about 112 study hours. At 10 hours a week that is roughly 12 weeks, and at 20 hours a week roughly 6 weeks. Your own timeline depends on how much of the material you already know.

What is the OSIR exam like?

8-hour exam proctored by an OffSec employee over a private VPN. Identify compromised systems with Splunk, then run forensic analysis on disk images. Evaluate the impact of the incident. No formal prerequisites; TCP/IP, Linux and Windows familiarity recommended. OSIR valid 3 years, renewable through exams or CPE.

How hard is OSIR?

We rate OSIR 2 out of 5. It suits defenders who want a hands-on incident response exam built around Splunk and disk forensics. No formal prerequisites. TCP/IP, Linux and Windows familiarity is recommended.

How much does OSIR cost?

Sold through OffSec as the IR-200 course with an exam attempt. Check OffSec for current pricing. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.

What should I study first for OSIR?

Start with the "Defender Warm-up" phase: TCP/IP networking refresher, Windows & Linux for responders, Splunk search fundamentals. The planner puts topics in a sensible order and scales the hours to the time you have.

What are the prerequisites for OSIR?

No formal prerequisites. TCP/IP, Linux and Windows familiarity is recommended.

What should I do the week before the OSIR exam?

Re-read the official exam guide for rules and banned tools, test your machine, network and VPN or lab connection, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.

How should I handle breaks and sleep during the OSIR exam?

Hour 0 to 0:30: Connect, confirm the VPN, read the brief and set up your notes. Hour 0:30 to 2: Enumerate everything first. Rank targets by points and how promising they look. Through the day: Work in blocks of about 90 minutes with a 10-minute break after each. Time-box each target and rotate when stuck. Meals: Eat real meals away from your desk roughly every 5 to 6 hours.

What should I take after OSIR?

Common next steps are OSDA, CDSA. See the roadmap to compare them.

Is the PWN PATH study planner free?

Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.

> Plan your path

Good stepping stones before OSIR:

Where it leads:

More in blue team & soc:

Not sure OSIR is right for you? Take the one-minute cert quiz.