OSIR Study Plan
Find the compromise, collect the evidence and close out the incident. A free, day-by-day OSIR schedule built from the official IR-200: Foundational Incident Response syllabus, scaled to your exam date and weekly hours.
Syllabus last verified Sep 30, 2026 · changelog
- Approx. cost
- Check vendor
- Difficulty
- ♥♥♥♥♥
- Study time
- about 112h
- Start level
- Junior
> How long does OSIR take?
The plan assumes about 112 study hours. Here is how that stretches across different weekly schedules.
| Hours per week | Time to finish |
|---|---|
| 5 hours | about 23 weeks (5.3 months) |
| 10 hours | about 12 weeks (2.8 months) |
| 15 hours | about 8 weeks (1.8 months) |
| 20 hours | about 6 weeks (1.4 months) |
| 30 hours | about 4 weeks (0.9 months) |
> OSIR exam format
OffSec · IR-200: Foundational Incident Response
- 8-hour exam proctored by an OffSec employee over a private VPN
- Identify compromised systems with Splunk, then run forensic analysis on disk images
- Evaluate the impact of the incident
- No formal prerequisites; TCP/IP, Linux and Windows familiarity recommended
- OSIR valid 3 years, renewable through exams or CPE
> OSIR syllabus and study hours
Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.
Defender Warm-up
The basics the course assumes: networking, both operating systems and Splunk.
- TCP/IP networking refresher4h · learn
- Windows & Linux for responders5h · learn
- Splunk search fundamentals6h · learn
IR-200: Concepts & Lifecycle
Frameworks, teams and how an incident unfolds.
- Incident Response Overview2h · learn
- Fundamentals of Incident Response3h · learn
- Phases of Incident Response3h · learn
- Incident Response Communication Plans2h · learn
- Common Attack Techniques4h · learn
IR-200: Hands-on Response
Detect, investigate, contain, recover and report.
- Incident Detection and Identification5h · learn
- Digital Forensics for Incident Responders5h · learn
- Incident Response Case Management2h · learn
- Active Incident Containment2h · learn
- Incident Eradication and Recovery2h · learn
- Initial Impact Assessment2h · learn
- Post-Mortem Reporting2h · learn
Training Grounds
Run whole investigations, not just modules.
- IR-200 Challenge Lab12h · lab
- Splunk investigation drills15h · lab
- Disk image forensics practice15h · lab
Final Boss Prep
Turn your notes into a workflow you trust on the day.
- Build an IR playbook & tool cheat sheet6h · review
- Practice post-incident write-up5h · review
- Timed 8-hour mock investigation10h · review
> Where to practise for OSIR
Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:
- Blue team challenges (CyberDefenders)
- Boss of the SOC datasets (BOTS) (Splunk)
- Packet capture exercises (Malware-Traffic-Analysis)
- SOC Level 1 path (TryHackMe)
> OSIR exam-day checklist
General logistics for exam week. The official exam guide always takes priority if it differs.
One to two weeks before
- Schedule your exam and add the start time, time zone and deadline to your calendar
- Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
- Have Splunk search patterns ready for finding compromised systems
- Practise forensic analysis of disk images and judging the impact of an incident
- Complete a full-length timed practice run (8 hours if you can) on your exam setup
- Finalize your note-taking setup and templates (see the notes starter below)
- Build and review your cheat sheets and command references
- Arrange time off, tell people you will be unavailable, and plan your meals ahead
- Check your ID is valid and matches the name on your exam account
Machine and network
- Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
- Plug in your laptop and turn off sleep, updates and notifications for the exam
- Test the VPN or lab connection early and know how to reconnect after a drop
- Update your attack VM, take a clean snapshot and keep a spare
- Install and test every tool you plan to use, and check none of them are banned
- Test your screenshot hotkeys and make sure you have plenty of free disk space
Proctoring and room
- Test your webcam, microphone and screen sharing on the proctoring platform
- Clear your desk and room as the rules require, and tell housemates not to interrupt
- Confirm what is allowed at your desk (second monitor, phone, notes, paper) and follow it exactly
- Learn the rules for breaks and for leaving the camera view
- Have your ID ready and know the check-in steps
During the exam
- Sleep well the night before, and skip last-minute cramming
- Prepare food and water, and set timers for break reminders
- Read the brief and scope carefully before you touch anything
- Write notes and capture proof as you go, not at the end
- Time-box each target and move on when stuck. You can come back later
- Stop new attacks with enough time left to verify your evidence
Report and submission (if required)
- Copy your report template and fill in the easy parts (scope, methodology) while you work
- Check every finding has reproducible steps and screenshots
- Proofread: could someone else follow each step?
- Export in the exact format and naming the exam guide requires
- Submit with a buffer before the deadline and confirm it was received
Suggested exam-day rhythm
- Hour 0 to 0:30. Connect, confirm the VPN, read the brief and set up your notes.
- Hour 0:30 to 2. Enumerate everything first. Rank targets by points and how promising they look.
- Through the day. Work in blocks of about 90 minutes with a 10-minute break after each. Time-box each target and rotate when stuck.
- Meals. Eat real meals away from your desk roughly every 5 to 6 hours.
- Around hour 4. Decide on a sleep window of 4 to 6 hours. A rested brain spots what a tired one misses.
- Last 1 hours. Stop new attacks unless you are very close. Verify proof, collect screenshots and outline the report.
- After the hands-on part. Write the report in one focused block, proofread, and submit with a buffer before the deadline.
▶ Open the interactive OSIR exam kit
The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.
> Passed OSIR with PWN PATH
No OSIR debriefs yet
Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.
▶ Share my debriefDebriefs are self-reported. See all pass stories.
> Recent OSIR changes
- Site OSIR, eCPPT, eMAPT, CRTE, BTL1: Added five new certs: OSIR, eCPPT, eMAPT, CRTE and BTL1, with a new Mobile app security track on the roadmap.
- Verified OSIR, CRTE: Checked against the official syllabus
> Frequently asked questions
How long does it take to prepare for OSIR?
PWN PATH builds the OSIR plan on about 112 study hours. At 10 hours a week that is roughly 12 weeks, and at 20 hours a week roughly 6 weeks. Your own timeline depends on how much of the material you already know.
What is the OSIR exam like?
8-hour exam proctored by an OffSec employee over a private VPN. Identify compromised systems with Splunk, then run forensic analysis on disk images. Evaluate the impact of the incident. No formal prerequisites; TCP/IP, Linux and Windows familiarity recommended. OSIR valid 3 years, renewable through exams or CPE.
How hard is OSIR?
We rate OSIR 2 out of 5. It suits defenders who want a hands-on incident response exam built around Splunk and disk forensics. No formal prerequisites. TCP/IP, Linux and Windows familiarity is recommended.
How much does OSIR cost?
Sold through OffSec as the IR-200 course with an exam attempt. Check OffSec for current pricing. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.
What should I study first for OSIR?
Start with the "Defender Warm-up" phase: TCP/IP networking refresher, Windows & Linux for responders, Splunk search fundamentals. The planner puts topics in a sensible order and scales the hours to the time you have.
What are the prerequisites for OSIR?
No formal prerequisites. TCP/IP, Linux and Windows familiarity is recommended.
What should I do the week before the OSIR exam?
Re-read the official exam guide for rules and banned tools, test your machine, network and VPN or lab connection, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.
How should I handle breaks and sleep during the OSIR exam?
Hour 0 to 0:30: Connect, confirm the VPN, read the brief and set up your notes. Hour 0:30 to 2: Enumerate everything first. Rank targets by points and how promising they look. Through the day: Work in blocks of about 90 minutes with a 10-minute break after each. Time-box each target and rotate when stuck. Meals: Eat real meals away from your desk roughly every 5 to 6 hours.
What should I take after OSIR?
Common next steps are OSDA, CDSA. See the roadmap to compare them.
Is the PWN PATH study planner free?
Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.
> Plan your path
Good stepping stones before OSIR:
Where it leads:
More in blue team & soc:
Not sure OSIR is right for you? Take the one-minute cert quiz.