Alla leverantörer

Vendor lineage

OffSec (Offensive Security)

Gives the tool away and charges for the proof that you can use it.

Mati Aharoni started what became Offensive Security around 2007 - the company was incorporated in 2008 - working from his living room with his wife Iris, and Wikipedia names Devon Kearns as co-founder. It makes Kali Linux, maintains ExploitDB, and issues the OSCP, whose 24-hour practical examination has a reputation that most certifications would trade a great deal for.

The lineage of the tool runs backwards through two mergers. BackTrack first appeared in May 2006, formed by combining WHAX - Aharoni's own Slax-based distribution, earlier called Whoppix and based on Knoppix - with the Auditor Security Collection. It ran on Slackware for three versions, moved to Ubuntu for two more, and ended at 5 R3 in August 2012. In March 2013 the team rebuilt it on Debian and released it as Kali Linux, which is a harder decision than it sounds: throwing away a distribution with an established name and a large user base, in favour of a foundation that made packaging and long-term maintenance tractable. They chose the maintainable base over the familiar name, which is the correct call and almost never the popular one.

The business model is worth stating plainly because it inverts the usual one. The tool is free and the proof is expensive. Kali costs nothing, is open source, and is used by people who will never buy anything. What OffSec sells is training and certification - and the free tool is what builds the audience for it. Compare that with the vendors elsewhere on this timeline who sell the product and give away the training; both models work, and they select for entirely different kinds of customer.

And then the assessment, which is the reason this entry sits beside Pearson VUE and Prometric rather than apart from them. Those companies exist to run controlled examinations in supervised rooms, where the question is whether the right person answered. The OSCP does the opposite: twenty-four hours, real machines on a test network, compromise them, then write the report. The exam is the work rather than a proxy for it. You cannot bluff a shell you did not get.

That inverts the trust problem rather than solving it, and the inversion has a documented cost. A multiple-choice examination can be memorised, which is why the delivery companies invest so heavily in verifying that the person in the chair is the candidate. A practical examination cannot be bluffed - but the target machines are reusable, so knowing them in advance is the cheat. In 2019 a critic published a walkthrough of one exam machine and threatened more, alleging that cheating was widespread and that the certification's value was being eroded from inside.

Put the two failure modes side by side and the general principle falls out. Every assessment model is vulnerable in exactly the place its strength comes from. Standardisation makes an exam scalable and memorisable. Realism makes an exam unfakeable and leakable. There is no design that is strong in both directions, which is why the serious question about any certification is not whether it can be gamed but which way it can be gamed, and whether the people relying on it know.

Aharoni left in 2019 after more than two decades in security. Jim O'Gorman took over as Kali project lead, with Raphaël Hertzog - a Debian developer - as a third technical pillar. The founder leaving without the project faltering is worth noting, because the timeline elsewhere records several tools that did not survive their author's departure.

The distribution also carries a cultural footprint disproportionate to its user count, having appeared repeatedly in *Mr. Robot* - which is the rare case of screen technology being accurate enough that practitioners were not embarrassed by it.

The timeline

  1. Ninety thousand downloads in five days

    Kali's reception on release. The number matters because it settles a question the rebuild raised: whether an established user base would follow a distribution to a new foundation and a new name. It did, immediately.

  2. Outside money, and a change of chair

    The first venture capital investment, from Spectrum Equity, and a new chief executive. The previous one had run the company from the Philippines for four years - which is a fair description of what it had been until then, and of how much the funding changed.

  3. Offensive Security becomes OffSec

    March. The shorter name arrived alongside a broader course catalogue, which is usually what a shortened name signals.

Flagship products and solutions

  • Kali LinuxThe distribution, free and open source, and the platform every course is taught on. It is simultaneously the product, the marketing and the entrance to the funnel.
  • Kali NetHunterThe mobile build, for testing from a phone rather than a laptop - which matters in physical engagements where carrying a laptop is the thing that gets noticed.
  • ExploitDBThe exploit archive, maintained as a public resource. Anybody researching a vulnerability ends up here eventually, whether or not they have heard of the company.
  • The certification ladderOSCP as the entry point, with more advanced examinations in exploit development, web application attack and evasion above it. Each is practical, and each takes considerably longer than the equivalent in any other programme.
  • Metasploit Unleashed and VulnHubFree training material and deliberately vulnerable machines to practise against - the tier below the paid courses, and the reason people arrive already committed.

Key innovations

  • An experiment is worth a thousand theoriesThe founder's own formulation, and the pedagogy in one line: you cannot know whether a defence works by reasoning about it, only by attacking it. Every course this company sells follows from that sentence, and so does the shape of its examinations.
  • Try Harder as a support policyThe motto is usually quoted as a slogan and functions as something harsher: it is what students are told instead of an answer. Refusing to help is an unusual thing to build a training brand on, and it selects hard for the kind of person who will keep going without being rescued - which is either the point or the criticism, depending on who is describing it.
  • Giving the whole toolkit awayHundreds of tools, packaged, maintained and free, used daily by people who will never pay anything. The maintenance burden is real and continuous, and it is carried because the distribution is what makes the certification mean something: the examination is credible precisely because everybody has the same tools available.

Main markets

Individual practitioners paying their own money far more often than employers paying for them, plus corporate security teams and government. The buyer is frequently the person sitting the exam, which is unusual in a market where certification is normally an employer's purchase and explains a good deal about how the courses are priced and written.

It competes with the vendor-neutral certification bodies elsewhere on this timeline and with the vendors' own security tracks, on a proposition none of them makes: that the assessment is the work itself rather than a description of it.

Analyst standing

  • There is no analyst coverage of a private training company of this size, and the relevant assessment is reputational rather than financial: hiring managers in offensive security treat the OSCP as evidence in a way they treat few other credentials.
  • The commercial question is separate from the assessment one the entry above discusses, and less often asked. A credential whose worth rests on scarcity is in tension with a business that grows by selling more of it, and an owner with outside investors has a view on which of those matters. Nothing in the record so far settles it either way.
From the company