OSCP AD Set V4 vs V5 practice is most useful when you compare how users, credentials, service accounts, Windows hosts, and Active Directory relationships combine into different attack paths.
Both environments feature identities such as a.betty, g.jarvis, u.gregory, and svc_mssql, but the important lesson is not memorizing which account supposedly comes next. Instead, use each AD set to practice a repeatable process for turning a small piece of authenticated access into deeper visibility across a Windows domain.
A useful methodology for both sets is:
Initial Access → Domain Enumeration → User/Service Mapping → Credential Discovery → Lateral Movement → Privilege Escalation → Re-enumeration
That process is directly relevant to current OSCP+ preparation because Active Directory remains a major part of the exam and OffSec’s current objectives.
OSCP AD Set V4 vs V5 at a Glance
The biggest value in comparing the two sets is seeing how the same methodology can produce different attack paths.
| Area | AD Set V4 | AD Set V5 |
|---|---|---|
| User Enumeration | a.betty, g.jarvis, u.gregory and related identities | Users plus service-account relationships |
| Credentials | Files, shares, reuse and authenticated access | Credentials connected to services and additional hosts |
| Service Accounts | Investigate when discovered | svc_mssql becomes especially relevant |
| MSSQL | Context-dependent | Important enumeration surface |
| Kerberos | SPNs and service relationships | Service-account relationships deserve close attention |
| Lateral Movement | Follow identity-to-host relationships | Follow identity, service and host relationships |
| Core Lesson | Build the attack graph | Re-enumerate when the obvious path stops |
The exact exploitation sequence should not be treated as universal. What matters is understanding why a discovered identity, credential, or service changes your available attack surface.
AD Set V4: Map Users Before Chasing Exploits
The OSCP AD Set V4 vs V5 comparison starts with one of the most transferable Active Directory skills: user enumeration.
Accounts such as:
a.betty
g.jarvis
u.gregory
may initially appear to be ordinary domain users.
That does not make them irrelevant.
For each identity, determine:
- group membership;
- accessible SMB shares;
- remote-access permissions;
- files and documents;
- application access;
- service relationships;
- delegated permissions;
- credential exposure;
- authentication scope.
A useful relationship map is:
User → Group → Permission → Resource → Host
Do not evaluate a user only by their username or obvious group memberships.
A low-privileged identity can still become important if it can read a sensitive share, access an internal application, authenticate to another host, or expose credentials belonging to another account.
a.betty and g.jarvis
When identities such as a.betty or g.jarvis appear during enumeration, first establish what changes after authenticating as them.
Compare anonymous and authenticated visibility.
Look at:
SMB → LDAP → Files → Groups → Services → Remote Access
If a new identity exposes information you could not previously see, update your attack map.
The question should always be:
What can this account access that my previous identity could not?
That prevents you from wasting time simply collecting usernames.
u.gregory: Why Low-Privilege Users Still Matter
u.gregory is another important entity in the existing V4/V5 content.
The useful lesson here is broader than the account itself.
An ordinary-looking domain user may become relevant through:
- nested group membership;
- delegated permissions;
- accessible shares;
- stored credentials;
- application access;
- password reuse;
- remote authentication;
- control over another AD object.
Instead of labeling an account as “low privilege” and moving on, record:
Identity → Direct Rights → Indirect Rights → Accessible Resources
Active Directory attack paths frequently depend on indirect relationships.
This is also where graph-based thinking becomes valuable. Whether you map relationships manually or use an allowed tool, the objective is the same: identify how one identity connects to another resource or privilege boundary.
Preparing for OSCP+ Active Directory?
Practice multiple AD sets so you learn to recognize relationships rather than memorize one solution. Our OSCP collection includes AD Set V4/V5 material, additional Active Directory scenarios, standalone machines, and exam-focused resources.
✓ Instant digital delivery · ✓ Free updates · ✓ Multiple OSCP AD Sets
→ Get OSCP+ AD Set Exam Material
AD Set V5: svc_mssql and Service-Driven Enumeration
The OSCP AD Set V4 vs V5 comparison becomes particularly useful when service accounts enter the picture.
svc_mssql immediately suggests a relationship with Microsoft SQL Server.
But a name is only a clue.
Do not assume:
svc_mssql = privileged
Instead verify:
Account → SPN → MSSQL → Host → Permissions
Investigate:
- Service Principal Names;
- group memberships;
- MSSQL authentication;
- database permissions;
- SQL Server roles;
- linked servers;
- service ownership;
- remote authentication;
- Windows privileges;
- accessible configuration.
This approach separates enumeration from assumption.
MSSQL as Part of the Attack Path
If MSSQL is available, determine what the current identity can actually do.
Map:
Credential → SQL Authentication → SQL Privilege → Server Capability → Windows Context
Useful questions include:
- Which account is authenticated?
- Which databases are accessible?
- What server roles exist?
- Is impersonation possible?
- Are linked servers configured?
- Which Windows account runs the SQL service?
- Does SQL access expose another credential or system relationship?
The goal is not simply finding SQL Server.
The goal is understanding whether SQL Server changes the attack path.
svc_mssql and Kerberos
A service account may also be associated with an SPN.
That makes Kerberos enumeration relevant.
Conceptually:
Service Account → SPN → Kerberos Service → Credential Security → Resulting Access
Kerberoasting may be relevant in an authorized lab when the configuration supports it, but the existence of an SPN does not automatically mean that it is the intended or useful attack path.
Always validate the environment first.
If a service credential becomes available, the next question should not be:
“I have the password—now what?”
Instead ask:
Where can this identity authenticate, and what privilege does that access provide?
That is the transferable OSCP skill.
Credential Reuse Across V4 and V5
Credential reuse is another reason to maintain organized notes.
Every discovered credential should enter a matrix such as:
| Identity | Source | SMB | WinRM | MSSQL | Other |
|---|---|---|---|---|---|
a.betty | Enumeration | Check | Check | Check | Record |
g.jarvis | File / share | Check | Check | Check | Record |
u.gregory | AD relationship | Check | Check | Check | Record |
svc_mssql | Service relationship | Check | Check | Check | Record |
Do not interpret this table as an instruction to spray credentials indiscriminately.
Use the environment to determine which authentication attempts are logical.
The useful chain is:
Credential → Identity → Expected Service → Authentication → Privilege
This reduces repeated work and makes credential reuse easier to identify.
Lateral Movement: Follow the Relationship
Lateral movement is where an AD set begins to feel like a connected environment rather than several Windows machines.
A conceptual V4/V5 attack path may resemble:
Initial Domain Identity
→ Authenticated Enumeration
→ Accessible Share / Resource
→ Additional Credential
→ Second Identity
→ Remote Service
→ Windows Host
→ Privilege Escalation
→ Additional Domain Information
→ Next Host
→ Domain Controller
This is a methodology model, not a fixed solution for V4 or V5.
The important point is that each successful stage should provide evidence for the next one.
Avoid jumping randomly between techniques.
Follow what the environment gives you.
Re-Enumeration Is More Important Than the Version Number
One of the strongest lessons from OSCP AD Set V4 vs V5 is that re-enumeration matters more than memorizing differences between the sets.
Use this loop:
Enumerate → Gain Identity → Re-enumerate → Gain Host → Re-enumerate → Gain Privilege → Re-enumerate
For example:
You obtain u.gregory.
→ Recheck authenticated SMB and domain information.
You discover svc_mssql.
→ Recheck SPNs, MSSQL and service relationships.
You obtain Windows access.
→ Recheck local credentials, services, routes and privileges.
You escalate locally.
→ Recheck protected files and credential stores.
You obtain another domain identity.
→ Repeat Active Directory enumeration.
Every change in security context changes what the environment may reveal.
This is one of the most important habits you can build before OSCP+.
Pivoting and Network Relationships
Do not assume every AD host is directly reachable.
After compromising a Windows system, check:
- network interfaces;
- routes;
- DNS configuration;
- active connections;
- additional subnets;
- internally reachable services.
If the compromised host can communicate with systems your Kali machine cannot reach directly, it may become part of the path toward another segment.
OffSec’s current OSCP+ FAQ explicitly states that pivoting may be required in the Active Directory portion because techniques included in PEN-200 can appear on the exam.
This makes network mapping part of AD enumeration rather than a separate skill.
OSCP AD Set V4 vs V5: What Should You Learn?
Do not finish these labs with only a command history.
Extract reusable lessons.
From V4
Focus on:
User Enumeration → Permissions → Credentials → Host Relationships
Practice recognizing why apparently ordinary accounts such as a.betty, g.jarvis, and u.gregory can become relevant after authenticated enumeration.
From V5
Focus on:
User → Service Account → MSSQL/Kerberos Relationship → Windows Context → Next Identity
svc_mssql is useful because it forces you to think about the relationship between Active Directory and an application service.
From Both
Practice:
- authenticated enumeration;
- credential management;
- service-account analysis;
- Windows privilege escalation;
- lateral movement;
- re-enumeration;
- attack-path documentation.
The technology may change.
The workflow should remain stable.
Want More OSCP AD Set Practice?
Use multiple environments to identify recurring patterns without depending on one memorized walkthrough.
→ Explore OSCP+ AD Sets & Exam Resources
How V4 and V5 Relate to the Current OSCP+ Exam
The current OSCP+ exam contains a three-machine Active Directory set worth 40 points. Candidates receive a username and password at the beginning of the AD portion, simulating an assumed-breach scenario.
The current structure is:
| AD Target | Points |
|---|---|
| Client #1 | 10 |
| Client #2 | 10 |
| Domain Controller | 20 |
| Total AD Set | 40 |
OffSec’s current authoritative objectives assign 26% to Active Directory, including domain enumeration, account enumeration, lateral movement, attacks against AD authentication and achieving high-privileged domain access. Documentation accounts for another 33%.
This is why V4/V5 practice should not focus exclusively on getting shells.
Practice documenting the relationship:
Finding → Evidence → Identity → Access → Next Step
Your notes should make the entire attack chain reproducible.
For the current exam structure and requirements, use the official OffSec OSCP+ Exam Guide.
Common OSCP AD Set V4 & V5 Mistakes
Memorizing a walkthrough.
You learn the environment rather than Active Directory methodology.
Assuming usernames indicate privilege.svc_mssql suggests a service relationship, but its actual rights must be enumerated.
Ignoring ordinary domain users.a.betty, g.jarvis, or u.gregory may expose information or access that changes the attack graph.
Testing credentials randomly.
Track where credentials came from and where they logically belong.
Stopping after gaining a shell.
Every compromised host is a new enumeration point.
Ignoring network configuration.
A host may provide access to another network segment.
Failing to re-enumerate.
New credentials and privileges change what you can see.
Leaving documentation until the end.
Record the attack path as it develops.
OSCP AD Set V4 vs V5 FAQ
What is the difference between OSCP AD Set V4 and V5?
They are useful as different Active Directory practice scenarios. Rather than memorizing a fixed distinction, compare how identities, credentials, services, host access and privilege relationships produce different attack paths.
Who are a.betty, g.jarvis and u.gregory?
They are user identities referenced in the V4/V5 environment discussed in this guide. Their importance depends on their actual permissions, accessible resources and relationships within the domain.
Why is svc_mssql important in AD Set V5?
svc_mssql suggests an MSSQL-related service identity. This makes SPNs, Kerberos, SQL Server authentication, database privileges and Windows service context useful areas to investigate.
Should I practice Kerberoasting for OSCP?
You should understand attacks against Active Directory authentication that are included within the PEN-200 scope. OffSec’s current objectives explicitly include attacks against AD authentication.
Can pivoting appear in the OSCP AD set?
Yes. OffSec states that pivoting may be required because material included in PEN-200 can appear on the exam.
How should I practice OSCP Active Directory?
OffSec recommends reviewing the relevant Active Directory modules, Assembling the Pieces, and locating and attacking the AD sets within PEN-200 Challenges.
Final Thoughts
The main lesson from OSCP AD Set V4 vs V5 is not that one version is harder or more linear than the other.
It is that Active Directory attack paths are built from relationships.
a.betty may reveal one resource.
g.jarvis may provide another security context.
u.gregory may expose a relationship you could not previously see.
svc_mssql may connect Active Directory to MSSQL and another Windows security context.
Each discovery matters because of what it changes.
Use the same question throughout both sets:
What does my newest identity, credential, host, or privilege allow me to see that I could not see before?
Then:
Enumerate → Correlate → Validate → Re-enumerate → Document
That methodology transfers to unfamiliar Active Directory environments far better than memorizing a V4 or V5 solution.
Ready to Practice OSCP+ AD Sets?
Get our OSCP+ preparation resources covering AD Set V4, AD Set V5, additional Active Directory scenarios, standalone machines and exam-focused preparation material.
✓ Multiple OSCP+ AD Sets
✓ Standalone machine resources
✓ Instant digital delivery
✓ Free updates included
→ Get OSCP+ AD Set Exam Material
Use penetration-testing techniques only against systems you own or are explicitly authorized to assess. Always verify current OSCP+ exam requirements directly with OffSec.
Vendor: https://www.offsec.com/certifications/offsec/oscp/
Check our oscp services: https://cyberservices.store/certifications/offsec/oscp/
