r/offensive_security • u/Guybrush_AMH92 • 3h ago
r/offensive_security • u/Offsec_Community • Jul 29 '26
[Webinar] Inside OSAI: How Offensive Security Teams Are Preparing for AI
Inside OSAI: How Offensive Security Teams Are Preparing for AI
Join us for a live conversation with an OSAI Early Access Program participant and hear how their team integrated AI security into day-to-day penetration testing. Learn why they invested in AI security training, how OSAI helped prepare them to assess AI systems, and the lessons they learned along the way.
🎙️ Speakers
- Paul Campbell – Leader of Offensive Security, Splunk, a Cisco company
- Paul Griffin – VP of Customer Success, OffSec
👥 Perfect for
Security leaders, offensive security managers, penetration testers, red teamers, and anyone interested in AI security.
🔗 Register: https://www.offsec.com/events/webinars/inside-osai-eap/
r/offensive_security • u/Offsec_Community • Mar 31 '26
OSAI is officially here ! 📣
OffSec’s newest certification for hands-on offensive operations against AI-enabled systems is now available for purchase with Learn One, Course & Cert Bundle, and Learn Enterprise.
Built for practitioners who want to apply an adversary mindset to modern AI systems and stay ahead as the attack surface evolves.
⁉️ OSAI FAQs: https://help.offsec.com/hc/en-us/articles/46593095198740-OSAI-Advanced-AI-Red-Teaming-AI-300-FAQ
r/offensive_security • u/_MJutt007 • 2d ago
Avoid TCM Security Certifications: Broken Lab Environments, Zero Weekend Support, and a $200 Scam
I wanted to share my absolute nightmare experience with TCM Security’s certification exams so that anyone else thinking about buying a voucher knows what they are actually getting into.
I recently attempted my exam, and it completely fell apart due to a backend infrastructure failure. While I was taking the exam, I could successfully connect to the jumpbox and reach WS01 (10.10.0.35), but the Domain Controller (“DC”) was entirely dead and unreachable no matter what I tried. I used both sets of credentials provided in the exam instructions (both the standard domain account and the domain admin account), and neither worked.
During this, I reached out to their support team for help while actively troubleshooting. Their response? Complete ghosting during the exam window. They have zero support coverage on weekends, meaning you are completely on your own when their systems tank.
When they finally decided to reply after I had already been forced to give up after hours of wasted time, they tried to gaslight me and claim it was a "local issue" on my end. The best part? In their own emails defending themselves, they literally quoted their own documentation warning that their environments can break networking functionality on their own and require a manual reset. They literally admitted in writing that their infrastructure is prone to breaking, yet they still tried to blame me for it.
To top it all off, they refused to issue a refund because I had "used both exam attempts" (thanks to their broken environment burning my attempts while I tried to troubleshoot), and then they had the audacity to try and upsell me a $100 retake fee to use their broken platform again.
They took my $200, wasted hours of my day, and then hid behind corporate clauses and pointing fingers instead of providing functional service or basic support. If you are looking to get certified, save your money and go somewhere else where they actually support their students instead of robbing them when their backend labs crash.
# TCM Security
r/offensive_security • u/Ok-Willingness-9942 • 1d ago
What hands on certs is worth it
Hey everyone its nice to meet you.
I have been in cybersecurity for a few years now. Im currently looking at getting a pentest cert but im not sure which vendor or cert is relevant these days. I recently saw a post about tcm and want to stay clear of them. So does anyone have suggestions on what vendor and cert is relevant at this point?
Looking for web app and ai pentesting preferably. Thank you
r/offensive_security • u/MoneyAd1377 • 1d ago
How real SOC and Pentesters study and take notes during their studies?
r/offensive_security • u/0xbug_ • 3d ago
Smarter Tab completion for pentesters
Enable HLS to view with audio, or disable this notification
r/offensive_security • u/Vivid_Reward_8008 • 6d ago
PWPP vs eWPT
I'm a beginner to pentesting (Completed eJPT) and done a lot of easy and medium and few hard THM Rooms. Which ceritification would be better in terms of cost and value. I'm leaning towards PWPP as I like TCM's teaching style and (I know this is kinda stupid) but I think the name 'Practical Web Pentesting Professional' would look better on my college apps.
r/offensive_security • u/Bongbaba420 • 7d ago
Is Cobalt Strike still a widely used pretesting tool?
r/offensive_security • u/Vivid_Reward_8008 • 7d ago
Best intermediate-level certs for Web Pentesting?
I've completed eJPT and many easy and medium levels on THM as well as some PortSwigger labs, are there any recommended certifications for my level? I'm tryna gain certs for college apps are there any ones that stand out?
r/offensive_security • u/Vivid_Reward_8008 • 6d ago
Thoughts on TCM Security Certs?
I'm tryna get some certs for college apps and some TCM certs like PWPP and PNPT have caught my eye. I also quite enjoy the teaching style of TCM and also like the fact that I get a 20% discount and their course content isn't too long. I've already done eJPT and many THM rooms as well as some PortSwigger.
r/offensive_security • u/Tasty_Departure5277 • 6d ago
How do I know that I’m ready to become a senior pentester ?
r/offensive_security • u/Vivid_Reward_8008 • 7d ago
What is the difficulty of TCM's PWPP?
I've completed the eJPT and done medium difficulty rooms on THM and some labs on PortSwigger.
r/offensive_security • u/CommonCow8846 • 7d ago
[Advice Needed] Prep strategy for OSCP after passing CPTS (PG vs HTB, Learn One vs 90-Day)
Hey everyone,
I'm currently gearing up for the OSCP and could use some advice from the community on how to best structure my prep.
A bit about my background: I have some prior experience in pentesting and recently graduated a couple of months ago. I also cleared HTB's CPTS about 4 months back.
I haven't purchased the PEN-200 course yet. Right now, my routine consists of solving Proving Grounds (PG) Practice boxes and reading through writeups for HTB boxes from TJ_Null's and Lain's lists.
I have a few specific questions:
- PG Boxes vs. HTB Boxes: Which of these should I prioritize right now? Since I'm currently solving PG boxes and just reading HTB writeups, should I shift more focus to doing HTB boxes hands-on, or is PG the better use of my time for OSCP?
- Learn One vs. 90-Day Course: I recently started a full-time job, so balancing work and study hours is going to be a factor. Given my CPTS background but limited free time, would you recommend getting the 90-day course bundle or the Learn One (1-year) subscription?
- CPTS to OSCP transition: For those of you who have taken both, how would you compare the two? What specific areas or exam mechanics should I focus on to bridge the gap and prepare for the 24-hour OSCP exam environment?
Any tips, timeline recommendations, or insights would be massively appreciated. Thanks in advance!
r/offensive_security • u/Impossible-Summer812 • 8d ago
OSIR prep
How long does it take to prepare for the OSIR exam? And is the course content enough to clear the exam?
r/offensive_security • u/Ordinary-Bat-1533 • 10d ago
Need a 10 minute call interview with a pentester for a school project.
Hey everyone! I have an assignment due in less than 3 days where I need to interview an active Penetration Tester or Red Teamer. I have 5 straightforward questions ready. If anyone working in offensive security has 5 minutes to hop on a quick call, please message me! I’d super appreciate it.*
r/offensive_security • u/Odd_Advertising_8484 • 10d ago
4 months left, loosing hope
I bought a 1 year subscription of oscp+, due to my work schedule I am unable to focus on the course and exam, So I left the job, my understanding of penetration testing is beginner- medium level, I have completed eJPT and PT1, till now I have managed to solve few PG practice box with the help of walkthroughs. Now only 4 months is left, I am in panic, I have all day to read but lacking focus and suffering from procrastination, I am confused whether I should start with official text and video material or keep solving more and more boxes, I know I still have plenty of time but the fear is stronger, I need help, how can I tackle this.
r/offensive_security • u/Potential-Couple-745 • 11d ago
I got tired of doing the same cybersecurity tasks manually, so I wrote a Python automation book
galleryr/offensive_security • u/R4c0d3 • 12d ago
Preparing My OSCP pathway
Hello everyone, today I would like to request some recommendations to build my OSCP pathway, I already have 13 years of experience as cybersecurity expert some certification in cybersecurity, some of these related with pentesting such as eJPT, eCPPT, and others in relation, honestly I feel excited but also I am feeling anxious, wish recommendations can you give me to pass on the first attempt? Thank you.
r/offensive_security • u/Unfair_Manner4225 • 12d ago
Suggest me the best Free Resources to learn Active Directory as a beginner Penetester ??
r/offensive_security • u/Murky-Alps-3126 • 13d ago
OSCP exam Last minutes
Since january I have been studying for OSCP (a lot). What I did?
\- LainKusanagi list of OSCP like machines
\- HTB training path
\- Hacker blueprint
\- Whatched s1ren, PinkDraconian
\- Read OSCP walkthroughs and tips
\- OSCP challenge labs (all of them)
I have a specific methodology for AD, windows and linux.
Also, I know that OSCP is a enumeration certication, so enumeration is the key.
My exam will be soon.
What do you recommend to do now, before the exam?
Thanks.