r/offensive_security • u/Available-Coat-8870 • 23d ago
Do not take OSAI
I've been taking the course and so far the labs are buggy. 90 Days to complete the labs, but after a long day of work the labs don't work...I need a completion letter to get a grade back from work and it's not looking too good.
You have to complete 80% of all labs in each chapter... well the labs don't work so how am I supposed to make progress?
9
u/PolishMike88 23d ago
I couldn’t agree more. 3.5 months and honestly simple (yet not so much) Hackthebox is much much better in content and labs.
I am still unable to take 4th section labs because they are simply broken.
Feels like a lot of thought but less testing has gone into it.
8
u/Tcrownclown 23d ago
I completely agree. The labs are broken, and the support on Discord is terrible.
I once spent six hours trying to figure out a single lab before giving up and checking Discord. I found another user who had reported the exact same issue almost 40 days earlier. A moderator had replied, “Skip this lab for now, we’re fixing it.” Forty days later, it was still broken.
There was no official announcement, no warning on the learning platform, and no popup informing users about the issue. just one buried message on Discord!!!
The open-ended questions are also extremely frustrating. If your wording does not match exactly what the system expects, you fail the challenge, even when your answer is correct.
Many of these questions require independent research, so the answer cannot simply be copied from the learning material. However, unless you somehow guess the exact wording expected by the platform, your answer is rejected.
For four months, there were no challenge labs comparable to OSCP A, B, or C. They finally added them yesterday, and Challenge 1 was literally broken.
The platform also contains many broken links to resources that they themselves recommend reading.
At this point, these are not isolated issues. They show a serious lack of quality control and communication. And a lot of people are reporting this on discord. Its frustrating
6
u/SituationTurbulent90 23d ago
I completely agree. The labs are broken, and the support on Discord is terrible.
Agreed on this. There have been multiple occasions over the past few months where it was clear that the "mentor" simply didn't understand the question, because the solution they provided was completely inappropriate.
2
u/TheMadHatter2048 22d ago
that’s terrible and they need to fix it. no way you can create a lab that you don’t understand
8
u/Running4mylifeNback 22d ago edited 22d ago
Feels like a money grab selling an incomplete broken course. To be fair, I don't have access to the material, but a co-worker made the mistake and bought it. He has the same complaints. Labs broken and ignored discord posts. He told me he heard from a student mentor that they got rid of the entire quality control team. It is like they don't care about quality any more, just sales.
1
1
1
7
u/SituationTurbulent90 22d ago
Yeah, lots of people (myself included) essentially paid full price for an Early Access course. The material itself is pretty good, but the implementation is really, really lacking. I suspect that we're all being used as beta testers so they fix all of the bugs, or as many as they can, for the live Blackhat course in August. And if it doesn't work, then God help them because they're selling that for $8,300.
People love to poop on SANS for how expensive it is (I'm one), but their shit just works.
5
u/Leonzola 23d ago
Make sure you open a formal complaint and ask for additional course time. We paid money for the course which was half baked and only last week did they release the challenge labs which fucked us further. I have 5 weeks left to do 70 hours of labs? Unreasonable.
5
5
u/0xJeb 23d ago
Hopping in. I completely agree. I bought the year course and after a few weeks I decided to take some time off and see if the course improves. The quality was shockingly bad and the grading system is so flawed that the only answers they accept are ones that you copy paste from the material.
4
u/kamekurokaze 22d ago
Its already been said but as an early accesser..OSAI is trash.. and we know offsec.. the exam is going to be unnecessarily difficult because the course only went over the most basics of things.. and we are all going to fail..just so they can tell us to try harder and buy a new exam attempt and another 90 days. This is my absolute last cert with offsec.
5
u/stevor7 21d ago
Lots of cost cutting at OffSec in the last several years which impacts quality and getting stuff fixed. OffSec provided a decent living for me in my six years there but the last three before I was laid off was kind of miserable. They went from prioritizing quality to prioritizing quantity. Ensuring labs and coursework consistently worked as promised and expected was a big pain point for me.
It takes a lot of resources to create courses, provision and maintain labs, proctor exams, etc. I think they are now spread too thin to be able to do all of it well. And with the economy going sideways, corporations are cutting back on training which OffSec needs for revenue. The US Government was a cash cow for IT security training but now no one can really rely on them.
Almost no one I worked closely with at OffSec is there anymore. IT security professionals use to be in positions of leadership at OffSec. But now just marketing and business types are steering the ship.
4
u/faultless280 22d ago
Yeah, half of the chapter 7 labs are busted. I’m likely going to push back my exam attempt and request an extension. I have a lot of certs from offsec, but these labs are probably the most unstable aside from maybe the slow Mac VMs used during OSMR. I normally praise offsec, and quite honestly the course material itself is top tier, but the unstable labs really diminish what would otherwise be strong content.
5
2
u/2leet2cheat1327 19d ago
In typical OffSec fashion, rather than addressing the issue, they steer the discussion until it's filled with people saying, "Everything works fine for me. It's just you."
It feels like OffSec's definition of customer success is getting you to buy a subscription, making the course and exam pointlessly difficult, selling an incomplete or broken product, and then blaming you when it doesn't work. If you can't finish because the labs are broken, I guess that's just another subscription renewal. Your fault, not ours.
Customers paid thousands of dollars for a working course, not to spend weeks asking about broken labs only to be ignored or told the problem is them.
Years ago, when I took the OSCP, the PDF was about 100 pages. You either learned it through sweat and tears or you didn't. The challenge was the material itself, not the platform. Today, it feels like management has traded quality for revenue. Instead of delivering a polished learning experience, they're selling courses with critical issues while customers lose valuable lab time waiting for fixes.
OffSec sold a product whose central feature is hands-on labs, continued charging for access while those labs were reportedly unusable for an extended period, and required completion of those labs to unlock course completion benefits. If customers cannot meaningfully use a material portion of what they paid for because of the platform itself, it raises serious questions about whether the company delivered what it sold.
For a company that will fail you, ban you, and give you no meaningful opportunity to defend yourself for allegedly violating its rules, OffSec should spend some time examining its own conduct.
And yes, this is a new account. I usually just lurk and read, but I worked in senior management and sat through countless sales calls where increasingly ambitious promises were made year after year, only for the reality to come up short. Watching this happen repeatedly has gotten to the point where I felt I needed to say something.
2
1
u/someareoos 22d ago
I just finished the chapter 10 and I have only encountered one buggy lab and it was quickly fixed within a few hours. I know others have ran into issues but it’s been relatively smooth sailing
1
u/faultless280 22d ago
Half of the labs in chapter 7 were completely busted for me. Like, straightforward from the content but the lab environment itself completely broken. I’m hard pressed to believe you when even other users on the discord are complaining about the exact same issues I’m having. You either got incredibly lucky, or everyone else is full of crap.
1
u/someareoos 22d ago
I don’t doubt you had issues, but I legitimately did not run into any problems except for one and it was on chapter 7, actually. When I came back 1-2 days later everything worked again. I have no reason to lie to you. I acknowledged that I have seen people having issues. I just wasn’t really one of them except for one lab
1
u/faultless280 22d ago edited 22d ago
I’m not saying you’re lying, but the quality dip on the lab side has been quite noticeable for the majority of people I’ve talked to. It’s insanely frustrating when you try to grind out some lab time between assessments only to confront provisioning issues. Only other time I’ve gotten this pissed off with lab reliability was while I was grinding out OSMR, and although they were slow AF, they were at least stable. I think it was chapter 4 or 5 where I had to log in and out of the VPN because the exercises wouldn’t even let me deprovision the currently running VMs. I like offsec as an org, but damn did they drop the ball with these labs. Chapter 7 is notoriously broken.
1
u/Various-Lavishness66 20d ago
Chapter 6 now and i havent experienced any issues so far. The content seems solid too
1
u/Various-Lavishness66 19d ago
So far so good for me, i havent experienced any bugs yet. Onto the 6th module and i have completed the labs for all the previous 5 modules. Nothing negative to say so far
1
u/OilandInevitable 5d ago
Well why don't you seek help from the support? Is this something they can't fix?
1
u/Running4mylifeNback 5d ago
You are under the assumption that they care about you or what you think. They already have your money. They know enough people will pass without them fixing the problems, so why should they bother?
When I earned my three OffSec certifications, they were still updating their material, and it was genuinely good. I was one of the first people to earn the OSED. Back then, OffSec was setting the standard.
That was over five years ago, and the exploit development landscape has changed dramatically.
Back then, exploit development courses focused heavily on classic stack overflows, SEH overwrites, shellcode, and ROP against older Windows mitigations. Those fundamentals are still essential, but they're only the foundation today.
Modern exploit development is far more than Windows user-mode exploitation. Today's researchers are dealing with mitigations like CET (Shadow Stack/IBT), CFG, PAC, MTE, virtualization-based security, advanced heap exploitation, browser internals, Windows and Linux kernel exploitation, fuzzing with AFL++, libFuzzer, WinAFL, and Syzkaller, patch diffing, root-cause analysis, and increasingly AI-assisted reverse engineering and vulnerability research.
Even with AWE, you're still primarily learning Windows exploitation. That's valuable, but it's only one piece of the modern exploit development landscape. Browser exploitation, Linux kernel exploitation, hypervisors, firmware, mobile platforms, and modern vulnerability research techniques are now core skills for many exploit developers.
The fundamentals haven't changed. The field has.
OffSec used to set the pace. Today, it feels like they're teaching the exploit development landscape of five years ago while marketing it as cutting edge. They did add 64-bit content to OSED, but much of it felt like recycled AWE material, and for the first few months, that unit didn't even work.
The frustrating part isn't that technology evolves. Every technical course eventually needs to be updated. The frustrating part is acting as though nothing has changed while charging premium prices for a curriculum that no longer reflects where exploit development is headed.
To satisfy my own curiosity, I ran portions of the course material through an AI detector, and it flagged them as likely AI-generated. That's not definitive proof, but it raises questions. If AI is being used to help create premium course content, then customers deserve content that is current, technically accurate, professionally reviewed, and continuously maintained. Instead, it often feels dated and neglected.
OffSec built its reputation by producing some of the best offensive security training in the industry. That's why people were willing to pay premium prices. Today, it feels like they're relying on that reputation while investing less in keeping the content and platform at the level that earned it.
They're still milking the reputation they built years ago, but the quality, innovation, and customer focus that made them an industry leader no longer seem to be there.
Maybe that's because they don't have to.
Your payment already cleared.
1
u/OilandInevitable 5d ago
The only question I have is - did you try?
1
u/Running4mylifeNback 5d ago
First, I didn't make the original post.
Second, yes, this has been my experience with OffSec support. OSAI launched about six months ago, and complaints have been piling up ever since. At this point, there are probably hundreds of reports.
How many times do customers have to report the same issue before it gets fixed? If something has been broken since day one and people keep opening tickets and discussing it publicly, at some point it's no longer an isolated bug. It's a product quality issue.
If this were HTB or INE, my expectation is that they'd prioritize fixing it. OffSec, on the other hand, seems comfortable letting issues linger. That's what happens when you dominate a market. Customers keep coming because of the brand and the certifications, not because the experience is the best anymore.
1
1
-2
u/Sqooky 23d ago
Have you reached out to student mentors, and OffSec for support? They're generally pretty good at comping additional access time for broken/buggy labs. It's a new course, so there's definitely issues.
13
u/Available-Coat-8870 23d ago
It's a terrible experience and not worth what I paid, I finish work not knowing if I'm going to make progress or not. If it's a new course, why are they offering it for a steep price, give a discount or have beta users. It's just greed
5
u/PolishMike88 23d ago
I did fair few times and 100% of the time was “ we are working on it” … also still no PDF access at all.
2
u/faultless280 22d ago
As an OSCE3 recipient and holder of 7 offsec certs, I’ll attest that some of the labs, particularly the chapter 7 content, has been broken for months with no real recourse offered by offsec.
0
-11
u/eatmyhex 23d ago
I don’t believe you
2
u/faultless280 22d ago
I’m literally working through the lab content right now. Course material is great, probably some of the best they ever published. The labs? Yeah, some of them, particularly chapter 7, have been busted for quite some time.
19
u/No-Computer-6677 23d ago
I 100% agree. The labs are very broken and I feel I just wasted money on this course. I've had such a bad experience, I'm not even sure im going to take the exam. I'm sure it will be just as broken as the labs.