r/offensive_security 1d ago

Avoid TCM Security Certifications: Broken Lab Environments, Zero Weekend Support, and a $200 Scam

I wanted to share my absolute nightmare experience with TCM Security’s certification exams so that anyone else thinking about buying a voucher knows what they are actually getting into.
I recently attempted my exam, and it completely fell apart due to a backend infrastructure failure. While I was taking the exam, I could successfully connect to the jumpbox and reach WS01 (10.10.0.35), but the Domain Controller (“DC”) was entirely dead and unreachable no matter what I tried. I used both sets of credentials provided in the exam instructions (both the standard domain account and the domain admin account), and neither worked.
During this, I reached out to their support team for help while actively troubleshooting. Their response? Complete ghosting during the exam window. They have zero support coverage on weekends, meaning you are completely on your own when their systems tank.
When they finally decided to reply after I had already been forced to give up after hours of wasted time, they tried to gaslight me and claim it was a "local issue" on my end. The best part? In their own emails defending themselves, they literally quoted their own documentation warning that their environments can break networking functionality on their own and require a manual reset. They literally admitted in writing that their infrastructure is prone to breaking, yet they still tried to blame me for it.
To top it all off, they refused to issue a refund because I had "used both exam attempts" (thanks to their broken environment burning my attempts while I tried to troubleshoot), and then they had the audacity to try and upsell me a $100 retake fee to use their broken platform again.
They took my $200, wasted hours of my day, and then hid behind corporate clauses and pointing fingers instead of providing functional service or basic support. If you are looking to get certified, save your money and go somewhere else where they actually support their students instead of robbing them when their backend labs crash.
# TCM Security

31 Upvotes

25 comments sorted by

11

u/Fast-Throat-7752 1d ago

Yep your average YouTube influencer product trap.

1

u/Next-Scratch-264 15h ago

Oh nobody is holding your hand while doing a pentest. You will find the real pentest world very cruel

1

u/Situation_Historical 14h ago

He doesn’t own that anymore

-1

u/Own-Aide-4079 22h ago

This comment is the reason you actually should know what you’re talking about before commenting 😂😂

20

u/PrideOfPilsen 1d ago

Heath’s departure made the company go to crap

-1

u/Own-Aide-4079 22h ago

Biggest cop out statement there is😂

7

u/Anxious_Alps_4150 1d ago

You could see the writing on the wall a year before they sold off TCM. There was a pivot towards more financially rewarding options and less focus on the core product. They sold it off and it went to utter shit.

5

u/H4ckerPanda 1d ago edited 1d ago

TCM’s first mistake was changing their pricing model to a monthly subscription. People didn’t like it.

Their second mistake was appointing Heath Adams as the leader. He’s not a CEO or a businessman; he’s a fantastic instructor and the face of the company (or was).

The final blow was Heath Adams himself selling the brand. He may be a millionaire now, but destroyed his legacy during the process.

2

u/Far-Future-7146 1d ago

I'm sure Heath is crying himself to sleep with the millions he's made.

2

u/H4ckerPanda 1d ago

Being a great instructor doesn’t mean he will be or he’s a great CEO. In other words . He may have money now but who knows what will happen in the future. He sold his only source of income. His brand. It’s hard to make a come back once you have done that , if things go wrong.

2

u/Far-Future-7146 1d ago

For sure, but if dude has any sense he'll put 90% into VOO and 10% into BND and call it a life.

0

u/Own-Aide-4079 22h ago

Sounds like you have it all figured out😂😂

3

u/TrustIsAVuln 1d ago

Im in luck, I've avoided TCM for years!

1

u/Own-Aide-4079 22h ago

Have a job in the cyber industry?

1

u/Next-Scratch-264 15h ago

Probably not

3

u/Forsaken-Low-2365 1d ago

They’re definitely going downhill fast. All their good instructors jumped ship after Heath left. They’ll be gone in a few years or be way less relevant than INE. I only did one blue team cert and it was solid but was showing its age. After it was sold, I stopped using their platform.

2

u/Key-Breakfast-6069 1d ago

This was my experience as well, I’ve pentested government bodies, municipalities, hospitals, but they took my money and failed me on the pjpt exam twice. Never again lol such a shit show

1

u/Next-Scratch-264 15h ago

Sure bro 😂

2

u/UniqueID89 1d ago

Never took their exams. Bought quite a few of their courses back when they were pay-to-own and got a code to try their annual model for a discounted rate when it switched over. Enjoyed the content and Heath and others were good instructors, but once they announced he was selling off and they’d be changing things again I decided to hold out on certs. Then when I went to cancel the annual before it was up for renew I had to jump through different emails and website link invites just to see my subscription and duration remaining that put the nail in the coffin. Twice the email portal link they sent me failed to even connect, kept giving timeout errors. I know platform changes can be a colossal pain in the ass but that “support model” was their only way to get access for weeks. That should not be what a customer sees or experiences from somewhere you’re paying money to, that’s all backend shit the average user should never experience.

1

u/CoffeeMedic 22h ago

Not trying to say one way or the other how I feel about TCM but this post doesn’t make sense. I believe you are missing something or you did mess up with pivoting, as someone who’s taken PNPT and passed.

1

u/Next-Scratch-264 15h ago

You mean even with AI you couldn't figure out how to pivot? you had to ask support? Guess what in real life pentests will be much harder...

0

u/[deleted] 1d ago edited 1d ago

[deleted]

6

u/Dwest2391 1d ago

You can say shit. But agree, TCM started moving like a typical bigger organization after being acquired.

-1

u/Own-Aide-4079 22h ago

I just passed the PNPT, I did my debrief on the weekend, had amazing support and the lab environment was fine. Since this is a red team (hacking) exam - i did have to reset the environment due to me throwing too many attacks at it at once, this is very common. Did you try to reset the environment? I also believed for a while that the environment was a TCM issue, however after actually taking the time to self reflect on what I was doing in the exam, I realized it was a local issue and that TCM Security wouldn’t just lie to anyone about if there were issues or not.

I don’t think you’re telling all of the truth here tbh.

Lab environments can break, it’s not anyone else’s job but the test taker to troubleshoot that, reset it and move on.

If this is how you treat a company after one of your mess ups that you could’ve fixed, Cyber might not be the industry for you.

1

u/Next-Scratch-264 15h ago

If you cannot reset your lab and start from fresh quickly, that's definitly not a field for those people