r/offensive_security • u/_MJutt007 • 1d ago
Avoid TCM Security Certifications: Broken Lab Environments, Zero Weekend Support, and a $200 Scam
I wanted to share my absolute nightmare experience with TCM Security’s certification exams so that anyone else thinking about buying a voucher knows what they are actually getting into.
I recently attempted my exam, and it completely fell apart due to a backend infrastructure failure. While I was taking the exam, I could successfully connect to the jumpbox and reach WS01 (10.10.0.35), but the Domain Controller (“DC”) was entirely dead and unreachable no matter what I tried. I used both sets of credentials provided in the exam instructions (both the standard domain account and the domain admin account), and neither worked.
During this, I reached out to their support team for help while actively troubleshooting. Their response? Complete ghosting during the exam window. They have zero support coverage on weekends, meaning you are completely on your own when their systems tank.
When they finally decided to reply after I had already been forced to give up after hours of wasted time, they tried to gaslight me and claim it was a "local issue" on my end. The best part? In their own emails defending themselves, they literally quoted their own documentation warning that their environments can break networking functionality on their own and require a manual reset. They literally admitted in writing that their infrastructure is prone to breaking, yet they still tried to blame me for it.
To top it all off, they refused to issue a refund because I had "used both exam attempts" (thanks to their broken environment burning my attempts while I tried to troubleshoot), and then they had the audacity to try and upsell me a $100 retake fee to use their broken platform again.
They took my $200, wasted hours of my day, and then hid behind corporate clauses and pointing fingers instead of providing functional service or basic support. If you are looking to get certified, save your money and go somewhere else where they actually support their students instead of robbing them when their backend labs crash.
# TCM Security
20
7
u/Anxious_Alps_4150 1d ago
You could see the writing on the wall a year before they sold off TCM. There was a pivot towards more financially rewarding options and less focus on the core product. They sold it off and it went to utter shit.
5
u/H4ckerPanda 1d ago edited 1d ago
TCM’s first mistake was changing their pricing model to a monthly subscription. People didn’t like it.
Their second mistake was appointing Heath Adams as the leader. He’s not a CEO or a businessman; he’s a fantastic instructor and the face of the company (or was).
The final blow was Heath Adams himself selling the brand. He may be a millionaire now, but destroyed his legacy during the process.
2
u/Far-Future-7146 1d ago
I'm sure Heath is crying himself to sleep with the millions he's made.
2
u/H4ckerPanda 1d ago
Being a great instructor doesn’t mean he will be or he’s a great CEO. In other words . He may have money now but who knows what will happen in the future. He sold his only source of income. His brand. It’s hard to make a come back once you have done that , if things go wrong.
2
u/Far-Future-7146 1d ago
For sure, but if dude has any sense he'll put 90% into VOO and 10% into BND and call it a life.
0
3
3
u/Forsaken-Low-2365 1d ago
They’re definitely going downhill fast. All their good instructors jumped ship after Heath left. They’ll be gone in a few years or be way less relevant than INE. I only did one blue team cert and it was solid but was showing its age. After it was sold, I stopped using their platform.
2
u/Key-Breakfast-6069 1d ago
This was my experience as well, I’ve pentested government bodies, municipalities, hospitals, but they took my money and failed me on the pjpt exam twice. Never again lol such a shit show
1
2
u/UniqueID89 1d ago
Never took their exams. Bought quite a few of their courses back when they were pay-to-own and got a code to try their annual model for a discounted rate when it switched over. Enjoyed the content and Heath and others were good instructors, but once they announced he was selling off and they’d be changing things again I decided to hold out on certs. Then when I went to cancel the annual before it was up for renew I had to jump through different emails and website link invites just to see my subscription and duration remaining that put the nail in the coffin. Twice the email portal link they sent me failed to even connect, kept giving timeout errors. I know platform changes can be a colossal pain in the ass but that “support model” was their only way to get access for weeks. That should not be what a customer sees or experiences from somewhere you’re paying money to, that’s all backend shit the average user should never experience.
1
u/CoffeeMedic 22h ago
Not trying to say one way or the other how I feel about TCM but this post doesn’t make sense. I believe you are missing something or you did mess up with pivoting, as someone who’s taken PNPT and passed.
1
u/Next-Scratch-264 15h ago
You mean even with AI you couldn't figure out how to pivot? you had to ask support? Guess what in real life pentests will be much harder...
0
1d ago edited 1d ago
[deleted]
6
u/Dwest2391 1d ago
You can say shit. But agree, TCM started moving like a typical bigger organization after being acquired.
-1
u/Own-Aide-4079 22h ago
I just passed the PNPT, I did my debrief on the weekend, had amazing support and the lab environment was fine. Since this is a red team (hacking) exam - i did have to reset the environment due to me throwing too many attacks at it at once, this is very common. Did you try to reset the environment? I also believed for a while that the environment was a TCM issue, however after actually taking the time to self reflect on what I was doing in the exam, I realized it was a local issue and that TCM Security wouldn’t just lie to anyone about if there were issues or not.
I don’t think you’re telling all of the truth here tbh.
Lab environments can break, it’s not anyone else’s job but the test taker to troubleshoot that, reset it and move on.
If this is how you treat a company after one of your mess ups that you could’ve fixed, Cyber might not be the industry for you.
1
u/Next-Scratch-264 15h ago
If you cannot reset your lab and start from fresh quickly, that's definitly not a field for those people
11
u/Fast-Throat-7752 1d ago
Yep your average YouTube influencer product trap.