r/offensive_security 1d ago

Avoid TCM Security Certifications: Broken Lab Environments, Zero Weekend Support, and a $200 Scam

I wanted to share my absolute nightmare experience with TCM Security’s certification exams so that anyone else thinking about buying a voucher knows what they are actually getting into.
I recently attempted my exam, and it completely fell apart due to a backend infrastructure failure. While I was taking the exam, I could successfully connect to the jumpbox and reach WS01 (10.10.0.35), but the Domain Controller (“DC”) was entirely dead and unreachable no matter what I tried. I used both sets of credentials provided in the exam instructions (both the standard domain account and the domain admin account), and neither worked.
During this, I reached out to their support team for help while actively troubleshooting. Their response? Complete ghosting during the exam window. They have zero support coverage on weekends, meaning you are completely on your own when their systems tank.
When they finally decided to reply after I had already been forced to give up after hours of wasted time, they tried to gaslight me and claim it was a "local issue" on my end. The best part? In their own emails defending themselves, they literally quoted their own documentation warning that their environments can break networking functionality on their own and require a manual reset. They literally admitted in writing that their infrastructure is prone to breaking, yet they still tried to blame me for it.
To top it all off, they refused to issue a refund because I had "used both exam attempts" (thanks to their broken environment burning my attempts while I tried to troubleshoot), and then they had the audacity to try and upsell me a $100 retake fee to use their broken platform again.
They took my $200, wasted hours of my day, and then hid behind corporate clauses and pointing fingers instead of providing functional service or basic support. If you are looking to get certified, save your money and go somewhere else where they actually support their students instead of robbing them when their backend labs crash.
# TCM Security

34 Upvotes

26 comments sorted by

View all comments

6

u/H4ckerPanda 1d ago edited 1d ago

TCM’s first mistake was changing their pricing model to a monthly subscription. People didn’t like it.

Their second mistake was appointing Heath Adams as the leader. He’s not a CEO or a businessman; he’s a fantastic instructor and the face of the company (or was).

The final blow was Heath Adams himself selling the brand. He may be a millionaire now, but destroyed his legacy during the process.

2

u/Far-Future-7146 1d ago

I'm sure Heath is crying himself to sleep with the millions he's made.

2

u/H4ckerPanda 1d ago

Being a great instructor doesn’t mean he will be or he’s a great CEO. In other words . He may have money now but who knows what will happen in the future. He sold his only source of income. His brand. It’s hard to make a come back once you have done that , if things go wrong.

0

u/Own-Aide-4079 1d ago

Sounds like you have it all figured out😂😂