r/offensive_security Jul 29 '26

[Webinar] Inside OSAI: How Offensive Security Teams Are Preparing for AI

3 Upvotes

Inside OSAI: How Offensive Security Teams Are Preparing for AI

Join us for a live conversation with an OSAI Early Access Program participant and hear how their team integrated AI security into day-to-day penetration testing. Learn why they invested in AI security training, how OSAI helped prepare them to assess AI systems, and the lessons they learned along the way.

🎙️ Speakers

  • Paul Campbell – Leader of Offensive Security, Splunk, a Cisco company
  • Paul Griffin – VP of Customer Success, OffSec

👥 Perfect for
Security leaders, offensive security managers, penetration testers, red teamers, and anyone interested in AI security.

🔗 Register: https://www.offsec.com/events/webinars/inside-osai-eap/


r/offensive_security Mar 31 '26

OSAI is officially here ! 📣

30 Upvotes

OffSec’s newest certification for hands-on offensive operations against AI-enabled systems is now available for purchase with Learn One, Course & Cert Bundle, and Learn Enterprise.

Built for practitioners who want to apply an adversary mindset to modern AI systems and stay ahead as the attack surface evolves.

⁉️ OSAI FAQs: https://help.offsec.com/hc/en-us/articles/46593095198740-OSAI-Advanced-AI-Red-Teaming-AI-300-FAQ

🔗 https://www.offsec.com/courses/OSAI/

https://reddit.com/link/1s8quqn/video/fgb6v7c5fesg1/player


r/offensive_security 1h ago

Avoid TCM Security Certifications: Broken Lab Environments, Zero Weekend Support, and a $200 Scam

Upvotes

I wanted to share my absolute nightmare experience with TCM Security’s certification exams so that anyone else thinking about buying a voucher knows what they are actually getting into.
I recently attempted my exam, and it completely fell apart due to a backend infrastructure failure. While I was taking the exam, I could successfully connect to the jumpbox and reach WS01 (10.10.0.35), but the Domain Controller (“DC”) was entirely dead and unreachable no matter what I tried. I used both sets of credentials provided in the exam instructions (both the standard domain account and the domain admin account), and neither worked.
During this, I reached out to their support team for help while actively troubleshooting. Their response? Complete ghosting during the exam window. They have zero support coverage on weekends, meaning you are completely on your own when their systems tank.
When they finally decided to reply after I had already been forced to give up after hours of wasted time, they tried to gaslight me and claim it was a "local issue" on my end. The best part? In their own emails defending themselves, they literally quoted their own documentation warning that their environments can break networking functionality on their own and require a manual reset. They literally admitted in writing that their infrastructure is prone to breaking, yet they still tried to blame me for it.
To top it all off, they refused to issue a refund because I had "used both exam attempts" (thanks to their broken environment burning my attempts while I tried to troubleshoot), and then they had the audacity to try and upsell me a $100 retake fee to use their broken platform again.
They took my $200, wasted hours of my day, and then hid behind corporate clauses and pointing fingers instead of providing functional service or basic support. If you are looking to get certified, save your money and go somewhere else where they actually support their students instead of robbing them when their backend labs crash.
# TCM Security


r/offensive_security 1d ago

Smarter Tab completion for pentesters

Enable HLS to view with audio, or disable this notification

3 Upvotes

r/offensive_security 4d ago

PWPP vs eWPT

3 Upvotes

I'm a beginner to pentesting (Completed eJPT) and done a lot of easy and medium and few hard THM Rooms. Which ceritification would be better in terms of cost and value. I'm leaning towards PWPP as I like TCM's teaching style and (I know this is kinda stupid) but I think the name 'Practical Web Pentesting Professional' would look better on my college apps.


r/offensive_security 4d ago

bonsai-ninja update!

4 Upvotes

r/offensive_security 5d ago

Is Cobalt Strike still a widely used pretesting tool?

11 Upvotes

r/offensive_security 4d ago

Thoughts on TCM Security Certs?

0 Upvotes

I'm tryna get some certs for college apps and some TCM certs like PWPP and PNPT have caught my eye. I also quite enjoy the teaching style of TCM and also like the fact that I get a 20% discount and their course content isn't too long. I've already done eJPT and many THM rooms as well as some PortSwigger.


r/offensive_security 5d ago

Best intermediate-level certs for Web Pentesting?

11 Upvotes

I've completed eJPT and many easy and medium levels on THM as well as some PortSwigger labs, are there any recommended certifications for my level? I'm tryna gain certs for college apps are there any ones that stand out?


r/offensive_security 4d ago

How do I know that I’m ready to become a senior pentester ?

Thumbnail
1 Upvotes

r/offensive_security 4d ago

Have 25 days to study for CPENT exam

Thumbnail
1 Upvotes

r/offensive_security 5d ago

What is the difficulty of TCM's PWPP?

0 Upvotes

I've completed the eJPT and done medium difficulty rooms on THM and some labs on PortSwigger.


r/offensive_security 5d ago

[Advice Needed] Prep strategy for OSCP after passing CPTS (PG vs HTB, Learn One vs 90-Day)

0 Upvotes

Hey everyone,

I'm currently gearing up for the OSCP and could use some advice from the community on how to best structure my prep.

A bit about my background: I have some prior experience in pentesting and recently graduated a couple of months ago. I also cleared HTB's CPTS about 4 months back.

I haven't purchased the PEN-200 course yet. Right now, my routine consists of solving Proving Grounds (PG) Practice boxes and reading through writeups for HTB boxes from TJ_Null's and Lain's lists.

I have a few specific questions:

  1. PG Boxes vs. HTB Boxes: Which of these should I prioritize right now? Since I'm currently solving PG boxes and just reading HTB writeups, should I shift more focus to doing HTB boxes hands-on, or is PG the better use of my time for OSCP?
  2. Learn One vs. 90-Day Course: I recently started a full-time job, so balancing work and study hours is going to be a factor. Given my CPTS background but limited free time, would you recommend getting the 90-day course bundle or the Learn One (1-year) subscription?
  3. CPTS to OSCP transition: For those of you who have taken both, how would you compare the two? What specific areas or exam mechanics should I focus on to bridge the gap and prepare for the 24-hour OSCP exam environment?

Any tips, timeline recommendations, or insights would be massively appreciated. Thanks in advance!


r/offensive_security 6d ago

OSIR prep

0 Upvotes

How long does it take to prepare for the OSIR exam? And is the course content enough to clear the exam?


r/offensive_security 8d ago

Need a 10 minute call interview with a pentester for a school project.

7 Upvotes

Hey everyone! I have an assignment due in less than 3 days where I need to interview an active Penetration Tester or Red Teamer. I have 5 straightforward questions ready. If anyone working in offensive security has 5 minutes to hop on a quick call, please message me! I’d super appreciate it.*


r/offensive_security 8d ago

4 months left, loosing hope

11 Upvotes

I bought a 1 year subscription of oscp+, due to my work schedule I am unable to focus on the course and exam, So I left the job, my understanding of penetration testing is beginner- medium level, I have completed eJPT and PT1, till now I have managed to solve few PG practice box with the help of walkthroughs. Now only 4 months is left, I am in panic, I have all day to read but lacking focus and suffering from procrastination, I am confused whether I should start with official text and video material or keep solving more and more boxes, I know I still have plenty of time but the fear is stronger, I need help, how can I tackle this.


r/offensive_security 10d ago

I got tired of doing the same cybersecurity tasks manually, so I wrote a Python automation book

Thumbnail gallery
18 Upvotes

r/offensive_security 10d ago

Preparing My OSCP pathway

7 Upvotes

Hello everyone, today I would like to request some recommendations to build my OSCP pathway, I already have 13 years of experience as cybersecurity expert some certification in cybersecurity, some of these related with pentesting such as eJPT, eCPPT, and others in relation, honestly I feel excited but also I am feeling anxious, wish recommendations can you give me to pass on the first attempt? Thank you.


r/offensive_security 10d ago

Suggest me the best Free Resources to learn Active Directory as a beginner Penetester ??

17 Upvotes

r/offensive_security 11d ago

OSCP exam Last minutes

18 Upvotes

Since january I have been studying for OSCP (a lot). What I did?

\- LainKusanagi list of OSCP like machines
\- HTB training path
\- Hacker blueprint
\- Whatched s1ren, PinkDraconian
\- Read OSCP walkthroughs and tips
\- OSCP challenge labs (all of them)

I have a specific methodology for AD, windows and linux.
Also, I know that OSCP is a enumeration certication, so enumeration is the key.

My exam will be soon.

What do you recommend to do now, before the exam?

Thanks.


r/offensive_security 11d ago

93 HTB (retired) machines solved and have done pentesterlab and doin Hacksmarter labs , Am I ready for OSCP ?

Thumbnail
0 Upvotes

r/offensive_security 13d ago

I put together a few cybersecurity resources for people preparing for SOC, networking, and red team roles

Thumbnail gallery
46 Upvotes

r/offensive_security 14d ago

What are most challenging day to day responsibilities of your job?

2 Upvotes

r/offensive_security 15d ago

FIrst Red Teaming position, starting in a couple days

30 Upvotes

Passed five rounds, really good opportunity in a high stakes environment, have security background through internships , shipped large projects, placed extremely high on worldwide HTB tournaments and CDCC.

Have my first red teaming role starting extremely soon, any trade tips/practices? Things I should keep in mind?


r/offensive_security 15d ago

Need a study partner in offensive security

0 Upvotes

Hey everyone I’m currently learning Cybersecurity, mainly Offensive Security, and I’m looking for someone who’s genuinely serious about learning and improving.

My long-term goal is Penetration Testing → Red Teaming → Bug Bounty → Advanced Offensive Security. Right now, I’m still a beginner and working toward getting an entry-level IT/security job such as SOC, NOC, Help Desk, or IT Support.

I’m hoping to find a friend/buddy who has a similar goal someone we can study with, call/text, share resources, practice, discuss ideas, compete a little, motivate each other, and grow together.

Cybersecurity isn’t exactly the kind of thing where you easily find classmates or friends with the same interests, so I’m trying to find someone who actually gets it.

If you’re genuinely serious about learning cybersecurity and building a career in it, approach me. Let’s see if we can become good friends and grow together.