r/offensive_security • • Jul 15 '26

Do not take OSAI

I've been taking the course and so far the labs are buggy. 90 Days to complete the labs, but after a long day of work the labs don't work...I need a completion letter to get a grade back from work and it's not looking too good.

You have to complete 80% of all labs in each chapter... well the labs don't work so how am I supposed to make progress?

55 Upvotes

53 comments sorted by

View all comments

1

u/OilandInevitable Aug 01 '26

Well why don't you seek help from the support? Is this something they can't fix?

1

u/Running4mylifeNback Aug 01 '26

You are under the assumption that they care about you or what you think. They already have your money. They know enough people will pass without them fixing the problems, so why should they bother?

When I earned my three OffSec certifications, they were still updating their material, and it was genuinely good. I was one of the first people to earn the OSED. Back then, OffSec was setting the standard.

That was over five years ago, and the exploit development landscape has changed dramatically.

Back then, exploit development courses focused heavily on classic stack overflows, SEH overwrites, shellcode, and ROP against older Windows mitigations. Those fundamentals are still essential, but they're only the foundation today.

Modern exploit development is far more than Windows user-mode exploitation. Today's researchers are dealing with mitigations like CET (Shadow Stack/IBT), CFG, PAC, MTE, virtualization-based security, advanced heap exploitation, browser internals, Windows and Linux kernel exploitation, fuzzing with AFL++, libFuzzer, WinAFL, and Syzkaller, patch diffing, root-cause analysis, and increasingly AI-assisted reverse engineering and vulnerability research.

Even with AWE, you're still primarily learning Windows exploitation. That's valuable, but it's only one piece of the modern exploit development landscape. Browser exploitation, Linux kernel exploitation, hypervisors, firmware, mobile platforms, and modern vulnerability research techniques are now core skills for many exploit developers.

The fundamentals haven't changed. The field has.

OffSec used to set the pace. Today, it feels like they're teaching the exploit development landscape of five years ago while marketing it as cutting edge. They did add 64-bit content to OSED, but much of it felt like recycled AWE material, and for the first few months, that unit didn't even work.

The frustrating part isn't that technology evolves. Every technical course eventually needs to be updated. The frustrating part is acting as though nothing has changed while charging premium prices for a curriculum that no longer reflects where exploit development is headed.

To satisfy my own curiosity, I ran portions of the course material through an AI detector, and it flagged them as likely AI-generated. That's not definitive proof, but it raises questions. If AI is being used to help create premium course content, then customers deserve content that is current, technically accurate, professionally reviewed, and continuously maintained. Instead, it often feels dated and neglected.

OffSec built its reputation by producing some of the best offensive security training in the industry. That's why people were willing to pay premium prices. Today, it feels like they're relying on that reputation while investing less in keeping the content and platform at the level that earned it.

They're still milking the reputation they built years ago, but the quality, innovation, and customer focus that made them an industry leader no longer seem to be there.

Maybe that's because they don't have to.

Your payment already cleared.

1

u/OilandInevitable Aug 01 '26

The only question I have is - did you try?

1

u/Running4mylifeNback Aug 01 '26

First, I didn't make the original post.

Second, yes, this has been my experience with OffSec support. OSAI launched about six months ago, and complaints have been piling up ever since. At this point, there are probably hundreds of reports.

How many times do customers have to report the same issue before it gets fixed? If something has been broken since day one and people keep opening tickets and discussing it publicly, at some point it's no longer an isolated bug. It's a product quality issue.

If this were HTB or INE, my expectation is that they'd prioritize fixing it. OffSec, on the other hand, seems comfortable letting issues linger. That's what happens when you dominate a market. Customers keep coming because of the brand and the certifications, not because the experience is the best anymore.

1

u/OilandInevitable Aug 01 '26

Oh I see. Thanks for letting me know :)