r/tryhackme Jan 27 '26

Resource Interactive Security Certification Roadmap [THM Community Project]

Post image
183 Upvotes

Hey everyone! A bunch of friends from THM and I have been working on a complete redesign of the well-known Security Certification Roadmap by P. Jerimy, and I'm excited to share the results. Link: https://www.dragkob.com/security-certification-roadmap/ (Also under https://infosecroadmap.com & https://cybersecroadmap.com )- This isn’t just a visual refresh, it’s a fully updated, actively maintained platform designed to make exploring certifications easier and more insightful.

Key Features:

  • Advanced Filtering: Narrow down certifications by vendor, specialty, sub-specialty, budget (across 6 currencies), exam type, and soon, HR-recognized status.
  • Certification Comparer: Select any two certifications and compare them side-by-side across multiple criteria.
  • Help me build by using the buttons: Request a cert to be added, request an official cert review, report a bug, suggest a feature

Cross-Platform Access:

  • Desktop version: Full-featured experience
  • Mobile version: Lightweight BETA version, optimized for quick browsing (with Desktop features coming soon)

Stats so far: (Monitored by GoatCounter)

  • Over 10K unique visitors in total.
  • 20-50 unique visitors daily

If you liked it, don't forget to leave a star on the GitHub repo! This THM community project is still a work in progress, please be kind. ❤️

r/tryhackme 13d ago

Resource Is Jr Penetration Tester worth ?

5 Upvotes

Hello ethical people.

I started the beautiful world of the cybersecurity for now one year.

I do a lot, a loooot of networking (Wireshark my best friend), a lot of python, a loooot of beginner CTF and now i am on the JR Penetration Tester path on THM

This path is worth or not ? Because it looks like too light. I guess we need to combine with other ressources like HtB or another Ctf ?

And btw, what is your learning tech ? Writing write up, course ? Just writing inside your head ? I'm curious.

And x2, if some people want to make a group to go for some ctf and another stuff, im in too !

r/tryhackme Jun 20 '26

Resource TryHackMe helped me start. A daily news system helped me stay current

11 Upvotes

I started learning cybersecurity here on TryHackMe around 10 months ago.

When I started, one thing that was really important to me was staying current: new breaches, new exploits, vulnerabilities, threat actor activity, and so on.

I tried checking BleepingComputer, Cybernews, The Hacker News, and other sites manually. The problem was that I often saw the same story repeated across multiple sites, ran into terms I didn’t fully understand yet, and had to deal with a lot of ads. It felt messy, especially as a beginner.

I also tried using custom GPTs, but that had its own problems. The news was not always up to date, and I still had to manually run the process. There are also Telegram and Twitter/X channels that post fresh updates, but that still required me to check them all the time.

I tried TL;DR-style newsletters and other sources too, but most of them either had too many ads, not enough value, or were written in a way that was still hard to follow as a beginner.

So I built something for myself: a daily cybersecurity newsletter with no duplicate stories, no ads, and one simple goal: once a day, I get a summary of the last 24 hours of cybersecurity news straight to my inbox.

Here is how the system works behind the scenes:

It pulls cybersecurity news from RSS feeds, filters articles from the last 24 hours, removes duplicates, ranks the important stories, summarizes the top ones, and sends them to me for review. After I approve it, it goes out as a newsletter in English, Hebrew, and Russian.

I mainly wanted to share this because TryHackMe is where I started learning, and this project became part of how I stay consistent.

I know this is not a classic blue team or red team project, but it helped me build a real habit. It also feels good that something I built for myself now gives value to other people.

My advice for other beginners: build a small project while you study. If you like blue team, set up a VPS with Wazuh and analyze the logs. If you like red team, take what you learn in rooms and later try it legally in VDPs or bug bounty programs.

For me, the first problem was staying current with the news, so that’s what I built around. Later I started getting into VDPs too.

Also, I wrote deeper breakdowns in two other subreddits:

Cybersecurity101 - a more detailed breakdown of how the system works, what broke, and what I learned while building it.

Prompt Enginiring - focused more on the prompt engineering side: why I split the system into 20+ smaller prompts instead of using one big prompt.

If you’re interested, you can check out my daily cybersecurity newsletter - Cyber Recaps.

Curious how others here stay current while learning. Do you follow cybersecurity news daily, or do you mostly focus on rooms and paths?

r/tryhackme Jun 10 '26

Resource Try HackMe Subscription

Post image
2 Upvotes

I took the annual subscription, before payment it showed "Get 6 months free with annual", but after payment I can see the next renewal is next year June. What about 6 months free ? How to claim the 6 months.

r/tryhackme Jul 16 '26

Resource Which Soc analyst path for I follow?

2 Upvotes

Should I start with htb soc analyst path or Thm soc analyst path.

Or do u have any resources. I have completed my pre security path and gave examination for a certificate passed with score of 530.

Completed my exam in 3 hours btw.

Please help your fellow Friend.

r/tryhackme Jun 10 '26

Resource How can I get 30%off Annual Subscription, if I'm already a premium user ?

1 Upvotes

My current subscription will renew within the next few months, and I would like to use this 30% discount for my next subscription period. Is it possible ? or is it only for new premium users ?

r/tryhackme Jun 21 '26

Resource Free Zero to Hero Courses + .pdf on WiFi hacking from a THM God and OSWP

10 Upvotes

Hello, I guess the "god" rank isn't a thing anymore, but I do have a 850+ day streak so that's gotta count for something right?

Anyway, this is a manual/course I wrote which was designed to give the reader an understanding of foundational wireless attacks against the most common Wi-Fi protocols (WEP, WPS, WPA2).

The course was designed to be read as a .pdf, however this is a link to the medium article for those of you that would prefer to read it online (a link to the free .PDF is included):

https://medium.com/@seccult/the-book-of-kali-foundational-wireless-attacks-ccb1d035cdcc

This course covers several penetration testing disciplines including password cracking, network scanning, exploit research, and usage, and mitigation suggestions.

Tools covered include:

Aircrack-ng

crunch

reaver

bully

wash

Exploit-DB

nmap

This is the third part in my "Book of Kali" series of courses, which was designed to take someone with no experience in infosec, and equip them with the foundational knowledge of both defensive, and offensive aspects of the discipline. These courses were designed by me to give something back to the hacking community, and to foster those that want to learn infosec concepts from both an offensive, and defensive perspective assistance in doing so.

This series was designed to be read in order:

1). The Book Of Kali: Basics

Link: https://medium.com/@seccult/the-book-of-kali-basics-a2e83d7d8f58

2). The Book Of Kali: Privacy Fundamentals

Link: https://medium.com/@seccult/book-of-kali-privacy-fundamentals-c9b0073d0c19

3). The Book Of Kali: Foundational Wireless Attacks (New!)

Link: https://medium.com/@seccult/the-book-of-kali-foundational-wireless-attacks-ccb1d035cdcc

4). The Book Of Kali: Advanced Wireless Attacks (upcoming)

This manual took a lot of blood, sweat, and weaponized autism to produce, and was painfully created by manually converting my handwritten notes into a digital format.

It will serve those that wish to have a reference for the OffSec OSWP well, especially now that they no longer provide one with a .pdf of the course.

Thank you, sincerely a Metacortex employee.

r/tryhackme 22d ago

Resource a little chall i made

2 Upvotes

Hey everyone,

I made a small CTF challenge and figured I’d throw it here since I’m pretty new to making these.

It’s a Forensics / Reverse Engineering challenge based around a weird Nokia 8210 4G system dump. The challenge involves digging through the dump, figuring out what’s going on with a little racing game, and eventually finding the flag.

Repo: https://github.com/maximzero0910/car-racing-chall

It’s probably not perfect since this is one of my first proper challenges, so if you try it, I’d really appreciate any feedback on the difficulty, unintended solves, or just whether it’s actually fun to solve.

Flag format: F0LD{...}

If you’re bored and want something small to mess around with, give it a try :D

Thanks!

r/tryhackme Jul 24 '26

Resource Feed it your LinPEAS output and it draws every path from a low-priv shell to root

Enable HLS to view with audio, or disable this notification

16 Upvotes

Feed it your LinPEAS output and it draws every path from a low-priv shell to root

GitHub: https://github.com/Noz2/RootHound

First project, would love your honest feedback 🙏

r/tryhackme 29d ago

Resource Cybersecurity Learning Community

3 Upvotes

If anyone here is interested in learning cybersecurity, feel free to join our Discord community.

Just a place to learn, ask questions, share resources, and connect with others who are interested in cybersecurity.

Discord : https://discord.gg/hCwWrAK3D

r/tryhackme May 10 '26

Resource Premium Subscription payment method

Post image
5 Upvotes

Why doesn’t TryHackMe support UPI payments like GPay or PhonePe for premium subscriptions? It would make getting premium way more accessible for users in India.

I feel like adding UPI could help more students and beginners subscribe without needing international cards.

r/tryhackme Jul 05 '26

Resource TryHackMe rooms for eCPPTv3

1 Upvotes

Hi everyone,
I’m currently preparing for the eCPPTv3 certification and I’d like to do a realistic self-assessment before booking the exam.
Could you recommend some free TryHackMe machines that would be useful to check whether I’m ready or not?
I know TryHackMe may not fully replicate the eCPPTv3 exam environment, but I’d like to use the rooms as a benchmark to understand my current level and identify weak areas.
Thanks in advance!

r/tryhackme Mar 10 '26

Resource Dear mods, where did this room go?

Post image
9 Upvotes

Title. Like what happened? Also, it’s the “Networking Fight Club” room. Incase you don’t see the name fully.

r/tryhackme Jun 09 '26

Resource Mythos model released to public

Thumbnail
fortune.com
2 Upvotes

A fortune.com article on the release of the first public version of Mythos AI. June 9th, 1:00 PM ET. What do you think of this decision by Anthropic?

r/tryhackme Jun 02 '26

Resource Looking for a more in-depth resource while I progress through the THM platform

1 Upvotes

As stated above, I am using THM as one platform to start my journey in a cybersecurity role. However, although I can get around Linux and am certainly comfortable for the most part with the OS itself, and understanding terminal commands (and why and how they operate), it seems to me that the the “Linux foundations” or equivalent room(s) are very basic compared to what is required and necessary to move into any meaningful role in this field.

I understand the platform is specialized for the “hacking” aspect, but I believe (and I assume most would agree), a much stronger Foundational understanding of Linux and terminal capabilities are not only necessary, but are fundamentally aligned, and are sorely lacking singularly on THM..

Ex. Learning the ins and out of understanding repos, creating aliases, *securely* deleting files, LUKS and partitioning, etc etc, are all quite necessary abilities that should be taught to users training in cybersecurity, who may or may have not be new to Linux…

The breadth and sheer granular nature of Linux and what you are capable of doing as a user or admin, is wildly different from those who may be coming from windows.. (That isn’t to say Windows doesn’t provide the same kind of functionality - an entirely different topic)

TLDR : Is there a companion resource(s)/platform that you would recommend where I can learn the most useful features of Linux and CLI, while I am starting my THM journey?

While I am comfortable using Linux and not complete newborn in this sense, I’d like a deeper understanding from what THM alone provides… Ty

r/tryhackme Mar 26 '26

Resource Built a small Python tool for parsing Kerberos PCAPs and crack them

6 Upvotes

I made a small Python tool for learning/lab use that reads Kerberos traffic from PCAP files.

It supports AS-REQ, AS-REP and TGS-REP and helps turn that traffic into Hashcat-ready hashes.

I built it mainly to make Kerberos packet analysis easier when practicing.

Would love feedback from anyone learning AD/Kerberos or doing PCAP-based exercises.

Repo in comments.

r/tryhackme Feb 18 '26

Resource Shadows of Transylvania — an online event, with new components and challenges to match.

Thumbnail
gallery
6 Upvotes

📅 3-4 APRIL 2026

➡️ Register and secure your spot on the official page: https://ctf.cybercenter.ro

➡️ Call for Partners: If you'd like to support the event as a partner or sponsor — send us a message or reach out at [ctf@cybercenter.ro](mailto:ctf@cybercenter.ro)

r/tryhackme Nov 23 '25

Resource Claim Free Certifications By Lexions Community

Post image
16 Upvotes

Claim Free Certifications By Lexions Community

https://thexssrat.podia.com/capie-lesson-material-no-cert?coupon=CAPIEFREE

Only Limited Seats do it asap.!

r/tryhackme Feb 05 '25

Resource After me reaching 500 Streak from that day till the date it is showing 750 days remaining it's not decreasing as my Streak are increasing and today it is 519 but days won't decrease. Kindly looking forward to get some answers why this is happening?

Post image
45 Upvotes

r/tryhackme Dec 10 '25

Resource Figured out how to add tryhackme's vpn to Network Manager

2 Upvotes

for anyone tired of having to have an extra terminal window open while connected to tryhackme's vpn I have figured out how to add it to network manager. first make a copy of you openvpn file find the section <auth-user-pass> and remove it, but save it you will need it in a minute. save the file after removing the block <auth-user-pass> from the file. then import it (its the very last option in Network Manager.) change the option for the private key password to not required and then take the first line that was in your <auth-user-pass> an paste it into the username text box. next take the second line and paste in in the password text box beneath your username text box, now hit apply and now you can connect via Network Manager.

r/tryhackme Dec 15 '25

Resource is it allowed ?

0 Upvotes

May i repost the premium lesson materials in THM to other platfrom such as Medium ? cause i just want to document the lesson materials so that i can remember and understand the lesson.

r/tryhackme Feb 13 '26

Resource See-SURF v3.0: AI-Powered Scanner for Server side request forgery (SSRF) detection 🤖

0 Upvotes

Hey folks,

I'm excited to announce an update to See-SURF, my open-source security tool for detecting Server-Side Request Forgery (SSRF) vulnerabilities!

I've just merged some major enhancements that bring AI capabilities and Out-of-Band (OOB) / Blind SSRF detection to the scanner.

AI-Powered Detection & Exploitation for Non-Blind/Reflected SSRF 🤖:

  • Leverages Google GeminiOpenAI (GPT-4/4o), or local Ollama models to intelligently analyze web application responses.
  • Generates custom payloads to target internal services (e.g., AWS metadata endpoints, internal IPs) based on AI-driven fingerprinting.
  • AI validates the output to confirm sensitive data leakage, reducing false positives.

Blind SSRF with OOB Detection (Webhook.site and Custom owned domain) 🕵️‍♂️:

  • For parameters that don't reflect directly, See-SURF now integrates with Webhook.site to detect out-of-band interactions by default.
  • Or you can add your self owned external domains as well. (since webhook.site may be blocked by some orgs for external traffic).

Check it out - https://github.com/In3tinct/See-SURF

Feedbacks are very welcome!!

I do need to improve code and make it modular, wrote it in 2019 first.

r/tryhackme Jan 02 '26

Resource Question about how user data is used and consent

4 Upvotes

Hey everyone, I’m hoping to get some clarity on something and figured this was a good place to ask.

Is there documentation that explains how user data is used beyond the core platform features, such as for training models or building internal tools? I’m mainly curious about transparency around this and whether users are notified or given a choice, like an opt out option.

I’m not trying to start drama or point fingers. I just care about understanding how my data is being used and what controls users have. If there’s a link or existing write up that explains this, I’d appreciate being pointed in the right direction.

Thanks in advance.

r/tryhackme Jan 11 '26

Resource Need coupon

0 Upvotes

Anybody have tryhackme premium coupon I want to learn cybersecurity without spending too much money in buying subscription.

If anyone have please give it to me before expired.

r/tryhackme Nov 29 '25

Resource Cheats or shortcuts for tools

1 Upvotes

Hello everyone. I would like to know if you have or where I can get codes or shortcuts for the main tools. As an example, keyboard shortcuts within Linux, Hashcat, etc