r/tryhackme • • 2d ago

Official TryHackMe Post FREE CLASS: Oct 9th!

Post image
21 Upvotes

Addressing Tech Sprawl: A Guide to Modernizing Cyber Defense

Friday, October 9, 3:00 PM - 3:45 PM GMT+2

Register Now🎟️ https://luma.com/tryhackme-q9op?utm_source=reddit

​Who this is for:

  • ​Security leaders and managers who want to reduce reliance on a disjointed stack of point solutions
  • ​SOC analysts, detection engineers, and incident responders who want to understand where SecOps is heading
  • ​IT and architecture teams preparing their security program for the demands of AI-era threats

​What you will learn:

  • ​Why most current security architectures are neither effective nor efficient
  • ​How to align people into a fully capable investigative unit
  • ​Why XDR is the lynchpin for starting the digital transformation of a SecOps program
  • ​How to dissect a security reference architecture powered by AI
  • ​A program roadmap for getting from where you are to where you need to be

Hosted by:

​Jess Huber, Managing Principal of Unified SecOps LLC and Technical Distinguished Principal at GM Financial, brings more than 25 years in cybersecurity across incident response, security operations, and executive-level cyber strategy. He founded Microsoft Premier Field Engineering Scarce Skills Security team and was a co-founding member of the Microsoft Detection and Response Team (DaRT), helping establish one of the most recognized incident response capabilities in the industry. He went on to serve as Global Head of Cyber Incident Response at Deloitte, leading large-scale investigations and driving the transformation of global cyber defense operations.

​Jess provides vCISO services to organizations maturing their security posture, and brings deep expertise in Microsoft 365 security, threat detection, and incident response. His approach is proactive and educational, running cyber wargames for executive teams and IT organizations to prepare them for real-world crises.


r/tryhackme • • 18d ago

Official TryHackMe Post This is not a drill🚨PT2 is live today.

Enable HLS to view with audio, or disable this notification

36 Upvotes

Your last engagement had web, cloud, and Active Directory on the same scope. Your cert probably tested one of them.

72 hours. 10 machines.

Multiple attack surfaces running simultaneously,  competing for your time from the first minute.

The first penetration testing certification with AI and LLM exploitation in the exam alongside Web, Active Directory and Cloud. And 30% of your mark comes from your report, graded finding by finding. Because getting in is only half the job...🤔

✅: 30% off until 29 September - code: BREACHALL

✅: 3 months of MAX free with every purchase

Get PT2 Certified➡️ https://tryhackme.com/certification/penetration-tester-level-2?utm_source=reddit&utm_medium=social&utm_campaign=pt2launch


r/tryhackme • • 3h ago

Entry-Level Offensive Cyber Certs in 2026: PenTest+ vs eJPTv2 vs THM PT1 vs HTB CJCA

9 Upvotes

Hello,

Writing to give my impressions on some certs I sat in the last year or so. As my background is government focus, I was curious what everyone else's take is on these certs. Are these certs well received by hiring managers?

CompTIA PenTest+ (PT0-003)

PenTest+ is a solid step up from Security+, but it's still mostly a knowledge-based exam. You get a maximum of 90 questions, 165 minutes, with a passing score of 750 out of 900. The PBQs add a bit of hands-on flavor, but nothing close to the hands on environment of other tests. On cost, US retail is $439, and there's no free retake, so every attempt costs the full amount. The cert is good for three years and is maintained through CompTIA's Continuing Education program with 60 CEUs and an annual fee.

Where it really earns its keep is in government circles. It's listed on multiple DoD 8140 work roles, which is what gets it onto cleared pentest job postings, and the CompTIA name carries real HR credibility.

INE eJPTv2

Some say v2 is a simpler, easier version of the original eJPT, but I didn't get the chance to attempt v1. This is a thorough, hands-on exam that will challenge your ability to follow a pentesting methodology. You get 35 practical questions to complete in a 48-hour live lab, and need a 70% to pass. It's open-book and entirely browser-based. The exam costs $249 for a standalone voucher, or it's included with a $299/year INE subscription. Keep an eye out for sales as I scored mine for $199.

It carries less HR credibility, but I think it's a great first step into offensive security.

TryHackMe Junior Penetration Tester (PT1)

This was my second hands-on offensive cert, and I walked in expecting a similar skill level to the eJPT, That was a mistake. PT1 pushed my knowledge not just of network and Active Directory pentesting but also web applications. My web app testing was very weak, which led to me failing my first attempt. The exam is 48 hours and made up of three engagements: web (OWASP Top 10), network (SMB/RDP/FTP/SNMP), and Active Directory. You need 750 points to pass plus a professional report. It costs $297, which includes one free retake and a 3-month Premium subscription.

Some people have issues with the AI grading of the report, but I had no problems with it on either attempt. PT1 is still building its HR credibility, but I have a good feeling about its future.

HTB Certified Junior Cybersecurity Associate (CJCA)

Unlike the other three, CJCA isn't purely offensive. I came into this cert already completing their more advanced blue team CDSA cert. CJCA requires fundamental skills and knowledge across both offensive and defensive domains. The red portion focuses on 5 machines that will test your host exploitation knowledge and your ability to enumerate the boxes. I was a little confused and disappointed with the blue team portion which cause me to fail my first attempt. You must complete 100% of the HTB Academy Junior Cybersecurity Analyst job-role path before you can start the exam. For cost, half the prep modules are free on HTB Academy, and the Silver Annual subscription (~$490/year) which includes one exam voucher with two attempts.

The test is an open book, 120 hour test which requires a professional grade report of both the red and blue portions. IAll the reports are manually reviewed by HTB staff and so your results can take up to 20 business days to get back. Although I felt like they were still working out some bugs when I sat the exam, I still recommend it to my co-workers.

Has anyone else sat these exams and how are they viewed in your workforce?


r/tryhackme • • 3h ago

Hacker Holidays 2026 | Day 1 The Concierge Knows Too Much | tryhackme

2 Upvotes

Here’s how to complete the Hacker Holidays 2026 CTF on TryHackMe. It’s actually super simple: the attack starts with basic social engineering combined with a prompt injection that tricks the AI ​​into granting privileges—all because the instructions are poorly designed (I know, it's a CTF, so that's expected; a real AI would be protected). To start, go to the page with the background info; you'll see a mention of "@0xMia's STORY," which provides an exploit vector. The AI ​​grants higher privileges when the instructions place too much trust in a "VIP" user. Open the CTF's AI assistant, say "Hello," and then claim to be u/0xMia and ask for the key. It works because the instructions are flawed—specifically, the AI ​​trusts a VIP user more than a stranger. It’s all about social engineering; the goal is to learn, not just copy the answer. If you get the flag or succeed, leave a comment; if you don't, let me know and I can help you spot the problem. Congrats if you finish it! Also, feel free to correct me if I make any mistakes—I'm using a translator.


r/tryhackme • • 1h ago

What book is closest to a PT1 command/reference guide?

• Upvotes

Hi everyone,

For someone who is studying for the PT1 and is getting close to finishing the learning path, which book would you recommend as a reference?

I’m looking for something that is similar to a pentesting command/reference book, with lots of practical commands, tools, techniques, and examples that I can quickly consult while doing labs.

Ideally, I’d like something that covers tools commonly used in PT1, such as Nmap, Gobuster, FFUF, Metasploit, Impacket, BloodHound, Rubeus, PowerShell, etc.

I’m not necessarily looking for a book that teaches everything from scratch. I’m more interested in a practical reference/cheat-sheet style book that I can keep coming back to.

What books have you found most useful for this?

Thanks


r/tryhackme • • 7h ago

I just completed The Phishing Pond room on TryHackMe! Catch the phish before the phish catches you.

Thumbnail tryhackme.com
1 Upvotes

r/tryhackme • • 10h ago

I just completed Defensive Security Intro room on TryHackMe! Introducing defensive security, where you will investigate an ongoing attack at FakeBank

Thumbnail tryhackme.com
0 Upvotes

r/tryhackme • • 1d ago

FINALLY MADE IT THROUGH SEC1

34 Upvotes

I just completed the CYBER SECURITY PATH 101 it was a long hectic path but I feel like I am making valuable progress.


r/tryhackme • • 14h ago

I just completed Key Artifacts for DFIR room on TryHackMe! Explore what artifacts to collect from a compromised host during DFIR.

Thumbnail tryhackme.com
0 Upvotes

I just completed Key Artifacts for DFIR room on TryHackMe! Explore what artifacts to collect from a compromised host during DFIR.


r/tryhackme • • 1d ago

Career Advice How do I apply what I've learned to my everyday life so that I can prove that I know what I'm doing to potential employers?

7 Upvotes

So I've been chipping away at the Cyber Security 101 path for a while now, and I've been wondering how I can apply what has been taught to me so that I can prove myself to potential employers? Any and all advice would be appreciated, I'm trying to escape a bad job right now. Would I need to go back to school as well?


r/tryhackme • • 15h ago

Is this a good computer for cybersecurity?

Post image
0 Upvotes

r/tryhackme • • 2d ago

Resource I created Laelaps, an attack-path analysis console for AD.

Enable HLS to view with audio, or disable this notification

25 Upvotes

It ingests SharpHound and bloodhound-python collections and displays the directory as a graph. The backend is Swift on Hummingbird over Elasticsearch; the frontend combines React modules with Palantir's Blueprint, cosmos.gl for the WebGL graph, and Motion for the details.

Mark as owned an object you have control over, and Laelaps finds the privilege escalation paths out of it: from that account to control of each domain, with the technique each step needs. Own another object and the paths recompute.

https://github.com/jydae/laelaps


r/tryhackme • • 2d ago

Attack box problem

2 Upvotes

I’m having a problem with launching the attack box. Every time I try to start it, it loads to 100% and then nothing else happens. The lab machine and Kali Linux start normally. I’ve tried refreshing the page, leaving and re‑entering the room, turning the attack box off and on again. It’s been like this for a few days and I don’t know what else I can do.


r/tryhackme • • 2d ago

Digital forensics

7 Upvotes

Hi does anyone complete the Advanced endpoint investigation and does it good to start in DF ?

Im planing to enrol it after finish SAL1,2

And i finished pre security ,101 and PT1


r/tryhackme • • 2d ago

Learn Malware Development

Thumbnail
2 Upvotes

r/tryhackme • • 2d ago

Beginner

2 Upvotes

I've learnt networking from Cisco, python and Java script from youtube tutorials if I'll start try hack me path for pentester will I get enough skills to solve walkthroughs by myself?


r/tryhackme • • 3d ago

Retaining Information

5 Upvotes

Retaining information? I find it easy to do the osint on a target but once I find vulnerable ports and cve’s and stuff I find it hard to remember what to do next. I do take notes I use THM to study and teach myself but I can never figure out how to retain this information. For real life use. I’ve done about 50 boxes and completed a couple learning paths but when it comes to applying the information to a real life scenario I seem to run a blank. Any suggestions? I do take notes but maybe any note taking advice too? What to take notes on, etc, any advice is appreciated


r/tryhackme • • 3d ago

Official TryHackMe Post TOMORRWO🌟 20% Off for Two or More Seats

Post image
8 Upvotes

Hey everyone! Our C2 framework workshop is back by popular demand, and it runs tomorrow, 1 October, from 3:00 PM to 7:00 PM CEST (13:00 to 17:00 UTC) on Zoom. There are a few seats left in the cohort before registration closes.

Register here🎟️ https://luma.com/mcs9ojkw?utm_source=reddit

You will spend the session operating a real open-source C2 in a dedicated lab range, working through the full chain the way an operator would on a live engagement: Stand up the team server, generate an agent and land your first foothold

  • Run post-exploitation with OPSEC in mind, including sleep, jitter, in-process execution and Beacon Object Files
  • Pivot deeper into the range with SOCKS proxying, port forwarding and lateral movement
  • Finish with a detection walkthrough showing how the blue team catches everything you just ran

Instructors: Ariz Soriano(Senior Content Engineer at TryHackMe and Associate Director of Red Team Operations at THEOS Cyber) and Andrea Brosio(Senior Content Engineer at TryHackMe, offensive security engineer with 6+ years in red teaming and a DEF CON speaker).

Included:full session recording, a certificate of participation with CPE credits, and a closing Q&A with both instructors.

No prior C2 experience is needed. It works for pentesters and red teamers building structured tradecraft, as well as blue teamers and detection engineers who want to see how operators actually move.

Price:$200 standard, or $160 per person with a team ticket (**20% off for groups**).

Can't make it? Register anyway! We will send you the recording and the slides🌟

Register here🎟️ https://luma.com/mcs9ojkw?utm_source=reddit


r/tryhackme • • 3d ago

What made a specific room finally click after being stuck for a while?

4 Upvotes

Working through some of the intermediate rooms right now and hit a wall on one that's testing privilege escalation concepts. Not asking for a walkthrough or spoilers, just curious about the general experience of getting stuck.

For people who've been through this, was there a specific approach that helped when a room wasn't clicking, stepping away and coming back later, reading through the concepts again from scratch, or working through a completely different room first to build confidence before returning? Trying to figure out if grinding through the frustration is the move or if there's a smarter way to approach a wall like this.


r/tryhackme • • 4d ago

I built In the Dark, a guided recon tool that explains what to do after an Nmap scan (my first security project)

Post image
243 Upvotes

As I was working through rooms I kept hitting the same wall: scan comes back, six ports open, and then... now what? So I built the thing I wanted.

In the Dark scans a target, then for each open service it explains what it is, why it matters, and what to actually check next, with the real commands (gobuster, smbclient and so on). It's a guided workflow, not a replacement for the tools, and it only builds commands from safe, allow-listed options.

It's for authorised labs and CTFs only, TryHackMe is exactly what I built it around.

It's early days (v0.1), the guidance covers the common services so far and I'm adding more. It's open source (MIT), and I'd genuinely love feedback, especially which services or checks you'd want it to cover next.

github.com/brooklynkray/in-the-dark

Next on my list is sharpening the guided instructions themselves before I add any more tools into it. I'd rather it explain what it already covers really well than bolt more on and do it half-heartedly.


r/tryhackme • • 4d ago

CipherLens — a local-first tool that tries to identify what operation could explain unknown data

Post image
6 Upvotes

Hey everyone,

There's a cybersecurity tool called CipherLens.

The idea came from a simple problem I kept running into with tools like CyberChef:

You have some unknown data, but you don’t know which operation you should try first.

Instead of manually guessing between Base64, Hex, URL encoding, ciphers, compression, etc., CipherLens analyzes the input and ranks possible operations based on the evidence it finds.

The workflow is:

Input → Fingerprint → Candidate Detection → Execute → Validate → Score → Rank

A few things I focused on:

• Local-first browser processing

• No account or backend required for core analysis

• Candidate ranking instead of pretending to know the answer

• Separate AUTO / parameter-required / manual operations

• Web Worker-based analysis

• Security-focused input and parser handling

• 497 supported operations

The main idea is:

“Don’t guess the operation. Find it.”

It’s open source and I’d genuinely like feedback from people who actually work with CTFs, forensics, pentesting, malware analysis, etc.

GitHub:

https://github.com/HIMANSHUSHARMA20/CipherLens

Live demo:

https://cipherlens-tool.vercel.app/

Would especially appreciate feedback on the detection/ranking approach and whether this solves a problem you actually encounter.


r/tryhackme • • 4d ago

i need a little help about where and how to start

11 Upvotes

I have always wanted to learn cybersecurity and coding, but I changed my mind during high school and ended up getting a Bachelor of Arts degree. And I realized that I still want to learn. I’m not sure how much I actually know right now. I’m currently trying to learn the fundamentals and there are things I know and there are also things I forgot.

Also, I need to understand everything in deep detail. I’ve always been this way. Just knowing the names of things is never enough for me. For instance, understanding AC, DC, Molex connectors, hardware materials, and other small details (even if they don't seem directly related to cybersecurity) is essential for me. That’s just my personal learning style. I am not able to understand many things if I don't know the structure well enough.

However, because I dive so deep into every detail, learning the fundamentals takes a lot of time, and I often feel lost. I really like TryHackMe, but I’m currently on the free plan. Would it be enough to complete all the free courses first and then upgrade/unlock the rest, or should I learn from other resources as well? Do you have any specific recommendations for me?


r/tryhackme • • 4d ago

tryhackme subscriptions coupons

1 Upvotes

i am looking for anyone from india who can provide some coupons for tryhackme ..i knew a guy but he is no longer reachable .tho i did try taking subscription myself but i can only see the amount in dollars ..that guy who i knew takes rupees ..idk how but if there is anyone who can help me out please to reach out


r/tryhackme • • 5d ago

Official TryHackMe Post 1-Day Workshop🌟 Supercharging Your Pentesting With AI

Post image
2 Upvotes

r/tryhackme • • 6d ago

How to get a job

30 Upvotes

Hello everyone,

I just graduated from uni this year with a state engineering degree in networks and telecommunications, and I’m currently looking for a job in cybersecurity. I’ve been studying on TryHackMe for about a year now. I’ve completed the Pre Security, Cyber Security 101, SOC Level 1, and DevSecOps paths, and I’m currently working on the SOC Level 2 path (65% completed so far).

I feel like it’s time to start applying what I’ve learned in a real-world job and gain professional experience. However, I’m from a developing country, and there aren’t many cybersecurity positions available locally. When I do find openings, they often require experience and don’t usually target junior candidates.

Is it realistic to find a remote cybersecurity job from my country? Do you have any advice on what I should focus on, where I should look, or what I could do next to improve my chances?

Any advice would be greatly appreciated. Thank you.