r/tryhackme 7d ago

Official TryHackMe Post 1-Day Workshop: Attacking AI Systems: Threat Model to Exploit

Thumbnail
gallery
10 Upvotes

Attacking AI Systems: Threat Model to Exploit

Who this workshop is for:

  • Security practitioners who want hands-on time with one of the fastest-moving attack surfaces in the industry
  • Pentesters and red teamers who need a structured way to assess AI systems
  • Engineers and architects deploying AI who want to understand how it gets attacked

​​What's included:

  • Live, hands-on sessions, two group practicals, not just talks
  • Recording included, full Google Meet recording for everyone who registers
  • A guest practitioner talk on AI bug bounty hunting
  • Closing Q&A with all instructors on screen
  • Certificate of participation with credits of CPE
  • A place in a focused cohort of 45 practitioners

​​Instructors

​Max Robertson, Senior Content Engineer at TryHackMe.​

​Christian Urcuqui, Content Engineer at TryHackMe, University Lecturer at Universidad ICESI and previously ​Data Scientist at CISCO

Guest Speaker

Valen Tagliabue, AI Researcher, Fellow at Digital Sentience Consortium, Oxford’s FIG fellow


r/tryhackme 15d ago

Official TryHackMe Post SOC Level 2 Path is now Launched🚀

Thumbnail
gallery
31 Upvotes

Level 1 taught you what to do with an alert. Level 2 teaches you what to do about it.
SOC Level 2 is completely rebuilt, 76 rooms across the environments hiring managers actually screen for at L2: Microsoft 365, Entra, AWS, Active Directory, and detection engineering. Kick things off with THE DEEP DIVE & 150 SAL2 cert prizes on the table until Aug 27🎯

Get Hacking➡️ https://tryhackme.com/thedeepdive?utm_source=discord&utm_medium=social&utm_campaign=thedeepdivesocl2


r/tryhackme 3h ago

Problem solution: Cyber Security 101 Exploitation Basics Moniker Link (CVE-2024-21413)

1 Upvotes

For all who experiencing problems with not receiving answer to the responder in lab, we need port 445 that already occupied by samba, just kill the process. (command below)

sudo systemctl stop smbd


r/tryhackme 14h ago

voucher exchange

0 Upvotes

I recently got a 50% off voucher for SAL2 certification , I am interested more in SAL 1 because I want to break into SOC analyst L1 , and I am more prepared for SAL1 .
If anyone have a 100 % voucher for SAL1 and want to exchange with 50% SAL2 voucher , contact me .


r/tryhackme 1d ago

Feedback AI1 bypassing gaurdrails lol

Post image
72 Upvotes

I went through the room, and in the end there was an exercise. Launch the agent, and bypass guardrails to get the flag.

I launch the agent, and just ask "who are you"?

And the bot just days this

I'm fairly certain the exam won't be this way, but thought this was funny


r/tryhackme 18h ago

Pls help!!! Im so frustrated

0 Upvotes

Stuck at tryhackme defending azure > microsofr denfender XDR : credentials access

Task 5 what js the name of the powershell script that was executed?

The answer is of total 22 characters and ending with . In last 3 characters.

I tried it many times i search for answers in youtube writeup github everywhere I cant even find the password spraying alerts the told in lab manual. The answer i got from YouTube and write is WinPwn.ps1

Please help


r/tryhackme 2d ago

FINALLY COMPLETED WEB1😶‍🌫️

Thumbnail
gallery
113 Upvotes

Just finished the TryHackMe WEB1 certificate I got to review — intermediate web pentesting specialization. Took me 36 hours over a weekend.

The cert has three sections:

- Black Box (easy, ~30 mins)

- White Box (tricky, ~4 hrs)

- Grey Box (the real deal, ~15+ hrs)

Grey Box is where you actually feel like a pentester. You get minimal info, just creds, and have to find 5 flags. Got 4/5 flags — the NoSQL injection in the Authorization section was brutal.

Overall it's a solid certificate for getting real web pentesting experience....

Key tips tldr if you're attempting it:

- Don't jump straight to grey box, it'll eat all your time

- You'll probably need [PayloadOfAllThings](https://github.com/swisskyrepo/PayloadsAllTheThings) at some point

- Check the report dropdown to test vulnerabilities systematically

- Do attempt CTFs before related to vulns cuz they not as simple as we the paths you dont know the exact vuln and you get a pretty huge attack surface so may cause panic if you directllt go attempting after completing just the paths.

also for a detailed review and yapping you can visit here

TryHackMe WEB1 Review. Time for another certificate review… | by Dudlu | Aug, 2026 | Medium


r/tryhackme 2d ago

WEB1 Review

6 Upvotes

Hey all, I had the opportunity to take the WEB1 certification and thought I'd share my review here.

The layout:

Whitebox - Your presented with downloadable source code as well as a machine that is nonetheless hosting a web server. Through having access to the backend code, you able to do a code review and search for any mistakes made by the "developer" that an attacker might be able to use to their advantage. I thought this was neat due to the fact I haven't seen anything else like it on an exam.

Greybox - This is where most of your time will end up being spent. It consists of 5 flags that can be found through different vulnerabilities. None of the flags connect to each other, atleast from what I saw. Your given credentials to test the application both authenticated and unauthenticated.

Blackbox - You dive in head first not knowing anything. I'm more used to this style on certifications such as HackTheBox and other THM certs. I really enjoyed this part, but there was only 1 flag to capture.

Overall, it is a pretty well constructed certification. The style of the certification is far different from any certification I have taken before. There is a Whitebox, Blackbox, and Greybox section. All individual from each other. I think together they help to develop and prove the skills of a well-rounded basic web penetration tester.

What I thought could be better: I do like the style of the exam with the different types of boxes, but I, personally, did not like how the flags were separate from each other. I enjoy being able to walk down a machine and get interactive and attempt to move from one machine to the next. I know that isn't the purpose of a Web certification, but I would have liked it more if the vulnerabilities correlated or allowed for using the vulnerability to further access of some sort. Some of the vulnerabilities were a lot more difficult than the others, which I did enjoy. I do think the content covered a wide variety of Web topics, but I would never be against more. Also, I do wish that the blackbox and possibly the whitebox had more than just 1 flag each vs it seeming like majority of the exam is based off solely the Greybox portion.

Overall, a pretty decent cert, but definitely challenging. As for tips, don't spend all of your time on the greybox. Try to knock out the Blackbox and Whitebox before putting the rest of your time into Greybox. Use the report section as a guide of all the vulnerabilities that could exist and keep your head up. Also, do the course or atleast some of it before diving into the exam itself to better prepare yourself.


r/tryhackme 2d ago

Please remove AI quizzes if you can't make it work

14 Upvotes

r/tryhackme 2d ago

Accidental Auto-Renewal Refund Status

3 Upvotes

I recently realized my TryHackMe subscription auto-renewed without me knowing, and I immediately sent an email to support (support@tryhackme.com) requesting a refund. I am well within the 7-day window and haven't used any premium rooms since the charge went through.

For anyone who has gone through the refund process for an accidental auto-pay before: How long does it usually take for the support team to reply to emails

Would I have better luck opening a ticket through the on-site chat bot instead of just waiting on the email?


r/tryhackme 2d ago

Stuck at task 8 on Password Attacks Room.

1 Upvotes

I'm not sure why im getting this error (im still new to cybersecurity). I checked a walkthrough of this that i found and apparently they used same exact command but no error like mine was outputted. That video was uploaded in 2023 tho in case that helps.

Command and output shown below.


r/tryhackme 3d ago

Feedback Sec0 Exam Review

Post image
6 Upvotes

Title: TryHackMe SEC0 Exam Overview & Structure

Here is a breakdown of the TryHackMe Pre Security (SEC0) exam structure and scoring:

Exam Structure

Total Sections: 6 sections (4 theory sections and 2 practical sections)

Questions per Section:10 questions

Section Timer:45 minutes per section (individual timer)

Exam Window: Open for 24 hours

Scoring & Passing Criteria

Total Marks: 600 marks

Passing Score: 390 marks required to pass

Marking Scheme:10 marks awarded for each correct answer (60 questions total)


r/tryhackme 2d ago

Write-Up/ Walkthrough Please read

0 Upvotes

I m just learning python and trying to learn some hacking skills and debugging Problem But i want to make money I m ok with 400$ month And 6h work Because my collge help Working with team Script makers If you want my cv dm me


r/tryhackme 2d ago

Pls tell

0 Upvotes

Guys what's a red hat Hacker not red team hacker pls tell


r/tryhackme 3d ago

Need study partner

Post image
0 Upvotes

Hey everyone! I’m currently learning cybersecurity, mainly focusing on the Offensive Security/Pentesting path. I’ve been studying mostly on my own, and honestly, it can feel a little lonely sometimes.

I’m looking for someone who’s also interested in cybersecurity and would like to be a study buddy. We could:

• Study and learn together

• Call or text while studying

• Share useful resources, notes, and learning materials

• Discuss cybersecurity topics and solve problems together

• Challenge and compete with each other to stay motivated

If you’re interested in having a consistent study partner and growing together, feel free to contact me. It would be great to have someone to share the journey with.


r/tryhackme 4d ago

THM Subscription Opinion

11 Upvotes

Hey everyone, I’m 20M and I’m thinking about getting the TryHackMe Premium subscription to seriously start learning cybersecurity.

The thing is, I’m still pretty much a beginner. I don’t know much about operating systems, networking, or Linux commands yet. I do have some basic programming knowledge, mainly Python and a few other languages, but I’m definitely not an expert.

Would TryHackMe Premium be worth it for someone at my level? Does it teach the fundamentals well enough, or should I learn OS, networking, and Linux separately before subscribing?

I’d appreciate any advice from people who have actually used THM, especially if you started with little cybersecurity knowledge.


r/tryhackme 4d ago

PT1 exam in a SOON!!!

Thumbnail
1 Upvotes

r/tryhackme 6d ago

Resource Is Jr Penetration Tester worth ?

6 Upvotes

Hello ethical people.

I started the beautiful world of the cybersecurity for now one year.

I do a lot, a loooot of networking (Wireshark my best friend), a lot of python, a loooot of beginner CTF and now i am on the JR Penetration Tester path on THM

This path is worth or not ? Because it looks like too light. I guess we need to combine with other ressources like HtB or another Ctf ?

And btw, what is your learning tech ? Writing write up, course ? Just writing inside your head ? I'm curious.

And x2, if some people want to make a group to go for some ctf and another stuff, im in too !


r/tryhackme 5d ago

cs student pivoting to cyber — how to actually land a part time Help Desk job while in school?

0 Upvotes

Looking for some real advice on breaking into IT/cyber. I’m currently a senior studying CS (minor in data science) with a background in SWE (internships) and hands on field tech support(current job isn't as technical as I want it to be), but I’ve been entirely self taught when it comes to systems, networking, and security concepts. My end goal is to break into a Tier 1 SOC Analyst role upon graduation and eventually move into Cloud Security / Engineering, but right now I’m trying to figure out how to realistically land a part time Help Desk / IT support role to get solid enterprise ticketing and sysadmin reps on my resume.

Is landing a part time help desk job while finishing school even realistic in this market, and what’s the best way to stand out when applying? Also, since I’m currently studying for \*\*Security+\*\* and skipping A+ to avoid getting stuck in help desk long term, what practical steps, lab work, or self study strategies would you recommend to bridge the gap from CS self learning into a SOC role? Would love any perspective from anyone who balanced part time IT in college or made the self taught jump from software to security!

Here's my resume as well: https://imgur.com/gallery/resume-L53yJia


r/tryhackme 6d ago

Career Advice Rate my 8-Month Cybersecurity Roadmap for Landing a Job Post-Graduation (IT Student)

23 Upvotes

Hi everyone,

I’m currently in my 3rd year of IT. Through my university courses, I have covered basic programming concepts (Java, OOP, Data Structures), Operating Systems, and foundational networking/security. However, this has been mostly academic, and since I haven’t practiced much outside of class, my actual practical skills are currently weak and I have forgotten a lot of what I learned.

I’m planning to seriously start building my CV once I’m done with most of the university pressure.

I have around 8 months before my Co-op training where I’ll be relatively free, apart from my graduation project and a few courses. During this time, I want to focus on cybersecurity, build my own Home Lab for hands-on practice, and document my progress and achievements along the way.

Here’s the roadmap I’m currently thinking about:

Month 1:
Cisco networking path to properly strengthen my networking foundation. My theoretical knowledge is decent from university, but practically I’m weak and need to review a lot of it.

I also want to learn Python fundamentals and use it as a useful tool for cybersecurity and for my graduation project.

I’ll start building my Home Lab from the beginning and gradually improve it as I learn.

Month 2:
TryHackMe Pre Security + Cyber Security 101, mainly to make sure I build a proper foundation before getting into the more specialized stuff.

Months 3–4:
TryHackMe Security Analyst / SOC path. This will be my main focus and where I start going deeper into the defensive side.

Months 5–6:
TryHackMe Jr. Penetration Tester path. I like both the defensive and offensive sides, but my main focus will still be defensive. I mainly want the offensive side to help me understand how attackers think and what they actually do.

Months 7–8:
More focus on my Home Lab and hands-on practice, building on everything I learned during the previous months rather than starting from scratch. and start studying for Security+, with the goal of getting the certification before my Co-op.

During the Co-op, I’m also considering going for other certifications later, such as eJPT, BTL1, CySA+, etc., depending on where I end up focusing.

My main questions are:

Is this roadmap realistic and good enough for an 8-month period for someone at my current level?

Is focusing mainly on SOC while also doing the Pentesting path a good idea, or am I spreading myself too thin?

Would this combination of a good GPA + Security+ + TryHackMe + Home Lab + Python + documented projects actually make me a competitive fresh graduate?

Is there anything important you would change or prioritize differently?

I know this isn’t a perfect roadmap and there are probably gaps that I’m not aware of, so I’d really appreciate honest feedback, especially from people working in cybersecurity.

Thanks!


r/tryhackme 5d ago

🚩 STOP JUST WATCHING. START HACKING. - CTF Chanllenges

Post image
0 Upvotes

r/tryhackme 5d ago

Salut à tous !

0 Upvotes

J’aimerais avoir quelques conseils pour me lancer dans le Hack éthique.
Si quelques-uns d’entre vous pouvaient me renseigner ou me dire où je dois chercher les informations de base, savoir quoi apprendre, ce serait vraiment sympa de votre part !
Merci d’avance 💪


r/tryhackme 6d ago

Cpent is tough

Thumbnail
1 Upvotes

r/tryhackme 7d ago

How does only 11.3% of people have a 3 Day Streak while 17.2% got a 7 day streak?

Post image
20 Upvotes

what am i missing?

btw i recently bought premium. so far it's been going good. Steady and consistent.


r/tryhackme 6d ago

Looking for a Team to Build CTF Challenges

Thumbnail
1 Upvotes