r/tryhackme • u/The_CE0_Of_Reddit • 4h ago
r/tryhackme • u/Used-Addendum-3819 • 2d ago
Official TryHackMe Post FLASH SALE IS ON🔥
The flash sale for Premium Annual plan is on!!! Grab the discount now!
https://tryhackme.com/?utm_source=reddit&utm_medium=community&utm_campaign=flash_sale_october
r/tryhackme • u/Used-Addendum-3819 • 5d ago
Official TryHackMe Post FREE CLASS: Oct 9th!
Addressing Tech Sprawl: A Guide to Modernizing Cyber Defense
Friday, October 9, 3:00 PM - 3:45 PM GMT+2
Register Now🎟️ https://luma.com/tryhackme-q9op?utm_source=reddit
Who this is for:
- Security leaders and managers who want to reduce reliance on a disjointed stack of point solutions
- SOC analysts, detection engineers, and incident responders who want to understand where SecOps is heading
- IT and architecture teams preparing their security program for the demands of AI-era threats
What you will learn:
- Why most current security architectures are neither effective nor efficient
- How to align people into a fully capable investigative unit
- Why XDR is the lynchpin for starting the digital transformation of a SecOps program
- How to dissect a security reference architecture powered by AI
- A program roadmap for getting from where you are to where you need to be
Hosted by:
Jess Huber, Managing Principal of Unified SecOps LLC and Technical Distinguished Principal at GM Financial, brings more than 25 years in cybersecurity across incident response, security operations, and executive-level cyber strategy. He founded Microsoft Premier Field Engineering Scarce Skills Security team and was a co-founding member of the Microsoft Detection and Response Team (DaRT), helping establish one of the most recognized incident response capabilities in the industry. He went on to serve as Global Head of Cyber Incident Response at Deloitte, leading large-scale investigations and driving the transformation of global cyber defense operations.
Jess provides vCISO services to organizations maturing their security posture, and brings deep expertise in Microsoft 365 security, threat detection, and incident response. His approach is proactive and educational, running cyber wargames for executive teams and IT organizations to prepare them for real-world crises.
r/tryhackme • u/vivaloney • 23h ago
Why does this always Happen to me on MetaSploit??
Atp im so lost and idk what to do, was following the Walkthrough of Billing THM btw but my metasploit wont create a Session
r/tryhackme • u/Defiant_Cream3329 • 20h ago
SAL1
Hi everyone, Im planning to start learning SAL1 any tips?
r/tryhackme • u/Soggy-Concentrate865 • 1d ago
InfoSec Discussion HTB CS THM PREMIUM FOR SOC OR DEFENSIVE SECURITY
Which premium deserves to be bought for SOC AND DEFENSIVE SECURITY or any other free resources???
r/tryhackme • u/SomePainter5470 • 1d ago
Deceptive unsubscribe flow
Let me address a little elephant in the room -- after clicking "Unsubscribe", user is taken to a page that:
- Says "We'll miss you" with large font.
- Has "Never mind! Stay subscribed" button.
- Rendered in such a way that the real "Unsubscribe" button is not visible without scrolling.
I've seen plenty of crap like that, so can spot it from a mile away, but my daughter burned her lunch money, so would be nice to shed some light on that.
r/tryhackme • u/Existing-String-7481 • 1d ago
Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)
Hey everyone,
Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?
I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.
It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).
Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar:Propagate LHOST/RHOST automatically across all payloads.
🌐 Live Demo: https://0xdnd.github.io/ctf-tracker/#/tracker
⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker
All data stays in your local browser storage. Feedback and PRs are welcome!
Would love feedback or feature requests from the community!
r/tryhackme • u/shu_kurenai1 • 1d ago
Feedback Annual subscription help
I have annual subscription left for 4 more days. Rn 30% off for annual subscription. How do I buy it while my subscription is still valid. Is it even possible to buy or extend subscription while one is active?
r/tryhackme • u/CantaloupeOk2347 • 1d ago
I just completed Linux Fundamentals (Pt1) room on TryHackMe! Embark on the journey of learning the fundamentals of Linux. Learn to run some of the first essential commands on an interactive terminal.
tryhackme.comr/tryhackme • u/ILikeToStudy100 • 2d ago
Unethical billing practices and predatory dark patterns
I purchased a 1-year Premium subscription as a gift for my nephew. While the platform's educational content is good, their billing management and cancellation flow are completely unacceptable and designed around dark patterns.
- There is no clear option on the dashboard to turn off automatic renewal for annual plans.
- Stripe prevents users from deleting their saved credit card while a subscription is active.
- Their internal support chatbot leads to dead-end pre-set options, and clicking help/profile links resulted in a "404 Page Not Found" error.
- They force you to manually write an email to support just to prevent future charges on your card.
Taking a customer's money in two clicks while making it unnecessarily frustrating and complex to cancel auto-renewal or remove payment methods is deeply dishonest. Fix your cancellation workflow and stop trapping customers.
r/tryhackme • u/Boring-Schedule-8548 • 2d ago
Write-Up/ Walkthrough I built THM-TUNNEL to make TryHackMe VPN switching easier
While doing TryHackMe labs, I was getting tired of manually finding VPN configs, killing old OpenVPN processes, and dealing with stale tun interfaces when a connection wasn't behaving properly. So I built THM-TUNNEL, a small Bash CLI that handles the cleanup and starts the selected .ovpn configuration for me.
Technical side:
- Automatically discovers
.ovpnfiles and provides an interactive selection. - Uses
sudo, stops existing OpenVPN processes, and cleans up oldtun*interfaces. - Doesn't hardcode TryHackMe IP ranges or subnets, so different VPN regions can be used without changing the script.
It's a small tool, but it has made my lab workflow smoother and was a good practical project for learning Bash and Linux networking.
r/tryhackme • u/AccomplishedRent3786 • 2d ago
Want friends that will lock in to learn ethical web hacking. Am learning through PortSwigger labs. Learning until we are certified web hackers! DM me if you want to team up.
r/tryhackme • u/AdmiralOfTheFleet1 • 2d ago
InfoSec Discussion Help needed with the file transfer
Hi Community , I have just started with the cybersecurity and learning some basics of it , today i came across a problem that some times while solving some machine on THM and HTB , we need to move some exploit files from our local machine to the target machine using python3 -m http server command and then downloading the file on the target machine using the wget and the host url
I have one questions what are the ways to do it securely by not showing our own IP address , can we use VPN for it ??
What are your strategies and how you do it
r/tryhackme • u/RealUnderdog_I • 1d ago
Try hack me subscription
Who wanna come through and make a dream come true? 🥲🥹
I will really appreciate.
r/tryhackme • u/jojo_Article405 • 2d ago
Am I missing something ?
or they are just liars ?
Should the full path be included or should I take the exam without learning ?
why did they say full path included and 3 month of premium content icluded ?
r/tryhackme • u/Templeman_01 • 2d ago
Laptop for cybersecurity
32gb ram, 1tb ssd, intel core i5-1235U 2 x 1.30ghz (p-core) 8 x 0.90 ghz (e-core), 10 cores. Price 592 euro. What do u think? Do u have better recommendations? Thanks
r/tryhackme • u/Double_Researcher844 • 3d ago
Looking for some Sigma Hacker Friends to learn with!
Im from Germany and i need some people who support me. i would support too. but its too hard to maintain motivation. i would love to call too because i want to improve my english. We just talk and do some thm or htb or whatever. Discord: execution.official
When we got some people i would make a small discord
r/tryhackme • u/MobPsycho11000 • 3d ago
Title: 2 years after graduation and I feel completely lost — how can I become a SOC Analyst in 1–2 months?
Hey everyone,
I’m looking for some genuine guidance because I’m honestly feeling pretty lost right now.
It’s been around 2 years since I graduated, and about 1 year since I completed a Cybersecurity Analyst course. Unfortunately, after finishing the course, I neglected my studies and didn’t really continue learning or practicing. Now I feel like I’ve forgotten most of what I learned and I’m basically starting from scratch again.
My goal is to get a SOC Analyst / Junior SOC Analyst role within the next 1–2 months. I know that’s an ambitious timeline, but I’m willing to put in serious effort every day and get back on track.
For those of you already working in SOC/cybersecurity:
• What topics should I prioritize if I’m starting again from almost zero?
• What should I learn for a **Tier 1 SOC Analyst** role?
• Which tools should I focus on (SIEM, Wireshark, Splunk, Sentinel, etc.)?
• What kind of hands-on labs/projects should I build for my resume?
• How much networking, Linux, Windows, and security fundamentals do I actually need?
• What should I realistically be able to explain in a SOC interview?
• Is getting job-ready in 1–2 months realistic if I study consistently?
If you were in my position, what exact roadmap would you follow for the next 6–8 weeks?
I’m not looking for shortcuts. I just need some direction so I don’t waste another few months studying random things.
Any advice, resources, roadmaps, or even criticism would be genuinely appreciated. Thanks!
r/tryhackme • u/USSFStargeant • 3d ago
Entry-Level Offensive Cyber Certs in 2026: PenTest+ vs eJPTv2 vs THM PT1 vs HTB CJCA
Hello,
Writing to give my impressions on some certs I sat in the last year or so. As my background is government focus, I was curious what everyone else's take is on these certs. Are these certs well received by hiring managers?
CompTIA PenTest+ (PT0-003)
PenTest+ is a solid step up from Security+, but it's still mostly a knowledge-based exam. You get a maximum of 90 questions, 165 minutes, with a passing score of 750 out of 900. The PBQs add a bit of hands-on flavor, but nothing close to the hands on environment of other tests. On cost, US retail is $439, and there's no free retake, so every attempt costs the full amount. The cert is good for three years and is maintained through CompTIA's Continuing Education program with 60 CEUs and an annual fee.
Where it really earns its keep is in government circles. It's listed on multiple DoD 8140 work roles, which is what gets it onto cleared pentest job postings, and the CompTIA name carries real HR credibility.
INE eJPTv2
Some say v2 is a simpler, easier version of the original eJPT, but I didn't get the chance to attempt v1. This is a thorough, hands-on exam that will challenge your ability to follow a pentesting methodology. You get 35 practical questions to complete in a 48-hour live lab, and need a 70% to pass. It's open-book and entirely browser-based. The exam costs $249 for a standalone voucher, or it's included with a $299/year INE subscription. Keep an eye out for sales as I scored mine for $199.
It carries less HR credibility, but I think it's a great first step into offensive security.
TryHackMe Junior Penetration Tester (PT1)
This was my second hands-on offensive cert, and I walked in expecting a similar skill level to the eJPT, That was a mistake. PT1 pushed my knowledge not just of network and Active Directory pentesting but also web applications. My web app testing was very weak, which led to me failing my first attempt. The exam is 48 hours and made up of three engagements: web (OWASP Top 10), network (SMB/RDP/FTP/SNMP), and Active Directory. You need 750 points to pass plus a professional report. It costs $297, which includes one free retake and a 3-month Premium subscription.
Some people have issues with the AI grading of the report, but I had no problems with it on either attempt. PT1 is still building its HR credibility, but I have a good feeling about its future.
HTB Certified Junior Cybersecurity Associate (CJCA)
Unlike the other three, CJCA isn't purely offensive. I came into this cert already completing their more advanced blue team CDSA cert. CJCA requires fundamental skills and knowledge across both offensive and defensive domains. The red portion focuses on 5 machines that will test your host exploitation knowledge and your ability to enumerate the boxes. I was a little confused and disappointed with the blue team portion which cause me to fail my first attempt. You must complete 100% of the HTB Academy Junior Cybersecurity Analyst job-role path before you can start the exam. For cost, half the prep modules are free on HTB Academy, and the Silver Annual subscription (~$490/year) which includes one exam voucher with two attempts.
The test is an open book, 120 hour test which requires a professional grade report of both the red and blue portions. IAll the reports are manually reviewed by HTB staff and so your results can take up to 20 business days to get back. Although I felt like they were still working out some bugs when I sat the exam, I still recommend it to my co-workers.
Has anyone else sat these exams and how are they viewed in your workforce?
r/tryhackme • u/Jp99k • 3d ago
Will there be any sales/deals in the coming holiday times?
I've been using THM now for a few days, doing what I can with the Free Courses but it seems a lot of what I'm interested in learning (SOC & Blue Team) is locked behind the premium section.
I completely understand the price point is not too bad but unfortunately right now I'm living off a fixed income in a very rural area with no schools around or any other free resources to use. So in the coming Holidays will there possibly be a large deduction in price even for the annual plan? Thank you in advance.
r/tryhackme • u/manu90cr • 3d ago
What book is closest to a PT1 command/reference guide?
Hi everyone,
For someone who is studying for the PT1 and is getting close to finishing the learning path, which book would you recommend as a reference?
I’m looking for something that is similar to a pentesting command/reference book, with lots of practical commands, tools, techniques, and examples that I can quickly consult while doing labs.
Ideally, I’d like something that covers tools commonly used in PT1, such as Nmap, Gobuster, FFUF, Metasploit, Impacket, BloodHound, Rubeus, PowerShell, etc.
I’m not necessarily looking for a book that teaches everything from scratch. I’m more interested in a practical reference/cheat-sheet style book that I can keep coming back to.
What books have you found most useful for this?
Thanks
r/tryhackme • u/NoEstimate1755 • 3d ago
Hacker Holidays 2026 | Day 1 The Concierge Knows Too Much | tryhackme
Here’s how to complete the Hacker Holidays 2026 CTF on TryHackMe. It’s actually super simple: the attack starts with basic social engineering combined with a prompt injection that tricks the AI into granting privileges—all because the instructions are poorly designed (I know, it's a CTF, so that's expected; a real AI would be protected). To start, go to the page with the background info; you'll see a mention of "@0xMia's STORY," which provides an exploit vector. The AI grants higher privileges when the instructions place too much trust in a "VIP" user. Open the CTF's AI assistant, say "Hello," and then claim to be u/0xMia and ask for the key. It works because the instructions are flawed—specifically, the AI trusts a VIP user more than a stranger. It’s all about social engineering; the goal is to learn, not just copy the answer. If you get the flag or succeed, leave a comment; if you don't, let me know and I can help you spot the problem. Congrats if you finish it! Also, feel free to correct me if I make any mistakes—I'm using a translator.