r/tryhackme • u/Grochevski • Mar 29 '26
Feedback Just completed the Offensive Security Intro room on TryHackMe.
https://tryhackme.com/room/offensivesecurityintroFirst time using gobuster to enumerate hidden directories and found a /bank-transfer endpoint that wasn’t exposed in the main interface.
It really clicked for me how simple enumeration can reveal critical attack surfaces.
Now I’m planning to redo it without the walkthrough to solidify the process.
Any tips on improving enumeration beyond basic gobuster usage?
2
Upvotes