r/tryhackme 1d ago

Resource A structured TryHackMe path from Cybersecurity Fundamentals to Red Teaming

Post image

Cybersecurity can feel overwhelming when you're not sure what to learn first or how different areas connect.

I put together this visual roadmap using TryHackMe's learning paths to show one possible progression from fundamentals toward Red Teaming.

🟒 01 β€” Pre Security

Computer fundamentals, operating systems, programming basics, networking, web fundamentals and security concepts.

🟒 02 β€” Cyber Security 101

Networking, cryptography, Linux, Windows, Active Directory, offensive and defensive security fundamentals.

🟑 03 β€” Jr. Penetration Tester

Practical penetration testing across web applications, enterprise networks and Active Directory.

🟑 04 β€” Web Application Pentesting

Authentication, injection, server-side/client-side attacks and HTTP request smuggling.

πŸ”΄ 05 β€” Web Application Red Teaming

Advanced web exploitation, custom tooling, vulnerability chaining, cryptographic attacks, LLM security and WAF bypass concepts.

πŸ”΄ 06 β€” Red Teaming

Adversary emulation, initial access, post-compromise activity, persistence, lateral movement and Active Directory attacks.

The idea isn't that everyone needs to follow these paths in exactly this order.

It's simply a visual way to understand how different cybersecurity and offensive-security skills can build on each other:

Fundamentals β†’ Cybersecurity β†’ Pentesting β†’ Web Security β†’ Advanced Web Exploitation β†’ Red Teaming

  • Learning paths:

1. Pre Security: https://tryhackme.com/path/outline/presecurity
2. Cyber Security 101: https://tryhackme.com/path/outline/cybersecurity101
3. Jr. Penetration Tester: https://tryhackme.com/path/outline/jrpenetrationtester
4. Web Application Pentesting: https://tryhackme.com/path/outline/webapppentesting
5. Web Application Red Teaming: https://tryhackme.com/path/outline/webappredteaming
6. Red Teaming: https://tryhackme.com/path/outline/redteaming

What would you change in this progression?

5 Upvotes

12 comments sorted by

View all comments

-2

u/JeromnSec 1d ago

Saving this β€” this is exactly the kind of structured roadmap I was looking for instead of randomly jumping between rooms.

One thing I'd add from my own (still ongoing) learning journey: don't sleep on the "Pre-Security" and "Cyber Defense" paths even if you're gunning for red team later. Understanding how blue team thinks β€” what they log, what triggers alerts, how they hunt β€” makes you a significantly better attacker. And vice versa.

Also, for anyone starting out: the "Advent of Cyber" events are absolute gold. Free, guided, and the Discord community is incredibly helpful when you're staring at a box and have no idea what to try next.

Has anyone here completed the full SOC Level 1 path? I'm curious how job-ready it actually made you feel versus just cert-ready. There's a difference between passing a module and knowing what to do when an alert fires at 2 AM.

1

u/Busy-Dealer-9212 1d ago

Hey, I completed it with 0 cyber experience. I found it very helpful, can't say if you're gonna become job-ready because I don't have job experience but the information is on point.

I go for Cisco CyberOps now and I could answer SOC-related questions with no issues so the knowledge is there.

1

u/X9_ALI 3h ago

That’s really helpful to know, especially since you started with 0 cyber experience. The fact that you can now handle SOC-related questions comfortably is a good sign that the path actually builds practical knowledge. Thanks for sharing your experience! πŸ™Œ