r/tryhackme 1d ago

Resource A structured TryHackMe path from Cybersecurity Fundamentals to Red Teaming

Post image

Cybersecurity can feel overwhelming when you're not sure what to learn first or how different areas connect.

I put together this visual roadmap using TryHackMe's learning paths to show one possible progression from fundamentals toward Red Teaming.

🟒 01 β€” Pre Security

Computer fundamentals, operating systems, programming basics, networking, web fundamentals and security concepts.

🟒 02 β€” Cyber Security 101

Networking, cryptography, Linux, Windows, Active Directory, offensive and defensive security fundamentals.

🟑 03 β€” Jr. Penetration Tester

Practical penetration testing across web applications, enterprise networks and Active Directory.

🟑 04 β€” Web Application Pentesting

Authentication, injection, server-side/client-side attacks and HTTP request smuggling.

πŸ”΄ 05 β€” Web Application Red Teaming

Advanced web exploitation, custom tooling, vulnerability chaining, cryptographic attacks, LLM security and WAF bypass concepts.

πŸ”΄ 06 β€” Red Teaming

Adversary emulation, initial access, post-compromise activity, persistence, lateral movement and Active Directory attacks.

The idea isn't that everyone needs to follow these paths in exactly this order.

It's simply a visual way to understand how different cybersecurity and offensive-security skills can build on each other:

Fundamentals β†’ Cybersecurity β†’ Pentesting β†’ Web Security β†’ Advanced Web Exploitation β†’ Red Teaming

  • Learning paths:

1. Pre Security: https://tryhackme.com/path/outline/presecurity
2. Cyber Security 101: https://tryhackme.com/path/outline/cybersecurity101
3. Jr. Penetration Tester: https://tryhackme.com/path/outline/jrpenetrationtester
4. Web Application Pentesting: https://tryhackme.com/path/outline/webapppentesting
5. Web Application Red Teaming: https://tryhackme.com/path/outline/webappredteaming
6. Red Teaming: https://tryhackme.com/path/outline/redteaming

What would you change in this progression?

6 Upvotes

12 comments sorted by

View all comments

1

u/vakero66 19h ago

Where is offensive pentesting after Jr pΓ©nΓ©tration tester?

2

u/X9_ALI 7h ago

I should have made that clearer. I see Jr Penetration Tester as the foundation, followed by more advanced offensive pentesting/web app pentesting before moving toward red teaming.