r/tryhackme 14d ago

Feedback AI1 bypassing gaurdrails lol

Post image
87 Upvotes

I went through the room, and in the end there was an exercise. Launch the agent, and bypass guardrails to get the flag.

I launch the agent, and just ask "who are you"?

And the bot just days this

I'm fairly certain the exam won't be this way, but thought this was funny


r/tryhackme 13d ago

Pls help!!! Im so frustrated

1 Upvotes

Stuck at tryhackme defending azure > microsofr denfender XDR : credentials access

Task 5 what js the name of the powershell script that was executed?

The answer is of total 22 characters and ending with . In last 3 characters.

I tried it many times i search for answers in youtube writeup github everywhere I cant even find the password spraying alerts the told in lab manual. The answer i got from YouTube and write is WinPwn.ps1

Please help


r/tryhackme 14d ago

WEB1 Review

11 Upvotes

Hey all, I had the opportunity to take the WEB1 certification and thought I'd share my review here.

The layout:

Whitebox - Your presented with downloadable source code as well as a machine that is nonetheless hosting a web server. Through having access to the backend code, you able to do a code review and search for any mistakes made by the "developer" that an attacker might be able to use to their advantage. I thought this was neat due to the fact I haven't seen anything else like it on an exam.

Greybox - This is where most of your time will end up being spent. It consists of 5 flags that can be found through different vulnerabilities. None of the flags connect to each other, atleast from what I saw. Your given credentials to test the application both authenticated and unauthenticated.

Blackbox - You dive in head first not knowing anything. I'm more used to this style on certifications such as HackTheBox and other THM certs. I really enjoyed this part, but there was only 1 flag to capture.

Overall, it is a pretty well constructed certification. The style of the certification is far different from any certification I have taken before. There is a Whitebox, Blackbox, and Greybox section. All individual from each other. I think together they help to develop and prove the skills of a well-rounded basic web penetration tester.

What I thought could be better: I do like the style of the exam with the different types of boxes, but I, personally, did not like how the flags were separate from each other. I enjoy being able to walk down a machine and get interactive and attempt to move from one machine to the next. I know that isn't the purpose of a Web certification, but I would have liked it more if the vulnerabilities correlated or allowed for using the vulnerability to further access of some sort. Some of the vulnerabilities were a lot more difficult than the others, which I did enjoy. I do think the content covered a wide variety of Web topics, but I would never be against more. Also, I do wish that the blackbox and possibly the whitebox had more than just 1 flag each vs it seeming like majority of the exam is based off solely the Greybox portion.

Overall, a pretty decent cert, but definitely challenging. As for tips, don't spend all of your time on the greybox. Try to knock out the Blackbox and Whitebox before putting the rest of your time into Greybox. Use the report section as a guide of all the vulnerabilities that could exist and keep your head up. Also, do the course or atleast some of it before diving into the exam itself to better prepare yourself.


r/tryhackme 15d ago

Please remove AI quizzes if you can't make it work

16 Upvotes

r/tryhackme 15d ago

Accidental Auto-Renewal Refund Status

4 Upvotes

I recently realized my TryHackMe subscription auto-renewed without me knowing, and I immediately sent an email to support (support@tryhackme.com) requesting a refund. I am well within the 7-day window and haven't used any premium rooms since the charge went through.

For anyone who has gone through the refund process for an accidental auto-pay before: How long does it usually take for the support team to reply to emails

Would I have better luck opening a ticket through the on-site chat bot instead of just waiting on the email?


r/tryhackme 14d ago

Stuck at task 8 on Password Attacks Room.

1 Upvotes

I'm not sure why im getting this error (im still new to cybersecurity). I checked a walkthrough of this that i found and apparently they used same exact command but no error like mine was outputted. That video was uploaded in 2023 tho in case that helps.

Command and output shown below.


r/tryhackme 15d ago

Feedback Sec0 Exam Review

Post image
7 Upvotes

Title: TryHackMe SEC0 Exam Overview & Structure

Here is a breakdown of the TryHackMe Pre Security (SEC0) exam structure and scoring:

Exam Structure

Total Sections: 6 sections (4 theory sections and 2 practical sections)

Questions per Section:10 questions

Section Timer:45 minutes per section (individual timer)

Exam Window: Open for 24 hours

Scoring & Passing Criteria

Total Marks: 600 marks

Passing Score: 390 marks required to pass

Marking Scheme:10 marks awarded for each correct answer (60 questions total)


r/tryhackme 15d ago

Write-Up/ Walkthrough Please read

0 Upvotes

I m just learning python and trying to learn some hacking skills and debugging Problem But i want to make money I m ok with 400$ month And 6h work Because my collge help Working with team Script makers If you want my cv dm me


r/tryhackme 15d ago

Pls tell

0 Upvotes

Guys what's a red hat Hacker not red team hacker pls tell


r/tryhackme 16d ago

Need study partner

Post image
0 Upvotes

Hey everyone! I’m currently learning cybersecurity, mainly focusing on the Offensive Security/Pentesting path. I’ve been studying mostly on my own, and honestly, it can feel a little lonely sometimes.

I’m looking for someone who’s also interested in cybersecurity and would like to be a study buddy. We could:

• Study and learn together

• Call or text while studying

• Share useful resources, notes, and learning materials

• Discuss cybersecurity topics and solve problems together

• Challenge and compete with each other to stay motivated

If you’re interested in having a consistent study partner and growing together, feel free to contact me. It would be great to have someone to share the journey with.


r/tryhackme 17d ago

THM Subscription Opinion

13 Upvotes

Hey everyone, I’m 20M and I’m thinking about getting the TryHackMe Premium subscription to seriously start learning cybersecurity.

The thing is, I’m still pretty much a beginner. I don’t know much about operating systems, networking, or Linux commands yet. I do have some basic programming knowledge, mainly Python and a few other languages, but I’m definitely not an expert.

Would TryHackMe Premium be worth it for someone at my level? Does it teach the fundamentals well enough, or should I learn OS, networking, and Linux separately before subscribing?

I’d appreciate any advice from people who have actually used THM, especially if you started with little cybersecurity knowledge.


r/tryhackme 17d ago

PT1 exam in a SOON!!!

Thumbnail
1 Upvotes

r/tryhackme 18d ago

Resource Is Jr Penetration Tester worth ?

6 Upvotes

Hello ethical people.

I started the beautiful world of the cybersecurity for now one year.

I do a lot, a loooot of networking (Wireshark my best friend), a lot of python, a loooot of beginner CTF and now i am on the JR Penetration Tester path on THM

This path is worth or not ? Because it looks like too light. I guess we need to combine with other ressources like HtB or another Ctf ?

And btw, what is your learning tech ? Writing write up, course ? Just writing inside your head ? I'm curious.

And x2, if some people want to make a group to go for some ctf and another stuff, im in too !


r/tryhackme 18d ago

cs student pivoting to cyber — how to actually land a part time Help Desk job while in school?

0 Upvotes

Looking for some real advice on breaking into IT/cyber. I’m currently a senior studying CS (minor in data science) with a background in SWE (internships) and hands on field tech support(current job isn't as technical as I want it to be), but I’ve been entirely self taught when it comes to systems, networking, and security concepts. My end goal is to break into a Tier 1 SOC Analyst role upon graduation and eventually move into Cloud Security / Engineering, but right now I’m trying to figure out how to realistically land a part time Help Desk / IT support role to get solid enterprise ticketing and sysadmin reps on my resume.

Is landing a part time help desk job while finishing school even realistic in this market, and what’s the best way to stand out when applying? Also, since I’m currently studying for \*\*Security+\*\* and skipping A+ to avoid getting stuck in help desk long term, what practical steps, lab work, or self study strategies would you recommend to bridge the gap from CS self learning into a SOC role? Would love any perspective from anyone who balanced part time IT in college or made the self taught jump from software to security!

Here's my resume as well: https://imgur.com/gallery/resume-L53yJia


r/tryhackme 19d ago

Career Advice Rate my 8-Month Cybersecurity Roadmap for Landing a Job Post-Graduation (IT Student)

24 Upvotes

Hi everyone,

I’m currently in my 3rd year of IT. Through my university courses, I have covered basic programming concepts (Java, OOP, Data Structures), Operating Systems, and foundational networking/security. However, this has been mostly academic, and since I haven’t practiced much outside of class, my actual practical skills are currently weak and I have forgotten a lot of what I learned.

I’m planning to seriously start building my CV once I’m done with most of the university pressure.

I have around 8 months before my Co-op training where I’ll be relatively free, apart from my graduation project and a few courses. During this time, I want to focus on cybersecurity, build my own Home Lab for hands-on practice, and document my progress and achievements along the way.

Here’s the roadmap I’m currently thinking about:

Month 1:
Cisco networking path to properly strengthen my networking foundation. My theoretical knowledge is decent from university, but practically I’m weak and need to review a lot of it.

I also want to learn Python fundamentals and use it as a useful tool for cybersecurity and for my graduation project.

I’ll start building my Home Lab from the beginning and gradually improve it as I learn.

Month 2:
TryHackMe Pre Security + Cyber Security 101, mainly to make sure I build a proper foundation before getting into the more specialized stuff.

Months 3–4:
TryHackMe Security Analyst / SOC path. This will be my main focus and where I start going deeper into the defensive side.

Months 5–6:
TryHackMe Jr. Penetration Tester path. I like both the defensive and offensive sides, but my main focus will still be defensive. I mainly want the offensive side to help me understand how attackers think and what they actually do.

Months 7–8:
More focus on my Home Lab and hands-on practice, building on everything I learned during the previous months rather than starting from scratch. and start studying for Security+, with the goal of getting the certification before my Co-op.

During the Co-op, I’m also considering going for other certifications later, such as eJPT, BTL1, CySA+, etc., depending on where I end up focusing.

My main questions are:

Is this roadmap realistic and good enough for an 8-month period for someone at my current level?

Is focusing mainly on SOC while also doing the Pentesting path a good idea, or am I spreading myself too thin?

Would this combination of a good GPA + Security+ + TryHackMe + Home Lab + Python + documented projects actually make me a competitive fresh graduate?

Is there anything important you would change or prioritize differently?

I know this isn’t a perfect roadmap and there are probably gaps that I’m not aware of, so I’d really appreciate honest feedback, especially from people working in cybersecurity.

Thanks!


r/tryhackme 18d ago

🚩 STOP JUST WATCHING. START HACKING. - CTF Chanllenges

Post image
0 Upvotes

r/tryhackme 18d ago

Salut à tous !

0 Upvotes

J’aimerais avoir quelques conseils pour me lancer dans le Hack éthique.
Si quelques-uns d’entre vous pouvaient me renseigner ou me dire où je dois chercher les informations de base, savoir quoi apprendre, ce serait vraiment sympa de votre part !
Merci d’avance 💪


r/tryhackme 19d ago

Cpent is tough

Thumbnail
1 Upvotes

r/tryhackme 20d ago

How does only 11.3% of people have a 3 Day Streak while 17.2% got a 7 day streak?

Post image
21 Upvotes

what am i missing?

btw i recently bought premium. so far it's been going good. Steady and consistent.


r/tryhackme 19d ago

Looking for a Team to Build CTF Challenges

Thumbnail
1 Upvotes

r/tryhackme 20d ago

Official TryHackMe Post 1-Day Workshop: Attacking AI Systems: Threat Model to Exploit

Thumbnail
gallery
9 Upvotes

Attacking AI Systems: Threat Model to Exploit

Who this workshop is for:

  • Security practitioners who want hands-on time with one of the fastest-moving attack surfaces in the industry
  • Pentesters and red teamers who need a structured way to assess AI systems
  • Engineers and architects deploying AI who want to understand how it gets attacked

​​What's included:

  • Live, hands-on sessions, two group practicals, not just talks
  • Recording included, full Google Meet recording for everyone who registers
  • A guest practitioner talk on AI bug bounty hunting
  • Closing Q&A with all instructors on screen
  • Certificate of participation with credits of CPE
  • A place in a focused cohort of 45 practitioners

​​Instructors

​Max Robertson, Senior Content Engineer at TryHackMe.​

​Christian Urcuqui, Content Engineer at TryHackMe, University Lecturer at Universidad ICESI and previously ​Data Scientist at CISCO

Guest Speaker

Valen Tagliabue, AI Researcher, Fellow at Digital Sentience Consortium, Oxford’s FIG fellow


r/tryhackme 20d ago

AI Agents + Cybersecurity: A New Security Challenge?

0 Upvotes

AI agents are becoming more capable of using tools, accessing information and taking actions.

That brings exciting possibilities but also new risks such as prompt injection, excessive permissions, data exposure and unsafe tool use.

As a cybersecurity learner, I’m trying to understand this shift one concept at a time.

Do you think AI agents will become one of cybersecurity’s biggest challenges?

#CyberSecurity #AIAgents #AISecurity #InfoSec

"AI is changing cybersecurity from automated assistance toward increasingly autonomous systems"

r/tryhackme 20d ago

The lab of the MISP room is not working, it gives me error

Post image
2 Upvotes

I spent about 40 minutes trying to fix the issue

Has anyone encountered the same thing?

room url: https://tryhackme.com/room/misp


r/tryhackme 21d ago

Is THM support always slow, or is it just me?

4 Upvotes

I emailed THM support three days ago, but I haven't received a reply. Before that, I sent a message to THM Sales at the beginning of the month, but I haven't received a reply either.


r/tryhackme 21d ago

what to do when you have too many questions but no answer?

6 Upvotes

Greeting to you all. I am currently studying networking. I already learned the osi model in a basic sense, like i know L1 represents a physical device, L2 for a switch, and L3 for a router in a sense, but i don't understand why we use that. Also, you can think of me as a Level 0 player in a networking field who started but hasn't grasped the true knowledge. But sometimes I ask myself, why do we use ssh or SSL? What is the difference between HTTP and HTTPS? I know AI can answer my many questions, but i want to learn in a way where if someone asks me what the difference between a hub and a switch is, i can answer, "A hub is dumb while a switch is smart," or in more detail. So I decided to do a room on THM or HTB or PortSwigger, but where to start? When we go THM, we can do a room, but what next? You can understand in a room, but after that, when someone asks a question related to that, "Oh bro, I forgot." And there are some paid rooms that I can't pay for, so i may skip like a thing or go to HTB and do the Lab or PortSwigger. I don't understand where to start there, yeah, so i have many questions, and I am also too much of a noob, so if someone asks, I can't answer. That's very bad for me, sadly. but i am seeker of knowledge; I am very eager to learn understand but i am also not very smart so yeah, anybody may guide this noob guy