TryHackMe
TryHackMe
TryHackMe walkthroughs, beginner-to-intermediate labs, and practical offensive security learning paths.
thm
VulnUniversity - TryHackMe Walkthrough
TryHackMe VulnUniversity walkthrough — exploiting a file upload vulnerability to get a reverse shell, then escalating privileges using SUID binaries on Linux.
Read Article
thm
Tutorial - TryHackMe room Writeup
TryHackMe Tutorial room walkthrough — beginner-friendly introduction to web enumeration, privilege escalation, and basic penetration testing methodology.
Read Article
thm
The Impossible Challenge - TryHackMe room Writeup
TryHackMe Impossible Challenge walkthrough — steganography techniques to hidden data in images and extract flags using command-line tools.
Read Article
thm
Owasp Top 10 - TryHackMe room to learn OWASP Top 10 2021
TryHackMe OWASP Top 10 walkthrough — hands-on exercises covering injection, broken authentication, XSS, IDOR, SSRF, and other critical web vulnerabilities.
Read Article
thm
Overpass 2 - Hacked | TryHackMe Walkthrough
TryHackMe Overpass 2 walkthrough — analyzing a pcap capture to find a backdoor SSH connection, then privilege escalation via a custom setuid binary.
Read Article
thm
Daily Bugle - TryHackMe room writeup
TryHackMe Daily Bugle walkthrough — exploiting a vulnerable Joomla instance with Metasploit and cracking a root password with John the Ripper.
Read Article
thm
ffuf - TryHackMe Directory Busting Writeup
TryHackMe ffuf room walkthrough — learning web fuzzing and directory brute-forcing with ffuf, including filtering, matching, and recursive discovery techniques.
Read Article
thm
Kenobi - TryHackMe Walkthrough (Samba, ProFTPd, Privesc)
TryHackMe Kenobi walkthrough — enumerating Samba shares, exploiting ProFTPd with searchsploit, and privilege escalation via SUID path variable manipulation.
Read Article
thm
CrackTheHash Writeup - TryHackMe room to learn hash cracking
TryHackMe CrackTheHash walkthrough — identifying hash types and cracking MD5, SHA1, NTLM, and bcrypt hashes using hashcat and online tools.
Read Article
thm
Blue - TryHackMe Room Solved Using EternalBlue
TryHackMe Blue walkthrough — exploiting EternalBlue MS17-010 with Metasploit to gain SYSTEM shell, then harvesting hashes with Mimikatz.
Read Article
thm
Attacktive Directory - TryHackMe Active Directory Lab
TryHackMe Attacktive Directory walkthrough — Kerbrute enumeration, AS-REP Roasting, Kerberoasting, and DCSync to compromise an AD domain.
Read Article