Software

How to Learn Cyber Security and Ethical Hacking from Scratch with TryHackMe

Talha AslanTalha Aslan 18 min read 1 views

TryHackMe is one of the most recommended starting points for anyone who wants to learn cyber security from zero. I have worked in digital marketing and web projects since 2012. Server, form and admin panel security show up in that work every single week. In this guide I explain how TryHackMe learning paths and rooms work, how the platform differs from Hack The Box, and where the legal lines of ethical hacking sit.

This is not a career map or a certification comparison. Instead, it is a practical guide to using the platform well. You will learn what order to follow, how to handle being stuck, and when to move on. My goal is simple: fewer wasted weeks.

What is TryHackMe and why is it good for learning cyber security from zero?

TryHackMe is a browser-based, gamified cyber security training platform. Its content comes in short lessons called rooms. Each room combines a short explanation, questions and, in most cases, a virtual machine you attack or defend. As a result, a complete beginner can practice on day one without installing anything.

The real benefit, however, is fast feedback. You type a command, you see the result, and you enter the answer. If it is right, you move on. If it is wrong, you read a hint. That loop removes the long, foggy phase where you read books and have no idea what you actually learned.

The platform also puts topics in order. First, it covers networking, how the web works and the Linux command line. Then it moves into offensive and defensive work. In other words, you spend your energy on learning rather than on deciding where to start.

What do you need before you start with TryHackMe?

You do not need a powerful computer or a special operating system. A free account, a modern browser and a steady time slot are enough. That said, a little preparation makes the first weeks far more productive.

  • Reading comfort in technical English, because almost every room uses it.
  • Some note system such as Obsidian, Notion or a plain text file.
  • A fixed schedule: three sessions a week beat irregular weekend marathons.
  • Two-factor authentication and a strong password two-factor authentication on your own account.

Do not skip the password step. You can create a long, unique password for every site with the password generator. Also, get a password manager. A security student who reuses one password on five sites is an irony worth avoiding.

In addition, keep a short list of questions that make you curious. For example, what actually happens between your browser and a server when a page loads? Questions like this connect the early lessons to things you already see every day. As a result, the material sticks instead of fading after a week.

How do TryHackMe learning paths work?

A learning path is a curriculum of rooms in a set order. Each path builds one skill set step by step. At the end, you get a completion badge or certificate. So instead of picking random rooms, you follow a ready sequence.

You can think of the paths in three layers. The first layer covers fundamentals such as networking, the web, Linux and Windows. The second layer points you toward a role. On the defensive side that means security operations center work; on the offensive side it means penetration testing. The third layer goes deep into advanced technical areas.

My advice is to finish the first two paths in order before you wander. However, if one room in the middle bores you, flag it and move to the next. That way you protect your motivation without breaking the overall order.

Also, treat the estimated time on each path as a rough idea, not a deadline. Some topics will feel familiar and go fast. Others will take twice as long. What matters is that you can explain each topic to someone else at the end. A simple test is to summarize every finished module in a few sentences of your own.

Which TryHackMe path should you follow first, and in what order?

Path names change from time to time, so treat the order below as a frame. Check the current list in your account. The Pre Security path needs no prior experience and starts with computer basics, networking, the web and core attack and defense ideas.

  1. Pre Security: computer, networking, web and Linux fundamentals.
  2. Cyber Security 101: a broad introduction to offensive and defensive tools.
  3. Pick a role: SOC Level 1 for defense or Jr Penetration Tester for offense.
  4. Specialize: web application security, red teaming or digital forensics.

The logic is simple. If you learn tools without fundamentals, you memorize commands but never understand why they work. For instance, a port scan means little if you do not know the TCP handshake. Therefore, do not rush the first path. Everything else stands on it.

Why do Linux and networking basics matter so much on TryHackMe?

Almost every security topic rests on two foundations: the operating system and the network. Whether you attack or defend, you will usually face a Linux server and some network traffic. Without these two foundations, progress feels like building on sand.

On the Linux side, focus on the file system, users and permissions, processes, services and log files. If the command line still feels awkward, every advanced room takes twice as long. For example, in a privilege escalation room the hard part is often not the exploit. It is finding the right file.

On the network side, learn IP addressing, ports, the difference between TCP and UDP, DNS and the structure of HTTP requests. In addition, opening a packet capture in Wireshark and reading it is close to mandatory for defenders. In short, every hour you spend in the basic rooms pays you back many times later.

How do TryHackMe rooms actually work?

A room usually contains several tasks. Each task has a reading section and questions. Some questions only check that you understood the text. Others ask you to connect to a target machine, find a file or capture a flag.

You reach the target in one of two ways. The first is the AttackBox, an attack machine that opens in your browser with the tools already installed. The second is an OpenVPN connection from your own computer to the platform network. Free accounts get limited AttackBox time, so learning the VPN route early saves you trouble.

In addition, there are two main room types. Walkthrough rooms guide you step by step. Challenge rooms give you only the target and leave the route to you. Start with walkthroughs, then try one easy challenge room after every five guided ones.

What is the difference between walkthrough and challenge rooms?

The table below compares the two room types with the other practice formats on the platform. As your level grows, spend more time on the formats lower in the table.

FormatWhat you getBest forWatch out for
Walkthrough roomExplanations, step-by-step questions, hintsBeginnersType commands yourself instead of copying answers
Challenge roomOnly a target and flag questionsThose who finished the basicsLook for a hint, not a full solution
EventsSeasonal, daily tasksAll levelsA good chance to build a daily habit
Competitive modesTimed tasks against other usersIntermediate and aboveCan hurt morale before basics are solid

Advent of Cyber runs every December and opens a new free task each day. For beginners, it is an easy way to build a steady study routine.

What should you do when you get stuck on TryHackMe?

Getting stuck is part of learning, because hard moments build skill. The real question is how you use that moment. If you open a solution video right away, you get the flag but not the skill. So I set myself a simple rule: at least thirty minutes of my own attempts before I look anywhere.

  1. Reread the question, since most blocks come from a misread task.
  2. Go back to the reading section, where the clue usually sits.
  3. Open the room hint.
  4. Check the tool help output or its official documentation.
  5. As a last resort, read a written solution, but only up to your blocked step.

After you read a solution, do not close the room. Repeat the same step without looking and write down why you were stuck. That way you avoid the same mistake in the next room.

The community helps too. The platform forum and Discord server are good places to ask. Still, always describe what you tried and what output you got. This habit gets you faster help. Often, you find the answer yourself while you describe the problem.

Is a free TryHackMe account enough, and when should you upgrade?

First, a free account is enough for the start. A large share of the foundation paths and many rooms are free. However, some rooms, most role-focused paths and unlimited AttackBox time require a subscription. Check the pricing page for the current scope.

My advice is to spend your first month on the free plan. If you logged in at least three days a week during that month, the subscription is worth it. On the other hand, if you logged in twice and stopped, the issue is your schedule, not the price.

Before you upgrade, learn to set up the OpenVPN connection on your own machine. Then the AttackBox limit matters less, and you also get to know your own tool setup.

How does TryHackMe compare with Hack The Box?

Hack The Box has a similar goal but serves a different audience. TryHackMe focuses on teaching. Hack The Box focuses more on testing and competition. Its machines usually come with no explanation, only a target.

That said, the Hack The Box Academy offers deep, module-based training. So Hack The Box is not purely a find-it-yourself platform. Still, the overall feel is tougher, and beginners are more likely to lose motivation there in the first weeks.

CriterionTryHackMeHack The Box
Main approachGuided learning and gamificationChallenges and competition, plus Academy
Entry difficultyLowMedium and up
Browser attack machineYes (limited on free)Yes (Pwnbox, depends on plan)
Best phaseFirst 6 to 12 monthsAfter the basics are solid

In short, the two are consecutive steps rather than rivals. Build the base on TryHackMe first. Then test yourself without guidance on Hack The Box.

When should you move from TryHackMe to Hack The Box?

Measure readiness by skill, not by calendar. If most of the signs below fit you, you are ready. This list is a starting benchmark from field experience, not a guarantee.

  • You finish easy challenge rooms without reading a solution.
  • Nmap output makes sense, and you decide on your own which service to check first.
  • You understand Linux file permissions, processes and basic privilege escalation.
  • On a web form, you can list what to test without a guide.

You can also use both platforms side by side. For example, learn a new topic on TryHackMe during the week. Then try the same technique on an easy Hack The Box machine at the weekend. This way learning and testing feed each other.

For your first machines there, pick easy retired boxes with good community write-ups. Having a reference when you are stuck protects your morale while you adapt. Over time you need it less, and the core skill of finding your own path grows.

How do you learn the defensive side, the blue team, on TryHackMe?

Many people think of security only as attack. Yet a large share of job openings sit on the defensive side. TryHackMe is strong here. The SOC Level 1 path covers log analysis, SIEM tools, threat intelligence, phishing triage and incident response with hands-on labs.

In practice, defensive rooms feel different. Instead of breaking into a machine, you trace the footprints of someone who already did. For example, you find a suspicious login in a log file, build a timeline and report what happened. This work demands patience and attention. It is also the skill the real world needs most.

My observation is simple. People who learn defense understand attacks better, and the reverse is also true. Therefore, whichever role you choose, solve a few rooms from the other side as well.

What should you focus on in penetration testing rooms?

On the offensive side, your first goal is a methodology. You follow the same order on every machine: reconnaissance, scanning, vulnerability discovery, exploitation, privilege escalation and reporting. Once that order sticks, a new machine stops looking scary. It just looks like a new puzzle.

  • Recon and scanning: reading Nmap output and prioritizing open services.
  • Web flaws: SQL injection, XSS, file upload and access control bugs.
  • Privilege escalation: spotting misconfigurations on Linux and Windows.
  • Reporting: describing the finding, its impact and the fix in plain language.

People often skip the last item. However, in a real penetration test the report is the only thing the client keeps. So writing a short report after every machine is as valuable as the technical skill itself.

Do streaks, leagues and badges actually help you learn?

TryHackMe uses gamification on purpose. Daily streaks, leaderboards, leagues and badges exist to bring you back. They help you build a routine. In the first weeks especially, protecting a streak is a strong reason to log in.

On the other hand, gamification has a side effect. Answering one trivial question each day just to keep a streak can replace real learning. Likewise, picking only fast-point rooms to climb a leaderboard leaves skill gaps.

So treat these mechanics as tools, not goals. Set your own measure instead. How many rooms did I finish this week without a solution, and how many new concepts did I add to my notes? Those two questions track progress far more honestly than any leaderboard.

What is ethical hacking, and where can you use what you learn on TryHackMe?

Ethical hacking means finding and reporting security flaws with the explicit, written permission of the system owner and within an agreed scope. Your techniques may match an attacker's. The difference lies in permission, scope and intent. Without permission, there is no ethical hacking.

Use what you learn only on systems you own or where you have clear permission. The platform machines exist exactly for this purpose. The IP address it gives you is your playground. Running the same command against a neighbor's router, a school website or a company server you are curious about is a completely different act.

In practice, legal outlets are wider than many expect. You can use your home lab, tests your employer approves in writing, bug bounty programs and CTF competitions. What they share is permission and scope defined in advance.

What are the legal limits of ethical hacking?

In the United Kingdom, where TryHackMe is based, the Computer Misuse Act 1990 makes unauthorized access to computer material an offence. It also covers unauthorized acts that impair a system and making or supplying tools for these offences. In the United States, the Computer Fraud and Abuse Act plays a similar role. Germany and Turkey have comparable criminal provisions.

Details differ by country, but the shared principle is clear: unauthorized access is a crime. "I only looked and changed nothing" does not protect you. I am not a lawyer, so for any concrete case, talk to one.

  • Never scan or attack a real system without written permission.
  • In bug bounty programs, stay away from out-of-scope domains.
  • Report flaws to the owner through responsible disclosure, not on social media.
  • Do not run a tool against someone else's system, even as a "quick test".

Which ethical rules apply while you learn on TryHackMe?

The platform rules matter as much as the law. Attacking machines other than your assigned target, other users or the platform infrastructure is strictly forbidden. Even competitive modes state clearly where you may attack.

There is also community etiquette to follow. Posting challenge room flags publicly spoils the experience for others. If you want to publish write-ups, read the platform guidance first. Most platforms allow write-ups only for certain kinds of rooms.

Finally, be honest with yourself. Copying solutions to climb the leaderboard earns badges but not skills. In a job interview or a real incident, that badge does nothing for you.

How should you plan your first 90 days on TryHackMe?

The plan below is a sample program for someone with 6 to 8 hours a week. It is a starting suggestion based on field experience, not a guarantee. Your pace depends on your background.

  • Month 1: Pre Security, covering networking, the web and the Linux command line, with one page of notes per room.
  • Second month: the first half of Cyber Security 101, core tools, web flaws and your first easy challenge room.
  • Month 3: the rest of that path and a role choice, then the first steps of a role path.

Reserve the last week of each month for review. Open no new rooms that week. Clean up your notes and solve two rooms that blocked you before. As a result, what you learned moves from short-term memory into lasting skill.

How do you turn your notes into a portfolio?

In security, note-taking is not a preference but a work method. In a real penetration test you record every step, command and finding, and the report comes out of those notes. Therefore, building the habit on TryHackMe pays off directly later.

For each room, write four headings: the target, the tools you used, where you got stuck and the lesson you learned. Keep it short, no more than two paragraphs. After three months, these notes become your own personal textbook.

For a portfolio, publish write-ups that follow platform rules on a personal blog. Employers usually want to see how you think. Two well-explained write-ups persuade more than a long list of badges. When you build the site, choose a simple, fast setup; my web design page shows what I focus on.

Where do TryHackMe lessons show up on real websites?

Most security issues I see in marketing projects match topics from the basic TryHackMe rooms. Weak admin passwords, outdated plugins, public backup files and unprotected contact forms top the list. So what you learn on the platform is anything but abstract.

For example, checking a domain's records with a DNS lookup is the simplest step of reconnaissance. Likewise, an IP lookup shows where a server is hosted. Still, use these tools only on your own or authorized systems.

Email is another example. A domain without SPF, DKIM and DMARC records stays open to phishing. I cover that topic in my guide to business email on a custom domain.

What are the most common mistakes when learning with TryHackMe?

The mistakes I have seen in myself and others look very similar. Knowing them up front saves you months.

  • Solving only easy rooms for badges and never raising the difficulty.
  • Skipping the foundation paths and diving straight into pentest rooms.
  • Taking no notes and relearning the same topic three times.
  • Reading solutions instantly and losing the learning moment of being stuck.
  • Trying a new technique on an unauthorized system out of curiosity.

The last item differs from the rest. In contrast, the first four only cost you time. The last one can end your career before it starts. So keep your curiosity inside the platform or your own lab.

How can you build your own lab beyond TryHackMe?

At some point the ready-made environment may feel narrow. Then a home lab is a good next step. You install Kali Linux and a few intentionally vulnerable training machines in VirtualBox or VMware. After that, you keep all traffic inside that virtual network.

The biggest benefit of your own lab is what you learn by building systems from scratch. For instance, when you set up a web server yourself and misconfigure it, you see exactly where the flaw comes from. Also, knowing your own IP address and network layout is the first step in keeping the lab from leaking outside.

Above all, keep the lab network separate from your home network. Leaving vulnerable machines exposed to the internet in bridged mode turns a learning space into a real risk.

Conclusion: what is the TryHackMe route to ethical hacking in short?

TryHackMe is one of the lowest-friction starting points for a complete beginner. Start with the foundation paths, move from walkthroughs to challenge rooms, take notes, and test yourself on Hack The Box once the basics are solid. This order works for anyone who stays patient.

Consistency beats speed in this field. Someone who studies a few hours a week for six months goes much further than someone who studies day and night for two weeks and quits. So set a realistic schedule and review your progress honestly each month.

One rule never changes along the way: permission. Use every technique only on systems you own or where you have explicit approval. What separates an ethical hacker from an attacker is not skill but that line.

If you want to bring security thinking into your own website and ad setup, see how I handle the technical side in my SEO consulting work. For more posts like this, browse the software category.

Frequently Asked Questions

Is TryHackMe completely free?
No, but a free account gets you a serious start. A large share of the foundation paths and many rooms are free. Most role-focused paths, some rooms and unlimited browser-based AttackBox time require a paid subscription. Because plans and prices change, check the official pricing page before you decide. Use the free tier for a month first.
Do I need to know programming to start TryHackMe?
No, you do not need programming to start. The Pre Security path teaches computer, networking and web basics from zero. Still, writing simple Bash and Python scripts makes later rooms much easier. So after your first three months, spend about an hour a week on basic Python, especially file handling and simple loops.
Is TryHackMe or Hack The Box better for beginners?
TryHackMe is the better first step for most beginners. Walkthrough rooms, reading sections and hints soften the learning curve. Hack The Box leans toward testing and competition, which makes it valuable once your basics are solid. Treat them as two consecutive steps rather than rivals, and move over when easy challenge rooms feel comfortable.
How long does it take to get a job with TryHackMe?
There is no honest fixed answer. Your pace depends on your background, weekly hours and target role. The platform builds skills, but a job also needs a portfolio, possibly certifications and solid communication. Someone who studies steadily gets comfortable with the basics in a few months, while real specialization takes much longer.
Is it illegal to try TryHackMe techniques on real websites?
Yes, trying them without permission is illegal in most countries. In the UK the Computer Misuse Act covers unauthorized access, and in the US the Computer Fraud and Abuse Act does. Use techniques only on your own systems, platform targets, written authorized tests and scoped bug bounty programs. When in doubt, do not touch it.
How many hours a week should I study on TryHackMe?
Consistency matters more than daily hours. Three or four sessions a week of one to two hours each is a sustainable pace for most people. This is a suggestion from field experience, not a guarantee. Aim to finish at least one room per session, keep notes and hold a review week at the end of each month.
#TryHackMe#Cyber Security#Ethical Hacking#Hack The Box#Penetration Testing#Software
Share:
Talha Aslan
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

No middlemen, no layers: you talk directly to the expert doing the work. The first consultation is free, I listen to your goal and come back with a clear roadmap.

WhatsApp Call Now