How 100 Tryhackme rooms made me the hottest guy in the room
It didn’t. That title is clickbait. But now that you’re here, a quote.
“Yeah there were challenges, and the prompts were intensive. And yeah, I actually was configuring CLI Metasploit with msvenom payloads and confirming vulnerabilities to commit exploit chains on an http server I was hosting on another machine. All of that actually happened, but that’s now how I’d have explained it when I did it. I’d have told you, ‘yeah so I kind of followed the guide and took notes, then for the challenge I just put the notes together and made things happen until I could find the flag.’ I learned something, but not immediately. I didn’t have context.”
That’s a quote from me. In a Discord with a SOC Analyst and a purple team professional with 20+ years’ experience.
The pro was a bit sad to hear that. The SOC Analyst, a Tryhackme acolyte, was confused.
Everyone advocates Tryhackme, and for good reason. This isn’t a roast article, by any means.
But how do you Tryhackme?
“It’s beginner friendly.”
What’s a beginner?
I don’t often hear my story. The one of, “Tryhackme didn’t teach me pentesting because I didn’t have the context.”
Rather, I hear, “I started pentesting by completing the Tryhackme paths.”
But I started from 0. Actual 0. In December, my tech skills included a 120wpm typing speed and the ability to open the sound mixer so that Spotify wasn’t blaring over a game. And the typing speed was because of the games, where I never thought twice (or once, for that matter) about the code– let alone the security implications therein.
So I was at absolute 0. But I trudged forward.
I completed labs on red team, the menu looked something like
Port enumeration
Metasploitable
Hash cracking
And of course I spent quality time with
SOC Simulator
Splunk rooms
Everything Phishing
And our honorable mentions
Bash basics
Powershell basics
CLI-tool use
But it wasn’t until I cross-referenced sources, put some elbow grease into other platforms, and got involved on LinkedIn and Reddit that I understood the context.
I’ll never forget typing into chatGPT,
“Why would cyberchef exist when I could have GenAI decode things for me.”
Or the classic,
“Should I put Wireshark or John the Ripper first in my resume skills list?”
There are countless examples of early-me being humorously off the mark. So far out of the context window that you could screenshot it, reverse the roles, and send the claim to OpenAI, “I thought 5.5 had fewer hallucinations”.
So what did I gain?
Perspective.
A foundation in 10’s of frameworks from blue to red to purple to whatever color team I’ll be working with. But most valuably, I gained the context needed in order to:
#1 Create an outline for my homelab
#2 Understand the context for Sec+
#3 Know my gaps and how to fill them (Cyber101 → SOC 1 → BTL1)
And all this digression rounds out to one thing: what makes a SOC Analyst?
Perspective.
You need to ascertain 100’s of assumptions at once for every individual alert. Especially as a SOC L1, you get approximately no time for approximately all the things.
If you have to google port numbers, domain name anatomy, “is this encoded or a hash,” basic querying language, “tools that identify malware”, email anatomy, etc, for every alert? Yeah, no.
To those of you reading, this may seem like obvious information. That’s great, you’ve got the framework. But to January’s version of me, this was hieroglyphics.
That’s what I got out of 100 Tryhackme rooms.
I’m not a fancy hacker or the Sherlock Holmes of cyber investigations. I’m a functioning SOC Analyst, and while I owe it to many sources, I can firmly stand my ground that Tryhackme is the reason I understood the context in my earliest days.
If you got this far, reach out to me and share your story. I’m always curious to know how other people frame Cybersecurity principles and what goes in their “mental-frameworks-I-cant-live-without.csv” file.