#room-ideas

1 messages · Page 2 of 1

tacit anvil
#

Please we need another Mr.Robot room please please please

tacit anvil
#

After finishing almost 7 paths, I'm lacking a lot of Windows knowledge

Maybe we need more Windows CTFs implemented in some of the learning paths?

#

But I'm not judging only by this Skills Matrix thingy, I can confirm I'm waaay more comfortable on Linux because of the lack of Windows CTFs in the paths

#

Also it would be cool if one of the options in /search was a Platform option

cunning thunder
tacit anvil
cunning thunder
#

Have you tried the search in the top Navbar as well (the looking-glass icon left from the bell icon)?

tacit anvil
#

Im able to look them up myself, but for the future beginners out there,

#

theyre gonna be following the learning paths

#

and their skills matrix will end up like mine, lacking in windows

#

its just an idea tho 🙂

cunning thunder
#

If you like Linux, it makes sense to avoid Windows at first based on preference, but eventually realizing it is an important attack surface to learn and understand. 😎 The Networks section also has great Active Directory content.

fossil iris
dusky eagle
#

i wanna ask how can i contact the thm rooms creation team ?

loud hornet
dusky eagle
#

i wanna like get more assistance and guide about it

feral fossil
#

any idea to bypass the code in the room U.A. High School

#

please give me a hint

loud hornet
feral fossil
#

thanks i just see

tacit anvil
#

this isn't really a room idea but I see a lot of digital forensics rooms in THM but I don't see a digital forensics path and I think that it would be really useful to some people that are into digital forensics

mild sapphire
#

I have an idea for a AOC room. Is there someone to speak with about that?

mild sapphire
# loud hornet This channel.

Thanks Scrubz. The idea is about building an "impersonations" task for AOC. It wouldn't be heavily technical, but it would be real-world and would advance the overall story. I think this is valuable because I've seen some pretty wild impersonation attempts in the last year. It will expose people to those types of attacks and inform them about potential responses. Most are not deep fakes, but those are also in the news.

marble currentBOT
#

Gave +1 Rep to @loud hornet (current: #1 - 2817)

lusty hearth
#

A Room or walkthrough for the latest Cups vulnerability would be awesome 🙂

karmic gulch
#

Hi I hope you are all doing well
I am making a room and uploading a windows server 2019 vm and it successfully converted but when i play the machine it gives me an error of VM: PARSING_ERROR

tacit quest
#

I was thinking of doing the Powershell for AD and DNS with another Windows 10 Machine and an Ubuntu machine

elfin agate
#

@coral ravine There is not really a C2 room, Empire is very old, there should be a new room on silver?

elfin agate
tacit quest
#

I'm uploading the Windows Server 2022 Datacenter core

elfin agate
#

For what? 👀

elfin agate
#

Hope tryhackme release a free Silver C2 based room. 😭

tacit quest
elfin agate
#

Nice

tacit quest
#

yeah most likely a room rather a challenge

#

probably limited to AD and connecting a few machines but I don't think I have that room

forest summit
#

sadly walkthrough or information instead of challenge rooms are currently not being processed or planned to be added from users on tryhackme

#

i.e for now it is only challenge rooms

tacit quest
#

oh because there's too much rooms?

coral ravine
tacit quest
#

ah okay

#

I hope they use my uploaded one then (Datacenter Core) when dealing with powershell

elfin agate
#

that might work out Sir.

twilit lagoon
#

Thanks a lot THM. Please bring complete in detail Mobile, Android and IOS pentesting course.

tacit quest
obtuse osprey
#

Go loco

tacit anvil
#

i feel like new rooms courses/paths and modules should be advanced window exploition all the way to basics-advanced full web pentesting course

#

include http smuggling

#

and malware development every malware dev charges so much

#

its perfect for tryhackme

coral ravine
tacit anvil
loud hornet
tacit anvil
#

As their is multiple docs about it

still shuttle
#

please some more azure content

sage verge
#

GraphQL room please. I believe the previous one that was created was privated. I am guessing it was probably outdated. Can an up to date one be released?

#

+1 on what PNG said as well

kind raft
#

Still searching for some good courses to dive deeper into advanced reverse engineering.
@wind osprey please add more of them 🙂

cyan mango
main pantherBOT
#

Done!

peak sentinel
#

Would anyone provide me the link of these tryhackme two rooms? 1. ccstego, 2. musicalstego.

icy trellis
native raptor
# peak sentinel Would anyone provide me the link of these tryhackme two rooms? 1. ccstego, 2. mu...

https://tryhackme.com/jr/ccstego
https://tryhackme.com/jr/musicalstego

Caveat: these are old rooms. They were made private for a reason. Use them at your own risk.

You can technically access them though.

azure light
#

I'm not sure if this is already a thing, but I'd like a room about steps to go about removing malware from an infected device. So far, the rooms have been about static and dynamic analysis (which is great from a researcher point of view)

#

Like, steps to follow if you've been infected, different types, etc. Again not sure if this already exists

slate bolt
native raptor
cinder willow
#

Have you thought abou making the user apply more the learned lecons like on duolingo making you repeat older lecons after some time even your weak points?

slate bolt
#

FYI: The Brim Room in SOC 1 Path reference a tool which was reneamed Zui in 2021 and is concidered Legacy tool by the devs.

acoustic forum
#

Are there any rooms on binary exploitation?

#

if not then that would be a cool room to add

crimson shell
dense tendon
#

Hello, I think it could be a real plus to have a module or learning path about mobile pentesting, or maybe just a few more rooms with .apk or .ipa files that we have to pentest. I kinda feel like there are not a lot of rooms about this on THM

azure light
#

Rooms on AI exploitation

abstract patrol
#

Osint module

tacit anvil
#

is there a room about notpetya? if not, i think it’d be cool

It uses eternal blue aswell and there's already a room about it so it would be cool 😁

cedar echo
#

there's already a blue room, dunno about notpetya

sage verge
#

not sure whether the filters for blue,red purple are working. I am assuming blue should only return defensive rooms but I am getting boxes that should be red when filtering for blue

loud hornet
#

I don't think there is a filter for a hat colour, more what is assigned to the room.

For example "Blue" would bring the Windows room blue.

sage verge
#

so you could filter it based on defensive and offensive rooms or mix i.e purple but I believe it was not working so looks to have been removed

cerulean vessel
#

Realm C2 Room would be cool, I've participated as a volunteer red teamer for a collegiate event. One of the other volunteer red teamers used Realm C2 as the beacons at the time weren't being detected by defender

lean lotus
#

Dont know if it exists already but i think it would be nice to have a room/module in gdb

opal fossil
#

This is not a room but a module idea as there are existing loose rooms which can be added to a module in the path - CyberSec 101

I've not seen it in either the Complete Beginner path or the CyberSec 101 path.
The idea is adding a module on Cybersec Law & Awareness as with power comes responsibility.

There are a few rooms I'd like to see in there and have been finding them, if you have any suggestions on any other rooms that can be added, please do share.
ISO - https://tryhackme.com/room/iso27001
History of Malware - https://tryhackme.com/room/historyofmalware
CyberSecurity Awareness - https://tryhackme.com/module/cyber-security-awareness
Security Awareness - https://tryhackme.com/room/securityawarenessintro
Governance and Regulation - https://tryhackme.com/room/cybergovernanceregulation
Common Attacks - https://tryhackme.com/room/commonattacks

native needle
#

a more advanced zeek room focused solely on zeek development and writing analyzers in SPICY

radiant hearth
#

Is there any room on pxe boot ?

lean lotus
#

a room/module in blockchain secruity/smart contracts

balmy hamlet
#

What if you add a upvote to writeups so users can leave a like and let others know which ones are good and maybe that could trigger other users to post theirs as well?

abstract patrol
#

A room on AI manipulation/exploitation

icy trellis
abstract patrol
tacit anvil
#

Add chat to network rooms to cooperate better with other users or just to avoid interupting their sessions

formal granite
#

Not really seeing anything on crypto currency and blockchain but some rooms on that might be interesting.

errant field
torpid briar
#

I submitted a room for review back in May 2024.
This January I got an email from THM asking a question about the room, I answered within the day. Have not heard back even after a follow up email.

Is there anything I can do to expedite the review process?

loud hornet
#

Cc @cunning thunder

crimson shell
torpid briar
#

Will do, thanks

crimson shell
#

Hello

Okay sorry, that was me, the email response got lost in my thread, apologies

I did review it and overall it looks like a solid room, the one question I have is about the S3 bucket. I am assuming that it is hosted publicly on the internet?

torpid briar
crimson shell
#

Thank you for letting me know

I will talk to my team on my Monday about this

The reason is because we don’t like to rely on things that are in the public domain as we have no control of them. Hence why we have stepped away from OSINT challenges for room for example.

But I’ll find out more information and get back to you on Monday

sage verge
#

can we get some blue team CTF challenge rooms in, I feel as though its almost always red.

azure light
#

Blockchain exploitation

#

Things like bypassing logic in smart contracts, double spending cryptocurrencies, and limited versions of 51% attacks would be cool

karmic oriole
#

Create an "Informational" room that guides you through creating a comprehensive bug report for the #1333993673381253162 channel. Perhaps the challenge section can generate an organized text block that can be copied into the channel or could message an email box or Discord API with attachments and all. 🙂

serene perch
#

Hi, I would appreciate a few more rooms in the context of containers and Kubernetes security. So a bit more deep dive than the existing ones. Or an OWASP Top 10 for CI/CD in this context.
Rooms on API 101 and API Security 101 would also be cool. And of course content on AI Security 101, OWASP Top 10 for LLM, MITRE ATLAS. Just as a suggestion. Apart from that, I love TryHackMe. You all do a great job!

dense spade
#

Most of the redteam CTFs released are medium, it could be easier

cinder bridge
lusty tundra
#

I haven’t found any rooms that were about how to read Apache logs, I think it could be something important to learn since all this exploits from Apache based software (tomcat) are coming out

dense spade
cinder bridge
slim citrus
#

I have question about how about do you made like sal1 offensive security or pentesting

iron shuttle
azure light
#

Rooms on the basics of quantum physics and quantum computing

#

Also on quantum exploitation, Shor's algorithm, etc

#

and PQC solutions like lattice-based cryptography

iron shuttle
#

i think i did come across one i am not very sure if its by tryhackme

slim citrus
#

Hello how are you guys how about the basics of the cloud for aws attack and defending azure ?

slim citrus
hardy plaza
#

Hey folks! A question: I was thinking of creating a simple room that would have a game tied into it that could be run via browser in the VM (using WebGL, build through Unity Engine). Would it be possible to have this running inside the VM on THM somehow? Has anyone tried this yet?

#

The jist of it would be to get the ticket by winning the game, but winning the game would be impossible/heavily time consuming without somehow figuring out a way to modify the memory during runtime or alternatively finding the flag by decrypting key game files somehow.

cunning thunder
ruby rock
hardy plaza
marble currentBOT
#

Gave +1 Rep to @cunning thunder (current: #17 - 540)

native raptor
#

That definitely worked

feral fossil
#

This room can't start Machine

#

How to fix it bro?

cinder bridge
regal meteor
#

Make a free room for LFI and RFI vulnerabilities

loud hornet
prime hound
#

it would be interesting to see a standalone module on game hacking and the basics of it

hasty orbit
#

Advent of Cyber has a couple short modules

#

And the 2024 sidequest has one too

#

But it's more of a challenge than an intro

prime hound
#

yeah, ive done the advent of cyber ones :D

wooden mirage
#

Is there a room planned about the basics of PHP?
I'm surprised there isn't one.
and it would really have helped me for "Injection Attack" Rooms
Edit: same for Python (actually there is a room for python but it's too basic compare to some examples we can see in advanced rooms)

abstract patrol
#

Blockchain security... it's becoming more and more popular, we should have a learning path (or at least a module) with this

strong roost
#

More rooms on IoT hacking/security plz

worthy dagger
#

A room about enum4linux (inspired by something @tacit anvil said 🙂 )

sturdy perch
#

DNS Hijacking and DNS Binding

worthy dagger
#

We need more adventury ctfs. I absolutely loved the One Piece CTF, and we need more of those. this is probably because I'm a kid and I'm dying for adventure and fun, but still

hasty orbit
royal dawn
#

https://tryhackme.com/room/androidhacking101 The whole room is of not-the-usual THM quality. I found needs of improvement in used language (even though English is not my mother tongue), visuals, mess of styles etc. There are a lot of long to read tasks but no clear learning goal (at least explained what it is that this is supposed to teach pedagogically). So I would suggest re-doing that room.

TryHackMe

Android Mobile Application Penetration Testing

crimson shell
amber knot
#

How about a room for locating and eliminating AI Based APT's (Ghost Domains attached to TPM modules and such)

gilded pecan
#

I’d love to see more APT focused rooms.

dense dew
#

Id love to see more OSINT rooms

vestal isle
#

Can you create a couple black boxes with pivoting?

loud hornet
placid yoke
#

Hi Team,

I noticed an error in the explanation provided in the "Packets & Frames" room:

Link: https://tryhackme.com/room/packetsframes

Specifically, the following paragraph is conceptually incorrect:

"Think of this as putting an envelope within an envelope and sending it away. The first envelope will be the packet that you mail, but once it is opened, the envelope within still exists and contains data (this is a frame)."

Correction:
The metaphor is reversed. The correct order of encapsulation should be:

Outer envelope: Frame (Layer 2, Ethernet Frame)

Inner envelope: Packet (Layer 3, IP Packet)

Payload: The actual data (e.g., TCP segment)

In other words, a Frame encapsulates a Packet, not the other way around.

Could you please review and correct this part to avoid confusion for other learners?

Thank you!

worthy dagger
placid yoke
# worthy dagger I think the paragraph is correct

Ok, thanks for your reply. Could you please clarify where exactly my reasoning is incorrect? From what I understand, the Ethernet frame (layer 2) encapsulates the IP packet (layer 3), not the other way around. Perhaps I'm misunderstanding something—would you mind giving me a more detailed explanation? It would really help me better understand the concept. Thank you!

marble currentBOT
#

Gave +1 Rep to @worthy dagger (current: #46 - 215)

worthy dagger
placid yoke
# worthy dagger layer 2 comes before layer 3, so I don't think it encapsulates layer 3, altho I ...

Ok, no problem—I’ll wait for one of the mods to clarify. But logically (at least for me), the encapsulation process goes from the top (Application layer) down to the bottom (Frame at layer 2). Then, when the data is received, it goes from the bottom (Frame) back up to the top (Payload). So, when my device receives a frame, it first strips off the frame header, revealing a packet (layer 3). Next, it strips the packet header to reveal the segment (layer 4). Finally, it strips the segment header to reveal the actual payload (application data).
Anyway, that's how I understand it—but maybe I'm missing something.

worthy dagger
loud hornet
#

But yes, from my understanding, you're correct.

#

it would be something like

Placing an envelope containing the IP packet, and then putting that inside another envelope ethernet frame.

worthy dagger
loud hornet
placid yoke
marble currentBOT
#

Gave +1 Rep to @loud hornet (current: #2 - 3881)

native raptor
worthy dagger
oblique roost
#

why thm isnt working rn ? is there any issue in the site or the problem in my laptop

distant prism
oblique roost
#

thats rly bad my content is gone

#

what am i suppose to do now

tacit anvil
hard ravine
#

Hello, I’m just starting in the hacking and I want to have some help like : what is the machine for hacking ? I see Linux and kali linux but I have MacBook M1 its not working.
If you can help me thanks ☺️

gilded pecan
#

Would it be possible to recommend a module? I see that there is an “Advanced Splunk” but I believe a new module called “Splunk Fundamentals” or similar should be created. Either that or the “Advanced Splunk” should include some of the below as well and likely be renamed to just “”Splunk”.

With these rooms:
-Splunk Basics
-Incident Handling with Splunk
-Investigating with Splunk
-Conti
-New Hire Old Artifacts

mortal creek
#

A room working with satellite hacking. i mean hacking through satellite wifi not through ethernet. Also, the satellite has an ability to see through everything like a high resolution telescope.

mortal creek
#

Why would any hacker hack into ICS/SCADA system like Industrial Intrusion and put people in a harm's way? The only explanation is to leverage people's mindset to do something that the hacker want most likely, for example, to generate more parking tickets avalanche to unfavorable people like 3 days in a row. By the way, parking ticket generator systems are running in municipal infrastructure like Industrial Intrusion public water infrastructure. It wouldn't be too hard to try parking ticket generator system if you solved Industrial Intrusion at some degree.

native raptor
icy bronze
#

Hi

Could TryHackMe consider adding a feature that allows multiple users to team up and work through Challenge rooms collaboratively?

This would make completing the challenges more engaging and rewarding.

worthy dagger
main pantherBOT
#

Done!

icy bronze
#

I think it is going to be pretty fun to have such a feature
Especially for those who enjoy teamwork

worthy dagger
icy bronze
worthy dagger
native raptor
icy bronze
native raptor
#

Funny you should say that. I noticed something the other day

native raptor
#

That's in the room editor now 🤷‍♂️

icy bronze
# native raptor

So it is based on the room editor's choice to whether allow or not, right?

native raptor
#

Looks like it

icy bronze
marble currentBOT
#

Gave +1 Rep to @native raptor (current: #10 - 892)

abstract patrol
#

A windows vm room. Just like the kali room, a simple windows vm that you can use to your liking. It would be awesome to test out exploits and just experiment with malware such as rootkits or Metasploit post exploitation modules.

native raptor
#

Either way though, remember that THM provides attack machines to support with their content.

If you just want to experiment (which you should), then you need to have a local lab (which is also a given).

upbeat schooner
native raptor
#

That's the one

dark horizon
#

How about code the system

night fossil
#

can we get a room that has something to do with a dating app, just so we can make the name of the room "TryDateMe"??

left hawk
#

ideas

worthy dagger
hasty orbit
#

But on a serious note, what kind of exploit are you thinking we could build into it?

night fossil
#

i was thinking like having it be a chat app and the vuln is some IDOR to hop around the different chats to eventually find the flag, bonus points if its lik /chats/1337 or somethin lol

hasty orbit
#

Fair enough

#

IDOR is one of the most common vulns in my experience, and we don't see nearly enough of it on THM

#

Can't make it an insane difficulty if it is just IDOR, but sacrifices must be made. I guess the self deprecating humour must be postponed

night fossil
#

lol yeah

left hawk
#

wew

safe mesa
#

Hi! I've created a beginner-level CTF VM with OSINT, stego, and privilege escalation. I'd like to publish it as a community room. Can someone guide me?

icy trellis
#

@night fossil ?

night fossil
icy trellis
#

Sure

restive coral
#

Does tryhackme have a room scenerio where somebody vibe codes a website or software and ends up pushing like env files or something sensitive to the live site or app? I think that would be a fun easy room for beginners and bring awareness with a modern touch.

proper pivot
#

Anyone know how to find ip’s

native raptor
nova ledge
#

It's ok honestly percentage means nothing and adds no value to your CV or anything.

frank hemlock
restive coral
plush tendon
#

how can i update kali linux bcz i just installed kali on last two days

short harbor
#

And sudo apt update

plush tendon
#

i am facing some prblm in kali that my mouse cursor not pointing at the actual point how can i fix it

whole vigil
#

Hello Team, for some time now, when you compleate a room, you get the nice summary, and next room link. However, the machine that was spawn, target or box, still remains live until it times out. Can you add a terminate button on one of those pages, as i have to go back to the room i just finished to terminate it or if it is my last room for the session, the machine will run needle$$ly. Thanks. If there is some other easy workaround, let me know.

lapis oyster
#

if not, real problem

cloud geode
cinder bridge
limpid torrent
#

It would be cool to have more rooms or an entire path dedicated to networking. Images of different cables, switches vs routers, VOIP setup, subnetting, etc. Things to help study and train for network+ certification.

cyan ingot
#

Any upcoming rooms for GRC related concepts?

If not, are there other CTF style platforms that also have GRC platforms. Would be keen to find one

lapis oyster
wind stag
#

hi'

feral zealot
#

HI, anybody here? waiting for honeynet CTF?

drowsy fjord
#

Yes As it Start?

cinder bridge
feral zealot
#

Yay

#

I have earned 310 poinnts

loud scarab
#

so i cant send an image yet?

#

basically, been breezing through pre security course all day since 11am, it is now 10pm, and this 1 single question has me stumped

#

room - linux fundamentals part 3
question : When will the crontab on the deployed instance (10.10.175.50) run?

#

what do you guys want here lol

#

answer : _ _ _ _ _ _

6 characters

cinder bridge
# loud scarab so i cant send an image yet?

This isn't a proper channel for a such a question , for room related help please post in #room-help channel 🙂 . In order to upload images you need to verify , follow instructions from the link below to learn how to do so 🙂

wind ospreyBOT
outer jewel
#

Any plans for a SCCM Compromise/Abuse room? Credential harvesting and lateral movement using SCCM.

unborn cloak
#

who whants to join me to make gods eye like in fast and furious?

finite seal
#

Hello TryHackMe team!
I’d love to suggest a room focused on Suricata IDS/IPS. It could include:

  • Introduction to Suricata
  • Hands-on rule creation (custom signatures)
  • Alert tuning (false positive reduction)
  • Detecting attacks (e.g. scans, brute force, malware traffic)
  • Incident detection and log analysis
  • Optional integration with Wireshark or ELK
    This would be really useful for SOC analysts and blue team learners.
    Thank you for your great platform! 🙏
tacit flame
#

hey , i'm new here , any help ?

#

pls 😉

cinder bridge
wind ospreyBOT
#
Pong!
API Latency

112ms

Client Ping

248ms

ionic void
#

anyone

viscid lantern
ionic void
#

Check how many results you get when searching for learn hacking. At the time of writing, we got 1.5 billion results when searching on Google.

low kraken
#

I wonder if it would be an idea to add an ethics room to the Pre Security. Just watched a great talk by Allison Nixon from Unit 221B at BSides in Las Vegas about how ethics are often skipped in cybersecurity courses. Just thinking out loud here. THM attracts a lot of younger people who are interested in cybersecurity and it could be a great place to make them aware of the ethics involved. (content warning for anyone thinking of watching it: covers some difficult topics)

glacial basin
#

Please add a advance room / module about GraphQL hacking.

cinder bridge
high venture
#

Please create an Anti-Disinformation toolkit room/module that shows tools to both identify disinformation/misinformation and that can especially identify or predict the likelihood of material being created by Generative tools. This can include AI generated images, what to look out for in potentially ai generated chats, voice/audio analysis tools, text analysis tools, and fact checking tools more broadly (https://www.snopes.com/ looking up common disinformation campaigns for instance). Critical thinking, investigation. and research skills (investigating and fact checking against multiple sources) to gain experience for identifying disinfo and misinfo would probably also be more important skills in infosec than ever.
I would also look into connecting with infosec professionals that work with journalists, especially for more advanced fact checking rooms, since i realize this is a pretty large topic to try to cover

Additionally social engineering tool kits for red teaming might be a good room both for those pentesting and more importantly for those wanting to understand what to look out for when identifying phishing emails and other attempts to reveal unauthorised information;

limpid torrent
#

Can we get more rooms focused on networking please? Like maybe even a series of rooms dedicated to networking. I love THM and find it as a very strong resource.

cinder bridge
limpid torrent
green aspen
#

@languid nova @tribal socket ACCESS

tawny zephyr
#

I have joined this server recently but feeling difficult to navigate properly
How can I connect with a learning buddy?

cinder bridge
wind ospreyBOT
#
Pong!
API Latency

115ms

Client Ping

238ms

wind ospreyBOT
#
Pong!
API Latency

122ms

Client Ping

308ms

deep rivet
#

Cyber tools inf

#

Cyber tools information

wind ospreyBOT
#
Pong!
API Latency

194ms

Client Ping

177ms

dense spade
#

CVE-2025-53770 Room

loud pollen
#

hi

worthy musk
#

To whom did you escalate the event associated with the malicious IP address

#

This Question answers

fluid grotto
#

HI, any room recommendations that practice from a non privilege user to AD hack

cinder bridge
indigo steeple
#

hello I have a room idea Creating prombt injection room that gives you a lab and these lab you must to take the flag from the ai and with any chapter you have completed its give
You challenges

indigo steeple
arctic iris
#

Kindly help me verify my account

pure moon
crisp cradle
#

Hello everyone

strong frigate
#

Change KoTH flags in every time.!

ember helm
#

More ADCS rooms

night trench
#

Can anyone share some resources on how to make a vulnerable lab?

#

I only know that we have to use ubuntu LTS for that

#

And don't know how to configure the machine for such platforms like THM and HTB

night trench
upbeat schooner
# night trench can you share a proper article where someone has made the machine from scratch u...

you mean Ubuntu LTS (Long Term Support) I guess
the closest I can think of is that sub-resource (https://help.tryhackme.com/en/articles/8979423-building-a-successful-community-room-with-outc4s7) from the link I gave you, but I think it is a bit old
otherwise, there is Discord channel for room creation that you can join: just ask a mod (like KGB) so you get the role and can ask other room creators

night trench
#

thanks for your help!

wind ospreyBOT
#
Pong!
API Latency

121ms

Client Ping

233ms

nova ledge
#

No promos in here.

tacit anvil
#

@copper bronze is a scammer

indigo latch
#

Instagram

#

Instagram hacke

ivory sail
#

Hi i found somewhat of a bug in one of the rooms , is ther ea chanel for me to report that ?

silent blade
deep notch
#

.

marble currentBOT
#

Gave +1 Rep to @silent blade (current: #3174 - 1)

pale agate
#

Would love to have Active directory certificate services module

nova ledge
#

Oh you're level 14, you probably did them already. kekw

pale agate
nova ledge
high venture
#

one thing i was wondering as i go through each of the many rooms and the various links they share is if there is some sort of room or tldr page that helps to organize the the various webapps and software that is used for each area of cybersecuirity. creating a flowmap of various tools used for different areas of cybersecurity, similar to the https://roadmap.sh/cyber-security for instance, would be a really helpful tool for building a pkm of the various tools most often used, especially for ctfs where time finding the right tools for each task is often a big part of the challenge;

roadmap.sh

Community driven, articles, resources, guides, interview questions, quizzes for cyber security. Learn to become a modern Cyber Security Expert by following the steps, skills, resources and guides listed in this roadmap.

rough scaffold
#

I am stuck on what is networkin? task3, the one it asks to spoof something for a month.Help

nova ledge
rough scaffold
#

Thanks

lavish wolf
#

Hi everyone today I had joined discord 😀

pale cloud
#

Hi

calm walrus
#

I'm doing Room "Threat modelling" task 6.

I would love if I have some kind of notepad to checkmark STRIDE threat categories for respectively teams during simulation. I need to do so using pencil and paper IRL.

And as a native Finnish speaker I'm not a huge fan of tight time limits which forces to rush through without actually thinking.

lime glacier
main pantherBOT
#

:hammer: astra_xx1#0 has been banned.

main pantherBOT
high venture
#

Having rooms that get into backup strategies and some of the tools like rsync and creating automated backup schedules to ensure effective backup would probably be important considering its one of the most important risk management strategies and one that will probably be essential to anyone in it especially if they are getting into cloud or datacenter risk management work;

dense trench
#

Suricata IDS IPS rooms pls

lofty talon
#

Can anyone help me to solve the basic io pentesting room which should I use to find ms folder

#

Iot pentesting room what tool is used to find ms folder through port 445

plain sluice
#

Hey, Im making a new active directory room and I want to implement ESC1 misconfiguration

#

But I dont know how to make a Certificate template vulnerable to ESC1, Anyone here that might have an Idea how to?

patent quartz
#

I would recommend rewriting some of the basic instructions for network core protocols room. Some of the instructions are misleading or simply not there, such as to open a wireshark session to watch the network traffic, too much generalized information, and that the step by step instructions do not have intuitive questions such as logic and reasoning questionaires for new learners.

#

Highlights and improvements page should not just include smart data results and personal reflections. Rather provide the actual string commands that would better a user to understand in this case 'visually' what they are needing to work on in their discovery of knowledge.

native raptor
nimble karma
#

I wanted to use Breaching Active Directory but I'm having trouble with the initial settings.
Please help me how to do it in attackbox.

patent quartz
#

In the following example, we use our Firefox browser to access the web server on MACHINE_IP. Our browser fetches the web page and displays it perfectly; however, we are interested in what happens behind the scenes.

  • To add: "Go ahead now and open Wireshark to watch incoming and outgoing traffic to your attackbox, as this data created from the software will help you with this Task's questions."
native raptor
patent quartz
#

the former not the latter

native raptor
#

Ah, gotcha

native raptor
patent quartz
#

Everyone can learn something. I am refreshing my studies regarding Computer Networking and Cybersecurity, to refresh what I know. The thing to note is that some of the students do not have CN degrees, and are exploring without knowing cleartext instructions. Subtle and somewhat intuitive without having previous knowledge about what the software does or even where to find it.

hot moon
#

What we cooking today chat?

marble oyster
#

Hello

#

This is an Algerian group

eternal temple
#

?

tranquil ivy
spice badger
spice badger
dense dew
#

Im not gonna tell you outright what it is

#

But take a closer look at this

spice badger
dense dew
#

Nahh

#

I wanted to paste a screenshot but this channel doesnt allow screenshots

#

You will have to take a closer look at the C:>netstat -abon terminal and your asnwer will be in there

spice badger
#

thanks

dense dew
#

Yw

elfin brook
#

Hi everyone. I m prepare for PT1 certifications. But these two rooms(Lateral Movement and Pivoting, AD: Basic Enumeration) are really hard to connect through attackbox. Ping don't work, I check the route table and have no idea. The default route table don't work.

tacit anvil
#

Hi everyone

civic citrus
#

room-idea: Etherhiding

quasi shale
#

hey how/where can i send photos?

nova ledge
sinful haven
#

hhii

hearty pelican
#

.

worthy zephyr
#

Hey guys, well, I need help to get started on the path to becoming a pentest

proud marsh
tacit anvil
proud marsh
frigid blade
#

hey can u guys make a feature that u can change in ur profile settings on THM for rooms not to show the answer,
like:
short for Internet Protocol:
thm rooms will show:
__

i want a feature that it doesnt give u a hint in the answer field

tacit anvil
#

In the CI/CD Building & security. I couldn't receive the http request that I mentioned in the Jenkins file.
Is there anyone who had the same issue?

cerulean ridge
#

I am planning to learn the CTF can you anyone suggest me from which room we need to start? Like recon vulnerability analysis exploit like that

coarse leaf
#

@main panther @remote socket I have a suggestion that you can consider if you want
How about doing a learning path about cloud penetration testing? And malware development
Thank you

marble currentBOT
#

Gave +1 Rep to @remote socket (current: #129 - 74)

#

Gave +1 Rep to @main panther (current: #246 - 38)

cursive ocean
#

I don't know if this has been asked before, but would a learning path for identity and access management be possible in the future?

brazen wagon
#

Code wifi hack

odd oar
#

Hello

hasty orbit
#

It'd be cool to see a room about url manipulation

#

Did some bug bounty work once (can't say for whom bc of confidentiality) with a site that had all of its services hidden behind a paywall. The initial page was essentially just a password/username box. I noticed that the URL was plain with the final part of the sequence being /login. Turned it into /home and managed to get in. Ridiculously simple hack, but still useful to know

#

Ironically enough, the site was really well made besides that (I couldn't pull off an SQLI, lockout after 3 incorrect inputs, passwords had a minimum length of I think ~10 symbols) and just had 1 stupid mistake that wrecked it

tribal cedar
#

A room with multiple tasks related to pcaps that have HID traffic would be cool.

high venture
#

Especially if we can get youtubers like Mad Hat, Network Chuck, David Bombell, etc that can walk through the rooms so that we have rooms likes the Advent calendar rooms that combine the rooms themselves with how to guides that help people understand how to solve rooms going forwards;

tranquil olive
#

@soft owl I have this error when I do a nmap scan in Attackbox but not in a vm with openvpn : mass_dns: warning: Unable to open /etc/resolv.conf. Try using --system-dns or specify valid servers with --dns-servers
mass_dns: warning: Unable to determine any DNS servers. Reverse DNS is disabled. Try using --system-dns or specify valid servers with --dns-servers

rough jasper
#

hack cctv jim browning type shit

haughty pelican
#

Hello, How do i submit the room to THM, is there any prerequiste etc?

untold pagoda
#

GRC rooms and path!

proven rover
#

its not a new room idea but i think it would be great to have chat in koth to talk to other people because only way we can communicate is by making txt files or wall command

rugged badge
#

hello

frigid urchin
#

will there be text to speak in the future?

zinc veldt
tired shale
#

What is the average time that a newly created room stays in 'submitted'?

native raptor
forest summit
river sandal
#

Does anybody have done metasploit meterpreter hashdump

neat elm
crystal epoch
#

´

rough jasper
#

Batman x TryHackMe collab

tacit anvil
#

Hello friends

empty bridge
#

Hello

errant lance
#

hi

rustic swallow
#

hi

inland siren
#

hi

native knoll
#

Hi Room developer my name is beginner aka full time hunter and a osint guy well tryhackme really helps me alot and i do lots of forensics and osint still mastering them and i have solved all osint rooms but they are good only the thing which is missing is that it's not on the real cases so i request you to add some osint rooms regarding investigation for ex nowadays there are so many scammers which are using virtual phone numbers to loot people and for normal one there are so many tools which we can use but am personally working on the virtual ohone numbers so please add room for investigating phone numbers and some more osint things

#

like username osint and many more not to the next level i really respect your policy but atleast a overview so that everyone can be familiar with osint cause osint is not about doxing people etc etc it's about understanding your target

#

so i hope you got me have fun

#

thanks

loud hornet
native knoll
native knoll
coral ravine
native knoll
#

cause nowaday people can use Ai for extortion type of scams too so it's important to aware people

#

before it all happened

late yoke
#

MongoBleed

placid swift
silent nova
native knoll
#

you guys are literally differ haha i haven't dated or done anything man now i will write full aka example not "ex" else you all will make again differ assumption

coral ravine
#

There are already a few osint challenges on the site

native knoll
silent nova
native knoll
crystal sail
#

i am going to focaus on red team what room you advice me to start with

royal mirage
#

will ever THM also relese machine like HTB ?

weary pike
#

Hii guys I want to learn free el ethical hacking h from basic , anyone have idea Abt free alternative. ?? Plz DM and reply me..

loud hornet
weary pike
weary pike
compact hill
#

Hello friends, I'm new here. I have a question: how can any system be hacked?

loud hornet
bold peak
#

hey, its been 2 months since I submitted my vuln machine on THM.
The status for 2 months has been “Submitted”.

When do they plan to check submitted machines? Are they short-staffed or what?

unreal cave
loud hornet
#

Well, possibly short staffed.

Still a long line of rooms.

gleaming phoenix
#

Does anyone know of a tutorial to make thm rooms?

burnt ermine
#

Hello Guys

#

How Are y'all doing ?

#

I created a room since last year, yet, no review, still no response

#

I wrote to THM through three different ways, but no answer

#

Can anyone provide me with some hint, or a way to contact thm ?

burnt ermine
nova ledge
#

AFAIK waiting time is 1 year.

burnt ermine
#

Wow, I didn't know that

smoky heart
#

Hello

late timber
#

a Room or multiple rooms about job interviews

#

and how to succeed in the interview

quartz leaf
#

Room: How to build a Pen test Report?

nova ledge
valid terrace
#

Hey there, I saw that there wasn't much educational content on TryHackMe related to secure code review.

I'm thinking of creating a medium-level walkthrough room dedicated to secure code review titled "Introduction to Whitebox Hacking". This room will be all about how to identify security issues by reading code. It will teach concepts like source-sink (top-bottom, bottom-up), how to use Visual Studio to make code review easier, and how to find common vulnerabilities like XSS, SQL Injection, deserialization, SSTI, and others in code.

At the end, there will be a challenge where you are presented with a folder full of code and you have to find all the vulnerabilities within the code.

quartz leaf
nova ledge
winter ibex
#

Hey, I got an idea. What if you could make instructions and tasks work so we could learn something? Fucking crazy, right?

haughty zealot
#

and i learned so much only in tryhackme its amazing from my pov

hollow dagger
#

Hi, I have a proposal for a new learning room focused on the security architecture of AI Agents, such as OpenClaw.

The room would explore how to harness the benefits of autonomous agents while maintaining strict human oversight. A key focus would be the isolation of the agent to mitigate the risks associated with 'Vibe Coding' The goal is to teach users how to build a 'secure cage' for AI so they can enjoy the productivity gains without losing control of their systems." Thanks 😃

winter ibex
winter ibex
last sequoia
#

Hello
can someone help me in Active Directory Basics room, My machine is applying computer settings for 15 minutes tried to terminate it and open still the same.

reef ember
#

I have built a vulnerable vm for submission who do I need to talk to?

nova ledge
reef ember
marble currentBOT
#

Gave +1 Rep to @nova ledge (current: #24 - 471)

nova ledge
reef ember
reef ember
molten cloak
#

@reef ember check this setting after creating the room

reef ember
marble currentBOT
#

Gave +1 Rep to @molten cloak (current: #1779 - 3)

molten cloak
loud hornet
reef ember
loud hornet
# reef ember ??

That's an average (and guessed mated) time frame, on how long it will take. 😄

reef ember
#

oh, cheers for letting me know.

molten cloak
#

seems like way too high to me tbh, did you ever submit labs then?

molten cloak
#

Yeah, because you seem to have an oppinion or experience about it, right?

#

honest question btw

low agate
#

Python libraries needed for cybersec

loud hornet
molten cloak
loud hornet
last sequoia
#

I'm trying to use the machine on Networking Concepts TASK 7 but it is not showing up.

round badger
loud hornet
round badger
#

That sounds pretty cool :3

last sequoia
#

Hi, I followed this instruction " Click on the Start AttackBox button at the top; click on the Start Machine button belowt to start the attached virtual machine (VM). "

but the target Ip address is different from the Ip address in the terminal. Can you help me? I can't finish the questions.

sterile crane
#

obviosuly, in termail you see a machine you are using, and you have to target the victim machine

last sequoia
#

Im a doing it right?

sterile crane
#

yes

sweet drift
#

Hello TryHackMe team, I am a regular user of THM since 2 months and the path i am currently learning "Web Application Pentesting" is so much half-baked kind of path. You did put the topics on, but the practical replication of the techniques seems so much low in the learning rooms. Even though the challenges are superb, but still the things you learn in the lernings do not qualify to have a good experience in the challenges. I request you to make the learning rooms much more harder and complex and more practical as I feel it to be half-cooked type sh. Thank you.

pseudo dock
#

Hi Team, I am new to these platform can any one suggest me what can be done access free labs and certifications as for cybersecurity analyst role

#

Can any suggest me how to learn path for certifications and free labs access without any paid labs? Is there any alternative for that?

winged yew
#

Hello everyone, I was thinking how can I improve my studying journey and I found what I can do to improve it A LOT. This is not really about new room ideas but maybe structure idea.

Whenever I finish a room, a learning room from a specific path like cyber 101, I would LOVE to have 2-3 examples of CTFs or other challenge rooms related to that room. To make sure I get more practice in, more hands-on experience before I move to other topics.

I sometimes have hard times finding the right rooms to do after my learning rooms.

bold wolf
winged yew
marble currentBOT
#

Gave +1 Rep to @bold wolf (current: #3663 - 1)

lone dagger
#

More AD guys, that's it, we need an insane AD machine

dusk swift
#

Hi there guys, could somebody help me to upload a room, i did before but couldn't figure out how create a room, i have files, docker is ready good to go, but there problem creating room on tryhackme to people could access, see and play if you help me dm please

nova ledge
leaden rune
#

hello, I'm not sure this is the appropriate channel, but I have a sort of bug using metasploit on the Attackbox : when I use an exploit, the name doesn't appear anymore

#

(ah, damn I can't paste an image here)

#

I got something like that :

msf > use exploit/windows/smb/ms17_010_eternalblue
[*] No payload configured, defaulting to windows/x64/meterpreter/reverse_tcp
msf exploit( ) > set rhosts 10.129.183.166
rhosts => 10.129.183.166
msf exploit( ) > set payload windows/x64/shell/reverse_tcp
payload => windows/x64/shell/reverse_tcp
msf exploit( ) > run

sharp bloom
#

hello

#

ا

#

سلام عليكم

#

في عرب؟

warm jackal
#

Hi everyone, I’d love to suggest adding some more Python-focused rooms. Python is such a versatile language, and having additional challenges—maybe covering topics like automation, web scraping, or advanced scripting—could be really helpful for learners. Thanks for considering this idea!

hearty robin
uneven iron
#

I’m wondering when will be focus o cert about AI pentesting like pathway as well more deep

arctic zodiac
#

Is there anyone who can hack handphone 😭

bleak nexus
sick plover
#

idea: anonymous course for using proxy in chains not proxychains->tor I mean a real chain of socks5 proxies

#

idea: guerilla -> how to use tor network for real life communication or using I2P

#

idea: what is the usenet

#

idea: what is the helium network and how you can hack it

#

idea: what is lorawan how you can use it

#

idea: universal radio hacker and how to use it

quick timber
#

السلام عليكم

stoic hamlet
#

how to learn to OSCP

thorny cipher
# warm jackal يا هلا

I second this. More Python courses are absolutely needed. It's a great skill to have in cybersecurity.

sick plover
#

python + socks proxies and python crafting own PoCs would be nice

#

wireshark or tcpdump showing DNS leaks

trim kettle
viral plume
#

hello Guys

#

what are the most important thing every cyber security guy must master

sick nova
#

you have roadmap with Cybersecurity career

#

but as in programming in general, many things

#

you must know about networking, OS, programming, assembly, knowledge about common technologies, cloud

cursive anchor
#

SSH is open and I got into the admin password is brute forcing the right move? It's saying 180 tries per minute so I think it's rate limited so anyone to suggest what to do or should I leave SSH and focus on the other open ports

crystal sandal
left hawk
#

anyone who is good in creating offensive and defensive style CTF boot2root machines

dm quick

zealous stirrup
remote shuttle
#

السلام عليكم

#

Hi everyone

#

I have questions, Which i do vertulmachine to attack for thim?
metasploitabol 2or3ir windows 10or7
?

bleak pasture
#

Hi everyone
I'm new to the server plus give me an idea what I should hack

sick plover
#

there are pathes which you can choose

zealous stirrup
marsh wyvern
#

I am currently working on the Fakebank task, but the AttackBox is not appearing on my screen. Could someone please assist me in resolving this issue?

verbal edge
#

@obsidian raft How I can create a room in tryhackme and what's I need to be capable to do it?

#

@cinder bridge

#

@grave cypress

cinder bridge
wary sorrel
#

Anyone to assist on best ways to track location via a phone number

bleak nexus
verbal edge
#

Nah

#

Why you said usa specially

solemn ferry
# marsh wyvern I am currently working on the Fakebank task, but the AttackBox is not appearing ...

I'n new to TryHackMe, but there is a blue button on the top of the page that says "Show Spilt View". Hitting that will open up AttackBox in Split-View mode. That should work.

Bonus: if you have at least two monitors, I like to hit the expanding arrows button on the very buttom left of the AttackBox side, which opens a new tab with the AttackBox in fullscreen. I like to drag that up to a new monitor, so I can have the room on one screen, and the AttackBox on the other.

hoary frost
#

Hy everyone

proven jay
#

This might be a good thing to put in one of the beginner rooms. I know that as part of enumeration, it talks about how you can use github. It might be valuable to mention to look at the security tab specifically, because that can be quite valuable.

marsh wyvern
solemn ferry
sick plover
#

Linux Agency very nice room, could be more like that

analog dust
#

does someone where i can find promotion codes for tryhackme payment?

sick plover
#

please more rooms with malware analysis with linux and tools

quick timber
#

hello

gaunt parrot
#

Hello

reef crown
#

Idea 💡
The room could focus on the MongoDB Mongo bleed (CVE-2025-14847) vulnerability where players interact with a misconfigured MongoDB instance vulnerable to a memory leak caused by improper compressed request handling. The objective would be to identify the exposed service and exploit the flaw to leak sensitive memory data such as credentials or tokens and use the recovered information to gain further access or capture flags This would teach the real world concepts like unauthenticated data exposure , memory leak exploitation and the importance of secure database configurations and patching.

reef ember
#

I have just finished creating a vulnerable VM based on the fast16 (predecessor to stuxnet) that in the new lately.

jagged vapor
#

Free rooms for learning the cli

oak notch
#

room idea: rate limiter fingerprinting

player gets 2 endpoints, both rate limited with different algos (token bucket / sliding window / fixed window / leaky bucket). they have to figure out which is which from behavior, then break each one accordingly

inspired by this https://bytebytego.com/courses/system-design-interview/design-a-rate-limiter — there's nothing like it on THM afaik, closest is Hammer but that's just bypass, no algo identification

solemn ferry
#

Everyone who reads this and agrees please upvote it.

I don't want a new room, I want a new path. A path teaching us how to attack Azure and/or AWS. Like tack it on to the Pentester set of paths on the /hacktivies page. There is a path on how to defend Azure, and then another path for Attacking & Defending AWS, but not a path only on how to attack either. And it could be a double, like how to attack Azure and AWS. It would be a great skillset, and strong addition to THM platform.

What do you think?

native raptor
solemn ferry
# native raptor In what world would you only need to *attack* a cloud platform?

I wouldn't. But I plan on becoming a Red Team Operator. That's my dream role. I was looking at the Pentesting set of paths that THM has laid out, and I noticed that the others have things related to AWS and Azure, but the Pentesting one doesn't. I just thought that it would be a nice thing to know how to do and put on a resume along with everything else from THM. And maybe not Azure and AWS exactly, but like Could Platforms in general. And maybe a Red Teamer would never touch those. But I thought it would be a useful skill to have as I said above.

Basically I would never need to only attack a cloud platform. But it would be another tool in a my toolbox of THM.

native raptor
#

A red teamer absolutely will end up working with cloud environments in pretty much any modern infrastructure. As will most pentesters.

That's a given.

But, can you tell me what the product offering of a pentest or adversary emulation exercise is?

#

i.e., why do companies pay for tests? What do they get for their money?

solemn ferry
#

Companies pay for pentests and adversary emulation exercises to understand where they are vulnerable before a real attacker finds those weaknesses first.

They’re paying for risk reduction.

The deliverable is not just “we attacked your environment,” but a professional assessment of exploitable weaknesses, proof of impact, how those weaknesses could affect business operations, and clear remediation guidance.

In a pentest, they get validation of security posture—what can actually be compromised versus what only looks risky on paper.

In adversary emulation or red teaming, they also get insight into how well their detection, response, and internal teams perform against realistic attacker behavior.

Basically, they’re paying to answer:
“If someone like a real attacker targeted us, what would happen, how bad would it be, and how do we fix it?”

Since cloud platforms like Azure and AWS now hold identities, critical infrastructure, and sensitive data, offensive cloud testing fits naturally into that because those environments are often the highest-value targets.

native raptor
#

Good answer, but one line in particular is the important bit.

What would happen, how bad would it be, and how do we fix it?

In a practical sense, they're paying for an SME to tell them what they need to do to improve their security posture.
They don't care how cool the exploit chain is -- they only care how to stop it from working.

solemn ferry
#

I am aware of that.

native raptor
#

Knowing how to defend is crucial for a pentester or a red teamer.
Arguably the most crucial thing.

#

If all you can do is attack, but not give accurate remediation advice, then what use are you?

solemn ferry
#

That is true for sure, and maybe I didn’t think it through enough.

I completely agree that knowing how to defend is critical—maybe the most important part—because the goal isn’t just to break something, it’s to help the client fix it and improve their security posture.

My thought wasn’t that offensive cloud content should replace defensive learning, but that having dedicated attacker-focused labs for cloud environments could strengthen that understanding. Sometimes understanding exactly how IAM abuse, privilege escalation, lateral movement, or persistence works in Azure or AWS helps you give better remediation advice because you understand the attack path more deeply.

I was thinking of it as complementing the defensive side, not separating from it. More of a “learn both sides to be better overall” approach rather than attack for the sake of attack.

Not a mixed—and then diluted—version, just one focusing on attacking, and there already is one on defending. And maybe it is a hard path, geared towards attacking those platforms from a Red Team Operators stance, not just general "how to hack Azure". Do you see what I am saying?

native raptor
#

Mhm. Instructional content on attacking cloud environments while also including foundational information on the services + remediation steps is indeed a good idea. Much better than a "path only on how to attack either" imo.

I also assume that's what the "Attacking & Defending AWS" path is for, but I'm not gonna bet on that 😆

solemn ferry
#

Yes, I can say I actually never looked at that path, though I knew it was there. And I was thinking more of Azure specifically, cause they are the faster growing company by far, and have almost the same market share as AWS.

Thanks for putting the heat on and showing that wasn't just randomly suggesting something. Are you a THM rep or something?

native raptor
#

Not these days, no. I used to work for them a few years back.

#

And yes, Azure is especially interesting because of the push towards EntraID and Hybrid AD environments. It's not just cloud resources, which makes it a very interesting target. AWS do have their own managed AD service which is fairly solid, but I'd wager it's not nearly as prevalent as Entra.

solemn ferry
#

Do you think I have a good idea, and was seeing if I actually was coming from somewhere and wanted me to flush it out, or something else? Personally, I thought I had a good idea, but then, I am kinda biased 😆.

native raptor
#

With the modification that you also need to include the defence side? Yes, absolutely a good idea.

Cloud is a huge attack surface. Knowing how to attack and harden the various providers is pretty much crucial.
Only issue is that's a massive amount of content. AWS, Azure, and GCP are the big three, but there are other slightly less mainstream providers like Oracle Cloud which are still widely used.
They usually all offer fairly similar products, so a lot of attacks work on more than one provider (to varying degrees), but getting to know the quirks of each one is... complicated.

solemn ferry
#

I see. But I don't mean a path covering each one. I mean a path for how to attack Azure from a Red Team Operators standpoint. They have a massive share, and are used by like some 95% of the Fortune 500 companies. There is no need for THM to cover even three of the biggest. Just Azure. They are big enough. And I know, it would probably be a lot of work. But would it be worth it? I think so, but I am just one person.

native raptor
#

It would be a good addition, definitely.

solemn ferry
#

Basically a path teaching how to attack Azure from a Red Team Operators stand point.
[there is a whole chat above for anyone interested. I hashed out my idea]

The defense side was already covered in the "Defending Azure" path. So if you wanted to learn the defensive side you could go there. Or they could just add in some of the key rooms from that path into this path that I am talking about.

Just looked at your bio and saw that you put Red Team Operator in there. Cool!! Can I send you a friend request?

marble currentBOT
#

Gave +1 Rep to @native raptor (current: #12 - 924)

onyx oasis
#

u guys could put a some rooms challengers on final of some modules, like recommendation.. cz we could practice directly the subjects that we see on module

#

maybe a carrosell of some recommendation rooms

jaunty marsh
#

hello

#

i need some guidance

#

i m thinking to take cybersecurity as major can anyone guide me .. how to do that and move toward that cybersecurity think

cinder bridge
shut cloak
#

hi

#

i am very much interested in digital forensix and would love a room dedicated to forensics from data recovery, analysis and the different types of forensix

unreal cave
burnt dustBOT
#

@velvet flare Please slow down. Further spam will result in a short timeout.

solemn ferry
#

Some more 5 minute hacks. I love those! Sometimes I don't have a lot of time, but I can sit down, and break into them. It might be even more fun if there was like one vuln we had to find and then exploit. Or a couple minor flaws we could chain together. Basically short and sweet.

light lynx
#

Something really unusual, like IoT or a router. Not sure how it'd be done, but it'd be fun 🙂

somber crow
#

Seconding IoT rooms. After all, the S in IoT stands for security.

tacit anvil
#

LOL

sleek elbow
#

Not a bad idea Bee...
I've got something unrelated in the works, but I'd be more than happy to explore this idea :d

quartz grove
#

So Qemu doesn't work on AWS?

remote socket
#

Not that I am aware of :?

terse needle
#

can't you install Qemu on EC2 Linux?

remote socket
#

It wont run properly as you need a certain instance type to get it to work

#

EC2 is a VM, so its another layer of virtualization

quartz grove
#

I'm pretty sure AWS EC2 uses qemu in some form as it's hypervisor asw

remote socket
#

Ill google it later 🙂

terse needle
#

pretty sure it will help you

dull adder
#

Another option would be to explain how setup your environment and show the attacks.

split viper
#

The IoT room idea would be great. But it sucks if Qemu doesn’t work

dull adder
#

yep

modest trail
#

Has anyone done any SSTI rooms yet?

dull adder
#

Nope

#

SSTI and SSRF no exist.

remote socket
#

Added to the list 🙂

#

Thanks for the suggestion!

final sun
#

Can I make a room request command, once done with enough requests, it'll reset but the request will be saved at DB, what you guys think?

tacit anvil
#

Hi, I'm have preparing reverse engineering crack mes for a while seen some interesting challanges, can I create a room with those crackmes

final sun
#

@tacit anvil Go for it

tacit anvil
#

I think some challanges most of the people have already solved I'll try to tweek hem

tacit anvil
#

Is there any guide for room creation ?

remote socket
#

A room to create a room!

#

I ❤️ it!

#

However, this should probably just be a page

#

Ont he site

#

Its on my to-do list

light lynx
#

actually

#

not a room

#

but a page

#

😉 @rocky gazelle

rocky gazelle
#

hmmmmmm???

#

Side note, the talk version of that is going live soon (TM)

#

Technically, I retweeted it on my twitter account so you can find the talk I did on that

autumn carbon
#

good talk ^

rocky gazelle
#

but I'll have it on my website soon

tacit anvil
#

How to delete an uploaded file in yourmaterials

#

???

split viper
#

@tacit anvil you can’t

rocky gazelle
#

Currently you can't, we're going to work on that but it's kind of a low priority

tacit anvil
#

No problem ! coolguy

tacit anvil
#

Oooooops I just uploaded allll my furry porn to THM, sooooooo sorry. I hope that my content doesnt taint your servers Hard drives. uwu

rocky gazelle
#

@tacit anvil please keep it SFW

tacit anvil
sleek elbow
#

smh be nice to dark m00

tacit anvil
#

I love dark

sleek elbow
#

Request:

  • AV Evasion; basic (Shikata Ga Nai) -> Moderate (Veil) -> Advanced Unicorn, etc-> Expert, Custom payload obfuscation
quartz grove
#

10-4 Dinosaur

final sun
#

Advanced Unicorn? Holy, second that.

final sun
#

Someone please make a moderate level room or recommend one.

rocky gazelle
#

I have malware obfuscation on the list of primer rooms but if someone wants to beat me to it go for it

somber crow
#

Regex room. I could make one after my currently planned room though

autumn carbon
#

Regex could be a step of the room, maybe think a bit wider by adding other useful likely notions?

somber crow
#

More of a learn regex than a challenge room

tribal bough
#

Do we have a crypto room?

placid flicker
#

there are some, but I forget the names

#

might just include crypto and not be dedicated to it

tribal bough
#

ohk that works

somber crow
#

There's an RSA room @tribal bough

#

And there's like cryptofun or something

tribal bough
#

Cool

haughty berry
#

An introduction to GHIDRA room

tacit anvil
#

Oo

#

I could do that

#

Ghidra is my bb

#

Ill have it done in a few hours or so @haughty berry

haughty berry
#

Holy shit, that'd be great! I've been wanting to learn how to properly use it @tacit anvil

tacit anvil
#

Yeah

#

This isnt gonna be a really task heavy room though

#

Its more gonna be a walkthrough of analyzing a binary, and then the final part will be you analyzing a binary on you're own

#

Very picture heavy room

light lynx
#

@tacit anvil this is great! CANT WAIT

#

oops

#

my capslock key got stuck for a sec

autumn carbon
#

Nice pars

tacit anvil
#

Aight

#

The room is done @light lynx

#

You want dev access to see if you want anything added?

light lynx
#

ah i'd love to 🙂

tacit anvil
#

@haughty berry the room is done and uploaded

haughty berry
#

@tacit anvil , you a beast

tacit anvil
#

Let me know if you have any issues :D

placid flicker
#

This is more of a request for the #650425164894568455 event, but since it's essentially a room request, I'm posting it here. Since the event is nearing its end, I wanted to say I'd really like to see some manual exploitation in one of the last few challenges

final sun
#

Manual as in, understand the workflow of a service and develop a exploit accordingly, should be good as a head start.

remote socket
#

^ We don't gave time to do that now - but we will do in the future

split viper
#

I’ll think about an AV bypass room. But right now what was considered moderate(Veil, fatrat) has the same detection rate as shikata ga nai.

#

I’ll have to think of some work arounds

remote socket
#

@split viper We have that in the works 🙂

molten spire
#

An introduction to memory analysis room

tacit anvil
#

We have one of those @molten spire

stuck topaz
#

o

tacit anvil
feral reef
#

Is it possible to get a kali 2019.4 and parrot as a subscribers room?

remote socket
#

ParrotOS is not possible.

#

But Kali 2019.4 is 🙂

#

Ill add it to my to do list

feral reef
#

is there a reason for that? do they not allow distribution?

#

Got a brilliant idea that just ticked now! Build your own kali distribution!! That should help people compile a build that is suitable for them rather than having a ram hog vm

remote socket
#

Nah, ParrotOS is just annoying to try and have hosted on the cloud infrastructure that runs THM

#

We can do it

#

But its fiddly

feral reef
#

oki dokes

#

but i still think that building your own kali will be a good starting point

#

let's drop parrot for now

remote socket
#

Yeah

#

Thats a good idea

#

My to-do list is really big - working on networks for now 🙂

#

Its pretty much done

#

The whole network configuring is all done

#

Really excited to release it 🙂

feral reef
#

if you need a hand with something and i can help let me know

stuck topaz
#

agree with Chev tho, that would be genuinely sick

#

make ur own

feral reef
#

more like a guide on how to build it from ground up

stuck topaz
#

thats what i thought u meant

#

that would be very good to have

feral reef
#

Oh. Okay. So we are on the same line

stuck topaz
#

big selling point for subsription imo too

feral reef
#

Even for non subscription

#

Because you build it yourself to suit your needs and interest

#

Like. If you are interested in Web pen testing you install x, y, z tools and configure them this way

#

Or windows

stuck topaz
#

do u mean from kernel up?

#

too

#

thatd be a sweet room

feral reef
#

i'm totally noob at this so i'm just throwing ideas out the window, but dunno, that might be a thing i think...?

stuck topaz
#

its called lfs

#

but would be super useful here too @remote socket

soft hamletBOT
#
TryHackMe
New issue

This is the input you are about to create:

Name

New Kali Box

Description

Upgrade Kali to 2019.4 on THM
-- Created by: Ashu

#

Issue has been created by @formal turtle!

languid ibex
#

What about creating a room introducing Unicornscan and hping3. I haven't seen any mentions of them in any room and I think they might be useful (for beginners level for example)

remote socket
#

Oooooo

#

Yeah thats actually a really good idea

feral reef
#

Yup. Agree!

tacit anvil
#

A small room on curl functionality and useage

flint viper
#

a room to get a good grasp upon maltego

somber crow
#

More sqli rooms, especially manual

sage python
#

pivoting boxes

modest trail
#

This is something I can possibly look into. However it depends if the platform can handle it. @remote socket any chance you could clarify for me?

remote socket
#

Pivoting will be possible in the future, but not at this current time 🙂

sage python
#

very cool, I just wanted to put it in the request list :). There's a few things on like vulnhub like 'myhouse'

modest trail
#

Pog

rocky gazelle
#

The networks that are in the works will allow for pivoting setup, I already have plans which require you to pivot

modest trail
#

Sounds good, I have a couple of ideas for a pivot box that I'd love to get running on here

#

though might take a while to develop

modest trail
#

Need some info from you all. What do you think is missing from the site in terms of content? Either walkthroughs of topics or challenge rooms?

quartz grove
#

subs recently got a survey about that, skidy or ashu might be able to provide more on that

modest trail
#

Ah sweet

#

Kinda wanna start a series of walkthroughs but don’t wanna dupe what’s already out

quartz grove
#

SQLi is always in demand

#

Harder challenges are often mentioned as well

#

And obv with harder challenges needs more walkthroughs for that level

modest trail
#

Yeah I may look into ssti as that’s my baby but walking people through may be hard due to limited documentation

#

Can easily make a medium/hard room with it

modest trail
#

Introduction to pwn

final sun
#

It's in development @modest trail

#

But not until 21-26

somber crow
#

Wireshark for capturing or filtering?

#

It'd help to learn both but capturing is eh

coarse jacinth
#

Introduction to pwntools

final sun
#

I'm sorry but it depends actually, pwntools just basically is combined version of capstone, binutils, socket and importantly the interaction with binary with subprocess which you can do on your own. But don't worry the upcoming room(s) will help you get familiar with pwntools or something else coughs as well.

coarse jacinth
#

🙂

final sun
#

Gotta wait for some weeks though.

tacit anvil
#

@coarse jacinth I gotchu

#

My new room on thursday will have a pwntools section

somber crow
#

awesome

tacit anvil
#

It wont be a comprehensive full intro though, but it will walk you through a basic exploit

#

As pwntools is an extremely complex library

final sun
#

I got you covered for that @tacit anvil

tacit anvil
#

Bet @final sun

somber crow
#

ARM re?

final sun
#

Sounds easy but damn it's hard.

#

Calling conventions is a pain in the ass.

somber crow
#

I'll have a look into it myself because I want to learn ARM.

final sun
#

Fair enough, count me in. I do want to learn about the ARM binary analysis.

coarse jacinth
somber crow
#

@coarse jacinth gonna have to point you to rule 8 dude

still ice
#

ssh tunnels

tacit anvil
#

@coarse jacinth pls no nsfw

somber crow
#

@still ice Gamezone has one

#

But that's it I think

remote socket
#

Yeah gamezone does

#

Good memory Ninja

somber crow
#

(I was doing this like 2 days ago)

still ice
#

@somber crow thanks brother

winter sun
#

OWASP API top 10 (2019)

somber crow
#

Owasp top 10 sounds like good rooms really

#

For a lot

modest trail
#

On the same strand a room what require exploitation of an idor which leads to account takeover

modest trail
#

Windows room that implements the use of kerberos tickets to gain authenticated access to information

somber crow
#

I think corp or attacktive directory has a little use of Kerberos tickets but I'd love to see more

modest trail
#

Windows is just an area in general that needs major focus

formal turtle
#

we have an app locker bypass and windows Priv esc room in the works :))

modest trail
#

Pog

sleek elbow
#

i feel bad for the windows Priv Esc guy, windows is so screwy

tacit anvil
#

Darkstar irl

sage python
#

Room Suggestion: VoIP room, there's one on Vulnhub, but on platform would be cool

somber crow
#

Ooh VoIP. I'll take a look at it and if I can come up with anything I'll probably try

sage scroll
#

DFIR / Analysis Room ?

sage python
#

Cool @somber crow DM me if you want to see the VH version

celest wyvern
#

malware author/writing room?

somber crow
#

IMO that's too blackhat

#

Very little room for that to be used for legitimate purposes

modest trail
sturdy monolith
#

Is there a SIEM room?

quartz grove
#

If anybody makes that is gonna be dark

#

Is splunk SIEM?

feral reef
#

Yes it is

quartz grove
#

Then there's BP: Splunk

fallow lichen
#

So you're saying that we can't get a HackTheNSA room?

sleek elbow
#
  • An introduction to Bloodhound
plush salmon
#

Will more oscp rooms will be added?

languid ibex
#

i am pretty sure yes

remote socket
#

@plush salmon yes, we have more being developed as we speak:)

supple ether
#

Anyone here who can decode this md5 code? I'm trying it from last 1-2 hours

somber crow
supple ether
#

ad50fa710fff9660b3788a169ee4a12e

somber crow
#

Wrong channel still

languid ibex
#

Report writing guide or Faraday usage tutorial

remote socket
#

Does anyone want to do a room on the new CVE-2019-18634 ?

native raptor
#

I've got a whitepaper to write on Privesc for Uni @remote socket -- looking into that would fit in quite nicely if you don't mind someone less experienced tackling it?

remote socket
#

Yeah not at all

#

I think it will be straight forward to set up anyway

#

But it would be great to have an up-to date vuln out and teach it in a room

somber crow
#

@remote socket I saw that and was tempted to pop it into my walkthrough, as long as I can find an exploit for that bof

remote socket
#

Plz do - any use of it is cool

somber crow
#

I'll give it a look at some point

remote socket
#

Great 😄

somber crow
#

@remote socket So far, only PoC. No exploits, and since I've never written a BOF I might have to give it a little while for an exploit to come out

#

Same PoC everywhere, the perl script that segfaults

remote socket
#

Yeah no worries:)

somber crow
#

If an exploit comes out for it, I'll be right on that. It's a pretty cool exploit

#

Also got some ideas for some more OWASP top 10 webapp vulns, since this wasn't too bad to dev

remote socket
#

^ thats perfect

#

Yeah there are still some top 10 vulns that have not been explained/demo'd on THM yet

final sun
#

Did someone say Buffer Overflow?

#

It's mostly depend on sudo binary because the protections will make it hard, if segfault happens then there is a way but trivial.

somber crow
#

@final sun Yeah it segfaults. Do you mean trivial or non-trivial? easy or hard?

#

I'm thinking Broken Authentication next, as it kind of leads on from this room

final sun
#

@NinjaJc01#7746 It will have all the protections:- PIE, NX Enabled, Canary and what not.

somber crow
#

So non trivial ok

final sun
#

Yeah my bad

split viper
#

@remote socket There already is a privesc related to that sudo CVE

#

I was thinking about putting it in one of my rooms, but Deskel did it first 🙂

#

As far as i remember. I also did that room

final sun
#

And iirc, that bof vulnerability in sudo now has a working POC.

split viper
#

xD

somber crow
#

@final sun it had a poc, as in it segfaulted

#

@split viper I'm interested if you have an exploit for it

split viper
#

Nope. Been doing mostly web lately

#

Smashed the hell out of an SSRF yesterday xD

somber crow
#

@split viper so there isn't a privesc from that sudo cve?

split viper
#

Mistook it

#

There is another sudo flaw designed room

somber crow
#

Ye

split viper
#

The one using sudo -u #-1. Or something similar

somber crow
#

There's no exploit for this yet, only a POC to show that a BOF exists

split viper
#

I got a bit tired of the linux boxes. You won’t find that many in a production environment/real assessment

final sun
somber crow
#

There's a step missing in there or something?

#

I can't see where it writes to temp.out

final sun
#

I guess we gotta wait for sometime

dull adder
brazen kayak
#

is there any PoC with a valid root privesc payload?

modest trail
#

For the sudo segfault? @brazen kayak

brazen kayak
#

yes

modest trail
#

not just yet, there's a guy on twitter claiming to have got root RCE using it but no payloads

#

think it's just been widely assumed that it was a fake attempt at glory

brazen kayak
#

lol why would he claim that he did it if he's not providing proof

modest trail
#

he provided a picture of the root rce

#

but not the payloads

#

so just kinda shooting himself

brazen kayak
#

well that proves nothing

modest trail
#

exactly

sage python
#

Hey, a room idea I had, using the phoneinfoga tool, it's a pretty useful tool, don't see it up on the system.

brazen kayak
#

that seems interesting

#

never used that, but just googled it

sage python
#

yea, it's pretty cool.

empty scroll
#

hackable webcam walkthrough room on the private network ?

sleek elbow
#

likely not going to happen

tacit anvil
#

That could fall under a more general IoT room

somber crow
#

More IoT would be cool

mighty hearth
#

Advance OSINT with google dorks and other tools

light lynx
#

Already on it 😎

worn socket
#

@light lynx whats ETA on it?

light lynx
#

I've been working on it since ~October, my biggest issue is Twitter's rate limiting and the fact my application to use their API keeps on getting rejected 😦 Might have to find another way

#

It's also a challenge room. Twitter limits you to 300 tweets / day, and the plan was 6 accounts with ~50k tweets. I might just create the JSON file as if its from the Twitter API and give it to the user

remote socket
#

thats probably better 🙂

#

Even going by the moto "do things that scale"

raw moat
#

I think a GraphQL room would be cool, with SQLi. Love

warped pagoda
#

Anyone tell me about name of network pentesting ctfs?

native raptor
#

@warped pagoda not the right channel, mate. Please don't just post in a variety of channels if you don't get an answer in one 😄
Head over to #general and ask there

rocky gazelle
#

Thank you for making the comment @native raptor

#

I was just about to haha

native raptor
#

Hehe, No problem!

feral egret
#

Would love some deep diving into buffer overflows coupled with the steps of disassembling binaries with and without symbols.

lunar plank
#

Not necessarily a request, but more of a proposal. Would there be interest in content covering actual Networking knowledge and practical's? LAN topologies, Layer-2/3 Switching and routing. Essentially CCENT content?

#

Putting a feeler out

devout shell
#

Burp Suite extensions - introduce maybe 3-6 popular/varying extensions and how they integrate and work w/ Burp to solve new tasks

dull adder
#

@raw moat

raw moat
#

@dull adder

dull adder
#

I'm making a basic room of graphql

raw moat
#

Yes!

#

I’d love to test it out, feel free to DM whenever necessary.

modest trail
#

@devout shell once my current room projects are completed I can potentially do this for a couple I tend to use for bug bounty but that’s a bit potential as my workloads quite high atm

devout shell
#

@modest trail no pressure on you or anyone else in particular, but i think it would make for a cool burp suite "next steps" room

modest trail
#

Yeah, the problem with that is the extensions are usually there to automate a lot of manual stuff. So for instance I could go over using extensions to find idors. But unless there’s a room teaching the basics to understand them. It’s not a great idea to show automation

#

As people skip the understanding of said vuln

somber crow
#

It's a nice thing to include at the end of a room

modest trail
#

Smtp related room?

fallow lichen
#

OpenSMTPD might be fun

indigo echo
#

Room like cyberwar with timings will be great

remote socket
#

? Elaborate plz

fallow lichen
#

Do you think a priv esc room for mail accounts would be fun?

long ivy
#

yeeesss

mighty hearth
#

A room for the tool responder?

feral egret
#

@lunar plank I would love to see that kind of stuff as well

lunar plank
#

Sorry you'll have to remind me, what kind of stuff? @feral egret 🙂

feral egret
#

Not necessarily a request, but more of a proposal. Would there be interest in content covering actual Networking knowledge and practical's? LAN topologies, Layer-2/3 Switching and routing. Essentially CCENT content?
Putting a feeler out

somber crow
#

Some of that will be a hell of a lot easier at some point

lunar plank
#

Oh! Thanks @feral egret . I'm debating on making a little practical room making a very simple LAN and seeing what interest comes from it 🙂

somber crow
#

TryHackMe networks are coming at some point

lunar plank
#

oh they are?

#

but if that sort of stuff is in the pipeline then I'll leave it in very-capable hands 🙂

native raptor
#

@lunar plank TryHackMe networks, to my understanding, just give us the ability to network multiple machines together and deploy the lot of them. It's almost certainly a lot more advanced than that 😁

somber crow
#

I mean someone will still need to make the content

native raptor
#

The actual networking content is a different ballgame

lunar plank
#

Oh right, that sounds pretty cool tbf @native raptor but yeah I meant more towards CCENT stuff

#

But I'll wait and see how that transpires before starting anything

native raptor
#

I know -- I remember you telling me 😄
I think that's something that would be well received

somber crow
#

I'll let you know once I know something, I'll see something about it in mid march

lunar plank
#

Legend :^

sleek elbow
#

@lunar plank I've been sitting on some ideas. if I have some free time ill make a CCNA R&S curriculum.

#

after all, i do have my ccna

lunar plank
#

Ah I gotcha! I've spent the last two years at Uni going from CCENT -> CCNA (despite it overhauling now) will be interesting to see what you come up with!

sleek elbow
#

It'll 100% be a tutorial style box

#

likely with not many answers

#

but a ton of content

#

I had pondered the idea of using GNS3

#

but I don't like the idea of the images being able to be downloaded

somber crow
#

The IOS images?

#

Those are legally sketchy iirc?

sleek elbow
#

I own several Cisco devices

#

so its not really an issue for me

#

but putting it on a TryHackMe box is borderline distributing

lunar plank
#

ah true, yeah it's a real close line

#

mhm didn't think of it that way

stable hull
#

@sleek elbow Have you looked at Open vSwitch or similar?

somber crow
#

I mean those are cool, but they don't really teach you the IOS you'd need for CCNA

sleek elbow
#

switching was a huge part of the CCENT and its really really hard to skip it

stable hull
#

Yeah getting on IOS is a definite requirement for learning but the options to provide a platform at scale are either somewhat impractical, unaffordable or illegal and they would require students to have routine access to switches and routers and an ability to preserve configurations

sleek elbow
#

honestly, what I think I'll do is just load a box w/ Packet Tracer on it and go from there

#

you can do everything up to DHCP with no issues

native raptor
#

Is it even worth loading a box for that @sleek elbow? Packet tracer is such a useful tool -- you might be as well just getting 'em to download it?

sleek elbow
#

Yeah, i was also considering that

#

but we also do have Guacamole so it could be accessible just by the website

native raptor
#

True

sleek elbow
#

so with that said

#

i wonder if we can make the box non accessible by the VPN

#

and only accessible by Guacamole

native raptor
#

No idea how to get a machine enabled with Guacamole though 😁
Guessing that's an admin thing?