Skip to main content
BLOG • 4 min read

Free TryHackMe Training: The Ultimate Guide for Beginners

You don't need money or a technical background to learn cyber security, just enough curiosity, discipline, (and this guide to free content on TryHackMe!)

We've got 650+ free rooms covering everything from networking basics to Windows privilege escalation, plus free events throughout the year. Want a quick win first? Pickle Rick is one of our most popular beginner CTFs, and it only takes about half an hour. No subscription needed to start, or to get genuinely good.

Work through the rooms below in order, and you'll cover the ground that most entry-level cyber security roles actually expect.

Level 1: Getting Started

Before any tooling, get oriented. These rooms cover what the different specialisations actually involve day to day, so you're choosing a direction with your eyes open rather than guessing.

Level 2: Tooling

The tools that come up constantly, regardless of which specialisation you end up in. We've led with the three tools people in security actually talk about most.

Level 3: Crypto and Hashes

Level 4: Web

Most real world attack surface lives here, so this is one of the longer sections.

Level 5: Reverse Engineering

Level 6: Networking

Level 7: Privilege Escalation

Level 8: CTF Practice

Easy

Medium

Level 9: Windows

Most of our Windows content sits behind Premium or MAX, but you can access these rooms for free to get a sense of the skills involved.

Level 10: Cloud, AI, and DevSecOps

Cloud, AI, and DevSecOps are newer specialisations, but they're already core to how modern security teams operate, and we've built free rooms covering all three. They get a level of their own here, since none of them really fits inside the categories above.

Cloud Security

  • Cloud Security Pitfalls, common security risks across IaaS, PaaS, and SaaS, and where SOC monitoring tends to have blind spots

AI Security

  • AI/ML Security Threats, foundational AI and ML concepts, and how the same tools get used by both attackers and defenders
  • AI Security Threats, the vulnerabilities AI introduces to an organisation, and how attackers actually weaponise them

DevSecOps

  • Introduction to DevSecOps, the fundamentals of shifting security left in the development lifecycle
  • DevSecOps Basics, how Waterfall became Agile became DevOps, and where security fits at each stage
  • Intro to IaC, infrastructure as code, on-prem versus cloud, and why it matters for a DevSecOps pipeline

Want more?

Ten levels in, you've covered more free, hands-on ground than most paid bootcamps offer. From here you've got three good options. Browse the full library of 650+ free rooms and keep exploring outside this roadmap, in whatever direction caught your interest most. Take out Premium or MAX once you're ready for structured paths, certifications, and the Windows content that sits behind a subscription. Or come build alongside other learners in the TryHackMe Discord, where new free rooms get talked about the moment they land.

authorBen Spring
Sep 28, 2026

Recommended

Get more insights, news, and assorted awesomeness around cyber training.

Join over 640 organisations upskilling their
workforce with TryHackMe