You don't need money or a technical background to learn cyber security, just enough curiosity, discipline, (and this guide to free content on TryHackMe!)
We've got 650+ free rooms covering everything from networking basics to Windows privilege escalation, plus free events throughout the year. Want a quick win first? Pickle Rick is one of our most popular beginner CTFs, and it only takes about half an hour. No subscription needed to start, or to get genuinely good.
Work through the rooms below in order, and you'll cover the ground that most entry-level cyber security roles actually expect.
Level 1: Getting Started
Before any tooling, get oriented. These rooms cover what the different specialisations actually involve day to day, so you're choosing a direction with your eyes open rather than guessing.
- Intro to Offensive Security
- Intro to Defensive Security
- Linux Fundamentals Part 1, the basics you'll lean on in almost every room from here on
- Careers in Cyber, a walk through what different security roles actually involve day to day
- SOC Fundamentals, what a security operations centre actually does, day to day
- Red Team Fundamentals, on how red teaming actually differs from a standard penetration test
- Search Skills, how to actually find what you need when you're stuck, more useful than any single tool in this list
- Security Awareness, the human side of security, and why people remain the easiest way in
- The Brochure, a browser-only OSINT challenge, no terminal required, a good place to start if you want a taste of investigative work before the more hands-on rooms below
Level 2: Tooling
The tools that come up constantly, regardless of which specialisation you end up in. We've led with the three tools people in security actually talk about most.
- Nmap Live Host Discovery, the tool you'll reach for first in almost every room from here on, for finding what's actually alive on a network
- Metasploit: Introduction, the framework behind a huge share of the exploits you'll run throughout this guide
- Burp Suite: Repeater, for manually replaying and modifying web requests
- Hydra, a password-cracking tool, useful the moment you hit a login form guarding something interesting
- Introduction to Antivirus, on how AV actually detects malicious files, and where it can be evaded
- Introduction to OWASP ZAP, a free alternative to Burp Suite for testing web applications
- Vulnversity
- Blue
- Simple CTF
- Bounty Hacker
- Brute It
- Linux PrivEsc, your first real dive into escalating from a low-privilege shell to root
Level 3: Crypto and Hashes
Level 4: Web
Most real world attack surface lives here, so this is one of the longer sections.
- Web Application Basics, the building blocks of how web apps actually work, before you start attacking them
- How Websites Work
- SQL Injection
- DNS in Detail
- HTTP in Detail
- OWASP Juice Shop
- Overpass
- Bolt
- TakeOver
- Corridor
- Bypass Disable Functions, a sharper look at getting code execution out of a locked-down PHP server
Level 5: Reverse Engineering
Level 6: Networking
- What is Networking?
- Introductory Networking
- Network Services
- Network Services 2
- Passive Reconnaissance
- Active Reconnaissance
- Sakura Room, an OSINT investigation, tracking a target across social media, metadata, and public records
- Nmap
- Traffic Analysis Essentials
- Snort
- Intro to Cyber Threat Intel, the sources and frameworks analysts use to track who's behind an attack, and why
- Threat Intelligence Tools, hands-on with the open source tools analysts actually use, urlscan.io, Abuse.ch, PhishTool, and Cisco Talos
- Threat Hunting: Foothold, on spotting an initial compromise from the logs it leaves behind
Level 7: Privilege Escalation
- Linux Privilege Escalation
- Windows PrivEsc
- Linux PrivEsc Arena
- Windows PrivEsc Arena
- Sudo Security Bypass
- Sudo Buffer Overflow
- Blaster
- Ignite
- Kenobi
- C4ptur3-th3-Fl4g
- Pickle Rick
Level 8: CTF Practice
Easy
- Break Out The Cage
- Lian Yu
- B3dr0ck
- Startup
- Room 404, from Hacker Holidays 2026, a hidden host reachable through an exposed port nobody documented
Medium
- VulnNet: Active
- Dogcat
- Eavesdropper
- Ollie
- CryptoCabana, a compromised crypto storage kiosk, also from Hacker Holidays 2026
- Infinity Pool, a boot2root tracing a network out to three undocumented systems, same event
Level 9: Windows
Most of our Windows content sits behind Premium or MAX, but you can access these rooms for free to get a sense of the skills involved.
- Windows Fundamentals 2
- Blue
- Attacktive Directory
- Retro
- Blueprint
- Anthem
- Relevant
- Windows Forensics 1
- LocalPotato
Level 10: Cloud, AI, and DevSecOps
Cloud, AI, and DevSecOps are newer specialisations, but they're already core to how modern security teams operate, and we've built free rooms covering all three. They get a level of their own here, since none of them really fits inside the categories above.
Cloud Security
- Cloud Security Pitfalls, common security risks across IaaS, PaaS, and SaaS, and where SOC monitoring tends to have blind spots
AI Security
- AI/ML Security Threats, foundational AI and ML concepts, and how the same tools get used by both attackers and defenders
- AI Security Threats, the vulnerabilities AI introduces to an organisation, and how attackers actually weaponise them
DevSecOps
- Introduction to DevSecOps, the fundamentals of shifting security left in the development lifecycle
- DevSecOps Basics, how Waterfall became Agile became DevOps, and where security fits at each stage
- Intro to IaC, infrastructure as code, on-prem versus cloud, and why it matters for a DevSecOps pipeline
Want more?
Ten levels in, you've covered more free, hands-on ground than most paid bootcamps offer. From here you've got three good options. Browse the full library of 650+ free rooms and keep exploring outside this roadmap, in whatever direction caught your interest most. Take out Premium or MAX once you're ready for structured paths, certifications, and the Windows content that sits behind a subscription. Or come build alongside other learners in the TryHackMe Discord, where new free rooms get talked about the moment they land.

Ben Spring