TryHackMe Roadmap 2026: CTF Writeups & Rooms in Order

By Mehmood Ali (Mr. Professor), CEH, CEI · TryHackMe profile: Top 1% Updated September 2026
Quick answer: The TryHackMe roadmap I recommend goes in this order:
- Intro rooms (Welcome, Tutorial, OpenVPN)
- Linux and Windows fundamentals
- Security basics
- Recon
- Scripting and networking
- Tools
- Crypto and web hacking
- Privilege escalation and Active Directory
- Easy, medium and hard CTF rooms
Almost everything below is free. With an hour or two a day, most beginners get through the core stages in four to six months.

Why I Made This Roadmap
When I joined TryHackMe, I did what most beginners do. I opened the room list, got excited, and jumped straight into a “Medium” CTF. Forty minutes later I had an Nmap scan I didn’t understand and no idea what to do next. I closed the tab and felt like hacking wasn’t for me.
The problem wasn’t the room. The problem was order. TryHackMe has well over a thousand rooms, and nobody tells you which ones to do first.
So I started keeping my own list. Every time a room taught me something the next one assumed, I noted the pair. Over time that list grew into this roadmap: 350+ rooms grouped into stages, in the order that finally made things click for me.
Today my profile shows 258 completed rooms, 30 badges and a Top 1% global rank. I also use this exact order with the students I train in my cybersecurity classes. I first published the list on GitHub in 2023, and I keep this page as the updated version with my own walkthroughs linked in.
The TryHackMe Roadmap at a Glance
| Stage | What you’ll learn | Rough time | Start here |
|---|---|---|---|
| 1. Intro rooms | How TryHackMe works, AttackBox vs OpenVPN | 1–2 days | Welcome, Tutorial |
| 2. Linux & Windows | Terminal, files, permissions, users | 1–2 weeks | Linux Fundamentals 1–3 |
| 3. Basics | Security principles, hacker methodology | 1 week | Principles of Security |
| 4. Recon | OSINT, Google dorking, DNS, content discovery | 1–2 weeks | Passive Reconnaissance |
| 5. Scripting | Python, Bash, a little JavaScript | 1–2 weeks | Python Basics |
| 6. Networking | TCP/IP, LAN, HTTP, DNS | 2 weeks | What is Networking? |
| 7. Tooling | Nmap, Metasploit, Burp Suite, Hydra | 2–3 weeks | Nmap |
| 8. Crypto, stego & web | Hash cracking, hidden data, OWASP Top 10 | 3–4 weeks | Crack the Hash, OWASP Top 10 |
| 9. Specialist tracks | Forensics, reversing, malware, PrivEsc, AD | 1–2 months | Linux PrivEsc |
| 10. CTFs | Full machines, start to root | Ongoing | Simple CTF, RootMe |
These times assume one to two hours of practice a day. Go slower if you need to. Nobody is timing you.
How to Use This TryHackMe Roadmap
A list of rooms is only useful if you use it well. Here is what worked for me and for my students.
Go stage by stage. Don’t skip Linux and networking to get to the “fun” rooms faster. Every CTF you’ll ever do is really a test of those two skills. Skipping them is the number one reason I see beginners give up.
Try for 30 minutes before opening a writeup. Being stuck is where the learning happens. When you do open a walkthrough, read only until you get the hint you need, then close it and continue on your own.
Keep your own notes. For every room, write down the commands you used, what failed, and one thing you learned. After fifty rooms, those notes become your personal cheat sheet. Mine did. It eventually turned into my Linux command cheat sheet.
Start with the AttackBox. The in-browser machine saves you from setup problems on day one. Once you are comfortable, connect your own Kali machine through OpenVPN (Linux guide · Windows guide).
Use the free rooms first. Most rooms in this roadmap are free. Premium is worth it later, when you want complete learning paths like Jr Penetration Tester or SOC Level 1, but it is not required to start.
What Each Stage Teaches You
1. Intro Rooms
This is where you learn how TryHackMe itself works: joining a room, answering task questions, starting a machine, and choosing between the AttackBox and OpenVPN. It feels basic, but it removes a lot of confusion later.
2. Linux & Windows Fundamentals
Almost every target you attack runs Linux or Windows, so you need to be at home on both. On Linux that means moving around the file system, reading and editing files, understanding permissions, and managing processes. The Windows rooms cover users, the file system, services and basic security settings.
3. Basics Rooms
These rooms explain how security actually works: the CIA triad, the steps of a penetration test, the hacker methodology, and even physical security. They are quick, but they give you the vocabulary you’ll see everywhere else.
4. Recon (Reconnaissance)
Good hackers spend more time gathering information than attacking. Here you learn passive and active reconnaissance, content discovery, Google dorking and OSINT. If you enjoy this stage, my OSINT and attack surface mapping guide goes much deeper.
5. Scripting
You don’t need to be a programmer, but basic Python and Bash will save you hours. These rooms teach you to automate boring tasks, read simple exploit code, and write small proof-of-concept scripts.
6. Networking
Networking is the backbone of everything else. You’ll learn IP addressing, TCP and UDP, how a LAN works, and what really happens when you open a website (HTTP and DNS). After this stage, Nmap output will finally make sense.
7. Tooling
This is the professional toolkit:
- Nmap for scanning
- Metasploit for exploitation
- Burp Suite and OWASP ZAP for web testing
- Hydra for brute forcing
- Wireshark and TShark for traffic analysis
Learn what each tool does and when to use it, not just which command to copy.
8. Crypto, Hashes & Steganography
You’ll crack password hashes, learn how common encryption works, and find data hidden inside images and audio files. These skills appear constantly in CTFs.
9. Web Security
Web applications are the biggest attack surface on the internet. These rooms cover the OWASP Top 10, SQL injection, XSS, file inclusion and server-side template injection. Practice happens on deliberately vulnerable apps like Juice Shop, DVWA and WebGoat.
10. Specialist Tracks and CTFs
Once the core is solid, pick a direction: forensics, reverse engineering, malware analysis, privilege escalation, Active Directory, PCAP analysis or buffer overflows. Then test everything together on full CTF machines, from easy to hard.
The Complete TryHackMe Roadmap: Every Room in Order
Rooms marked with 📝 have a full walkthrough on Cracking Station. I add new writeups here as I publish them.
Intro Rooms
- TryHackMe | Welcome 📝
- TryHackMe | How to use TryHackMe 📝
- TryHackMe | Tutorial 📝
- TryHackMe | OpenVPN 📝
- TryHackMe | Learning Cyber Security 📝
- TryHackMe | Starting Out In Cyber Sec 📝
- TryHackMe | Introductory Researching 📝
- TryHackMe | CC: Pen Testing 📝
- TryHackMe | Regular expressions
Linux Fundamentals
- TryHackMe | Learn Linux
- TryHackMe | Linux Modules
- TryHackMe | Linux Fundamentals Part 1
- TryHackMe | Linux Fundamentals Part 2
- TryHackMe | Linux Fundamentals Part 3
- Companion guide: Linux Command Cheat Sheet 📝
Windows Fundamentals
- TryHackMe | Windows Fundamentals 1
- TryHackMe | Windows Fundamentals 2
- TryHackMe | Windows Fundamentals 3
Basics Rooms
- TryHackMe | Basic Pentesting
- TryHackMe | Pentesting Fundamentals
- TryHackMe | Principles of Security
- TryHackMe | The Hacker Methodology
- TryHackMe | Physical Security Intro
- TryHackMe | Linux Strength Training
- TryHackMe | OpenVAS
- TryHackMe | ISO27001
- TryHackMe | UltraTech
Recon
- TryHackMe | Passive Reconnaissance
- TryHackMe | Active Reconnaissance
- TryHackMe | Content Discovery
- TryHackMe | OhSINT
- TryHackMe | Shodan.io
- TryHackMe | Google Dorking
- TryHackMe | WebOSINT
- TryHackMe | Sakura Room
- TryHackMe | Red Team Recon
- TryHackMe | Searchlight – IMINT
- Companion guide: OSINT & Attack Surface Mapping 📝
Scripting
- TryHackMe | Python Basics
- TryHackMe | Python Playground
- TryHackMe | Intro PoC Scripting
- TryHackMe | Peak Hill
- TryHackMe | JavaScript Basics
- TryHackMe | Bash Scripting
- TryHackMe | Learn Rust
Networking
- TryHackMe | Introductory Networking
- TryHackMe | What is Networking?
- TryHackMe | Networking
- TryHackMe | Intro to LAN
- TryHackMe | HTTP in detail
- TryHackMe | DNS in detail
- TryHackMe | Dumping Router Firmware
Tooling
- TryHackMe | Metasploit: Introduction
- TryHackMe | Metasploit
- TryHackMe | tmux
- TryHackMe | REmux The Tmux
- TryHackMe | Hydra
- TryHackMe | Sublist3r
- TryHackMe | Toolbox: Vim
- TryHackMe | Introduction to OWASP ZAP
- TryHackMe | Phishing: HiddenEye
- TryHackMe | RustScan
- TryHackMe | Nessus
- TryHackMe | Nmap Live Host Discovery
- TryHackMe | Nmap
- TryHackMe | TShark
- TryHackMe | ffuf
- TryHackMe | YARA
- TryHackMe | Burp Suite: The Basics
- TryHackMe | Burp Suite: Repeater
Crypto & Hashes
- TryHackMe | Cryptography for Dummies
- TryHackMe | Crack the hash
- TryHackMe | Crack The Hash Level 2
- TryHackMe | Agent Sudo
- TryHackMe | Brute It
Steganography
- TryHackMe | CC: Steganography
- TryHackMe | Cicada-3301 Vol:1
- TryHackMe | Musical Stego
- TryHackMe | Madness
- TryHackMe | Psycho Break
- TryHackMe | Unstable Twin
Web
- TryHackMe | Web Fundamentals
- TryHackMe | WebAppSec 101
- TryHackMe | Vulnerabilities 101
- TryHackMe | Walking An Application
- TryHackMe | OWASP Top 10
- TryHackMe | OWASP Juice Shop
- TryHackMe | Web Scanning
- TryHackMe | OWASP Mutillidae II
- TryHackMe | WebGOAT
- TryHackMe | DVWA
- TryHackMe | VulnNet
- TryHackMe | Juicy Details
- TryHackMe | Vulnversity
- TryHackMe | Injection
- TryHackMe | LFI Basics
- TryHackMe | Inclusion
- TryHackMe | SQL Injection Lab
- TryHackMe | SSTI
- TryHackMe | SQL Injection
- TryHackMe | Ignite
- TryHackMe | Overpass
- TryHackMe | Year of the Rabbit
- TryHackMe | Develpy
- TryHackMe | Jack-of-All-Trades
- TryHackMe | Bolt
Android
Forensics
- TryHackMe | Linux Server Forensics
- TryHackMe | Forensics
- TryHackMe | Memory Forensics
- TryHackMe | Volatility
- TryHackMe | Disk Analysis & Autopsy
- Companion guide: 7 Best Data Carving Tools 📝
Wi-Fi Hacking
Reverse Engineering
- TryHackMe | Intro to x86-64
- TryHackMe | Windows x64 Assembly
- TryHackMe | Reverse Engineering
- TryHackMe | Reversing ELF
- TryHackMe | JVM Reverse Engineering
- TryHackMe | CC: Radare2
- TryHackMe | CC: Ghidra
- TryHackMe | Aster
- TryHackMe | Classic Passwd
- TryHackMe | REloaded
Malware Analysis
- TryHackMe | History of Malware
- TryHackMe | MAL: Malware Introductory
- TryHackMe | Basic Malware RE
- TryHackMe | MAL: Researching
- TryHackMe | Mobile Malware Analysis
- TryHackMe | Carnage
- TryHackMe | Dunkle Materie
Privilege Escalation
- TryHackMe | Linux Privilege Escalation
- TryHackMe | Linux PrivEsc
- TryHackMe | Linux PrivEsc Arena
- TryHackMe | Windows PrivEsc
- TryHackMe | Windows PrivEsc Arena
- TryHackMe | Linux Agency
- TryHackMe | Sudo Security Bypass
- TryHackMe | Sudo Buffer Overflow
- TryHackMe | Blaster
- TryHackMe | Kenobi
- TryHackMe | c4ptur3-th3-fl4g
- TryHackMe | Pickle Rick
Windows Exploitation & Investigation
- TryHackMe | Investigating Windows
- TryHackMe | Investigating Windows 2.0
- TryHackMe | Investigating Windows 3.x
- TryHackMe | Blueprint
- TryHackMe | VulnNet: Active
- TryHackMe | Anthem
- TryHackMe | Blue
Active Directory
- TryHackMe | Attacktive Directory
- TryHackMe | Post-Exploitation Basics
- TryHackMe | USTOUN
- TryHackMe | Enterprise
- TryHackMe | RazorBlack
PCAP Analysis
Buffer Overflow
- TryHackMe | Buffer Overflow Prep
- TryHackMe | Gatekeeper
- TryHackMe | Chronicle
- TryHackMe | Intro To Pwntools
Easy CTF
- TryHackMe | GamingServer
- TryHackMe | OverlayFS – CVE-2021-3493
- TryHackMe | Bounty Hacker
- TryHackMe | Fowsniff CTF
- TryHackMe | RootMe
- TryHackMe | AttackerKB
- TryHackMe | Library
- TryHackMe | Thompson
- TryHackMe | Simple CTF
- TryHackMe | LazyAdmin
- TryHackMe | Anonforce
- TryHackMe | Wgel CTF
- TryHackMe | Dav
- TryHackMe | Ninja Skills
- TryHackMe | Ice
- TryHackMe | Lian_Yu
- TryHackMe | The Cod Caper
- TryHackMe | Encryption – Crypto 101
- TryHackMe | Brooklyn Nine Nine
- TryHackMe | KoTH Food CTF
- TryHackMe | Easy Peasy
- TryHackMe | Tony the Tiger
- TryHackMe | CTF collection Vol.1
- TryHackMe | Smag Grotto
- TryHackMe | Couch
- TryHackMe | Source
- TryHackMe | Gotta Catch’em All!
- TryHackMe | kiba
- TryHackMe | Poster
- TryHackMe | Chocolate Factory
- TryHackMe | Startup
- TryHackMe | Chill Hack
- TryHackMe | ColddBox: Easy
- TryHackMe | GLITCH
- TryHackMe | All in One
- TryHackMe | Archangel
- TryHackMe | Cyborg
- TryHackMe | Lunizz CTF
- TryHackMe | Badbyte
- TryHackMe | Team
- TryHackMe | VulnNet: Node
- TryHackMe | VulnNet: Internal
- TryHackMe | Atlas
- TryHackMe | VulnNet: Roasted
- TryHackMe | Cat Pictures
- TryHackMe | Mustacchio
Also good practice at this level (already listed above): Psycho Break, Pickle Rick, c4ptur3-th3-fl4g, Ignite, Kenobi, Blaster, Year of the Rabbit, Jack-of-All-Trades, Madness, Overpass, Bolt, Overpass 2.
Medium CTF
- TryHackMe | Mr Robot CTF
- TryHackMe | GoldenEye
- TryHackMe | StuxCTF
- TryHackMe | Boiler CTF
- TryHackMe | HA Joker CTF
- TryHackMe | Biohazard
- TryHackMe | Break it
- TryHackMe | Willow
- TryHackMe | The Marketplace
- TryHackMe | Nax
- TryHackMe | Mindgames
- TryHackMe | Anonymous
- TryHackMe | Blog
- TryHackMe | Wonderland
- TryHackMe | 0day
- TryHackMe | CTF collection Vol.2
- TryHackMe | CMesS
- TryHackMe | Deja Vu
- TryHackMe | hackerNote
- TryHackMe | dogcat
- TryHackMe | ConvertMyVideo
- TryHackMe | KoTH Hackers
- TryHackMe | Revenge
- TryHackMe | harder
- TryHackMe | HaskHell
- TryHackMe | Undiscovered
- TryHackMe | Break Out The Cage
- TryHackMe | The Impossible Challenge
- TryHackMe | Looking Glass
- TryHackMe | Recovery
- TryHackMe | Relevant
- TryHackMe | Ghizer
- TryHackMe | Mnemonic
- TryHackMe | WWBuddy
- TryHackMe | The Blob Blog
- TryHackMe | Cooctus Stories
- TryHackMe | One Piece
- TryHackMe | toc2
- TryHackMe | NerdHerd
- TryHackMe | Kubernetes Chall TDI 2020
- TryHackMe | The Server From Hell
- TryHackMe | Jacob the Boss
- TryHackMe | Unbaked Pie
- TryHackMe | Bookstore
- TryHackMe | Overpass 3 – Hosting
- TryHackMe | battery
- TryHackMe | Madeye’s Castle
- TryHackMe | En-pass
- TryHackMe | Sustah
- TryHackMe | KaffeeSec – SoMeSINT
- TryHackMe | Tokyo Ghoul
- TryHackMe | Watcher
- TryHackMe | broker
- TryHackMe | Inferno
- TryHackMe | VulnNet: dotpy
- TryHackMe | Wekor
- TryHackMe | pyLon
- TryHackMe | The Great Escape
- TryHackMe | SafeZone
- TryHackMe | NahamStore
- TryHackMe | Sweettooth Inc.
- TryHackMe | CMSpit
- TryHackMe | Super-Spam
- TryHackMe | That’s The Ticket
- TryHackMe | Debug
- TryHackMe | Red Stone One Carat
- TryHackMe | Cold VVars
- TryHackMe | Metamorphosis
- TryHackMe | SQHell
- TryHackMe | Fortress
- TryHackMe | CyberCrafted
- TryHackMe | Road
Hard CTF
- TryHackMe | Motunui
- TryHackMe | Spring
- TryHackMe | Brainpan 1
- TryHackMe | Borderlands
- TryHackMe | hc0n Christmas CTF
- TryHackMe | Daily Bugle
- TryHackMe | Retro
- TryHackMe | Jeff
- TryHackMe | Racetrack Bank
- TryHackMe | Dave’s Blog
- TryHackMe | CherryBlossom
- TryHackMe | Iron Corp
- TryHackMe | Carpe Diem 1
- TryHackMe | Ra
- TryHackMe | Year of the Fox
- TryHackMe | For Business Reasons
- TryHackMe | Anonymous Playground
- TryHackMe | Misguided Ghosts
- TryHackMe | Theseus
- TryHackMe | Internal
- TryHackMe | Year of the Dog
- TryHackMe | You’re in a cave
- TryHackMe | Year of the Owl
- TryHackMe | Year of the Pig
- TryHackMe | envizon
- TryHackMe | GameBuzz
- TryHackMe | Fusion Corp
- TryHackMe | Crocc Crew
- TryHackMe | Uranium CTF
- TryHackMe | Year of the Jellyfish
- TryHackMe | Rocket
- TryHackMe | Squid Game
- TryHackMe | EnterPrize
- TryHackMe | Different CTF
- TryHackMe | VulnNet: dotjar
- TryHackMe | M4tr1x: Exit Denied
- TryHackMe | Shaker
Misc
- TryHackMe | Introduction to Django
- TryHackMe | Git Happens
- TryHackMe | Meltdown Explained
- TryHackMe | Splunk
- TryHackMe | Linux Backdoors
- TryHackMe | Jupyter 101
- TryHackMe | Geolocating Images
- TryHackMe | Tor
- TryHackMe | tomghost
- TryHackMe | DLL HIJACKING
- TryHackMe | Intro to IoT Pentesting
- TryHackMe | Attacking ICS Plant #1
- TryHackMe | Attacking ICS Plant #2
- TryHackMe | Printer Hacking 101
- TryHackMe | DNS Manipulation
- TryHackMe | Introduction to Flask
- TryHackMe | MITRE
- TryHackMe | magician
- TryHackMe | JPGChat
- TryHackMe | Baron Samedit
- TryHackMe | CVE-2021-41773/42013
- TryHackMe | Binary Heaven
- TryHackMe | Git and Crumpets
- TryHackMe | Polkit: CVE-2021-3560
- TryHackMe | Hip Flask
- TryHackMe | Bypass Disable Functions
- TryHackMe | WordPress: CVE-2021-29447
- TryHackMe | Linux Function Hooking
- TryHackMe | REvil Corp
- TryHackMe | Solar, exploiting log4j
- TryHackMe | Conti
- TryHackMe | Dirty Pipe: CVE-2022-0847
- TryHackMe | The find command
Special Events
- Advent of Cyber 2025: all 24 days explained 📝
- Advent of Cyber 2025 Prep Track walkthrough 📝
- TryHackMe | Advent of Cyber 2024
- TryHackMe | Advent of Cyber 2023
- TryHackMe | Advent of Cyber 2022
- TryHackMe | Advent of Cyber 3 (2021)
- TryHackMe | Advent of Cyber 2 (2020)
- TryHackMe | Advent of Cyber 1 (2019)
- TryHackMe | 25 Days of Cyber Security
- TryHackMe | Cyber Scotland 2021
- TryHackMe | Hacker of the Hill #1
- TryHackMe | Learn and win prizes
- TryHackMe | Learn and win prizes #2
My TryHackMe Journey
I have been on TryHackMe for over two years. In that time I have completed 258 rooms and earned 30 badges, and my rank is now inside the top 1% of users worldwide. I’m not saying that to show off. I’m saying it because I remember very clearly being the person who closed the tab after one failed CTF.
What changed things for me was not talent. It was showing up almost every day and doing one room properly instead of five rooms badly. Some weeks I spent three evenings on a single privilege escalation box. Those were the weeks I learned the most.
The community helped a lot too. Room discussions, Discord and other people’s writeups taught me tricks I would never have found alone. That is also why I started writing my own walkthroughs on Cracking Station: to give something back to the people who helped me.
Today I work as a cybersecurity consultant and trainer. When a student asks me where to start, I don’t send them a list of 1,000 rooms. I send them this page.
Final Advice for Beginners
If you remember only four things from this page, make them these:
- Be consistent. One room a day beats a ten-hour weekend.
- Don’t fear failure. Every room you get stuck on is teaching you something.
- Ask questions. Use the room discussions and the community. Nobody learns this alone.
- Practice outside the rooms. Rebuild what you learned in your own lab.
Start with the Welcome room walkthrough, work down the list, and come back to this page whenever you are not sure what to do next.Happy hacking! Mehmood Ali (Mr. Professor)
Frequently Asked Questions
What is the best TryHackMe roadmap for beginners?
Start with the intro rooms (Welcome, Tutorial, OpenVPN), then Linux and Windows fundamentals, networking, recon, scripting and tools. After that, learn web hacking and privilege escalation, and finish with easy, medium and hard CTF rooms. This page lists more than 350 rooms in that order.
Is TryHackMe free?
Yes. TryHackMe has a free plan with hundreds of rooms, including most rooms on this roadmap. Premium adds complete learning paths such as Jr Penetration Tester and SOC Level 1, plus faster machines. It is useful later but not required to start.
How long does it take to complete this TryHackMe roadmap?
With one to two hours a day, most beginners finish the core stages (intro rooms through web security) in about four to six months. The CTF section never really ends. It is where you keep practicing.
Do I need programming knowledge to start TryHackMe?
No. The intro, Linux and networking rooms need no coding at all. You will pick up basic Python and Bash in the scripting stage, and that is enough for most beginner and intermediate CTFs.
What are TryHackMe CTF writeups?
A writeup is a step-by-step explanation of how someone solved a room or CTF, including the commands they used and why. Use writeups after you have tried a room yourself, to check your answers and learn techniques you missed.
Can TryHackMe help me get a cybersecurity job?
It builds the hands-on skills employers test in interviews, and its paths map to entry-level roles such as SOC analyst and junior penetration tester. Combine TryHackMe with a recognized certification and a portfolio of your own writeups to stand out.




Best roadmap to become a best hacker.
Best roadmap to become a best hacker.
Best roadmap to become a best hacker.
Boss keep it up.
Happy Hacking
This comprehensive cybersecurity roadmap for beginners is the perfect guide to start your journey with TryHackMe. It highlights every step clearly from Linux and Windows fundamentals to networking, reconnaissance, scripting, and web security. The structured approach ensures learners gain both theoretical knowledge and hands-on experience through real-world labs. Whether you’re preparing for ethical hacking, penetration testing, or building a career in cybersecurity, this TryHackMe beginner guide provides the right direction to master essential skills and grow with confidence.