Tutorials & Guides

TryHackMe Roadmap 2026: CTF Writeups & Rooms in Order

Cracking Station TryHackMe walkthroughs

By Mehmood Ali (Mr. Professor), CEH, CEI · TryHackMe profile: Top 1% Updated September 2026

Quick answer: The TryHackMe roadmap I recommend goes in this order:

  1. Intro rooms (Welcome, Tutorial, OpenVPN)
  2. Linux and Windows fundamentals
  3. Security basics
  4. Recon
  5. Scripting and networking
  6. Tools
  7. Crypto and web hacking
  8. Privilege escalation and Active Directory
  9. Easy, medium and hard CTF rooms

Almost everything below is free. With an hour or two a day, most beginners get through the core stages in four to six months.

TryHackMe roadmap 2026 for beginners by Cracking Station

Why I Made This Roadmap

When I joined TryHackMe, I did what most beginners do. I opened the room list, got excited, and jumped straight into a “Medium” CTF. Forty minutes later I had an Nmap scan I didn’t understand and no idea what to do next. I closed the tab and felt like hacking wasn’t for me.

The problem wasn’t the room. The problem was order. TryHackMe has well over a thousand rooms, and nobody tells you which ones to do first.

So I started keeping my own list. Every time a room taught me something the next one assumed, I noted the pair. Over time that list grew into this roadmap: 350+ rooms grouped into stages, in the order that finally made things click for me.

Today my profile shows 258 completed rooms, 30 badges and a Top 1% global rank. I also use this exact order with the students I train in my cybersecurity classes. I first published the list on GitHub in 2023, and I keep this page as the updated version with my own walkthroughs linked in.

The TryHackMe Roadmap at a Glance

StageWhat you’ll learnRough timeStart here
1. Intro roomsHow TryHackMe works, AttackBox vs OpenVPN1–2 daysWelcome, Tutorial
2. Linux & WindowsTerminal, files, permissions, users1–2 weeksLinux Fundamentals 1–3
3. BasicsSecurity principles, hacker methodology1 weekPrinciples of Security
4. ReconOSINT, Google dorking, DNS, content discovery1–2 weeksPassive Reconnaissance
5. ScriptingPython, Bash, a little JavaScript1–2 weeksPython Basics
6. NetworkingTCP/IP, LAN, HTTP, DNS2 weeksWhat is Networking?
7. ToolingNmap, Metasploit, Burp Suite, Hydra2–3 weeksNmap
8. Crypto, stego & webHash cracking, hidden data, OWASP Top 103–4 weeksCrack the Hash, OWASP Top 10
9. Specialist tracksForensics, reversing, malware, PrivEsc, AD1–2 monthsLinux PrivEsc
10. CTFsFull machines, start to rootOngoingSimple CTF, RootMe

These times assume one to two hours of practice a day. Go slower if you need to. Nobody is timing you.

How to Use This TryHackMe Roadmap

A list of rooms is only useful if you use it well. Here is what worked for me and for my students.

Go stage by stage. Don’t skip Linux and networking to get to the “fun” rooms faster. Every CTF you’ll ever do is really a test of those two skills. Skipping them is the number one reason I see beginners give up.

Try for 30 minutes before opening a writeup. Being stuck is where the learning happens. When you do open a walkthrough, read only until you get the hint you need, then close it and continue on your own.

Keep your own notes. For every room, write down the commands you used, what failed, and one thing you learned. After fifty rooms, those notes become your personal cheat sheet. Mine did. It eventually turned into my Linux command cheat sheet.

Start with the AttackBox. The in-browser machine saves you from setup problems on day one. Once you are comfortable, connect your own Kali machine through OpenVPN (Linux guide · Windows guide).

Use the free rooms first. Most rooms in this roadmap are free. Premium is worth it later, when you want complete learning paths like Jr Penetration Tester or SOC Level 1, but it is not required to start.

What Each Stage Teaches You

1. Intro Rooms

This is where you learn how TryHackMe itself works: joining a room, answering task questions, starting a machine, and choosing between the AttackBox and OpenVPN. It feels basic, but it removes a lot of confusion later.

2. Linux & Windows Fundamentals

Almost every target you attack runs Linux or Windows, so you need to be at home on both. On Linux that means moving around the file system, reading and editing files, understanding permissions, and managing processes. The Windows rooms cover users, the file system, services and basic security settings.

3. Basics Rooms

These rooms explain how security actually works: the CIA triad, the steps of a penetration test, the hacker methodology, and even physical security. They are quick, but they give you the vocabulary you’ll see everywhere else.

4. Recon (Reconnaissance)

Good hackers spend more time gathering information than attacking. Here you learn passive and active reconnaissance, content discovery, Google dorking and OSINT. If you enjoy this stage, my OSINT and attack surface mapping guide goes much deeper.

5. Scripting

You don’t need to be a programmer, but basic Python and Bash will save you hours. These rooms teach you to automate boring tasks, read simple exploit code, and write small proof-of-concept scripts.

6. Networking

Networking is the backbone of everything else. You’ll learn IP addressing, TCP and UDP, how a LAN works, and what really happens when you open a website (HTTP and DNS). After this stage, Nmap output will finally make sense.

7. Tooling

This is the professional toolkit:

  • Nmap for scanning
  • Metasploit for exploitation
  • Burp Suite and OWASP ZAP for web testing
  • Hydra for brute forcing
  • Wireshark and TShark for traffic analysis

Learn what each tool does and when to use it, not just which command to copy.

8. Crypto, Hashes & Steganography

You’ll crack password hashes, learn how common encryption works, and find data hidden inside images and audio files. These skills appear constantly in CTFs.

9. Web Security

Web applications are the biggest attack surface on the internet. These rooms cover the OWASP Top 10, SQL injection, XSS, file inclusion and server-side template injection. Practice happens on deliberately vulnerable apps like Juice Shop, DVWA and WebGoat.

10. Specialist Tracks and CTFs

Once the core is solid, pick a direction: forensics, reverse engineering, malware analysis, privilege escalation, Active Directory, PCAP analysis or buffer overflows. Then test everything together on full CTF machines, from easy to hard.

The Complete TryHackMe Roadmap: Every Room in Order

Rooms marked with 📝 have a full walkthrough on Cracking Station. I add new writeups here as I publish them.

Intro Rooms

Linux Fundamentals

Windows Fundamentals

Basics Rooms

Recon

Scripting

Networking

Tooling

Crypto & Hashes

Steganography

Web

Android

Forensics

Wi-Fi Hacking

Reverse Engineering

Malware Analysis

Privilege Escalation

Windows Exploitation & Investigation

Active Directory

PCAP Analysis

Buffer Overflow

Easy CTF

Also good practice at this level (already listed above): Psycho Break, Pickle Rick, c4ptur3-th3-fl4g, Ignite, Kenobi, Blaster, Year of the Rabbit, Jack-of-All-Trades, Madness, Overpass, Bolt, Overpass 2.

Medium CTF

Hard CTF

Misc

Special Events

My TryHackMe Journey

I have been on TryHackMe for over two years. In that time I have completed 258 rooms and earned 30 badges, and my rank is now inside the top 1% of users worldwide. I’m not saying that to show off. I’m saying it because I remember very clearly being the person who closed the tab after one failed CTF.

What changed things for me was not talent. It was showing up almost every day and doing one room properly instead of five rooms badly. Some weeks I spent three evenings on a single privilege escalation box. Those were the weeks I learned the most.

The community helped a lot too. Room discussions, Discord and other people’s writeups taught me tricks I would never have found alone. That is also why I started writing my own walkthroughs on Cracking Station: to give something back to the people who helped me.

Today I work as a cybersecurity consultant and trainer. When a student asks me where to start, I don’t send them a list of 1,000 rooms. I send them this page.

Final Advice for Beginners

If you remember only four things from this page, make them these:

  • Be consistent. One room a day beats a ten-hour weekend.
  • Don’t fear failure. Every room you get stuck on is teaching you something.
  • Ask questions. Use the room discussions and the community. Nobody learns this alone.
  • Practice outside the rooms. Rebuild what you learned in your own lab.

Start with the Welcome room walkthrough, work down the list, and come back to this page whenever you are not sure what to do next.Happy hacking! Mehmood Ali (Mr. Professor)

Frequently Asked Questions

What is the best TryHackMe roadmap for beginners?

Start with the intro rooms (Welcome, Tutorial, OpenVPN), then Linux and Windows fundamentals, networking, recon, scripting and tools. After that, learn web hacking and privilege escalation, and finish with easy, medium and hard CTF rooms. This page lists more than 350 rooms in that order.

Is TryHackMe free?

Yes. TryHackMe has a free plan with hundreds of rooms, including most rooms on this roadmap. Premium adds complete learning paths such as Jr Penetration Tester and SOC Level 1, plus faster machines. It is useful later but not required to start.

How long does it take to complete this TryHackMe roadmap?

With one to two hours a day, most beginners finish the core stages (intro rooms through web security) in about four to six months. The CTF section never really ends. It is where you keep practicing.

Do I need programming knowledge to start TryHackMe?

No. The intro, Linux and networking rooms need no coding at all. You will pick up basic Python and Bash in the scripting stage, and that is enough for most beginner and intermediate CTFs.

What are TryHackMe CTF writeups?

A writeup is a step-by-step explanation of how someone solved a room or CTF, including the commands they used and why. Use writeups after you have tried a room yourself, to check your answers and learn techniques you missed.

Can TryHackMe help me get a cybersecurity job?

It builds the hands-on skills employers test in interviews, and its paths map to entry-level roles such as SOC analyst and junior penetration tester. Combine TryHackMe with a recognized certification and a portfolio of your own writeups to stand out.

Mehmood Ali

I am a Cybersecurity Consultant with over 8+ years of experience in SOC analyst, digital forensics, cloud security, network security, and incident response. With 20+ international certifications, I have successfully designed secure systems, led vulnerability assessments, and delivered key security projects. I am skilled at improving incident response times, mitigating threats, and ensuring compliance with ISO 27001 standards.

Related Articles

16 Comments

  1. This comprehensive cybersecurity roadmap for beginners is the perfect guide to start your journey with TryHackMe. It highlights every step clearly from Linux and Windows fundamentals to networking, reconnaissance, scripting, and web security. The structured approach ensures learners gain both theoretical knowledge and hands-on experience through real-world labs. Whether you’re preparing for ethical hacking, penetration testing, or building a career in cybersecurity, this TryHackMe beginner guide provides the right direction to master essential skills and grow with confidence.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button