The Best TryHackMe Learning Path (After Completing 170+ Rooms)

I Completed 170+ TryHackMe Rooms — Here's the Learning Path I Wish I Started With

I Completed 170+ TryHackMe Rooms — Here's the Learning Path I Wish I Started With

I Read 50 Real CVE Reports — 5 Lessons Every Cybersecurity Student Should Know

Here's what I know about TryHackMe: it works. I'm Top 2% globally with 170+ rooms completed. I've earned 6 learning path certifications. I've moved from zero cybersecurity knowledge to SOC internship at a commercial MSSP. TryHackMe was the primary learning platform for all of that.

But I wasted about 60 hours doing rooms in the wrong order. I started rooms because they looked interesting, not because they built systematically on prior knowledge. I did penetration testing rooms before I understood Linux well enough to exploit systems efficiently. I skipped foundational paths because I was bored with basics. Then I hit walls where I was missing critical knowledge I could have learned earlier.

This post is the roadmap I wish I'd had. It's not "do every TryHackMe room in order." It's "here's the optimal learning path through TryHackMe for different career goals, based on what actually prepared me for real work."

What this covers: The 6 TryHackMe learning paths ranked by priority and prerequisites. Which paths build on which. Which ones you can skip. Which ones are non-negotiable. How I progressed from complete beginner to Top 2%. The honest ROI of each path for different career goals (SOC analyst vs penetration tester).
The Optimal Learning Sequence:
  1. Phase 0: Foundations (what you should know before any path)
  2. Phase 1: The Essential Paths (do these first, in order)
  3. Phase 2: Specialisation Paths (choose based on career goals)
  4. Phase 3: Advanced Paths (for depth, not breadth)
  5. Common mistakes I made (and how to avoid them)
  6. How to maintain momentum and avoid burnout

The Honest Truth: Not All TryHackMe Paths Are Created Equal

My Starting Point

In December 2024, I had zero cybersecurity knowledge. I knew Python basics from a university course. I'd never heard of Kali Linux or Burp Suite. I applied to TryHackMe mostly because it was free and had good reviews. I joined, looked at the learning paths, and started with Pre Security because it looked beginner-friendly.

That decision probably saved me 40+ hours of wasted time, even though I didn't understand why it mattered at the time.

Phase 0: Foundations — Before You Touch Any Learning Path

These aren't learning paths on TryHackMe. These are prerequisite knowledge that you should have before starting the actual paths. If you skip these, you'll struggle understanding the paths themselves.

Understand Command Line Basics (Linux/Windows)
Prerequisite • 2-3 days • Non-negotiable

Before you do anything on TryHackMe, you need to be comfortable typing commands in a terminal. Not expert-level. Just comfortable enough that running `ls`, `cd`, `cat`, `grep` doesn't feel like magic. If you're completely new to command line, spend 2-3 days with free YouTube tutorials (NetworkChuck, John Hammond) or Linux Academy free tier before touching TryHackMe.

Why this matters: Every TryHackMe room assumes you can navigate file systems and run tools from command line. If you can't, you'll spend half the room fighting your environment instead of learning security concepts.
Understand How Networks Work (Very Basic)
Prerequisite • 1-2 days • Essential

Understand the difference between IP addresses, ports, and protocols at a surface level. You don't need to memorize OSI layers yet. You just need to know that a port is a communication endpoint and that protocols like HTTP and SSH use specific ports. TryHackMe's Pre Security path teaches this, but it helps to have encountered it before.

Phase 1: The Essential Paths — Do These First, In This Order

These three paths build on each other and establish all foundational knowledge you'll need for any specialisation later.

1. Pre Security
Foundational • 8-10 rooms • 20-25 hours • Difficulty: Easy
ESSENTIAL FIRST

Pre Security covers: networking basics (IP, TCP/UDP, DNS), Linux command line fundamentals, Windows system basics, and how computers communicate. This path is deliberately beginner-friendly. Some rooms feel repetitive if you already know the material, but that repetition helps it stick.

Why first: Every single room you do after this assumes you understand the basics covered here. If you skip it because it feels too beginner, you'll struggle with later rooms trying to understand concepts they don't explain because they assume Pre Security knowledge.

Time investment: 20-25 hours over 3-4 weeks. ROI: Critical. This path directly enables everything that follows.

What it teaches: The shared language of cybersecurity. After Pre Security, you understand what a port is, what a packet is, how DNS resolution works, the difference between HTTP and HTTPS. This is the foundation.

2. Cyber Security 101
Foundational • 10-12 rooms • 25-30 hours • Difficulty: Easy-Medium
ESSENTIAL SECOND

Cyber Security 101 bridges foundational knowledge and actual security practices. It covers: incident response fundamentals, threat analysis, defensive security principles, and how security teams actually work. This is where you start thinking like a defender rather than a network administrator.

Why second: Pre Security teaches you how computers work. Cyber Security 101 teaches you how to defend computers and respond when they're attacked. The sequence matters because you need to understand the "what" before you can understand the "how to protect it."

Time investment: 25-30 hours over 4-5 weeks. ROI: Critical. This path directly supports SOC and incident response careers.

What it teaches: The incident response process, threat analysis frameworks, defensive security strategies. After this path, you understand why certain logs are monitored and how alerts translate to actual security decisions.

3. Web Fundamentals
Foundational-Intermediate • 12-15 rooms • 30-35 hours • Difficulty: Medium
ESSENTIAL THIRD

Web Fundamentals covers web application architecture, common web vulnerabilities (SQL injection, XSS, CSRF), web testing tools, and how to think about application security. This path is the bridge between "I understand networks" and "I can identify application vulnerabilities."

Why third: By this point you understand networks and defensive principles. Web Fundamentals teaches you how those principles apply specifically to web applications — which is where most vulnerabilities actually live in modern systems.

Time investment: 30-35 hours over 5-6 weeks. ROI: Very High. Web security knowledge applies to both offensive (penetration testing) and defensive (SOC, security scanning) work.

What it teaches: The difference between network-layer and application-layer attacks. After this path, you understand why web application firewalls exist, what SQL injection actually does, why developers need secure coding training.

Why These Three Paths First

After Pre Security + Cyber Security 101 + Web Fundamentals, you have 50-70 hours of structured learning covering:

  • Defensive knowledge: How to detect, respond to, and understand attacks
  • Network literacy: Understanding how systems communicate
  • Application security: Where most real vulnerabilities live
  • Incident response process: The actual workflow for responding to security events
  • Threat thinking: How to approach security problems from attacker perspective

These three paths take 3-4 months and establish all knowledge you need for SOC analyst or junior penetration tester roles. If you only have time to do TryHackMe paths and nothing else, these three are the minimum viable knowledge.

📚 Books That Helped Me Learn Faster

TryHackMe gives you hands-on practice, but I found that combining labs with a few great books helped me understand the concepts much faster.


🐧 Linux Basics for Hackers

The best beginner-friendly Linux book for cybersecurity students. It explains the Linux command line, networking, scripting, and Kali Linux in a practical way that perfectly complements the Pre Security learning path.

📖 View on Amazon

🐍 Black Hat Python

Once you finish the basics, this book teaches how Python is used in penetration testing, automation, malware analysis, networking, and offensive security.

📖 View on Amazon

🌐 The Web Application Hacker's Handbook

One of the most recommended books for understanding web application security, Burp Suite workflows, authentication flaws, SQL injection, XSS, and modern penetration testing methodology.

📖 View on Amazon

Disclosure: As an Amazon Associate, I earn from qualifying purchases at no additional cost to you.

Phase 2: Specialisation Paths — Choose Based on Your Target Role

After Phase 1, your career path bifurcates. Choose your specialisation and go deep.

If You're Targeting SOC/Incident Response/Defensive Roles:

SOC Level 1
Intermediate • 15+ rooms • 35-45 hours • Difficulty: Medium
SPECIALISATION - DEFENSIVE

SOC Level 1 is the most directly applicable path for anyone targeting SOC analyst roles. It covers: SIEM concepts, log analysis, alert triage, incident response workflows, and threat intelligence. Each room simulates realistic SOC scenarios where you're analyzing logs, identifying malicious activity, and making alert tuning decisions.

Why take this: This path teaches you the exact workflow you'll do in a SOC analyst role. By the time you finish, you've practiced alert analysis, log investigation, and incident response decision-making dozens of times.

Time investment: 35-45 hours over 6-8 weeks. ROI: Extremely High for SOC roles. This path directly prepared me for my Inhok Technologies internship.

What it teaches: SIEM tool usage patterns, log parsing and analysis, threat hunting methodology, how to escalate alerts appropriately. This is the path that actually teaches SOC work.

If You're Targeting Penetration Testing/Offensive Roles:

Jr Penetration Tester
Intermediate-Advanced • 25+ rooms • 50-60 hours • Difficulty: Medium-Hard
SPECIALISATION - OFFENSIVE

Jr Penetration Tester is the offensive counterpart to SOC Level 1. It covers: scanning and enumeration, exploitation techniques, privilege escalation, post-exploitation, and complete attack chains. Rooms progress from "here's a vulnerable service, exploit it" to "here's a network, get from foothold to domain admin."

Why take this: If you want to do penetration testing, this path systematically teaches you every step of a real penetration test. You practice actual attack techniques against intentionally vulnerable systems.

Time investment: 50-60 hours over 8-10 weeks. ROI: Extremely High for penetration testing roles. This path directly prepares you for OSCP-level thinking.

What it teaches: Complete attack chains. How to chain individual vulnerabilities into a full exploitation path. Why privilege escalation is critical. Post-exploitation and maintaining access.

The Fork in the Road

After Phase 1, you choose: SOC Level 1 (defensive) or Jr Penetration Tester (offensive). Both are valuable. Both teach skills you need. But they require different time investments and lead to different career paths.

You don't have to pick one forever. But if you're picking one first, I recommend picking based on your immediate job target. If you're applying for SOC positions, do SOC Level 1. If you're targeting penetration testing, do Jr Penetration Tester. You can do both, but not in your first 6 months unless you're dedicating 15+ hours per week.

Phase 3: Advanced/Specialised Paths

After Phase 1 + one Phase 2 path, you have solid foundation knowledge. Phase 3 paths go deep into specific domains.

Complete Beginner to Pentester
Comprehensive • 40+ rooms • 80+ hours • Difficulty: Medium-Hard

This is a mega-path that combines penetration testing content from beginner to intermediate level. If you want comprehensive offensive security training, this consolidates a lot of it. However, it overlaps significantly with Jr Penetration Tester.

Honest take: If you've already done Jr Penetration Tester, Complete Beginner to Pentester has diminishing returns. If you're starting from zero and want one comprehensive path, this might be better than doing three separate paths.

Offensive Security Learning Paths
Multiple specialised paths • Variable • Difficulty: Variable

TryHackMe has paths focused on specific tools and techniques: Burp Suite, Nmap, Metasploit, Active Directory attacks, etc. These are valuable for depth but assume you've already done foundational paths.

When to take: After Phase 1 + Phase 2. Use these for practicing specific tools or filling specific knowledge gaps, not as primary learning.

The Timeline: How I Actually Progressed

Months 1-2: Pre Security + Cyber Security 101
25-30 hours per month. Build foundational knowledge. Lots of repetition. Feels slow but critically necessary. After this, you understand networks and basic security principles.
Months 3-4: Web Fundamentals + Early SOC Level 1
30-35 hours per month. Start specialising. Realise web vulnerabilities and how they apply to real applications. Begin understanding SIEM concepts.
Months 5-6: SOC Level 1 Completion + Supporting Paths
35-40 hours per month. Finish SOC Level 1. Start taking tool-specific paths (Splunk, Wazuh) to deepen knowledge. Begin internship at Inhok Technologies.
Months 7-8: Jr Penetration Tester + Depth Specialisation
30-35 hours per month. Explore offensive side. Realise deep understanding of web security and network security. Maintain offensive/defensive balance.
Months 9+: Selective Deep Dives
20-25 hours per month. Stop chasing completion. Focus on specific topics you're weak in. Practice rooms instead of learning new paths. Focus shifts to real job interview prep.

Total from zero to 170+ rooms: about 9 months at 30-40 hours per month, alongside university and internship work.

Common Mistakes I Made (Learn From Them)

Mistake 1: Skipping Pre Security Because I Thought I Knew Networking

I tried to start with Web Fundamentals because Pre Security looked "too basic." I got stuck understanding concepts that the rooms assumed I knew. I went back and did Pre Security. Problem solved. Lesson: Do the foundational paths even if they feel repetitive. Especially if you didn't learn those topics formally.

Mistake 2: Doing Random Rooms Without Following Paths

Around month 3, I started picking interesting-sounding rooms without following a structured path. I did penetration testing rooms before finishing Web Fundamentals. I did Active Directory rooms without understanding Windows administration. This wasted time and created knowledge gaps. Lesson: Follow the paths sequentially. The sequencing is thought-out.

Mistake 3: Treating Rooms as Pass/Fail Instead of Learning Opportunities

Early on, I'd rush through a room, get the flag, move on. After month 4, I realised rooms are teaching tools. I started spending time on rooms even after getting flags — understanding why the vulnerability exists, what the mitigation is, how it would appear in logs. Rooms became 2-3x more valuable. Lesson: Slow down. Understand concepts, not just exploit steps.

Mistake 4: Not Keeping Notes While Doing Rooms

I did 40+ rooms before I started keeping a structured learning journal. By that point, I'd forgotten half the lessons from early rooms. When I started documenting: "What did I learn? What tools did I use? What concept did this teach?" — retention improved dramatically. Lesson: Document as you learn. Future you will be grateful.

Mistake 5: Assuming I Was "Done" After Completing Paths

After SOC Level 1, I thought I'd learned everything needed for a SOC analyst role. I was wrong. I then had to do separate SIEM training on Splunk and Wazuh specifics. I then had to practice threat hunting. Lesson: Learning paths teach concepts, not tool mastery. You need supporting learning beyond just paths.

Beyond TryHackMe: What You Still Need

Important: TryHackMe paths are not sufficient by themselves for most cybersecurity jobs. They teach concepts and provide hands-on practice. But they don't teach:
  • Specific SIEM tools (Splunk, Wazuh) at professional depth
  • Real-world incident response procedures for specific companies
  • How to write detection rules that actually catch threats
  • Programming beyond Python basics
  • Professional communication and report writing

TryHackMe got me 60% of the way to a SOC analyst role. The other 40% came from: Inhok Technologies internship, hands-on SIEM training (Splunk and Wazuh), writing detection rules in practice, reading actual incident response reports, and doing bug bounty hunting to apply offensive knowledge to real systems.

The Optimal Learning Path Summary

The Minimum Path (3-4 months)

  • Pre Security (20-25 hrs)
  • Cyber Security 101 (25-30 hrs)
  • Web Fundamentals (30-35 hrs)

Total: 75-90 hours over 3-4 months

After this, you have foundational knowledge. You're not ready for a job, but you understand cybersecurity enough to pursue internships or continue learning more advanced topics.

The SOC Specialist Path (5-6 months)

  • Pre Security (20-25 hrs)
  • Cyber Security 101 (25-30 hrs)
  • Web Fundamentals (30-35 hrs)
  • SOC Level 1 (35-45 hrs)

Total: 110-135 hours over 5-6 months

After this path + supporting SIEM training (Splunk, Wazuh), you're competitive for SOC L1 positions. This is the path I followed.

The Penetration Tester Path (5-7 months)

  • Pre Security (20-25 hrs)
  • Cyber Security 101 (25-30 hrs)
  • Web Fundamentals (30-35 hrs)
  • Jr Penetration Tester (50-60 hrs)

Total: 125-150 hours over 5-7 months

After this path, you understand penetration testing methodology. You're not ready for OSCP yet, but you have solid foundation for exploit development and real penetration testing work.

TryHackMe Learning Paths — FAQs

How many hours per week do I need to dedicate to TryHackMe to progress reasonably?
Realistically: 10-15 hours per week if you want to progress through Phase 1 + Phase 2 in 5-6 months. That breaks down to 2-3 hours most weekdays and more on weekends. If you can only do 5-7 hours per week, extend the timeline to 8-10 months but don't rush — understanding matters more than speed. If you can do 20+ hours per week (full-time study), you can complete Phase 1 + Phase 2 in 2.5-3 months, but burnout is real at that pace.
Can I skip Pre Security because I already know Linux?
Probably not. Even if you know Linux command line, Pre Security teaches cybersecurity-specific networking concepts that later rooms assume. You might save 5-10 hours by skipping it, but you'll waste 10+ hours later when rooms reference Pre Security concepts without explaining them. Do Pre Security. It's foundational.
Should I do SOC Level 1 or Jr Penetration Tester first?
Depends entirely on your job target. If you're applying for SOC analyst positions, do SOC Level 1. If you're targeting penetration testing, do Jr Penetration Tester. Both teach valuable skills, but the sequencing should match your immediate career goal. You can do both eventually, but in your first 6 months, pick one specialization and go deep.
I'm on my 50th room and feeling burned out. What should I do?
First: that's normal. Learning pace at 50 rooms is typically month 2-3, which is when foundational learning is most repetitive. Options: (1) take a 1-2 week break, (2) switch to rooms that feel more interesting/advanced to regain motivation, (3) shift focus to supplementary learning (bug bounty, real labs, projects) to get practical variety. Don't quit. Burnout is real, but it passes.
Is Top 2% ranking really achievable, and does it matter for jobs?
Top 2% is achievable with consistent work over 6-9 months. To hit it, you need 150+ rooms completed plus some badges/certificates. Does it matter for jobs? Moderately. Recruiters notice it. It's a conversation starter. But it's not the deciding factor — internship experience and demonstrated project work matter significantly more. Use the ranking as motivation, not the primary goal.
Should I join TryHackMe's subscription or is free enough?
Free TryHackMe is enough for Phase 1 (foundational paths are completely free). For Phase 2, most of SOC Level 1 and Jr Penetration Tester are free, but subscription gives access to specific rooms and faster server access. If you're serious (targeting actual jobs), subscription ($30-40/month) is worth it for 6 months. If you're just exploring, free tier is sufficient for your first month to decide if you want to continue.

About the Author

Amardeep Maroli

MCA (Master of Computer Applications) — PES University, Bengaluru
TryHackMe — Top 2% Globally | 170+ Rooms | Jr Penetration Tester Certified
Cybersecurity Intern — Inhok Technologies (SOC/SIEM experience)
Bug Bounty Hunter — HackerOne with validated findings

Learning path strategy: foundation first, specialization second, depth third. Currently targeting SOC L1 roles at MSSPs.

Tags: TryHackMe learning path, TryHackMe roadmap, cybersecurity learning sequence, best TryHackMe paths, SOC level 1, jr penetration tester, TryHackMe for beginners, ethical hacking learning path

What's your current room count, and are you following a structured path or doing random rooms? The comments usually reveal whether the sequencing I recommend matches others' experiences — let me know what worked for you.

Post a Comment

0 Comments