TryHackMe
Structured rooms and guided practical exercises suitable for building cybersecurity skills progressively.
Open PlatformβPractice cybersecurity concepts inside controlled environments, vulnerable applications, virtual machines, and dedicated security training platforms.
Use these environments only for systems you own or have explicit permission to test. Never perform security testing against unauthorized systems.
Start with structured online environments before creating your own local cybersecurity lab.
Structured rooms and guided practical exercises suitable for building cybersecurity skills progressively.
Open PlatformβTechnical modules and hands-on environments for developing deeper offensive and defensive security skills.
Open PlatformβInteractive web-security labs covering vulnerabilities and practical web application security testing.
Open PlatformβSecurity challenges designed to strengthen Linux, command-line, and problem-solving fundamentals.
Open PlatformβIntentionally vulnerable virtual machines designed for authorized local security practice.
Open PlatformβOpen security projects and intentionally vulnerable applications for learning application security.
Open PlatformβA local lab gives you complete control over the environment. You can run intentionally vulnerable machines and applications inside isolated virtual networks.
An intentionally vulnerable environment for practicing security assessment techniques in an isolated lab.
A deliberately insecure web application designed for learning and practicing web application security.
A vulnerable web application environment for understanding common web security weaknesses.
An OWASP educational application designed to teach web application security concepts.
A collection of vulnerable machines that can be deployed locally for controlled security practice.
Progress from simple environments to increasingly complex systems as your understanding improves.
Practice Linux, Windows, networking, command-line operations, and basic system administration.
Apply basic security concepts through guided rooms, challenges, and controlled environments.
Build practical understanding of web application security using intentionally vulnerable applications.
Practice authorized reconnaissance, vulnerability assessment, exploitation concepts, and post-exploitation fundamentals.
Explore Windows, Active Directory, identity, authentication, and enterprise security concepts.
Move toward realistic challenges, vulnerable machines, research environments, and specialized security labs.
Choose the environment according to the skill you are currently learning.
Juice Shop β’ DVWA β’ WebGoat β’ PortSwigger
Packet Tracer β’ Wireshark β’ Network Labs
Linux VM β’ OverTheWire β’ Linux Labs
Windows VM β’ AD Lab β’ HTB Academy
Kali Linux β’ Metasploitable β’ Vulnerable VMs
SIEM β’ Logs β’ Detection β’ Incident Response Labs
Practice on your own systems.
Use dedicated vulnerable environments.
Keep testing environments isolated.
Follow the scope of authorized programs.
Do not access unnecessary private data.
Document and report findings responsibly.
Follow the roadmap, choose the appropriate lab, and turn theory into practical cybersecurity skills.