TryHackMe → AYSEC Mapping

Complete free + paid TryHackMe rooms and paths mapped to AYSEC.

TryHackMe — Mapping to AYSEC Modules

A complete mapping of TryHackMe (THM) free + paid rooms and learning paths to AYSEC modules. Use this to direct students to free hands-on practice.

Note: TryHackMe room names and learning-path names are public catalog entries. Always check the latest at https://tryhackme.com — rooms occasionally change names or move between free/paid tiers.


Recommended TryHackMe Learning Paths by AYSEC Track

AYSEC Track THM Path
AYSEC-000 (Foundations) Pre-Security (free)
AYSEC-101 (Pentest) Jr Penetration Tester (paid) → Red Teaming path
AYSEC-102 (SOC/Blue) SOC Level 1 (paid) → SOC Level 2
AYSEC-103 (DFIR) SOC Level 2 + DFIR-tagged rooms
AYSEC-104 (GRC) (THM has limited GRC; supplement with ISACA/ISC2)
AYSEC-105 (Cloud) Cloud Security path
AYSEC-106 (AppSec) Web Fundamentals + Burp Suite path

AYSEC-000 Foundations

Module 01 — Networking Fundamentals

Module 02 — Linux for Security

Module 03 — Windows for Security

Module 04 — Python for Security

Module 05 — Security Fundamentals


AYSEC-101 Penetration Testing

Module 01 — Pentesting Fundamentals & Methodology

Module 02 — Reconnaissance & OSINT

Module 03 — Network Scanning & Enumeration

Module 04 — Vulnerability Assessment

Module 05–06 — Web Attacks

Module 07 — Exploitation Frameworks

Module 08 — Buffer Overflows

Module 09 — Linux Privesc

Module 10 — Windows Privesc

Module 11–12 — Active Directory

Module 13 — Pivoting

Module 14 — C2 / Adversary

Module 15 — Reporting

Module 16 — Capstone


AYSEC-102 SOC / Blue Team

Module 01 — SOC Mission

Module 02 — Logs & Telemetry

Module 03 — Splunk SPL

Module 04 — Sentinel KQL

Module 05 — Network Traffic

Module 06 — Endpoint EDR

Module 07 — ATT&CK / Detection Engineering

Module 08 — Threat Intelligence

Module 09 — Phishing

Module 10 — Malware Triage

Module 11 — IR Process

Module 12 — Threat Hunting

Module 13 — Cloud SOC


AYSEC-103 DFIR

Module 01 — Forensic Foundations

Module 02 — Windows Filesystem

Module 03–04 — Registry / Event Logs

Module 05 — Browser/Email

Module 07 — Memory Forensics

Module 08 — Malware Triage

Module 09 — Timeline Analysis

Module 11 — Hybrid Cloud IR

Module 14 — Capstone


AYSEC-104 GRC

THM has minimal direct GRC content. Recommended supplements:


AYSEC-105 Cloud Security


AYSEC-106 AppSec / Bug Bounty

Module 02 — Burp Suite

Module 03 — Recon

Module 04 — Auth & Session

Module 05 — Access Control

Module 06 — Injection

Module 07 — XSS / CSRF

Module 08 — SSRF / XXE / Deserialization

Module 09 — SSTI

Module 10 — APIs

Module 13 — Mobile

Module 16 — Capstone


AYSEC-150 IoT/OT


AYSEC-151 AI Security


AYSEC-152 Cryptography


AYSEC-201 Red Team


AYSEC-202 RE & Malware


AYSEC-203 Threat Hunting


AYSEC-204 Mobile AppSec


How to Use This Mapping in AYSEC Curriculum

For each AYSEC module, after the "Hands-On" task, link to:

  1. The TryHackMe room name (mapped above).
  2. A note: "Free room" or "Paid (THM Premium ~$10/mo annual)."
  3. Estimated time.

This lets students click straight from your LMS to free / cheap practice.


Updates

Verify the latest catalog at https://tryhackme.com/r/hacktivities. New rooms are added monthly. Some rooms move between free / paid; recheck before publishing your course.