TryHackMe → AYSEC Mapping
Complete free + paid TryHackMe rooms and paths mapped to AYSEC.
TryHackMe — Mapping to AYSEC Modules
A complete mapping of TryHackMe (THM) free + paid rooms and learning paths to AYSEC modules. Use this to direct students to free hands-on practice.
Note: TryHackMe room names and learning-path names are public catalog entries. Always check the latest at https://tryhackme.com — rooms occasionally change names or move between free/paid tiers.
Recommended TryHackMe Learning Paths by AYSEC Track
| AYSEC Track |
THM Path |
| AYSEC-000 (Foundations) |
Pre-Security (free) |
| AYSEC-101 (Pentest) |
Jr Penetration Tester (paid) → Red Teaming path |
| AYSEC-102 (SOC/Blue) |
SOC Level 1 (paid) → SOC Level 2 |
| AYSEC-103 (DFIR) |
SOC Level 2 + DFIR-tagged rooms |
| AYSEC-104 (GRC) |
(THM has limited GRC; supplement with ISACA/ISC2) |
| AYSEC-105 (Cloud) |
Cloud Security path |
| AYSEC-106 (AppSec) |
Web Fundamentals + Burp Suite path |
AYSEC-000 Foundations
Module 01 — Networking Fundamentals
- Network Fundamentals (free)
- Networking Concepts (free)
- Networking Essentials (free)
- Wireshark: The Basics (free)
- Wireshark 101 (free)
Module 02 — Linux for Security
- Linux Fundamentals 1, 2, 3 (free)
- Linux Strength Training (free)
- Bash Scripting (free)
- OverTheWire Bandit (external; free)
Module 03 — Windows for Security
- Windows Fundamentals 1, 2, 3 (free)
- Active Directory Basics (free)
- Windows PowerShell (free)
- Windows Forensics 1, 2
Module 04 — Python for Security
- Python Basics (free)
- Python for Pentesters
- Python for Hackers (free)
- Hashing — Crypto 101 (free)
Module 05 — Security Fundamentals
- Introductory Researching (free)
- Principles of Security (free)
- Common Attacks (free)
- Cyber Kill Chain (free)
- Pyramid of Pain (free)
- Diamond Model (free)
- Unified Kill Chain
AYSEC-101 Penetration Testing
Module 01 — Pentesting Fundamentals & Methodology
- Pentesting Fundamentals (free)
- Principles of Security (free)
- Red Team Engagements (free)
Module 02 — Reconnaissance & OSINT
- Passive Reconnaissance (free)
- Active Reconnaissance (free)
- Google Dorking (free)
- Shodan.io (free)
- OhSINT (free) — practical OSINT
- Sakura (free) — OSINT challenge
Module 03 — Network Scanning & Enumeration
- Nmap (free)
- Nmap: The Basics
- Enumeration
- Vulnerability Capstone (free)
Module 04 — Vulnerability Assessment
- Vulnerabilities 101 (free)
- Nessus
- OpenVAS
- Vulnversity (free)
Module 05–06 — Web Attacks
- Web Fundamentals (free)
- OWASP Top 10 (free)
- Web Application Security path
- Burp Suite: The Basics (free)
- Burp Suite: Repeater, Intruder, Other Modules
- Junior Penetration Tester — Web Hacking modules
- Pickle Rick (free) — beginner web
- Mr Robot CTF — CTF-style
- Bolt (free)
- RootMe (free)
- Skynet (free)
Module 07 — Exploitation Frameworks
- Metasploit: Introduction (free)
- Metasploit: Exploitation
- Metasploit: Meterpreter
- Vulnversity (free)
- Blue (free)
- Ice (free)
Module 08 — Buffer Overflows
- Buffer Overflow Prep (free)
- Brainstorm
- Brainpan 1, 2, 3
- Gatekeeper
- Tomghost
Module 09 — Linux Privesc
- Linux PrivEsc (free)
- Linux PrivEsc Arena
- Common Linux Privesc (free)
- LinEnum
- Sudo Vulnerabilities
Module 10 — Windows Privesc
- Windows PrivEsc (free)
- Windows PrivEsc Arena
- Steel Mountain
- Blaster
- Internal
Module 11–12 — Active Directory
- Attacking Kerberos
- Attacktive Directory (free)
- Post-Exploitation Basics
- Holo
- Hacking Hadoop (advanced)
- Throwback Network
- Wreath Network
- Forest (HTB-style on THM)
Module 13 — Pivoting
- Wreath Network (extensive pivoting)
- Networking Concepts
- Pivoting (free)
Module 14 — C2 / Adversary
- Empire (free)
- MITRE (free)
- Caldera (free)
- Atomic Red Team
Module 15 — Reporting
- Reporting (free)
- Documentation rooms
Module 16 — Capstone
- HackPark (medium)
- Anonymous
- Daily Bugle
- Wreath — full network practice
- OSCP-like rooms (e.g. Devel, Lame, Optimum equivalents)
AYSEC-102 SOC / Blue Team
Module 01 — SOC Mission
- Intro to SOC (free)
- SOC Level 1 Path: Cyber Security 101
- Junior Security Analyst Intro (free)
Module 02 — Logs & Telemetry
- Logging for Accountants
- Endpoint Security Fundamentals
- Splunk: Basics
- Sysmon (free)
- Sysinternals
Module 03 — Splunk SPL
- Splunk: Basics
- Splunk 2
- Splunk 3
- Boss of the SOC v1, v2, v3 (free)
- Investigating with Splunk
- Benign (Splunk-based)
- PS Eclipse (Splunk)
Module 04 — Sentinel KQL
- Microsoft Sentinel
- KQL rooms
Module 05 — Network Traffic
- Wireshark: Packet Operations
- Wireshark: Traffic Analysis
- Tshark
- Snort
- Snort Challenges 1, 2
- Zeek (Bro)
Module 06 — Endpoint EDR
- Sysmon (free)
- Osquery: The Basics
- Velociraptor
- MISP
- Threat Hunting: Pivoting (Sysmon-based)
Module 07 — ATT&CK / Detection Engineering
- MITRE (free)
- Yara (free)
- Sigma
- Cyber Kill Chain
- Pyramid of Pain
Module 08 — Threat Intelligence
- Intro to Cyber Threat Intel (free)
- Threat Intelligence Tools (free)
- MISP
- OpenCTI
- Diamond Model
Module 09 — Phishing
- Phishing Emails 1, 2, 3, 4, 5 (free for some)
- Greenholt Phish
Module 10 — Malware Triage
- Malware Analysis Fundamentals
- Analyzing Malicious Documents
- MalDoc: Static Analysis
- REMnux: Getting Started
Module 11 — IR Process
- Intro to ISAC
- Tardigrade (IR)
- Investigating Windows
- Disk Analysis & Autopsy
- Volatility
Module 12 — Threat Hunting
- Threat Hunting: Foothold
- Threat Hunting: Endgame
- Threat Hunting: Pivoting
Module 13 — Cloud SOC
- AWS Basics
- Cloudy with a Chance of APT
AYSEC-103 DFIR
Module 01 — Forensic Foundations
- Disk Analysis & Autopsy
- Volatility (free)
Module 02 — Windows Filesystem
- Windows Forensics 1, 2
- NTFS
Module 03–04 — Registry / Event Logs
- Windows Forensics 2
- Windows Event Logs (free)
- Investigating Windows
- Investigating Windows 2.0
- Investigating Windows 3.x
Module 05 — Browser/Email
- Investigating with ELK 101
- Email Analysis
Module 07 — Memory Forensics
- Volatility (free)
- Memory Forensics
Module 08 — Malware Triage
- MalwareTech rooms
- Malware Analysis Fundamentals
- Reverse Engineering path
Module 09 — Timeline Analysis
- Timeline Analysis
- Plaso/Log2Timeline rooms
Module 11 — Hybrid Cloud IR
- Office365: Defending
- Investigating Microsoft 365
Module 14 — Capstone
- DFIR: An Introduction (free)
- Crylo
- Disgruntled (DFIR scenario)
AYSEC-104 GRC
THM has minimal direct GRC content. Recommended supplements:
- ISO27001 room
- Compliance & Regulations
- For deeper: ISACA / ISC2 / IAPP courses
AYSEC-105 Cloud Security
- AWS Basics
- Cloudy with a Chance of APT
- AWS S3 Basics (free)
- AWS S3 Buckets
- Acme IT Support (cloud-themed)
AYSEC-106 AppSec / Bug Bounty
Module 02 — Burp Suite
- Burp Suite: The Basics
- Burp Suite: Repeater
- Burp Suite: Intruder
- Burp Suite: Other Modules
- Burp Suite: Extensions
Module 03 — Recon
- Subdomain Enumeration
- Content Discovery
Module 04 — Auth & Session
- Authentication Bypass (free)
- Session Management
Module 05 — Access Control
- IDOR (free)
- Broken Access Control
Module 06 — Injection
- SQL Injection (free)
- NoSQL Injection
- Command Injection
Module 07 — XSS / CSRF
- Cross-site Scripting (free)
- DOM-Based Attacks
- CSRF
Module 08 — SSRF / XXE / Deserialization
Module 09 — SSTI
- Server-Side Template Injection
Module 10 — APIs
Module 13 — Mobile
Module 16 — Capstone
- RootMe
- VulnNet: Web
- VulnNet: Internal
- Bolt
- Skynet
AYSEC-150 IoT/OT
- Industrial Intrusion
- MQTT
- Internet of Things 101
AYSEC-151 AI Security
- Hijack (LLM-themed)
- AI-flagged rooms (sparse on THM; supplement with HackTheBox AI modules)
AYSEC-152 Cryptography
- Crypto 101 (free)
- Hashing — Crypto 101 (free)
- Public Key Cryptography
- Cryptography for Dummies
AYSEC-201 Red Team
- Red Team Path (paid)
- Red Team Fundamentals (free)
- Red Team Recon
- Red Team Engagements
- Red Team Threat Intel
- Red Team OPSEC
- Phishing
- Red Team Tools
- Empire
AYSEC-202 RE & Malware
- Reverse Engineering path
- x86 Architecture
- Reversing ELF
- Windows Reverse Engineering
- Buffer Overflow Prep
- Pwnkit
AYSEC-203 Threat Hunting
- Threat Hunting path
- Threat Hunting: Foothold
- Threat Hunting: Endgame
- Threat Hunting: Pivoting
AYSEC-204 Mobile AppSec
How to Use This Mapping in AYSEC Curriculum
For each AYSEC module, after the "Hands-On" task, link to:
- The TryHackMe room name (mapped above).
- A note: "Free room" or "Paid (THM Premium ~$10/mo annual)."
- Estimated time.
This lets students click straight from your LMS to free / cheap practice.
Updates
Verify the latest catalog at https://tryhackme.com/r/hacktivities. New rooms are added monthly. Some rooms move between free / paid; recheck before publishing your course.