We use cookies to ensure you get the best user experience. For more information see our cookie policy.

TryHackMe logo.
  • Learn

  • AI Upskilling

  • Education

  • Pricing

TryHackMe logo.
Join for FREE
Back to all modules

Custom Tooling

Custom Tooling icon

Build and automate custom tools (including AI-driven) using Python, Burp Suite, and browser automation to exploit and test web applications efficiently.

In real-world engagements, off-the-shelf tools can fall short. This module focuses on developing custom tooling to extend your offensive capabilities. You’ll start with Python to automate requests, manage sessions, and script around protections. Then, you’ll write custom Burp Suite extensions to inspect and manipulate encrypted or obfuscated traffic. Finally, you’ll use browser automation to simulate user actions, bypass client-side controls, and exploit dynamic applications. By the end of this module, you’ll know how to build targeted, reusable tools tailored for complex web application scenarios.

Custom Tooling icon

0%

Custom Tooling Using Python

walkthrough

Creating custom tooling for application testing using Python.

0%

Custom Tooling using Burp

walkthrough

Creating custom tooling for application testing using Burp Plugins.

0%

Tooling via Browser Automation

walkthrough

Creating custom tooling for application testing using Selenium and Playwright.

0%

NoScope: Finding RCE

walkthrough

NoScope found an Alf.io RCE zero-day (CVE-2026-35482). Exploit it manually and watch AI solve it.

0%

CAPTCHApocalypse

challenge

When crypto interferes, automate.

Topic Rewind Recap

Lock in what you learned with a recap. Earn points and keep your streak.

Need to know

Need to know: Cryptographic Failures

Cryptographic Failures

Learn to exploit cryptographic vulnerabilities, including ECB Oracles, Padding Oracles, Insecure Randomness, and Length Extension Attacks.

Need to know: Authentication

Authentication

Master exploiting authentication mechanisms through real-world scenarios, covering enumeration and brute force, session management, OAuth, MFA/2FA and JWT vulnerabilities.

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Hierarchical diagram showing how learning pathways contain modules, which contain individual rooms.

Learning

  • Hands-on labs
  • For Business
  • For Education
  • Competitive Hacking
  • Certifications

Resources

  • About Us
  • Newsroom
  • Blog
  • Glossary
  • Work at TryHackMe
  • Careers in Cyber

Privacy & Legal

  • Privacy Policy
  • Terms of Use
  • AI Terms of Use
  • Acceptable Use Policy
  • Cookie Policy

Get in touch

  • Contact Us
  • Affiliates
  • Student Discount

Shop

  • Swag Shop

We're a gamified, hands-on cyber security training platform that you can access through your browser.

128 City Road, London, United Kingdom, EC1V 2NX

Copyright TryHackMe 2018-2026

ISO27001 Compliant