A hand-picked guide to some of the best free rooms on TryHackMe covering networking, web hacking, Active Directory, malware, reverse engineering, forensics, and more. Just log in and start hacking.
Can you actually learn cyber security for free?
Yes. TryHackMe has hundreds free rooms covering the same skills you'd learn in paid bootcamps from network penetration testing, web application security, SOC analysis, malware analysis, digital forensics, Active Directory attacks, and reverse engineering. You practise in a real browser-based lab.
This guide pulls together some of the free rooms worth doing, sorted into 8 core topics. Whether you're breaking into cyber security, prepping for an interview, or filling a specific skill gap, there's a starting point here.
How to use this guide
- Total beginner? Start with Intro to Networking, What Is Networking?, and Beginner Path Intro.
- Want to break into offensive security? Focus on Networking → Web → Active Directory.
- Aiming for a SOC or blue team role? Focus on Windows → Malware → Forensics.
- Just here to learn a specific skill? Jump straight to the topic you need.
Every room below is 100% free, click any link and it opens on TryHackMe.
01. Networking
What you'll learn: How networks actually work, common network services, network security fundamentals, and how attackers exploit them. This is the foundation for every other cyber security discipline you can't hack a system if you don't understand how it talks to the rest of the internet.
Best for: Beginners, aspiring pentesters, network defenders, anyone prepping for CompTIA Network+ or Security+.
- What Is Networking?
- Intro to Networking
- Networking Concepts
- Beginner Path Intro
- Network Traffic Basics
- DNS in Detail
- Layer 2
- OpenVPN
- Network Security Essentials
- Passive Recon
- Active Recon
- Nmap
- Further Nmap
- Network Services
- Network Services 2
- Network Services (Advent of Cyber 2025)
- Hydra
- Guided Pentest: Infrastructure
- Brute It
- Hijack
- Bugged
- Publisher
- Lookup
- ChillHack
- Printer Hacking 101
- Cowboy Hacker
- Brooklyn Nine Nine
- Agent Sudo
- Lianyu
02. Tooling
What you'll learn: The core tools every cyber security professional uses day-to-day Nmap for scanning, Burp Suite for web testing, Metasploit for exploitation, CyberChef for data analysis, and Python for building your own tools. These are the tools that show up on every job description and every real-world engagement.
Best for: Anyone who wants to become fluent in the standard cyber security toolkit. Essential for pentesters, SOC analysts, and CTF players.
- Search Skills
- Python Basics
- Custom Tooling with Python
- CyberChef: The Basics
- OhSINT
- Intro to Cyber Threat Intel
- Further Nmap
- Burp Suite: Repeater
- Metasploit: Introduction
- CTF Collection Vol. 1
- Become a Hacker
03. Active Directory
What you'll learn: How to enumerate, attack, and defend Active Directory the identity system running inside the vast majority of enterprise networks. AD attacks (Kerberoasting, AS-REP roasting, certificate template abuse) are the bread and butter of modern penetration tests and red team engagements.
Best for: Aspiring pentesters, red teamers, SOC analysts monitoring AD environments.
- Introduction to Active Directory Authentication
- AD Basics: Enumeration
- Introduction to Active Directory Breaching
- Attacktive Directory
- VulnNet: Roasted
- AD Certificate Templates
- Post-Exploitation Basics
- Soupedecode 01
- Monitoring Active Directory
04. Windows
What you'll learn: How Windows works under the hood, how to attack Windows systems, and how to defend them. Covers the Windows API, command line, logging, endpoint detection and response (EDR), SIEM fundamentals, and hands-on Windows exploitation rooms.
Best for: SOC analysts, blue teamers, incident responders, and offensive security learners who need Windows tradecraft.
- Operating Systems Introduction
- Windows Command Line
- Windows API
- Vulnerabilities 101
- Defensive Security Intro
- Intro to Endpoint Security
- Introduction to EDRs
- Intro to SIEM
- Windows Logging for SOC
- Pyramid of Pain
- Investigating Windows
- Servidae
- Ice
- Blue
- Blaster
- Blueprint
- Atlas
05. Malware
What you'll learn: What malware is, how it works, how it's classified, and how analysts pick it apart. Covers phishing emails, Android malware, antivirus evasion, common attack techniques, and the fundamentals of malware research.
Best for: Aspiring malware analysts, SOC analysts triaging suspicious files, threat intel researchers, and blue teamers building detection logic.
- History of Malware
- MalMal: Introductory
- Malware Classification
- Common Attacks
- Intro to Antivirus
- Malware Researching
- x86-64 Architecture
- Phishing Emails 1
- Phishing Emails 2
- Parrot Post
- Android Malware Analysis
- HTA & PowerShell (Advent of Cyber 2025)
06. Reverse Engineering
What you'll learn: How to read compiled binaries, understand x86-64 assembly, analyse PE files, and reverse-engineer malware and Android apps. Reverse engineering is one of the highest-paid specialisms in cybersecurity and it starts with the fundamentals in these rooms.
Best for: Malware analysts, exploit developers, vulnerability researchers, and anyone curious about how software really works underneath.
- x86-64 Architecture
- MalMal: Introductory
- Valley PE
- MMA (Malware Analysis)
- Android Malware Analysis
- 0x41haz
- Dear QA
07. Web
What you'll learn: How web applications work, how they get hacked, and how to test them. Covers the full OWASP Top 10 spectrum SQL injection, cross-site scripting (XSS), race conditions, NoSQL injection, authentication flaws plus tools like Burp Suite and ffuf, and how to write a professional pentest report at the end.
Best for: Aspiring web application penetration testers, bug bounty hunters, developers who want to write more secure code, and anyone eyeing an application security role.
- Intro to Web Application Security
- Web Application Basics
- Web Security Essentials
- HTTP in Detail
- Vulnerabilities 101
- Web Hacking Using curl (Advent of Cyber 2025)
- XSS (Advent of Cyber 2025)
- Race Conditions (Advent of Cyber 2025)
- NoSQL Injection Tutorial
- ffuf
- Breaking Crypto the Simple Way
- Detecting Web Attacks
- Writing Pentest Reports
- Guided Pentest: Web
- Juicy Details
- ColddBox: Easy
- Pickle Rick
- Cyborg
- Basic Pentesting
- Tech Supp0rt 1
- Agent Sudo
08. Forensics
What you'll learn: How to investigate a compromised system, recover deleted files, analyse memory dumps, examine mobile devices, and reconstruct what an attacker did. Digital forensics and incident response (DFIR) is one of the fastest-growing areas in cyber security and these rooms cover Windows, Linux, macOS, and mobile.
Best for: Incident responders, SOC analysts, DFIR practitioners, and anyone interested in the investigative side of cybersecurity.
- Intro to Digital Forensics
- Intro to DFIR
- Intro to Logs
- Intro to Endpoint Security
- Intro to Cold System Forensics
- Forensic Imaging
- Memory Analysis Introduction
- Memory Forensics
- Investigating Windows
- Linux Filesystem Analysis
- Linux Incident Surface
- macOS Forensics Basics
- Mobile Acquisition
- Autopsy
- IR Playbooks
- Crack the Hash
- Parrot Post
- h4cked
- c4ptur3th3fl4g
- Critical
- Case B4DM755
Where to go next
Free rooms are the perfect way to build fundamentals, test whether cyber security is right for you, and start earning badges you can put on your CV or LinkedIn. Once you've worked through a topic and you're hungry for more, TryHackMe's structured learning paths guide you from beginner to job-ready in specific roles SOC Analyst, Junior Penetration Tester, Red Teamer, and more.
Every skill starts with a single room. Pick one from the list above and open it now.
Frequently asked questions
Are TryHackMe rooms really free? Yes. There are hundreds of rooms on TryHackMe that are completely free. You just need a free account to spin up the labs. Premium unlocks additional content, faster machines, and full learning paths, but you can learn a huge amount without paying anything.
Do I need cyber security experience to start? No. Rooms like What Is Networking?, Intro to Networking, and Beginner Path Intro are designed for absolute beginners. They walk you through the concepts step by step, with guided tasks and answers checked as you go.
How long does a TryHackMe room take? Most beginner rooms take 30 minutes to 2 hours. CTF-style rooms and harder walkthroughs can take a full afternoon. Rooms save your progress, so you can pick up where you left off.
Which topic should I start with? Networking. Everything in cyber security offensive, defensive, forensics, malware assumes you understand how systems communicate. Once you've got the basics of networking, branch into whichever side interests you most: offensive (Web, Active Directory, Tooling) or defensive (Windows, Malware, Forensics).
What's a CTF? CTF stands for capture the flag. It's a cyber security challenge where you hack into a system to find a hidden "flag" a string of text that proves you solved it. CTFs are how the community trains, competes, and interviews. Many of the rooms above are CTF-style.
Carah Els