TryHackMe Practice Library
Welcome to the GoHackersCloud Academy TryHackMe Practice Library.
This library provides a curated collection of hands-on cybersecurity practice environments organized around the skills you need to develop.
The objective is not to complete every room.
Instead, use this library to:
- strengthen concepts learned in GoHackersCloud courses
- practise individual cybersecurity skills
- revisit weak technical areas
- prepare for GoHackersCloud Labs
- develop investigation and problem-solving skills
- prepare for technical interviews
- build confidence before moving into independent projects
Choose rooms based on the skill you need to develop—not simply because another room is available.
How to Use This Library
Section titled “How to Use This Library”We recommend following this progression:
Learn → Guided Practice → Skill Practice → Challenge → Lab → Runbook → Project
If you are new to cybersecurity, begin with the 90-Day Cybersecurity Career Plan rather than attempting this entire library sequentially.
Use this page as your long-term practice catalogue.
Practice Library
Section titled “Practice Library”Level 1 — Core Foundations
Section titled “Level 1 — Core Foundations”Build the technical knowledge required across almost every cybersecurity role.
| Practice Area | Rooms | Recommended For |
|---|---|---|
| 01 — Getting Started | 10 | Everyone |
| 02 — Linux Fundamentals | 5 | Everyone |
| 03 — Windows Fundamentals | 3 | Everyone |
| 04 — Cybersecurity Fundamentals | 9 | Everyone |
| 05 — Networking | 7 | Everyone |
| 06 — Scripting | 8 | Security Engineers / Pentesters |
| 07 — Cryptography & Hashing | 5 | Everyone |
Foundation Total: 47 rooms
Level 2 — Security Assessment Skills
Section titled “Level 2 — Security Assessment Skills”Develop the core methodology used during authorized security assessments.
| Practice Area | Rooms | Primary Skill |
|---|---|---|
| 08 — Reconnaissance & OSINT | 10 | Attack Surface Discovery |
| 09 — Security Tooling | 17 | Security Tools |
| 10 — Web Security | 27 | Application Security |
| 11 — Privilege Escalation | 13 | Linux / Windows Security |
| 12 — Windows Security | 7 | Windows Assessment |
| 13 — Active Directory | 5 | Enterprise Identity |
| 14 — Buffer Overflow | 4 | Exploit Development Foundations |
Level 3 — Defensive Security & Investigation
Section titled “Level 3 — Defensive Security & Investigation”Develop evidence analysis, incident investigation and security-analysis skills.
| Practice Area | Rooms | Primary Skill |
|---|---|---|
| 15 — Digital Forensics | 5 | Evidence Analysis |
| 16 — PCAP Analysis | 4 | Network Investigation |
| 17 — Malware Analysis | 7 | Malware Investigation |
| 18 — Reverse Engineering | 11 | Binary Analysis |
These areas are particularly valuable for:
- SOC Analysts
- Security Analysts
- Incident Responders
- Threat Hunters
- Malware Analysts
- DFIR professionals
Level 4 — Specialized Security Practice
Section titled “Level 4 — Specialized Security Practice”Use these rooms after developing the relevant foundations.
| Practice Area | Rooms | Focus |
|---|---|---|
| 19 — Steganography | 6 | Hidden Data Analysis |
| 20 — Android Security | 1 | Mobile Security |
| 21 — Wireless Security | 1 | Wi-Fi Security |
| 22 — Specialized & Miscellaneous | 35 | Emerging / Specialist Topics |
Do not treat specialist topics as prerequisites for entry-level cybersecurity roles.
Choose them based on your career direction.
Level 5 — Cybersecurity Challenges
Section titled “Level 5 — Cybersecurity Challenges”Challenges should test whether you can apply multiple skills without being given every step.
Easy Challenges
Section titled “Easy Challenges”58 rooms
Recommended after completing your core foundations.
Use them to practise:
- reconnaissance
- enumeration
- Linux
- Windows
- web security
- basic privilege escalation
- troubleshooting
Medium Challenges
Section titled “Medium Challenges”73 rooms
Use these after you are comfortable solving easy challenges independently.
Expect greater emphasis on:
- multi-stage investigation
- deeper enumeration
- attack-path reasoning
- application weaknesses
- privilege escalation
- independent research
Hard Challenges
Section titled “Hard Challenges”38 rooms
These should not be treated as beginner learning material.
Use them when you are ready to work through unfamiliar environments with substantially less guidance.
The objective is not speed.
The objective is independent problem solving.
Special Events
Section titled “Special Events”The library also contains:
9 Special Event rooms
These can be useful for:
- revision
- mixed-skill practice
- seasonal challenges
- exploring unfamiliar security topics
Treat these as supplementary practice rather than part of your mandatory learning sequence.
Recommended Career Routes
Section titled “Recommended Career Routes”You do not need to complete all 378 rooms.
Select practice based on your target role.
SOC Analyst Route
Section titled “SOC Analyst Route”Recommended progression:
Foundations → Networking → Windows → Security Fundamentals → Tooling → PCAP Analysis → Forensics → Malware Analysis → Easy Challenges
Prioritize:
- Windows
- networking
- logs
- packet analysis
- SIEM concepts
- malware indicators
- investigation
- incident analysis
Ethical Hacker Route
Section titled “Ethical Hacker Route”Recommended progression:
Foundations → Networking → Reconnaissance → Tooling → Web → Privilege Escalation → Windows → Active Directory → CTFs
Prioritize:
- reconnaissance
- enumeration
- service analysis
- web security
- Linux
- Windows
- privilege escalation
- Active Directory
Web Security Route
Section titled “Web Security Route”Recommended progression:
Networking → Web Fundamentals → Tooling → Web Security → Easy CTF → Medium CTF
Prioritize:
- HTTP
- application mapping
- Burp Suite
- OWASP concepts
- authentication
- access control
- injection
- application-security testing
Active Directory Security Route
Section titled “Active Directory Security Route”Recommended progression:
Windows Fundamentals → Networking → Windows Security → Privilege Escalation → Active Directory → Medium/Hard Challenges
Prioritize:
- Windows administration
- authentication
- permissions
- users and groups
- Kerberos
- enterprise identity
- attack-path thinking
Incident Response / DFIR Route
Section titled “Incident Response / DFIR Route”Recommended progression:
Foundations → Windows → Networking → Forensics → PCAP Analysis → Malware Analysis → Reverse Engineering
Prioritize:
- evidence collection
- Windows investigation
- packet analysis
- memory analysis
- disk analysis
- malware triage
- incident timelines
Recommended Beginner Starting Point
Section titled “Recommended Beginner Starting Point”If you are new to cybersecurity, do not open the CTF section and randomly choose machines.
Start with:
Getting Started
↓
Linux Fundamentals
↓
Windows Fundamentals
↓
Networking
↓
Cybersecurity Fundamentals
↓
Choose Your Career Practice Path
Then follow the relevant specialization.
Practice Difficulty Model
Section titled “Practice Difficulty Model”Use the following Academy model when choosing exercises.
Foundation
Section titled “Foundation”You are learning the technology.
Guided
Section titled “Guided”You understand the technology and follow instructions to practise it.
Applied
Section titled “Applied”You receive an objective and determine some of the steps yourself.
Challenge
Section titled “Challenge”You independently investigate and solve the scenario.
Professional
Section titled “Professional”You can investigate, document, explain and recommend remediation without relying on a walkthrough.
Your objective should be to move gradually from:
Foundation → Guided → Applied → Challenge → Professional
Room Completion Standard
Section titled “Room Completion Standard”Do not mark a room as professionally complete simply because TryHackMe shows:
Completed ✓
For GoHackersCloud Academy, consider it complete when you can answer:
- What did I learn?
- Which technology was involved?
- Which security weakness or defensive concept was demonstrated?
- Which tools did I use?
- Why did I use those tools?
- What evidence did I observe?
- What mistakes did I make?
- What would an attacker see?
- What would a defender see?
- How would I explain this in an interview?
- Could I perform a similar task without the walkthrough?
Practice Record
Section titled “Practice Record”Use this template for important rooms:
Room:
Category:
Difficulty:
Date:
Objective:
Technology:
Security Concept:
Tools Used:
Important Observations:
Evidence:
What I Learned:
Mistakes / Challenges:
Attacker Perspective:
Defender Perspective:
Recommended Mitigation:
Interview Questions:
Can I Repeat This Independently?
[ ] Yes[ ] Needs More PracticeProgress Dashboard
Section titled “Progress Dashboard”Track capability rather than room count alone.
| Practice Domain | Total | Started | Completed | Independent |
|---|---|---|---|---|
| Getting Started | 10 | |||
| Linux Fundamentals | 5 | |||
| Windows Fundamentals | 3 | |||
| Cybersecurity Fundamentals | 9 | |||
| Reconnaissance | 10 | |||
| Scripting | 8 | |||
| Networking | 7 | |||
| Security Tooling | 17 | |||
| Cryptography & Hashing | 5 | |||
| Steganography | 6 | |||
| Web Security | 27 | |||
| Android Security | 1 | |||
| Digital Forensics | 5 | |||
| Wireless Security | 1 | |||
| Reverse Engineering | 11 | |||
| Malware Analysis | 7 | |||
| Privilege Escalation | 13 | |||
| Windows Security | 7 | |||
| Active Directory | 5 | |||
| PCAP Analysis | 4 | |||
| Buffer Overflow | 4 | |||
| Easy Challenges | 58 | |||
| Medium Challenges | 73 | |||
| Hard Challenges | 38 | |||
| Specialized / Miscellaneous | 35 | |||
| Special Events | 9 | |||
| Total | 378 |
The GoHackersCloud Practice Standard
Section titled “The GoHackersCloud Practice Standard”The goal is not:
378 rooms completed.
The goal is:
Skills developed, practised, demonstrated and explained.
Ten carefully studied labs that you can reproduce, investigate and explain professionally can be more valuable than dozens of rooms completed by following walkthroughs.
Use the library to identify the next skill you need, practise it, document it, and then apply it in a larger lab.
Recommended Academy Progression
Section titled “Recommended Academy Progression”Your overall journey should look like:
GoHackersCloud Course
↓
Academy Documentation
↓
90-Day Career Plan
↓
TryHackMe Practice Library
↓
Challenge Tracking
↓
GoHackersCloud Labs
↓
GoHackersCloud Runbooks
↓
Projects
↓
Portfolio & Interview Preparation
“How many rooms have I completed?”
Start asking:
“Which cybersecurity tasks can I now perform independently?”
### I would also change the Academy navigation
The uploaded README currently presents all **378 rooms in one very long page**, grouped into categories such as Linux, Windows, Recon, Tooling, Web, Forensics, Malware Analysis, PrivEsc, AD and CTF difficulty. :contentReference[oaicite:1]{index=1}
For the Academy, I recommend splitting it:
TryHackMe│├── 00 Introduction├── 01 Beginner Cybersecurity Path├── 02 SOC Analyst Practice├── 03 Ethical Hacking Practice├── 04 Web Security Practice├── 05 Active Directory Practice├── 06 Cloud Security Practice│├── 07 90-Day Cybersecurity Career Plan│├── 08 Practice Library│ ├── 01 Foundations│ ├── 02 Linux│ ├── 03 Windows│ ├── 04 Networking│ ├── 05 Reconnaissance│ ├── 06 Security Tooling│ ├── 07 Web Security│ ├── 08 Privilege Escalation│ ├── 09 Active Directory│ ├── 10 Forensics & PCAP│ ├── 11 Malware & Reverse Engineering│ └── 12 Specialized Practice│├── 09 Challenge Arena│ ├── Easy│ ├── Medium│ └── Hard│├── 10 Challenge Tracking└── 11 LabsThis is much more Academy-like than exposing students to a 378-item checklist immediately. The original room names and room links can then live inside each corresponding Practice Library page, so we retain the useful source collection while giving it a proper learning architecture.