TryHackMe or Hack The Box what to choose: 3 months plan

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
548
Reaction score
952
Deposit
0$
Why compare TryHackMe and Hack The Box


Virtual security laboratories are dozens: VulnHub, PentesterLab, PortSwigger Academy, OverTheWire. But TryHackMe and Hack The Box are the only two CTF platforms for beginners that cover the entire path of the pentester from “what is a terminal” to the preparation for OSCP. THM provides structured ethical hacking training from scratch, HTB is a realistic environment with vulnerable machines to practice. Read more in our article on cybersecurity training.





The rest close the individual niches. PortSwigger is only a web vulnerability. VulnHub is an offline machine without support and upgrades (and some of them are so ancient that exploits are no longer collected on modern cores). OverTheWire – wargames without reference to real pentest scenarios. Choosing between TryHackMe vs Hack The Box is choosing a learning strategy rather than a set of features. That is why the comparison of these two platforms closes the main question: how to start learning a pentest and not lose motivation.






Platform philosophy: training vs test



TryHackMe is a step-by-step mentor


TryHackMe is built on the principle of progressive difficulty. Content is organized into “rooms” – self-sufficient modules: theory, step-by-step tasks, questions for verification. Rooms are grouped in Learning Paths – tracks for specific roles (Junior Pentester, SOC Analyst, Red Teamer). Only 9+ tracks, all included in a single subscription.





The typical room takes 1-2 hours. First introductory – why you need equipment. Then the theory with examples. Then the tasks with the tips. At the end, a challenge without support. For the person who opened the terminal yesterday, it works: progress is felt every day.





The opposite is that the clues become a crutch. According to HackerDNA, “some learners complete hundreds of rooms until once upon once by a machine without instructions.” In my CTF-club watched this more than once: a person passed 80 rooms on THM, but could not independently solve the Easy machine on HTB. I got used to the format "read, repeat" - and here is silence and naked IP.






Hack The Box – real pentest without hints


HTB throws on Wednesday, as close as possible to the work of the pentester. You get the IP address of the machine, that's all. No instructions, no hints from the platform. This is what the real project looks like: the client gives the scoup, you know further yourself.





The process of working with the HTB machine: exploration (1-3 hours), exploitation studies (2-4 hours), attempts to operate (3-6 hours), receiving flags. Easy machine on HTB - 4-8 hours for a beginner with a base. Without a base – endless frustration and a closed laptop.





HTB launched the Academy, a platform with structured modules similar to THM. But the core stays in the cars. Academy and Labs are two separate products, and this is critical when planning a budget.

What platform to choose for hacking: solution algorithm


Instead of abstract advice, three questions. Answer honestly.





Question 1: Do you work confidently in the Linux terminal? You know ls, cd, cat, grep, you can read the man page and understand the team's arguments. If not, start with TryHackMe (Pre Security Path). If yes, question 2.





Question 2: Do you understand the basic network protocols? TCP/IP, HTTP, DNS, the difference between ports 80 and 443, why ARP is needed. If not, TryHackMe (Complete Beginner Path). If yes, question 3.





Question 3: Have you launched nmap at least once and understand its conclusion? If not, TryHackMe, modules on tools. If yes, you can start with HTB Starting Point (guided machines) in parallel with THM.





In practice, 90% of newcomers who come to me answer no to the first question. For them, TryHackMe is the only reasonable start to the practice of hacking for beginners.






Pentest training plan for 3 months


This plan is designed for 8-10 hours a week. More time, speed up. Less – stretch, but do not miss the stages. Each week is tied to specific rooms, techniques and results.






Month 1: Foundation on TryHackMe (weeks 1-4)


Week 1: Linux and Terminal. Rooms: Linux Fundamentals Part 1, Part 2, Part 3. Objective: to confidently navigate the file system, work with rights, understand pipe and redirect output. At the outlet, you should write a simple bash script that searches for files by mask. If three rooms are given in 2-3 days, you are no longer at zero, in parallel, take Network Fundamentals.





Week 2 – Networks and Protocols. Rooms: Networks, Intro to Networking. Objective: to understand the OSI model on a practical level, to know the key ports (22, 80, 443, 445, 3389), to be able to read the conclusion nmap. After these rooms, run a scan of your home network:



nmap -sV -sC -oN scan_results.txt 192.168.1.0/24





Flag -sV determines the service versions, -sC triggers standard scripts, -oN saves the result to the file. Solve every open port is the first intelligence skill without which no car is solved.





Week 3 – First encounter with attacks. Intro to Offensive Security, Web Fundamentals. This is the first time you will try to find a vulnerability and exploit it. In terms of MITRE ATT&CK, it is a Exploit Public-Facing Application (T1190, Initial Access) – a technique that begins most real invasions. According to the Mandiant M-Trends 2025, exploitation of vulnerabilities (exploits) remains the most popular primary access vector — 38% of incidents for 2024. Not “one of the threats” but specifically the first place.





Week 4 – Pentester Tools. Rooms: Metasploit Introduction, Nmap (extended room), Burp Suite Basics. By the end of the week you should be able to: start msfconsole, find the module for a specific exploit, set up payload, get shell. In parallel, get acquainted with Brute Force (T1110, Credential Access) – a basic technique that is often found on HTB Easy machines. The Valid Accounts (T1078) technique – the use of stolen or legitimate credentials – is worked out later, through Hydra/CrackMapExec and in the context of AD attacks (week 11).





The result of the month is 1: confident work in Linux, understanding of network basics, mastering basic tools (nmap, Metasploit, Burp Suite). TryHackMe has 25-30 rooms.






Month 2: transition to self-practice (weeks 5-8)


Here begins the main fracture: from guided learning to solving problems without step-by-step instructions. You stay on THM, but add HTB Starting Point.





Week 5 – Web vulnerabilities on THM. Rooms from Web Fundamentals Path: SQL Injection, XSS, Command Injection. Each of these vulnerabilities is Injection (A03:2021 on OWASP Top 10). On THM will give a step-by-step walkthrough. Critical: After deciding each room, close the walkthrough and try repeating the attack from memory. If you can't reproduce without clues, you don't understand, but copied. Write each team in notes – in a month they will become your directory.





Week 6 – HTB Starting Point. Register for Hack The Box and start Starting Point — a series of guided machines to transition from the THM level. These are not full-fledged Easy machines: there are questions-hints, but there are no step-by-step instructions. Recommended order: Meow (ping, telnet), Fawn (FTP, anonymous access), Dancing (SMB, listing balls), Redeemer (Redis, working with non-standard services).





Week 7 – Privilege Escalation. THM Rooms: Linux PrivEsc, Windows PrivEsc. This is the Abuse Elevation Control Mechanism (T1548) by MITRE ATT&CK – for example, the abuse of SUID bits on Linux. At this stage, it becomes clear: getting shell is half the case. The second half is to raise the privileges to root/SYSTEM. And here this second half usually takes more time than the first.



find / -perm -4000 -type f 2>/dev/null





This command searches for files with a SUID-bit installed – a classic privilege-raising vector on Linux. GTFOBins (gtfobins.github.io) describes how to abuse standard binary like find, less, make to obtain a privileged shell. Bookmark GTFOBins - you will go back there constantly.





Week 8 – First self-driving machines. Continue HTB Starting Point (Tier 1 and Tier 2). In parallel to THM, go to Ice or Alfred room – they are closer to the HTB format. By the end of the week, try to solve one car from Starting Point without prompts at all: only nmap and your notes.





The result of the month is 2: understanding the full cycle of attack (exploration, operation, increasing privileges), basic skills in dealing with web vulnerabilities, first experience in solving machines without instructions. Count: 40-50 rooms THM + 8-10 Starting Point machines.






Month 3: HTB machines and first pentest report (weeks 9-12)


Week 9 – First Easy-to-Easter HTB. Choose one of the classic retired Easy machines: Lame (Linux, SMB), Blue (Windows, MS17-010/EternalBlue), Jerry (Tomcat, default credentials). Retired machines are available with VIP+ subscription ($25/month), but they have official writeups. Algorithm: Try 3-4 hours yourself. Stuck — read writeup, but do not copy the commands, but understand the logic of the solution. Copipasta writeup is not learning, it is self-deception.





Week 10 – Two cars in a week. The goal is to get pace. Try Netmon (PRTG) and Bashed (web shell + privesc). For each machine, keep notes in the format of a mini-report: scan results, detected services, used exploit, method of increasing privileges. This skill will be useful for preparing for OSCP, and for real work pentester.





Week 11 – Active Directory (introductory). Return to THM: Active Directory Basics and Attacking Kerberos rooms. AD environments are the basis of corporate networks. Most real pentests include domain attacks. At this stage, only theory and basic techniques. These are SMB/Windows Admin Shares (T1021.002, Lateral Movement) and PowerShell (T1059.001, Execution) in action: after receiving the first foothold, you move around the network by collecting credentials. AD is a separate world, and in one week it cannot be mastered. But laying the foundation is quite.





Week 12 – Fixing. Solve 2 more HTB Easy machines yourself, without writeups. Stuck for more than 6 hours - let's say one hint from the forum. Review the notes for 3 months, highlight weaknesses. It is usually privilege on Windows or web vulnerabilities more difficult than SQL Injection.





The result of the month is 3: 5-7 solved Easy machines on HTB, understanding the full loop of the pentest, structured notes for each machine. Total in 12 weeks: 55-65 rooms THM + 15-20 HTB (Starting Point + Easy) machines.
 
Top Bottom