Skip to content

Repository files navigation

TryHackMe — Junior Penetration Tester

A structured collection of personal notes, commands, methodologies, and key takeaways from the TryHackMe Junior Penetration Tester learning path.

The purpose of this repository is to document my learning journey, reinforce cybersecurity concepts through note-taking, and maintain a searchable reference for future study and practical lab work.

Note: These notes are intended for educational purposes and authorized security testing only.


About the Path

The Junior Penetration Tester path provides foundational knowledge in offensive security, web application security, network reconnaissance, vulnerability research, exploitation frameworks, and privilege escalation.

Category Details
Platform TryHackMe
Path Junior Penetration Tester
Modules 8
Rooms 39

Repository Structure

thm_jrPenTester
│
├── 1. Intro to CySec
│   ├── OffSec Intro
│   ├── DefSec Intro
│   └── Careers in Cyber
│
├── 2. Intro to Pentesting
│   ├── Pentesting Fundamentals
│   └── Principles of Security
│
├── 3. Intro to Web Hacking
│   ├── Content Discovery
│   ├── Walking An Application
│   ├── Subdomain Enumeration
│   ├── Authentication Bypass
│   ├── IDOR
│   ├── File Inclusion
│   ├── Intro to SSRF
│   ├── Intro to XSS
│   ├── Race Conditions
│   ├── Command Injection
│   └── SQL Injection
│
├── 4. Burp Suite
│   ├── Burp Suite- The Basics
│   ├── Burp Suite- Repeater
│   ├── Burp Suite- Intruder
│   ├── Burp Suite- Other Modules
│   └── Burp Suite- Extensions
│
├── 5. Network Security
│   ├── Passive Reconnaissance
│   ├── Active Reconnaissance
│   ├── Nmap Live Host Discovery
│   ├── Nmap Basic Port Scans
│   ├── Nmap Advanced Port Scans
│   ├── Nmap Post Port Scans
│   ├── Protocols and Servers
│   ├── Protocols and Servers 2
│   └── Net Sec Challenge
│
├── 6. Vulnerability Research
│   ├── Vulnerabilities 101
│   ├── Exploit Vulnerabilities
│   └── Vulnerability Capstone
│
├── 7. Metasploit
│   ├── Metasploit- Introduction
│   ├── Metasploit- Exploitation
│   └── Metasploit- Meterpreter
│
├── 8. Privilege Escalation
│   ├── What the Shell?
│   ├── Linux Privilege Escalation
│   └── Windows Privilege Escalation
│
└── README

Modules

1. Intro to Cyber Security

Introduction to cybersecurity concepts, security domains, career paths, and the distinction between offensive and defensive security.

2. Intro to Pentesting

Fundamental penetration testing concepts, security principles, methodologies, and engagement lifecycles.

3. Intro to Web Hacking

Web application enumeration, testing methodologies, and common vulnerabilities including SQL Injection, XSS, SSRF, IDOR, File Inclusion, and Command Injection.

4. Burp Suite

Practical use of Burp Suite for web application testing, request manipulation, fuzzing, and traffic analysis.

5. Network Security

Network reconnaissance, host discovery, service enumeration, protocol analysis, and Nmap scanning techniques.

6. Vulnerability Research

Vulnerability identification, assessment, scoring methodologies, exploit research, and practical exploitation workflows.

7. Metasploit

Use of the Metasploit Framework for scanning, exploitation, payload management, and post-exploitation activities.

8. Privilege Escalation

Linux and Windows privilege escalation techniques, shell management, enumeration, and post-compromise methodologies.


Tools & Technologies

  • Burp Suite
  • Nmap
  • Metasploit Framework
  • Meterpreter
  • Searchsploit
  • Browser Developer Tools
  • Linux Command Line
  • Windows Command Line

Repository Goals

  • Document progress through the Junior Penetration Tester pathway
  • Build a structured cybersecurity knowledge base
  • Create a quick-reference resource for labs and practice environments
  • Reinforce concepts through note-taking and practical application

Official link

TryHackMe — Jr Penetration Tester


Legal Disclaimer

All information contained in this repository is provided for educational and research purposes only.

The techniques and methodologies documented here should only be used in environments where explicit authorization has been granted, such as personal labs, Capture The Flag (CTF) challenges, and training platforms like TryHackMe.

The author assumes no responsibility for misuse of the information contained within this repository.


Author

@kayShahbaaz (kayn0x)

About

My notes from TryHackMe's Junior Penetration Tester path. Covers web hacking fundamentals like SQL injection, XSS, IDOR and SSRF, plus Burp Suite, network reconnaissance with Nmap, Metasploit, and privilege escalation on Linux and Windows.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors