A structured collection of personal notes, commands, methodologies, and key takeaways from the TryHackMe Junior Penetration Tester learning path.
The purpose of this repository is to document my learning journey, reinforce cybersecurity concepts through note-taking, and maintain a searchable reference for future study and practical lab work.
Note: These notes are intended for educational purposes and authorized security testing only.
The Junior Penetration Tester path provides foundational knowledge in offensive security, web application security, network reconnaissance, vulnerability research, exploitation frameworks, and privilege escalation.
| Category | Details |
|---|---|
| Platform | TryHackMe |
| Path | Junior Penetration Tester |
| Modules | 8 |
| Rooms | 39 |
thm_jrPenTester
│
├── 1. Intro to CySec
│ ├── OffSec Intro
│ ├── DefSec Intro
│ └── Careers in Cyber
│
├── 2. Intro to Pentesting
│ ├── Pentesting Fundamentals
│ └── Principles of Security
│
├── 3. Intro to Web Hacking
│ ├── Content Discovery
│ ├── Walking An Application
│ ├── Subdomain Enumeration
│ ├── Authentication Bypass
│ ├── IDOR
│ ├── File Inclusion
│ ├── Intro to SSRF
│ ├── Intro to XSS
│ ├── Race Conditions
│ ├── Command Injection
│ └── SQL Injection
│
├── 4. Burp Suite
│ ├── Burp Suite- The Basics
│ ├── Burp Suite- Repeater
│ ├── Burp Suite- Intruder
│ ├── Burp Suite- Other Modules
│ └── Burp Suite- Extensions
│
├── 5. Network Security
│ ├── Passive Reconnaissance
│ ├── Active Reconnaissance
│ ├── Nmap Live Host Discovery
│ ├── Nmap Basic Port Scans
│ ├── Nmap Advanced Port Scans
│ ├── Nmap Post Port Scans
│ ├── Protocols and Servers
│ ├── Protocols and Servers 2
│ └── Net Sec Challenge
│
├── 6. Vulnerability Research
│ ├── Vulnerabilities 101
│ ├── Exploit Vulnerabilities
│ └── Vulnerability Capstone
│
├── 7. Metasploit
│ ├── Metasploit- Introduction
│ ├── Metasploit- Exploitation
│ └── Metasploit- Meterpreter
│
├── 8. Privilege Escalation
│ ├── What the Shell?
│ ├── Linux Privilege Escalation
│ └── Windows Privilege Escalation
│
└── README
Introduction to cybersecurity concepts, security domains, career paths, and the distinction between offensive and defensive security.
Fundamental penetration testing concepts, security principles, methodologies, and engagement lifecycles.
Web application enumeration, testing methodologies, and common vulnerabilities including SQL Injection, XSS, SSRF, IDOR, File Inclusion, and Command Injection.
Practical use of Burp Suite for web application testing, request manipulation, fuzzing, and traffic analysis.
Network reconnaissance, host discovery, service enumeration, protocol analysis, and Nmap scanning techniques.
Vulnerability identification, assessment, scoring methodologies, exploit research, and practical exploitation workflows.
Use of the Metasploit Framework for scanning, exploitation, payload management, and post-exploitation activities.
Linux and Windows privilege escalation techniques, shell management, enumeration, and post-compromise methodologies.
- Burp Suite
- Nmap
- Metasploit Framework
- Meterpreter
- Searchsploit
- Browser Developer Tools
- Linux Command Line
- Windows Command Line
- Document progress through the Junior Penetration Tester pathway
- Build a structured cybersecurity knowledge base
- Create a quick-reference resource for labs and practice environments
- Reinforce concepts through note-taking and practical application
TryHackMe — Jr Penetration Tester
All information contained in this repository is provided for educational and research purposes only.
The techniques and methodologies documented here should only be used in environments where explicit authorization has been granted, such as personal labs, Capture The Flag (CTF) challenges, and training platforms like TryHackMe.
The author assumes no responsibility for misuse of the information contained within this repository.
@kayShahbaaz (kayn0x)