🔗 TryHackMe Profile: https://tryhackme.com/p/kanakpbansal
A structured collection of TryHackMe walkthroughs and CTF writeups that I have worked through. notes, methods, and things learned while solving them.
| # | Room Name | Difficulty | Type | Description | Room Type |
|---|---|---|---|---|---|
| 1 | Juicy Details | Easy | Log Analysis | Analyze logs from a breached juice shop environment | Challenge |
| 2 | MD2PDF | Easy | HTML Injection | Exploit HTML injection to access internal admin endpoint | Challenge |
| 3 | Dev Diaries | Easy | OSINT | OSINT-based investigation of subdomains and commits | Challenge |
| 4 | Neighbour | Easy | IDOR | Exploit a direct object reference to access another user's profile and retrieve the flag | Challenge |
| 5 | Corridor | Easy | IDOR | Analyze predictable hashed endpoints and exploit IDOR to access hidden rooms and retrieve the flag | Challenge |
| 6 | Library | Easy | Boot2Root (Privilege Escalation + Enumeration) | Brute-forced SSH with Hydra and escalated to root via Python module hijacking | Challenge |
| 7 | Brute It | Easy | Brute Force+Privilege Escalastion | Perform brute-force attacks, crack credentials, and escalate privileges to gain root access | Guided CTF |
| 8 | Have A Break | Medium | Digital Forensics + OSINT | A digital forensics + OSINT challenge to identify an insider behind a cargo theft | Challenge |
| # | Event Name | Date | Description |
|---|---|---|---|
| 1 | Hacker Holiday 2026 | July–August 2026 | A 14-day cybersecurity event featuring free daily challenges across multiple domains |
## ⚡ Approach
these writeups focus on:
- how i approached the room
- commands and steps that worked
- small takeaways from each challenge
⚠️ Note: This repository does not yet include writeups for all the rooms I have completed. I will be adding more writeups regularly.
Happy Hacking! ✨
