TryHackMe Free Tier
Access and status
Cost
Partly free
Part of it is free and part is not. The entry says which part; read that before you plan around it.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A browser-based hands-on security learning platform. The free tier gives limited access to learning paths, access to rooms marked free, and one hour of AttackBox use per day. Paid plans are Premium at about EUR 10.50 per month billed annually and MAX at about EUR 17.99 per month billed annually, which unlock full path access, unlimited AttackBox and certificates.
Who it is for, and when
The free rooms include usable introductory DFIR content — disk and memory triage, log analysis, Volatility and Autopsy walkthroughs — in an environment where you do not have to build a lab first. That removes the main barrier for someone starting out on a personal machine.
What it does not cover
The free tier is deliberately partial: most structured paths, certificates and unlimited lab time are paywalled, and the one-hour daily AttackBox limit makes longer forensic exercises awkward. The platform as a whole is offensive-security weighted, so DFIR content is a minority of it.
Go to the source
Open at tryhackme.com (opens in a new tab)https://tryhackme.com/pricing
Details
- Type
- Free training
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Topics
- free-training, training, ctf, memory-forensics, log-analysis, triage
- Checked at source
Related entries
Antisyphon Pay What You Can Training
Partly freeAntisyphon runs selected courses on a Pay What You Can model, stating that it wants to help people who cannot afford conventional training prices. Courses confirmed on the page at the time of checking are SOC Core Skills in the Age of AI with John Strand (live and on-demand) and the Professionally Evil CISSP Mentorship Program (live, multiple instructors).
A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
13Cubed
Partly freeA YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.
Cellebrite C2C Summit and User Forums
Partly freeCellebrite's customer event programme. Through 2026 the listing is dominated by regional user forums and government forums — Toronto, Halifax, Bern, Seattle, Jakarta, several US district attorney technology days, a London CTF — with the large C2C User Summit itself shown as a 2027 event.