TryHackMe DFIR rooms

About

Interactive tutorials and investigations with guided tasks (Windows/Linux forensics, log analysis).

The format

  • Learn by doing: Hands-on from minute one.

  • Beginner-friendly: Step-by-step walkthroughs available.

  • Varied scenarios: From dead-box analysis to live triage.

Example room:

“Investigate a compromised web server, find how they got in and what they stole.”

Rooms worked through