Pyramid of Pain Tryhackme Walkthrough

The Pyramid of Pain is one of those frameworks that sounds more interesting than it actually is, but it comes in handy when you are trying to explain threat intelligence to people who have never thought about IoCs before. The concept was popularized by David Bianco and it ranks indicators of compromise by how much pain an attacker experiences when you block them. I spent a lot of time in blue team positions where we would obsess over hashes, only to realize too late that the attacker had already rotated them. On TryHackMe, the Pyramid of Pain room walks you through each level methodically. You start at the bottom and work your way up. The room is designed for beginners, so do not expect it to challenge you past the fundamentals. It is still useful if you are studying for Security+ or CompTIA CySA+ and need a structured introduction to IOC hierarchy.

Pyramid Of Pain Tryhackme Walkthrough

When you launch the room, you are greeted with a series of questions tied to different layers of the pyramid. Each layer represents a type of indicator and a corresponding difficulty level for the adversary. Here is what you will encounter. Hash values sit at the very bottom. These are MD5, SHA-1, or SHA-256 checksums of malicious files. They are the easiest indicator to manipulate. A single character change in a file produces a completely different hash. I worked on an incident where we blocked fifty hashes and the attacker came back with a repacked version within forty minutes. It is not a meaningful investment of your time unless you are operating at scale with automated tooling that correlates across multiple feeds. Network artifacts come next. This includes IP addresses, domains, and URLs associated with C2 infrastructure. Blocking these requires more effort from the attacker because they have to provision new servers, register new domains, or rotate DNS records. Still, with cheap VPS hosting and bulletproof providers, this layer is more of a nuisance than a hard barrier. I have seen threat actors use dynamic DNS services that regenerate addresses faster than analysts can update blocklists. That said, network indicators are still worth monitoring because they give you early warning before host-level compromise occurs.

Host artifacts involve file paths, registry keys, scheduled tasks, and other persistence mechanisms left behind on the machine. These require the attacker to modify their implant behavior or adopt different infection vectors. In my experience, this is where things get interesting. When you map out the full set of host artifacts from a sample, you often uncover additional malware that was dropped silently. The TryHackMe room has you examine registry persistence entries and WMI event subscriptions, which is practical because those are real techniques used in the wild. Tooling sits above host artifacts. This refers to the specific malware binaries, exploits, or custom tools the attacker deploys. If you force them to switch tools, they have to reconfigure their entire toolkit chain. Many groups stick with the same droppers and loaders for months because rewriting code is expensive. However, commercial malware-as-a-service platforms have eroded this advantage significantly. Anyone with a credit card can spin up a fresh RAT without writing a line of code. TTPs form the top of the pyramid. Tactics, techniques, and procedures describe how the attacker operates at a behavioral level. This is MITRE ATT&CK territory. Changing your TTPs means rewriting playbooks, retraining operators, and abandoning proven methods. It is the most painful layer for an adversary and the most valuable for defenders to track. The problem is that TTP detection requires context, good logging, and skilled analysts. You cannot simply drop a signature and call it a day.

Get the Full Details

TryHackMe SOC Level 1 - Pyramid Of Pain Walkthrough - InfoSec Pat 2023 - YouTube
TryHackMe SOC Level 1 - Pyramid Of Pain Walkthrough - InfoSec Pat 2023 - YouTube

During the TryHackMe walkthrough, you will answer questions about real-world examples for each layer. There are also hands-on exercises where you extract IOCs from samples and classify them. One thing the room does not emphasize enough is the overlap between layers. A single incident often produces evidence across multiple tiers simultaneously. You should be extracting and correlating all of them rather than picking just one category to focus on. Another practical detail that catches people off guard is that not all hash blocking is useless. If you are dealing with a well-known family of malware using hardcoded staging URLs, blocking the original URL alongside the hash can create a meaningful chokepoint. I once disrupted a worm campaign by pairing a SHA-256 block with a DNS sinkhole on the secondary callback domain. The worm stopped propagating within six hours across three continents. It was not the hash that did the work. It was the combination of indicator types working together. The TryHackMe room also touches on how detection engineering should prioritize the upper layers. That aligns with what I have seen in production environments. Teams that invest in behavioral detection and TTP mapping achieve higher signal-to-noise ratios than teams drowning in hash blocklists. The downside is that building those capabilities takes time, quality data, and people who understand both offensive and defensive tradecraft. If your environment only supports basic EDR logging, you will struggle to detect TTP-level anomalies effectively.

If you are going through the room, take your time with the exercises. The machine access section lets you examine actual artifacts, and that is where the framework stops being abstract. Running strings, checking registry hives, and reviewing scheduled tasks manually will cement what the questions are testing. I found that going beyond the required answers and pulling extra artifacts from the same sample revealed about twice as many indicators as the room suggested. That is normal and worth noting. The TryHackMe pricing model means you need a subscription to access this room. It falls under the Security tracks, so if you already have general access you should be fine. There is no separate download required. Everything runs in-browser through the provided Linux machine. You will use standard forensic and analysis tools like strings, grep, and registry viewers that are pre-installed on the box. One caveat worth mentioning. The Pyramid of Pain is a mental model, not a detection strategy. It does not tell you how to collect, correlate, or act on indicators. It only ranks them. I have seen teams treat it as a checklist and stop thinking after they classified their findings. That approach leaves gaps. Pair it with a solid IOC lifecycle process and you get something functional. Without that discipline, it is just a diagram on a slide deck.

If you want to extend your learning after this room, look into the MITRE ATT&CK framework and its related detection guides. The Pyramid of Pain maps naturally onto ATT&CK's technique hierarchy. Combining both gives you a clearer picture of where to invest detection effort relative to the effort required to disrupt the attacker.

TryHackMe: Pyramid Of Pain Walkthrough (SOC Level 1)
TryHackMe: Pyramid Of Pain Walkthrough (SOC Level 1)