pashki975/thm-claude-kit

A coach for TryHackMe, powered by Claude Code. A consistent methodology (classify → enumerate → foothold → privesc), room-state tracking, ready-made commands, and specialist subagents for CVE research, privesc, and write-ups — all guiding you through each room step by step rather than solving it for you. A hands-on alternative to reading write-ups.

This repository also configures its own agents. See what thm-claude-kit tells them →

2Stars on the repository
31Mods indexed here, across every type
23d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

network-forensics

01

pashki975/thm-claude-kit

Skill Claude Code

Methodology for TryHackMe packet-capture / traffic-analysis rooms. Use when the room hands you a .pcap/.pcapng (or a Wireshark/tshark task), when the goal is to reconstruct what happened on the wire, or when asked "what next" on a capture. Guides the load → overview → follow-the-story → extract flow, distinct from the…

not rated 2 23d ago A 117 tokens original MIT

thm-methodology

02

pashki975/thm-claude-kit

Skill Claude Code

Standard operating procedure for solving a TryHackMe box. Use when starting a new room, when the user asks "what next", or when stuck and needing a methodical next step. Guides the recon → enum → foothold → privesc → loot flow and enforces scope discipline.

not rated 2 23d ago A 63 tokens original MIT

thm-trainer

03

pashki975/thm-claude-kit

Skill Claude Code

The core decision loop for driving any TryHackMe room. Use at the START of every room, whenever the user asks "what next", and whenever progress stalls. Teaches classify -> observe -> hypothesize -> test -> decide, so the approach is chosen from what the room is actually teaching rather than defaulting to…

not rated 2 23d ago A 89 tokens original MIT

pashki975/thm-claude-kit

Skill Claude Code

Standard operating procedure for solving Windows and Active Directory TryHackMe boxes. Use when the target is Windows/domain-joined (SMB/LDAP/Kerberos/WinRM ports open, or the room mentions AD/domain), when asked "what next" on a Windows room, or when a Linux-oriented approach isn't fitting. Guides the recon → AD enum…

not rated 2 23d ago B 89 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: