Hack The Box vs TryHackMe: choosing a lab platform for a team
We compare Hack The Box and TryHackMe: approach, levels, community and plans, and what each one is for when you are training a security team.
Since January 2024 this page had been recommending six specific courses from the Cisco academy, with their hours and their free-of-charge label. That format stopped being honest: the catalogue is Cisco’s, it changes when Cisco wants it to, and we find out late or not at all. So there is no course list here any more. There is what we can actually stand behind: what kind of knowledge those courses give, where that road ends, and how you carry on if what you want is to learn to attack systems, which is what we do.
Cisco Networking Academy is the Cisco training programme and it lives at netacad.com. Its catalogue moves around networking, cybersecurity fundamentals, operating systems and programming. Historically part of that catalogue has been free and self-paced, with no start date and no assigned tutor, and that is the reason this page exists and the reason people arrive here searching.
What you will not find here is how many courses there are, how long each one lasts, or which ones are free today. Cisco publishes that, Cisco changes it when it wants, and any number we wrote would go stale without anyone noticing. Look at it on their site, which is the only source that is always current.
It sounds like a formality and it is not. When we reviewed this page, every one of the direct links that pointed at the six courses it recommended had moved. The courses still existed, but the addresses we published in 2024 were no longer theirs. If that happens to the addresses, imagine what happens to the hours and to the price.
With the criticism out of the way, the good part deserves saying, because it is real and because a well-made introductory course solves a problem that nothing else solves: not knowing where to start.
If you are starting from zero, that is a perfectly reasonable starting point, and it is cheaper and more orderly than working through scattered videos. We sell none of it and we would recommend it anyway.
This is where this article differs from the one that used to be here, and where it is worth staying if your goal is to work in security and not only to know what it is about.
An introductory course teaches you to recognise concepts. Security work consists of producing a result on a system that you were not meant to own and that nobody prepared for you. Between those two things there is a distance that no syllabus covers, and it takes three concrete forms:
None of this is a defect of the Cisco courses in particular. It is what a course is and what a course cannot be.
Offensive security is the half of the trade that consists of attacking your own systems, with written permission and a signed scope, to find what an attacker would find before he finds it. If the term is new to you, the piece that explains it end to end is what penetration testing is, and if what you are looking at is who to hire rather than how to train yourself, that is hiring an ethical hacker.
Inside that half there are exercises that resemble each other very little, and it is worth not confusing them, because they are not learned the same way:
And if the certification route interests you, the ones asked for in this job are OSCP, OSCE³, OSWE, OSEP, CRTO and CRTP. They all share one thing that separates them from a course: the exam is hands-on. You do not pass by having read, you pass by having achieved something inside a system.
If you arrived looking for free courses and you leave with one idea, let it be this one: courses are the first of three steps and the shortest of the three.
The most expensive mistake we see is skipping the second step: people with a lot of courses passed who have never got into anything. The second most expensive is stopping at the second step: people who solve hard labs and freeze the first time a real company is put in front of them, because in a real company you have to explain the risk to somebody who is not technical.
Everything above is aimed at somebody who wants to learn on their own. If the question in front of you is a different one, and it is how to raise the level of a team that already works, quite a lot changes.
We run training for company teams on exactly that second half: on your stack and on the threats that actually apply to you. It does not replace a course or a lab, and we are not saying that out of modesty: to pick up the base, a free course is cheaper and better than we are. What it does not give you is the part that depends on your own house.
This piece originally recommended six specific courses, each one with its length in hours and with the claim that it was free. All of that has been removed. It is data from a catalogue that is not ours and that changes without telling us, and publishing it without being able to review it every month is asserting something about a third party we do not control. When we went to check, the six direct links we gave were no longer the right addresses.
That is why there is only one outbound link here, to the front page of the academy, and no figures. What we can stand behind is the other part: what kind of knowledge those courses give and what is needed afterwards. That does not change when Cisco reorganises its catalogue.
Last reviewed: 3 August 2026. Originally published on 4 January 2024.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Talk to a senior pentesterPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.