Back to Transmission Log
TechSecurity

My Advent of Cyber 2025 Journey: Exploring AI, Malware, Phishing, and More

December 10, 2025 3 min read

Every December, the cybersecurity world lights up with one of the best learning events of the year: TryHackMe’s Advent of Cyber. The 2025 edition has been packed with fresh concepts, hands-on exercises, and a surprising amount of AI-focused content. I’m currently on Day 9, and so far, the journey has been both challenging and deeply rewarding.

This post is my recap of the experience up to now, especially for anyone considering joining or catching up. Spoiler: it’s absolutely worth it.

TryHackMe | Advent of Cyber 2025: Free 24-Day Cyber Security Challenge

TryHackMe

Phishing: Crafting and Detecting Malicious Links

The early tasks covered phishing and malicious URLs.
 Instead of just theory, the challenge walks you through:

  • How attackers craft deceptive links

This gave me a stronger awareness of social engineering tactics and the technical tricks behind them.


Detecting Anomalies with Splunk

Next, I explored log analysis and anomaly detection using Splunk.
 The exercises included:

  • Reviewing event logs
  • Building queries to spot suspicious behavior
  • Understanding how SOC analysts track attackers inside a network

This was an eye-opener on how “boring logs” become one of the strongest defensive tools.


Malware Analysis: Seeing How the Bad Stuff Works

Another highlight was the malware analysis section.
 I got hands-on experience with:

  • Investigating malicious files
  • Extracting indicators of compromise
  • Observing the behavior of malware samples

It’s always fascinating to watch how stealthy (or sometimes sloppy) malware authors can be.


AI Security: My Favorite Part So Far

This year includes two rooms dedicated to AI hacking and security, which instantly became the most exciting part of the challenge for me.

1. Using AI for Offensive and Defensive Security

This room shows how to get more out of AI tools by guiding them with effective prompts. It’s practical and shows how AI can support security tasks like analysis, detection, and exploitation.

2. Prompt Injection and AI Function Abuse

This one introduced the world of prompt injection attacks.
 The most thrilling exercise for me was the function listing challenge, where we crafted prompts to make an AI reveal its internal functions. It perfectly demonstrates how vulnerable LLM-based systems can be without strict controls.

These rooms changed how I think about AI — not just as a tool, but also as a target with its own attack surface.

Looking Ahead

With many days still left in Advent of Cyber 2025, I’m expecting even more interesting topics to come. So far, the experience has been consistently engaging and packed with real-world value.

If you’re curious about cybersecurity, want hands-on labs, or simply enjoy learning through challenges, I strongly recommend joining this year’s Advent of Cyber. It’s free, accessible for beginners, and incredibly rewarding for anyone in the field.

Link: TryHackMe | Advent of Cyber 2025: Free 24-Day Cyber Security Challenge
 From: bl4ckf0xk
 #AdventOfCyber2025

Transmission Complete \\
Home
Blog
Portfolio
About
Vault
Contact