877 words
4 minutes
CySA+ (CS0-003) Lab

Overview#

This roadmap covers the full CompTIA CySA+ (CS0-003) exam through hands-on TryHackMe labs. Each section is mapped to the exam domain it supports, and the labs inside each section are ordered from foundations to more advanced topics. Every link opens the lab directly.

The roadmap was put together by Netriders Academy, with the labs curated by Ahmed Sultan. Pair it with my CySA+ Study Notes for the theory behind each topic.

Total labs74
PlatformTryHackMe
Sections14
Exam coverageCompTIA CySA+ (CS0-003)

Note: TryHackMe occasionally changes which rooms are free and which require a subscription. If you find a lab that is locked, let me know and I will update the list.

Exam Domains at a Glance#

DomainExam WeightSections in This Roadmap
Domain 1 - Security Operations33%01, 02, 04, 05, 08, 09, 10, 11, 13
Domain 2 - Vulnerability Management30%03, 12
Domain 3 - Incident Response and Management20%06, 07
Domain 4 - Reporting and Communication17%Covered in the theory notes (no dedicated labs)

Section Map#

#SectionExam DomainLabs
01System Internals & WindowsDomain 1 - Security Operations7
02SIEM, Log Analysis & MonitoringDomain 1 - Security Operations10
03Secure Development & AppSecDomain 2 - Vulnerability Management4
04Networking & Traffic AnalysisDomain 1 - Security Operations5
05Security Operations (SOC)Domain 1 - Security Operations9
06Incident ResponseDomain 3 - Incident Response and Management6
07Digital ForensicsDomain 3 - Incident Response and Management10
08Threat HuntingDomain 1 - Security Operations4
09Threat IntelligenceDomain 1 - Security Operations3
10Threat Modeling & Detection EngineeringDomain 1 - Security Operations6
11Malware & Reverse EngineeringDomain 1 - Security Operations1
12Vulnerability ManagementDomain 2 - Vulnerability Management7
13CryptographyDomain 1 - Security Operations1
14Extra LabsSupplementary1

Suggested Learning Path#

  1. Foundations: System Internals & Windows → Networking & Traffic Analysis → SIEM & Log Analysis
  2. Security operations: SOC → Threat Intelligence → Threat Hunting → Threat Modeling & Detection Engineering
  3. Vulnerability management: Vulnerability Management → Secure Development & AppSec
  4. Response and investigation: Incident Response → Digital Forensics → Malware & Reverse Engineering
  5. Wrap-up: Cryptography → Extra Labs

01. System Internals & Windows#

Exam Domain: Domain 1 - Security Operations
Labs: 7

Understand how Windows works under the hood: processes, Sysinternals tools, event logs, PowerShell, and Active Directory basics. This is the baseline knowledge every analyst needs before investigating an endpoint.

#LabPlatform
01Windows InternalsTryHackMe
02SysinternalsTryHackMe
03Windows Event LogsTryHackMe
04Osquery: The BasicsTryHackMe
05Active Directory BasicsTryHackMe
06Windows PowerShellTryHackMe
07Windows Internals (Advanced)TryHackMe

02. SIEM, Log Analysis & Monitoring#

Exam Domain: Domain 1 - Security Operations
Labs: 10

Collecting, searching, and correlating logs. Covers log fundamentals, SIEM concepts, and a full Splunk track from basics to SPL and data manipulation.

#LabPlatform
08Splunk: BasicsTryHackMe
09Splunk 2TryHackMe
10Log FundamentalsTryHackMe
11Introduction to SIEMTryHackMe
12Intro to LogsTryHackMe
13Log OperationsTryHackMe
14Intro to Log AnalysisTryHackMe
15Splunk: Exploring SPLTryHackMe
16Splunk: Setting up a SOC LabTryHackMe
17Splunk: Data ManipulationTryHackMe

03. Secure Development & AppSec#

Exam Domain: Domain 2 - Vulnerability Management
Labs: 4

Finding vulnerabilities in code and dependencies with static analysis (SAST), dynamic analysis (DAST), and software composition analysis.

#LabPlatform
18Dependency ManagementTryHackMe
19SASTTryHackMe
20DAST (ZAP)TryHackMe
21Code AnalysisTryHackMe

04. Networking & Traffic Analysis#

Exam Domain: Domain 1 - Security Operations
Labs: 5

Network visibility and traffic analysis with Wireshark, Tcpdump, and Nmap, plus the role of firewalls and intrusion detection systems.

#LabPlatform
22Wireshark: The BasicsTryHackMe
23NmapTryHackMe
24TcpdumpTryHackMe
25Firewall FundamentalsTryHackMe
26IDS FundamentalsTryHackMe

05. Security Operations (SOC)#

Exam Domain: Domain 1 - Security Operations
Labs: 9

How a SOC operates day to day: search skills, core security principles, tactical detection, threat intelligence for SOC teams, Sigma rules, and SOAR automation.

#LabPlatform
27Search SkillsTryHackMe
28SOC FundamentalsTryHackMe
29Security PrinciplesTryHackMe
30FixitTryHackMe
31SlingshotTryHackMe
32Tactical DetectionTryHackMe
33Threat Intelligence for SOCTryHackMe
34SigmaTryHackMe
35SOARTryHackMe

06. Incident Response#

Exam Domain: Domain 3 - Incident Response and Management
Labs: 6

The full incident response lifecycle, step by step: preparation, identification and scoping, containment, eradication and remediation, and lessons learned.

#LabPlatform
36Incident Response FundamentalsTryHackMe
37PreparationTryHackMe
38Identification and ScopingTryHackMe
39Intel Creation and ContainmentTryHackMe
40Eradication and RemediationTryHackMe
41Lessons LearnedTryHackMe

07. Digital Forensics#

Exam Domain: Domain 3 - Incident Response and Management
Labs: 10

Evidence analysis using memory forensics, disk forensics, and malware triage tooling: CyberChef, CAPA, REMnux, FLARE VM, Volatility, Redline, and Autopsy.

#LabPlatform
42CyberChef: The BasicsTryHackMe
43CAPA: The BasicsTryHackMe
44REMnux: Getting StartedTryHackMe
45FLARE VM: Arsenal of ToolsTryHackMe
46VolatilityTryHackMe
47Investigating WindowsTryHackMe
48Windows Forensics 2TryHackMe
49RedlineTryHackMe
50AutopsyTryHackMe
51Disk Analysis & AutopsyTryHackMe

08. Threat Hunting#

Exam Domain: Domain 1 - Security Operations
Labs: 4

Proactively hunting for adversaries across the attack chain, from the initial foothold through pivoting to the end game.

#LabPlatform
52Introduction to Threat HuntingTryHackMe
53Threat Hunting: FootholdTryHackMe
54Threat Hunting: PivotingTryHackMe
55Threat Hunting: EndgameTryHackMe

09. Threat Intelligence#

Exam Domain: Domain 1 - Security Operations
Labs: 3

Turning raw indicators into actionable intelligence, including investigations of payment collection and typosquatting campaigns and sharing intel with MISP.

#LabPlatform
56Payment CollectorsTryHackMe
57TyposquattersTryHackMe
58MISPTryHackMe

10. Threat Modeling & Detection Engineering#

Exam Domain: Domain 1 - Security Operations
Labs: 6

Modeling threats, emulating adversary behavior with Atomic Red Team, mapping to MITRE ATT&CK, and writing detections with Yara.

#LabPlatform
59Threat ModellingTryHackMe
60Atomic Red TeamTryHackMe
61Atomic Bird Goes Purple #1TryHackMe
62Atomic Bird Goes Purple #2TryHackMe
63MITRETryHackMe
64YaraTryHackMe

11. Malware & Reverse Engineering#

Exam Domain: Domain 1 - Security Operations
Labs: 1

Recognizing the techniques malware authors use to resist analysis.

#LabPlatform
65Anti-Reverse EngineeringTryHackMe

12. Vulnerability Management#

Exam Domain: Domain 2 - Vulnerability Management
Labs: 7

The vulnerability management lifecycle: scanning with Nessus and OpenVAS, understanding and exploiting vulnerabilities, and a capstone that ties it together.

#LabPlatform
66Vulnerability Scanner OverviewTryHackMe
67Vulnerabilities 101TryHackMe
68Exploiting a VulnerabilityTryHackMe
69Vulnerability CapstoneTryHackMe
70NessusTryHackMe
71OpenVASTryHackMe
72Zero LogonTryHackMe

13. Cryptography#

Exam Domain: Domain 1 - Security Operations
Labs: 1

Public key cryptography concepts that underpin PKI, TLS, and certificate-based authentication.

#LabPlatform
73Public Key CryptographyTryHackMe

14. Extra Labs#

Exam Domain: Supplementary
Labs: 1

Additional practice that complements the core roadmap.

#LabPlatform
74TardigradeTryHackMe

Tips for Getting the Most Out of These Labs#

  • Take notes on every lab: the tool, the query or command, and the idea behind it, so you can come back to them later.
  • Avoid walkthroughs until you have genuinely tried on your own.
  • Repeat labs a few days later without looking at the solution. This is what makes the knowledge stick.
  • Map each lab to its exam domain to reinforce your preparation, and focus extra time on Domain 1 and Domain 2, which together make up most of the exam.

These labs are for learning and practice in authorized environments only. Never test any technique on systems you do not own or have explicit permission to test.

CySA+ (CS0-003) Lab
https://bad-glitch.github.io/posts/labs/comptia-securityplus---labs/cysa-plus-labs/
Author
Amr Abdel Hamide
Published at
2026-09-19