🎯 Goal

Today’s goal was to begin exploring basic programming concepts through two introductory TryHackMe rooms:

  • Python Simple Demo
  • JavaScript Simple Demo

The objective was not to become a programmer yet, but to understand how scripting languages work, because in cybersecurity these languages are frequently used for:

  • automation
  • malware
  • detection engineering
  • offensive security tooling
  • security research

Learning the basics now helps me understand what attackers automate and how defenders analyze scripts.


πŸ›  What I Did

Today I completed the following TryHackMe rooms:

  • https://tryhackme.com/room/pythonsimpledemo
  • https://tryhackme.com/room/javascriptsimpledemo

Python Simple Demo

This room introduced the core idea that Python is a scripting language used heavily in cybersecurity because it is:

  • simple
  • readable
  • extremely powerful with libraries
  • widely used in security tooling

Examples of things Python is commonly used for in security include:

  • vulnerability scanners
  • brute-force tools
  • automation scripts
  • malware prototypes
  • log analysis

Some of the basic concepts covered included:

  • printing output
  • simple variables
  • executing small scripts
  • understanding how code runs step by step

Even though the examples were simple, the important realization is that many real offensive security tools are essentially larger versions of scripts like these.


JavaScript Simple Demo

The JavaScript room focused on how JavaScript runs inside the web browser environment.

Unlike Python, JavaScript is deeply connected to:

  • web pages
  • user interaction
  • client-side logic

Important ideas introduced:

  • JavaScript runs inside the browser
  • it can interact with the page (DOM – Document Object Model)
  • it reacts to user actions such as clicks
  • it can modify page content dynamically

This is extremely important in cybersecurity because many web attacks rely on JavaScript behavior.

Examples include:

  • Cross-Site Scripting (XSS)
  • malicious scripts injected into webpages
  • browser-based exploitation

Understanding how JavaScript works helps when investigating web application attacks.


πŸ”— Key Cybersecurity Connections

Although these rooms were beginner-level programming introductions, the concepts connect directly to real cybersecurity work.

Python in security

Python is used in tools such as:

  • Reconnaissance tools
  • Exploit scripts
  • Automation frameworks
  • Log analysis utilities

Many penetration testing tools are built with Python or use Python modules.

Examples include:

  • parts of Metasploit modules
  • many OSINT tools
  • custom red-team scripts

JavaScript in security

JavaScript is central to many web attacks.

For example:

XSS (Cross-Site Scripting) happens when attackers inject malicious JavaScript into a webpage that other users load.

When the victim loads the page:

Browser loads page
↓
Malicious JavaScript executes
↓
Attacker steals cookies or session data

SOC analysts and web security engineers must understand JavaScript behavior to detect these attacks.


πŸ” Investigation Questions

When analyzing suspicious scripts or malicious code behavior, a SOC analyst might investigate questions such as:

  • What script or code was executed on the system?
  • What process launched the script interpreter (Python, JavaScript, PowerShell, etc.)?
  • Did the script perform network connections or downloads?
  • Was the script executed from a user-writable directory?
  • Did the script spawn additional processes or modify system files?
  • Are similar scripts being executed across multiple endpoints?

These questions help determine whether a script is legitimate automation or part of a malicious activity.


🚨 Detection Opportunities

Possible detection strategies involving scripts include:

  • monitoring unusual execution of scripting interpreters such as Python or PowerShell
  • detecting scripts executed from temporary or user-controlled directories
  • identifying suspicious network activity initiated by scripts
  • monitoring browser activity for JavaScript injection behavior
  • detecting abnormal process spawning patterns associated with scripts

Telemetry sources useful for these detections include:

  • endpoint process logs
  • network logs
  • browser telemetry
  • EDR monitoring systems.

🧭 MITRE ATT&CK Techniques

Malicious scripting activity often relates to several MITRE ATT&CK techniques:

  • T1059 – Command and Scripting Interpreter
  • T1059.007 – JavaScript
  • T1059.006 – Python
  • T1059.001 – PowerShell

These techniques describe how attackers use scripting environments to execute malicious code during attacks.


⚠ Challenges

The main challenge today was not the difficulty of the material, but rather understanding how these programming concepts connect to cybersecurity.

The rooms are intentionally simple demonstrations, so the important takeaway is recognizing:

  • where these languages appear in real attacks
  • how attackers automate things with scripts
  • how defenders analyze suspicious code

Another challenge is accepting that programming will likely become a necessary skill over time for security work.


πŸ“š What I Learned

Key lessons from today:

  • Python is one of the most important languages in cybersecurity
  • JavaScript is critical for web security understanding
  • scripting languages allow attackers to automate attacks
  • defenders must understand scripts to analyze malicious behavior

Even basic scripts can evolve into:

  • malware loaders
  • phishing page scripts
  • exploit automation
  • data exfiltration tools

So learning the basics early is important.


➑ Next Steps

Next steps moving forward:

  • continue exploring scripting fundamentals
  • learn how Python is used in security automation
  • understand how malicious JavaScript appears in web attacks
  • continue completing TryHackMe rooms related to programming and security

As my studies progress, I expect scripting to become a tool for:

  • log analysis
  • detection engineering
  • automation in SOC workflows

🧠 Reflection

Today’s rooms were a reminder that cybersecurity is not only about tools and investigations.

A large part of security involves understanding code, because attackers frequently use scripts to automate their operations.

Even though the rooms were introductory, they reinforce an important idea:

To become effective in cybersecurity, it helps to understand the languages attackers use.


🧩 Lessons Learned

What worked

  • Simple TryHackMe demos helped introduce programming concepts without overwhelming complexity.

What broke

  • The rooms are intentionally basic, so the cybersecurity connection is not immediately obvious without thinking about real-world usage.

Why it broke

  • Programming tutorials focus on syntax, but security professionals need to think about how code is used operationally.

Fix / takeaway

  • Continue learning programming concepts while always asking:
    How would an attacker use this?
    How would a defender detect this?

πŸ“ˆ Skill Progression Context

This learning step fits into the broader progression of building a cybersecurity skillset.

So far my journey has included:

  • Linux command line investigation
  • log analysis
  • SOC investigation mindset
  • detection engineering concepts
  • Windows telemetry and Sysmon lab setup

Learning Python and JavaScript now adds another layer:

  • understanding how scripts are written
  • recognizing malicious code patterns
  • eventually writing security automation tools

Over time this will support:

  • detection engineering
  • threat hunting
  • malware analysis
  • red team automation