TryHackMe - SOC Level 1


Blue Team Introduction

  • Junior Security Analyst Intro
  • SOC Role in Blue Team
  • Humans as Attack Vectors
  • Systems as Attack Vectors

SOC Team Internals

  • SOC L1 Alert Triage
  • SOC L1 Alert Reporting
  • SOC Workbooks and Lookups
  • SOC Metrics and Objectives

Core SOC Solutions

  • Introduction to EDR
  • Introduction to SIEM
  • Splunk: The Basics
  • Elastic Stack: The Basics
  • Introduction to SOAR

Cyber Defense Frameworks

Phishing Analysis

  • Phishing Analysis Fundamentals
  • Phishing Emails in Action
  • Phishing Analysis Tools
  • Phishing Prevention
  • The Greenholt Phish
  • Snapped Phish-ing Line
  • Phishing Unfolded

Network Traffic Analysis

  • Network Traffic Basics
  • Wireshark: The Basics
  • Wireshark: Packet Operations
  • Wireshark: Traffic Analysis
  • NetworkMiner

Network Security Monitoring

  • Network Security Essentials
  • Network Discovery Detection
  • Data Exfiltration Detection
  • Man-in-the-Middle Detection
  • IDS Fundamentals
  • Snort

Web Security Monitoring

  • Web Security Essentials
  • Detecting Web Attacks
  • Detecting Web Shells
  • Detecting Web DDoS

Windows Security Monitoring

  • Windows Logging for SOC
  • Windows Threat Detection 1
  • Windows Threat Detection 2
  • Windows Threat Detection 3

Linux Security Monitoring

  • Linux Logging for SOC
  • Linux Threat Detection 1
  • Linux Threat Detection 2
  • Linux Threat Detection 3

Malware Concepts for SOC

  • Malware Classification
  • Intro to Malware Analysis
  • Living Off the Land Attacks
  • Shadow Trace

Threat Analysis Tools

  • Intro to Cyber Threat Intel
  • File and Hash Threat Intel
  • IP and Domain Threat Intel
  • Invite Only

SIEM Triage for SOC

SOC Level 1 Capstone Challenges