SOC Level 1
TryHackMe · Blue team operations
An end-to-end SOC analyst path: ingest the logs, triage the alerts, and write up what happened.
- SIEM fundamentals, log ingestion pipelines, and structured alert triage in Splunk and ELK
- Investigated simulated phishing, malware, brute-force, and lateral movement incidents, with full reports, timelines, and IOCs
- Wireshark traffic analysis for C2 beacons and exfiltration, endpoint forensics, and threat intelligence enrichment
Bill of materials
- U1
- Splunk
- U2
- ELK / Kibana
- U3
- Wireshark
- M1
- MITRE ATT&CK