This repository contains my hands-on labs and simulations from TryHackMe SOC Simulator, with a primary focus on Security Operations Center (SOC) activities.
It is designed to showcase practical SOC experience to recruiters and hiring managers.
All scenarios are completed using the TryHackMe SOC Simulator, covering real-world tasks such as alert triage, phishing investigation, and incident response across multiple SIEM platforms.
Although examples may show one SIEM, all labs have been repeated using Splunk, ELK, and Microsoft Sentinel.
It covers topics including:
- Alert triage and investigation
- Phishing analysis
- Log correlation
- Incident response
- False positive validation
- Threat detection
The hands-on experience in this repository is primarily based on TryHackMe SOC simulations, supported by:
- Native TryHackMe SOC Simulator environment
- Realistic enterprise log sources
- Simulated phishing and malware scenarios
- Repeated exercises across different SIEM tools
- SIEM Platforms: Splunk, ELK Stack, Microsoft Sentinel
- SOC Operations: Alert handling, escalation, reporting
- Threat Intelligence: MITRE ATT&CK framework
- Log Sources: Email, firewall, endpoint, authentication
Some logs or screenshots may contain masked or redacted fields (e.g., missing session IDs or anonymized data).
There may also be a lack of screenshots in some areas.
This is required as these labs are part of TryHackMeโs business-exclusive training environments.