
TryHackMe — Boogeyman 1
Julianne, a finance employee at Quick Logistics LLC, opens a phishing email disguised as an invoice follow-up. The attachment compromises her workstation. Three artefacts remain: the phishing email...

Julianne, a finance employee at Quick Logistics LLC, opens a phishing email disguised as an invoice follow-up. The attachment compromises her workstation. Three artefacts remain: the phishing email...

sift is a command-line tool for SOC alert triage. It ingests SIEM exports, clusters and prioritizes alerts using rule-based logic, and optionally generates AI-powered narrative summaries with actio...

barb is a command-line tool for heuristic phishing URL analysis. It runs entirely offline, requires no API keys, and delivers structured verdicts directly in the terminal. This post covers how it w...

You are an SOC analyst at Managed Server Provider TrySecureMe. An L1 analyst has flagged two suspicious indicators — an IP address and a SHA256 hash — and escalated them for deeper analysis. The ta...

Where the previous Snort rooms used PCAP files, this one is different: the traffic is live. The task is to write a Snort rule, run it in IPS mode against traffic that’s actively hitting the machine...

Practical follow-up to the Snort Room in the SOC Level 1 path. Instead of reading about concepts, this room is about writing actual rules and testing them against PCAP files. Eight tasks covering d...

A machine has been compromised. The only evidence: a packet capture recorded during the attack. The task splits into two phases — first, reconstruct what the attacker did by analysing the PCAP in W...

vex is a command-line tool for enriching Indicators of Compromise (IOCs) via the VirusTotal API. It automatically detects the IOC type — hash, IP, domain, or URL — and returns structured, actionabl...

A group of self-declared “black hat hackers” left behind a confidential case file. Inside the PDF: a QR code — partially covered by a red triangle overlay. The mission: uncover the original QR code...

A suspicious email has arrived with a strange-looking attachment. The task: uncover the flag hidden inside it. The attachment is a .docm file — a macro-enabled Word document — one of the most commo...