A curated list of free TryHackMe rooms focused entirely on Security Operations Center (SOC) training. Ideal for SOC Analysts (Level 1 & 2), Blue Teamers, and cybersecurity students, these hands-on labs cover core skills like SIEM analysis, incident response, Windows event log monitoring, and threat detection.
Whether you're a beginner or preparing for certifications like:
- CompTIA CySA+
- SC-200: Microsoft Security Operations Analyst
- Blue Team Level 1 (BTL1)
- Security Blue Team (SBT)
- SSCP / GCIH
...these labs will help you develop skills in:
โ
Alert triage
โ
Incident playbook response
โ
Threat hunting
โ
Windows log analysis
โ
APT detection
โ
SOC tool familiarity (like ELK, Splunk, Sysmon)
๐ These rooms are 100% free at the time of writing and updated regularly.
| Icon | Title | Subtitle | Link |
|---|---|---|---|
| ๐ต | SOC Role in Blue Team | Discover security roles | ๐ Visit |
| ๐ก๏ธ | Defensive Security Intro | Introducing defensive security and related topics, such as Threat Intelligence, SOC, DFIR, Malware Analysis, and SIEM | ๐ Visit |
| ๐ | Introduction to SIEM | Introduction to SIEM | ๐ Visit |
| ๐ฅ๏ธ | Introduction to EDR | Learn the fundamentals of Endpoint Detection and Response | ๐ Visit |
| ๐ | IR Playbooks | IR Playbooks | ๐ Visit |
| ๐๏ธ | File and Hash Threat Intel | Threat Intel & File Hashes | ๐ Visit |
| ๐ง | Splunk: Exploring SPL | Splunk: Exploring SPL | ๐ Visit |
| ๐ง | SOC Analyst Basics | SOC L1 Alert Reporting | ๐ Visit |
| ๐ต๏ธ | Threat Hunting Without Logs | Logless Hunt | ๐ Visit |
| โ๏ธ | APT Detection (Volt Typhoon) | Volt Typhoon | ๐ Visit |
| ๐ชต | Windows Log Analysis | Windows Logging for SOC | ๐ Visit |
| ๐ | Windows Threat Detection | Windows Threat Detection 1 | ๐ Visit |
| ๐ง | Linux Threat Detection 1 | Explore how attackers break into Linux systems and how you can detect this in logs | ๐ Visit |
| ๐ฏ | Initial Access Pot | Investigate the first, Linux part of the Honeynet Collapse! | ๐ Visit |
| ๐งพ | Intro to Logs | Intro to Logs | ๐ Visit |
| ๐ ๏ธ | Splunk 101 | Splunk Basics (101) | ๐ Visit |
| ๐งฟ | Wazuh | Wazuh SIEM Lab | ๐ Visit |
| ๐ | ELK 101 | Investigating with ELK 101 | ๐ Visit |
| ๐งฎ | ELK: Servidae | Log Analysis in ELK | ๐ Visit |
| ๐ถ | Network Traffic Basics | Network Traffic Analysis Basics | ๐ Visit |
| โ๏ธ | TShark | Network Traffic Analysis | ๐ Visit |
| ๐ | Wireshark | Wireshark: The Basics | ๐ Visit |
| ๐ | Event Horizon | Wireshark + file analysis | ๐ Visit |
| ๐งพ | NetworkMiner | NetworkMiner Forensics | ๐ Visit |
| ๐ | Network Security Essentials | Network security monitoring & protection | ๐ Visit |
| ๐ | Network Discovery Detection | Detect network asset discovery activity | ๐ Visit |
| ๐ช | Windows Event Logs | Windows Event Analysis | ๐ Visit |
| ๐จโ๐ป | Investigating Windows | Event Log Forensics | ๐ Visit |
| ๐ | Investigating Windows 2.0 | Windows Log Forensics | ๐ Visit |
| ๐ป | Osquery | Endpoint Detection & Response | ๐ Visit |
| ๐ง | Linux Server Forensics | Linux Log Forensics | ๐ Visit |
| ๐ง | Memory Forensics | RAM Dump & Analysis | ๐ Visit |
| ๐ง | Volatility | Memory Dump Analysis | ๐ Visit |
| ๐ฌ | YARA | Malware Rules & Detection | ๐ Visit |
| ๐ง | YARA Advanced | Threat Hunting with YARA | ๐ Visit |
| ๐ | SOC Alert Triage | SOC L1 Alert Triage | ๐ Visit |
| ๐ฏ | First Shift CTF | The first SOC shift won't be that challenging, right? | ๐ Visit |
| ๐ | MS Sentinel | MS Sentinel: Just Looking | ๐ Visit |
| ๐ณ๏ธ | h4cked | PCAP Investigation | ๐ Visit |
| ๐ท๏ธ | Carnage | Traffic Analysis Challenge | ๐ Visit |
| ๐ | CCT2019 | PCAP Forensics Competition | ๐ Visit |
| ๐ก | Overpass 2 - Hacked | IR via Log Analysis | ๐ Visit |
| โก | Detecting Web Attacks | Explore web attacks and detection methods | ๐ Visit |
| ๐ | Identification & Scoping | A look into the second phase of the Incident | ๐ Visit |
| ๐ก๏ธ | AppSec IR | Application Security Incident Response | ๐ Visit |
| ๐ | Chaining Vulnerabilities | Exploit Chain Analysis | ๐ Visit |
| ๐ง | Linux Logging for SOC | Linux Log Analysis for SOC | ๐ Visit |
๐ These rooms are 100% free at the time of writing and updated regularly.
If you find this project helpful and want to support my work:
- โ Buy Me a Coffee
- ๐ธ Donate via PayPal
- โฟ BTC wallet: 0xB8061916BF00F1ca7C4C252533BdEeC18B86bcD3
Your support helps me keep this project up to date for the Blue Team community ๐
- Log in to TryHackMe
- Click each room link above
- Start learning and practicing real-world SOC skills โ no subscription required
SOC TrainingโขFree Cyber LabsโขSIEMโขIncident ResponseโขSOC Analyst LabsโขTryHackMe Blue TeamโขSOC L1โขBlue Team LabsโขWindows LoggingโขThreat Detection
Found more free SOC-related rooms? Open a pull request and Iโll update the list.
This repository is licensed under the MIT License.
