Skip to content

devnewhero1909-ship-it/tryhackme-soc-free-labs

ย 
ย 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

28 Commits
ย 
ย 
ย 
ย 

Repository files navigation

๐Ÿ” Free TryHackMe SOC Labs โ€“ SIEM, Threat Detection, IR & Blue Team Practice

A curated list of free TryHackMe rooms focused entirely on Security Operations Center (SOC) training. Ideal for SOC Analysts (Level 1 & 2), Blue Teamers, and cybersecurity students, these hands-on labs cover core skills like SIEM analysis, incident response, Windows event log monitoring, and threat detection.


๐Ÿš€ Why This List?

Whether you're a beginner or preparing for certifications like:

  • CompTIA CySA+
  • SC-200: Microsoft Security Operations Analyst
  • Blue Team Level 1 (BTL1)
  • Security Blue Team (SBT)
  • SSCP / GCIH

...these labs will help you develop skills in:

โœ… Alert triage
โœ… Incident playbook response
โœ… Threat hunting
โœ… Windows log analysis
โœ… APT detection
โœ… SOC tool familiarity (like ELK, Splunk, Sysmon)


๐Ÿ“š TryHackMe SOC Room List (Free)

๐Ÿ†“ These rooms are 100% free at the time of writing and updated regularly.


Icon Title Subtitle Link
๐Ÿ”ต SOC Role in Blue Team Discover security roles ๐Ÿ”— Visit
๐Ÿ›ก๏ธ Defensive Security Intro Introducing defensive security and related topics, such as Threat Intelligence, SOC, DFIR, Malware Analysis, and SIEM ๐Ÿ”— Visit
๐Ÿ“Š Introduction to SIEM Introduction to SIEM ๐Ÿ”— Visit
๐Ÿ–ฅ๏ธ Introduction to EDR Learn the fundamentals of Endpoint Detection and Response ๐Ÿ”— Visit
๐Ÿ“˜ IR Playbooks IR Playbooks ๐Ÿ”— Visit
๐Ÿ—‚๏ธ File and Hash Threat Intel Threat Intel & File Hashes ๐Ÿ”— Visit
๐Ÿง  Splunk: Exploring SPL Splunk: Exploring SPL ๐Ÿ”— Visit
๐Ÿง  SOC Analyst Basics SOC L1 Alert Reporting ๐Ÿ”— Visit
๐Ÿ•ต๏ธ Threat Hunting Without Logs Logless Hunt ๐Ÿ”— Visit
โš”๏ธ APT Detection (Volt Typhoon) Volt Typhoon ๐Ÿ”— Visit
๐Ÿชต Windows Log Analysis Windows Logging for SOC ๐Ÿ”— Visit
๐Ÿ“‚ Windows Threat Detection Windows Threat Detection 1 ๐Ÿ”— Visit
๐Ÿง Linux Threat Detection 1 Explore how attackers break into Linux systems and how you can detect this in logs ๐Ÿ”— Visit
๐Ÿฏ Initial Access Pot Investigate the first, Linux part of the Honeynet Collapse! ๐Ÿ”— Visit
๐Ÿงพ Intro to Logs Intro to Logs ๐Ÿ”— Visit
๐Ÿ› ๏ธ Splunk 101 Splunk Basics (101) ๐Ÿ”— Visit
๐Ÿงฟ Wazuh Wazuh SIEM Lab ๐Ÿ”— Visit
๐Ÿ“Š ELK 101 Investigating with ELK 101 ๐Ÿ”— Visit
๐Ÿงฎ ELK: Servidae Log Analysis in ELK ๐Ÿ”— Visit
๐Ÿ“ถ Network Traffic Basics Network Traffic Analysis Basics ๐Ÿ”— Visit
โ„๏ธ TShark Network Traffic Analysis ๐Ÿ”— Visit
๐ŸŒ Wireshark Wireshark: The Basics ๐Ÿ”— Visit
๐ŸŒ Event Horizon Wireshark + file analysis ๐Ÿ”— Visit
๐Ÿงพ NetworkMiner NetworkMiner Forensics ๐Ÿ”— Visit
๐Ÿ”’ Network Security Essentials Network security monitoring & protection ๐Ÿ”— Visit
๐Ÿ” Network Discovery Detection Detect network asset discovery activity ๐Ÿ”— Visit
๐ŸชŸ Windows Event Logs Windows Event Analysis ๐Ÿ”— Visit
๐Ÿ‘จโ€๐Ÿ’ป Investigating Windows Event Log Forensics ๐Ÿ”— Visit
๐Ÿ” Investigating Windows 2.0 Windows Log Forensics ๐Ÿ”— Visit
๐Ÿ’ป Osquery Endpoint Detection & Response ๐Ÿ”— Visit
๐Ÿง Linux Server Forensics Linux Log Forensics ๐Ÿ”— Visit
๐Ÿง  Memory Forensics RAM Dump & Analysis ๐Ÿ”— Visit
๐ŸงŠ Volatility Memory Dump Analysis ๐Ÿ”— Visit
๐Ÿ”ฌ YARA Malware Rules & Detection ๐Ÿ”— Visit
๐Ÿง  YARA Advanced Threat Hunting with YARA ๐Ÿ”— Visit
๐Ÿ“‘ SOC Alert Triage SOC L1 Alert Triage ๐Ÿ”— Visit
๐ŸŽฏ First Shift CTF The first SOC shift won't be that challenging, right? ๐Ÿ”— Visit
๐Ÿ“Š MS Sentinel MS Sentinel: Just Looking ๐Ÿ”— Visit
๐Ÿ•ณ๏ธ h4cked PCAP Investigation ๐Ÿ”— Visit
๐Ÿ•ท๏ธ Carnage Traffic Analysis Challenge ๐Ÿ”— Visit
๐Ÿ“Œ CCT2019 PCAP Forensics Competition ๐Ÿ”— Visit
๐Ÿ“ก Overpass 2 - Hacked IR via Log Analysis ๐Ÿ”— Visit
โšก Detecting Web Attacks Explore web attacks and detection methods ๐Ÿ”— Visit
๐Ÿ”Ž Identification & Scoping A look into the second phase of the Incident ๐Ÿ”— Visit
๐Ÿ›ก๏ธ AppSec IR Application Security Incident Response ๐Ÿ”— Visit
๐Ÿ”— Chaining Vulnerabilities Exploit Chain Analysis ๐Ÿ”— Visit
๐Ÿง Linux Logging for SOC Linux Log Analysis for SOC ๐Ÿ”— Visit

๐Ÿ†“ These rooms are 100% free at the time of writing and updated regularly.


๐Ÿ’™ Support the Project

TryHackMe Badge

If you find this project helpful and want to support my work:

Your support helps me keep this project up to date for the Blue Team community ๐Ÿ™


๐Ÿ“Œ How to Use This

  1. Log in to TryHackMe
  2. Click each room link above
  3. Start learning and practicing real-world SOC skills โ€” no subscription required

๐Ÿง  Related Topics / Tags (for SEO)

SOC Training โ€ข Free Cyber Labs โ€ข SIEM โ€ข Incident Response โ€ข SOC Analyst Labs โ€ข TryHackMe Blue Team โ€ข SOC L1 โ€ข Blue Team Labs โ€ข Windows Logging โ€ข Threat Detection


๐Ÿ› ๏ธ Contribute

Found more free SOC-related rooms? Open a pull request and Iโ€™ll update the list.


๐Ÿ“„ License

This repository is licensed under the MIT License.

About

๐Ÿ” Free TryHackMe SOC labs for SIEM, IR, and Blue Team analyst training.

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors