Skip to content

Repository files navigation

TryHackMe Badge

█████╗ ███╗   ██╗██████╗ ██╗   ██╗██╗   ██╗
██╔══██╗████╗  ██║██╔══██╗╚██╗ ██╔╝╚██╗ ██╔╝
███████║██╔██╗ ██║██║  ██║ ╚████╔╝  ╚████╔╝ 
██╔══██║██║╚██╗██║██║  ██║  ╚██╔╝    ╚██╔╝  
██║  ██║██║ ╚████║██████╔╝   ██║      ██║   
╚═╝  ╚═╝╚═╝  ╚═══╝╚═════╝    ╚═╝      ╚═╝  

SOC Analyst in Training · Blue Team · TryHackMe Top 5%


TryHackMe Rank Rooms SOC LinkedIn


┌──(andyy㉿kali)-[~/Cybersecurity-Writeups]
└─$ whoami

  Andrew D Souza     | Final-year BCA Student

→ Target Role        : SOC Analyst L1
→ Focus              : Blue Team · Threat Detection · Incident Response
→ Currently On       : THM SOC Level 1 (Splunk, Detection Engineering)
→ Certifications     : Google Cybersecurity Professional Certificate (in progress)
→ End Goal           : Cloud Security Engineer

What This Repository Is

This is my structured cybersecurity learning journal — every room I complete on TryHackMe gets documented here as a write-up.

Not just what I did, but why it matters in a real SOC environment.

Each write-up follows a consistent format:

  • Key findings
  • Hands-on activities
  • SOC Analyst relevance table
  • Key takeaways

"If you can't explain it simply, you don't understand it well enough."


Stats

Metric Value
Global Rank Top 5%
Title [0x9][MAGE]
Active Streak 46+ days
Rooms Completed 106+
Write-ups Actively updated

Why This Maps to SOC Work

A few direct lines from lab to job floor:

  • Log Fundamentals + SIEM → triaging alerts, spotting anomalies in Splunk before they escalate
  • Wireshark + TCPdump + Nmap → reading traffic to confirm or rule out a suspected compromise
  • Incident Response + Digital Forensics → following an IR lifecycle from detection through containment
  • Active Directory + Windows fundamentals → understanding the environment most SOC alerts originate from

Repository Structure

Cybersecurity-Writeups/
│
├──  README.md
├──  attacks-and-defenses/
│   ├── cryptography/
│   ├── eternal-blue/
│   ├── exploitation-basics/
│   ├── metasploit/
│   └── password-attacks/hydra/
├──  computer-fundamentals/
├──  cybersecurity/
├──  google-cybersecurity-professional-cert/
├──  linux/
├──  malware-analysis/
├──  network-concepts/
├──  os-basics/
├──  soc-security-operations-center/
│   ├── blue-team-fundamental/
│   ├── digital-forensics/
│   ├── edr/
│   ├── ids/
│   ├── incident-response/
│   ├── log/
│   ├── nmap/
│   ├── ping/
│   ├── siem/
│   ├── soc-level-1/
│   ├── splunk/
│   ├── tcpdump/
│   ├── threat-intelligence/
│   ├── vulnerability-scanning/
│   └── wireshark/
├──  software-basics/
│   ├── javascript/
│   └── python/
└──  web-security/
    ├── burp-suite/
    ├── gobuster/
    └── sqlmap/

Completed Rooms

SOC & Blue Team

Room Difficulty Write-up
SOC Fundamentals Easy
Security Principles Easy
Log Fundamentals Easy
Incident Response Easy
Digital Forensics Easy
SIEM Basics / Splunk Basics Easy
Introduction to EDR Easy
IDS Fundamentals Easy
Threat Intelligence: Pyramid of Pain Easy
Defensive Security Intro Easy
Operating System Security Easy
Become a Defender Easy

Network Traffic Analysis

Room Difficulty Write-up
Wireshark Easy
TCPdump Easy
Nmap Easy
Vulnerability Scanning Easy

Networking

Room Difficulty Write-up
OSI Model Easy
Intro to LAN Easy
DNS in Detail Easy
HTTP in Detail Easy
Networking Core Protocols Easy
Networking Secure Protocols Easy
How Websites Work Easy
Firewall Fundamentals Easy

Cryptography & Attacks

Room Difficulty Write-up
Hashing Basics Easy
Cryptographic Concepts Easy
Hydra Easy
Metasploit (Intro / Exploitation / Meterpreter) Easy
EternalBlue Easy

Web Security

Room Difficulty Write-up
Web Application Basics Easy
JavaScript Essentials Easy
Burp Suite Basics Easy
Gobuster Basics Easy
SQLMap Basics Easy
OWASP Top 10 Easy

Linux

Room Difficulty Write-up
Linux Fundamentals Part 1-3 Easy
Linux CLI Basics Easy
Linux Shell Easy

Windows

Room Difficulty Write-up
Windows Fundamentals 1-3 Easy
Windows CLI / Command Line / PowerShell Easy
Active Directory Basics Easy

Malware Analysis

Room Difficulty Write-up
CAPA the Basics Easy
CyberChef the Basics Easy
FLARE-VM the Basics Easy
REMnux Getting Started Easy

SOC Skills Map

SKILL                    TOOLS & CONCEPTS COVERED
─────────────────────────────────────────────────────────
Log Analysis         →   Log Fundamentals, SIEM, Splunk
Network Analysis     →   Wireshark, TCPdump, Nmap
Threat Detection     →   SIEM, EDR, IDS, Alert Triage
Threat Intelligence  →   Pyramid of Pain, IOC Analysis
Malware Analysis     →   CAPA, CyberChef, FLARE-VM, REMnux
Digital Forensics    →   Evidence Handling, Autopsy
Cryptography         →   Hashing (MD5/SHA), Hydra
Web Security         →   Burp Suite, Gobuster, SQLMap, OWASP Top 10
OS Hardening         →   Linux, Windows, Active Directory
Incident Response    →   IR Lifecycle, Containment, Recovery

Tools & Platforms

Kali Linux TryHackMe Wireshark Linux Windows GitHub Nmap Python Cisco SIEM Splunk Enterprise Wazuh Microsoft Sentinel Elastic ELK Burp Suite SQLMap OWASP Hydra Metasploit


Disclaimer

All write-ups are created for educational purposes only. All activities are performed inside legal, controlled lab environments provided by TryHackMe. No real systems were targeted. Always hack ethically.


╔══════════════════════════════════════════════════════╗
║           BUILT IN PUBLIC. LEARNING OUT LOUD.        ║
║                                                      ║
║   Every commit is a step closer to the SOC floor.    ║
╚══════════════════════════════════════════════════════╝

Andrew D'Souza (Andyy)

TryHackMe LinkedIn GitHub

Releases

Packages

Used by

Contributors