#soc-level-1-path

1 messages ยท Page 4 of 1

quasi bough
#

Somebody will reach out to you asap , please be patient ๐Ÿ™‚

dusky maple
#

No. Unfortunately I'm still stuck. I've tried to input the information in many different variations and it doesn't really give me an answer except - "this rule has been enabled" or "this rule has already been enabled". But, nothing really happens after that. I am using the IP address from the sample, and Im using the receiving IP addresses given in the sample as well to create a Firewall Rule. However, I'm not achieving anything by doing that.

lost olive
lost olive
#

Alright.

dusky maple
# lost olive Alright.

Think I'll just keep trying to figure this out. I kinda feel like Im getting closer to an answer, but I'll be in touch if I need anymore help. Thanks.

hazy kettleBOT
#

Gave +1 Rep to @lost olive (current: #686 - 8)

lost olive
lost olive
wary siren
#

I'm enjoying the content and training material in the SOC lvl 1 path. The only thing that's consistently frustrating is forcing the Split View for learning.

Is there a reason why it's done this way vs letting us use rdp or ssh into the machine?

Also, I've only worked through the Network Security Section, so maybe this is not the case in later sections.

edgy anchor
quasi bough
wary siren
wary siren
dapper flame
#

@quasi bough

quasi bough
hazy kettleBOT
#

Gave +1 Rep to @dapper flame (current: #967 - 5)

dapper flame
#

Thanks to you

carmine comet
#

I have this issue in kape room where by i can't search targets and modules in gui kape application i am using browser vm any who can help me pass this obstacles

serene surge
#

Evening all - anyone studying for SAL1

quasi bough
urban stump
#

anyone can support with SOC Level1 > Network Security and Traffic Analysis > Snort Challenge - The basics ?

#

anyone on? trynna get top3 in my league xD

storm cove
#

task 6 what's the problem here. Don't seem to see it

sinful vigil
#

Ofc if you still have the Problem)

pseudo oxide
#

Is there anybody else in the snort room?

dark shadow
#

I am stuck at threat intell tool room Task 7 where i dont see the downloadable file to check on virus tool

alpine peak
quasi bough
dark shadow
quasi bough
oak haven
#

anyone in this path?

#

I'm at snort rn

oak haven
paper pewter
#

i'm building my own SIEM stack with Wazuh, suricata, sigma, maybe zeek and something more proactive for immediate response later on top.

snort was just too filthy for me. i can always sniff with something more humane.

so yeah - best way to learn is to build a stack at your home lab. taught me a lot.

oak haven
paper pewter
#

you can simplify so many things in cybersec. so much stuff is unnecessarily complicated.

"In software development, the rule of least power argues the correct programming language to use is the one that is simplest while also solving the targeted software problem."

https://en.wikipedia.org/wiki/Occam's_razor

oak haven
#

100% true

vagrant sinew
sinful vigil
#

lmk if you need further help afterwards

humble tendon
#

Hi there! I have an issue in Yara room, more specifically working with Valhalla. This question: "Do the same for file 2. What is the name of the first Yara rule to detect file 2?"

When I copy SHA-256 to Valhalla I can see that the first YARA rule name is: "WebshellRepo_convert". Am I missing something or is there a bug? When typing the answer in, I am getting autofilled some extra underscores.

#

Oh, now I got it...However, I think the question is a bit missleading or maybe it is bcs of my English? ๐Ÿ˜…

quasi bough
humble tendon
quasi bough
fathom swanBOT
humble tendon
#

That's the hash: 53fe44b4753874f079a936325d1fdc9b1691956a29c3aaf8643cdbd49f5984bf

#

It think, what I got confused is, that the question is asking for the first YARA rule, which in this case is WebshellRepo_convert, but then I found out that it is actually asking for the rule1, if that makes sense.

quasi bough
humble tendon
quasi bough
humble tendon
quasi bough
humble tendon
#

thanks for the help

quasi bough
dusty kiln
#

hello guys, anyone on this SOC path?

pre security > cyber security 101 > SOC LVL1 > SOC LVL 2 ???

humble tendon
#

Hi there! In the OpenCTI room in the Investigation Scenario, where I should investigate CaddyWiper malware. I should find answer to this question: How many malware relations are linked to this Attack technique?

Am I missing something here? (see screenshot)

#

Is the question asked for CaddyWiper or for Native API? The input should be 3 digit, so maybe the Native API, but 149 nor 135 works

#

Oh, got it...it is asking for the malware relations for Native API...which is a different number

hasty gazelle
humble tendon
torpid glacier
dusty kiln
torpid glacier
topaz viper
#

Completed investigating with Splunk, which room should i do next?

wheat scroll
#

Hi everyone! ๐Ÿ‘‹

Iโ€™m Shashank, based in the UK ๐Ÿ‡ฌ๐Ÿ‡ง and currently starting my journey into cybersecurity, with a strong interest in becoming a SOC Analyst (blue team side ๐Ÿ”ต).

Iโ€™m here to connect, learn, share progress, and get advice from others further along the path. If youโ€™ve got tips for getting into a SOC role or want to study together, feel free to reach out!

Looking forward to learning with you all!

pale wigeon
#

I am a little confused by 'Windows Event Logs' Room, Task 4 'Get-WinEvent'.(https://tryhackme.com/room/windowseventlogs) Question 3 states: "Execute the command from Example 8. Instead of the string Policy search for PowerShell. What is the name of the 3rd log provider?" I don't see any "Example 8". What is this in reference to? In only see Examples 1 - 3 in the Task Room. Where or What is "Example 8" Also Question 4 references an "Example 9". Again have no idea what this is referencing since I only see three examples on the task page

pale wigeon
#

Oh nevermind... I think this is coming from the examples in the https://learn.microsoft.com/ docs, not the examples in the THM task room itself..

pale wigeon
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5272)

topaz lark
#

Hello everyone..I started in this sector until recently..I need a study partner..more like learning partner..i am doing THM Soc path and also doing ISC2 CC so it would help if anyone is starting like me..and would love to study together..

rich glade
#

soc-lavel-1-path have any lab practise

quasi bough
hexed nexus
quasi bough
hexed nexus
#

you are god for me rn bro. you are the best helper here.

hexed nexus
quasi bough
hazy kettleBOT
#

Gave +1 Rep to @hexed nexus (current: #1927 - 2)

desert prairie
#

Hey guys, I'm in the SysMon room in the SOC Level 1 > Endpoint Security Monitoring Pathway. For Task 4, Q2...

This command in powershell

Get-WinEvent -Path C:\Users\THM-Analyst\Desktop\Scenarios\Practice\Filtering.evtx -FilterXPath '*/System/EventID=3' | Measure-Object

Returns 73,591, the correct answer for the question.
But going through event viewer and filtering for event id 3 returns 74,970.
Anyone know why this is?
Also I'm not sure if I should've sent this to Room-Help.

wintry cradle
#

hey, i just started doing soc path 1, i would like to have someone with me who i can study along with.

#

hey everyone, i have a question from the first part. why did the malicious person left a message when i blocked his ip address on the firewall, i dont know if this is something which usually happens or is it just for us to complete the lab and give answer for the question like a Capture the flag

quasi bough
wintry cradle
#

thank you, i thought when we block an IP address in firewall. we usually get message from the blocked person like that๐Ÿ˜…

wintry cradle
#

hey anyone know the correct order for the last task in the cyber kill chain

wintry cradle
#

yeah i figured it out, thank you.

wintry cradle
#

hey guys, does everyone have tryhackme premium with them.

visual lagoon
#

i personally don't yet am new to the site so i rather see before spending money to learn more why do you ask?? am curious

wintry cradle
#

i was doing SOC-level 1 and after the cyber kill chain, it asks to get premium for getting access to rest of the modules in the path.

#

i am also new to tryhackme, so i don't know how this works, am i supposed to get premium before continuing or is there any way to access the rest of the modules without getting premium

quasi bough
humble tendon
#

Hi guys! Quick question. I am working on the "Writing IDS Rules (Torrent Metafile)" room. Question: "What is the name of the torrent application?". When I read snort.log, I can see in the log the application name is "x-bittorrent". However, it gave me a wrong answer, when I am submitting it. Am I missing something?

#

Ahh, ok. Found out what the answer should be. A bit missleading, but whatever :/

quasi bough
humble tendon
quasi bough
humble tendon
quasi bough
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5422)

humble tendon
reef pelican
#

Hey in Pyramid Of Pain modulus what should I do in the Domian Names section ?
Cuz I faced this issue but did not understand the question tbh ):

#

Ah I think I got it maybe using virus total to see the directed website okay

#

yep it worked xd (:

#

I guess I'm a type of person who ask in dis to know what is this HAHHAH

quasi bough
mossy gate
#

Well, was doing well and really enjoying the SOC1 path...untill i done Friday overtime.... I found that so difficult. I feel like it is way above my current capabilities. Is there anything else i should be looking into for more practice on these types of rooms? It hit me out of the blue this one!

#

First time i guess i felt way out of my current depth!

#

Know there is plenty more of those moments to come ...

humble tendon
#

Hi there, anyone here can help me with this error message?
I am trying to run the zeek with given pcap file and run with the signature file

humble tendon
#

I've tried to restart the VM too, but no difference

loud fable
loud fable
rancid rain
#

Hi everyone,

Iโ€™m currently working through the Splunk 201 section in the TryHackMe SOC Level 1 room, and Iโ€™ve hit a bit of a challenge. The jump in difficulty from the previous Splunk material feels pretty steep โ€” the queries are more complex, and thereโ€™s a lot of new information to take in.

Iโ€™ve been taking handwritten notes, which worked fine up to this point, but now itโ€™s getting harder to keep everything organized and retain what Iโ€™m learning. Iโ€™m starting to feel a bit overwhelmed and not as confident moving forward.

somber chasm
mossy gate
hazy kettleBOT
#

Gave +1 Rep to @somber chasm (current: #2995 - 1)

marble laurel
#

Hello everyone just joined the platform and l need study partners for my SOC1 path. Currently on the Network Security and Traffic analysis module(Snort room)

humble tendon
humble tendon
humble tendon
#

Anyone here can guide me here with this question: "Investigate the dns.log file. Filter all unique DNS queries. What is the number of unique domain queries?" In the Anomalous DNS exervise in the Zeek Exercises
I know I need to zeek-cut the query parameter from the log, I am also piping sort -nr and uniq, but I am getting a huge number as result...the answer should be 1 digit only

Here's my command: cat dns.log | zeek-cut query | sort -nr | uniq | wc -l

marble laurel
hazy kettleBOT
#

Gave +1 Rep to @humble tendon (current: #3000 - 1)

marble laurel
#

What is the destination address of packet 63?

#

when i use the destination ip in the log file it says the answer is wrong

humble tendon
marble laurel
#

yes please

humble tendon
#

It's the IDS rules (http) room, right?

marble laurel
#

yes

humble tendon
#

hmm, ok it worked for me. How does your local.rules file look like?

marble laurel
#

alert TCP any 80 <> any any (msg: โ€œTask 2โ€; sid: 1000001; rev: 1;) and alert TCP any any <> any 80 (msg: โ€œTask 2โ€; sid: 1000002; rev: 1;)

humble tendon
#

also what is the output you're getting when you are trying to display the 63rd alert from the log file?

#

bsaically, I thin the local rule you have is fine, but there might be a issue having it as 2 lines/2 different rules, so I'd try doing them in one line as I proposed and see if that changes anything

opaque sail
#

Can anyone help me with the same issue as this one above?

#

I get the destination IP but the answer is incorrect

humble tendon
opaque sail
#

That is also the problem is that I do not see the logfile being created

humble tendon
opaque sail
#

If I just do "sudo snort -c local.rules -r mx-3.pcap -n 63" I see the 63rd packet but the ip is not what the answer is accepting

#

I have tried appending "-l ." but it does not create a log file

humble tendon
#

try doing: sudo snort -c local.rules -A full -l . -r mx-3.pcap

opaque sail
#

I have run that as well but a log file does not get created

humble tendon
#

what do you see when you ls?

humble tendon
opaque sail
opaque sail
humble tendon
#

try cat-ing 63 log from alert

opaque sail
#

It is a 0 bytes file

#

I have tried

humble tendon
#

are you sure your local.rules is correct?

opaque sail
humble tendon
#

looks good to me

opaque sail
#

The first issue i am trying to figure out why the log file is not being created

humble tendon
#

what happens when you run this command: sudo snort -c local.rules -A full -l . -r mx-3.pcap

#

don't you get a output with how many things it created?

#

you should get 164 alerts, right? From the previous question

opaque sail
humble tendon
#

you're missing . in the command, no?

opaque sail
#

I was able to get that answer from here

humble tendon
#

before -r, I think that's why you didn't get log file generated

hexed glen
#

Hello everyone!

I got stuck at Snort Task 5. tcpreplay failed for some reason. What am i missing?

opaque sail
humble tendon
marble laurel
# opaque sail I appreciate your help!!

so please try using this rule instead alert TCP any any <> any 80 (msg: โ€œTask 2โ€; sid: 1000002; rev: 1;) and run snort using this command sudo snort -c local.rules -A full -l . -r mx-3.pcap. When it is done do ls to see if you will find any logfile created.

marble laurel
humble tendon
opaque sail
#

After a few restarts of the machine I was able to see the log file. Thank you @marble laurel @humble tendon !!

hazy kettleBOT
#

Gave +1 Rep to @marble laurel (current: #3002 - 1)

forest zealot
forest zealot
spare flicker
#

Any tips on getting into cybersecurity? Iโ€™m currently thinking of either taking the google cybersecurity or IBM cybersecurity analyst courses and after finishing one of them I want to try to get my CompTIA sec+ certification. Any tips on what course would help more?

humble tendon
dense forge
#

Is this a bug?

#

I k ow I entered more info than this, and itโ€™s also telling me itโ€™s incorrect and correct at the same time

naive totem
#

Hi, I would like to at least get a job as a soc analyst level 1. But I don't know which tools to learn or certs to focus on. Really would appreciate anyone to enlighten me on this. Much love from Vietnam ๐Ÿ˜˜

quasi bough
naive totem
#

Thanks. Will do so

midnight dust
#

are you guys like beginners

hasty gazelle
#

How do you do to not give up on Task 2 'Snort Challenge - The Basics https://tryhackme.com/room/snortchallenges1 ? It is annoying now. It is supposed to be the "Basics". Please, @fast prairie and @quasi bough what do you know about this task that you can share with us without revealing the actual answer?

hasty gazelle
quasi bough
hasty gazelle
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5641)

calm comet
#

Shoutout to the people behind the Wireshark Traffic Analysis room, the documentation is put together so well

grim orchid
quasi bough
quasi bough
hexed glen
hexed glen
#

But still can't reproduce as the task does in examples.

obsidian junco
#

how do i post image in this chat

#

literally no options/ cant even drag/drop

quasi bough
fathom swanBOT
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5653)

obsidian junco
#

This is the 4th time im restarting the machine...no VM window opens...its just stuck counting down timer...What do i click to open my VM Window to complete this assignment??

quasi bough
weary dew
#

Hello @quasi bough
Been a while. Can see you are a Mod now. Well deserved๐Ÿ™‚

hazy kettleBOT
#

Gave +1 Rep to @weary dew (current: #3036 - 1)

quasi bough
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5659)

hasty gazelle
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5663)

hard dome
#

I can't press the start machine button?

#

Does anyone have a solution?

quasi bough
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5685)

hasty gazelle
#

Hi everybody. I am still stuck in room 'Snort Challenge - The Basics', this time with Task 3. None of the two digits number I get match the answer for the question about 'failed FTP login attempts'. I am not giving up yet. I do not know if any of the commands in the snapshot is not suitable for this task. Anybody knows anything about it?

marble laurel
#

Hi ProbaN you can try this to see if it would work
alert tcp any 21 -> any any (content:"530 "; msg:"FTP Login Failed"; sid:1004;)

quasi bough
opaque sail
#

Hi, I would like some help with the sysmon room. When I try to start sysmon using the command provided "Sysmon.exe -accepteula -i ..\Configurations\swift.xml" IT says failed to start the service even though I am trying from PowerShell as Admin

hasty gazelle
hazy kettleBOT
#

Gave +1 Rep to @marble laurel (current: #2002 - 2)

hasty gazelle
quasi bough
ember egret
#

hello

humble mica
#

hello does anyone know why thunder bird wont work i try to sign up it wont work i am refferring to tht threat intelligence tool room

quasi bough
fading umbra
#

Hello

#

Can anyone help with wazuh??

nocturne cave
#

hello. for the first question in Task 2 of "Snort Challenge - The Basics" room, i got the right answer by writing a rule to match any source and destination ip address and port, but how come that's the case if they asked "to detect all TCP packets from or to port 80" ?

opaque jetty
quiet osprey
#

Hello, I need your help on the arrangement of these items in the kill-chain:

  1. exploit public-facing application
  2. data from local system
  3. powershell
  4. dynamic linker hijacking
  5. spearphishing attachment
  6. fallback channels
quiet osprey
#
  1. exploit public-facing application- exploitation
  2. data from local system- actions on objective
  3. powershell- installation
  4. dynamic linker hijacking- weaponisation
  5. spearphishing attachment- delivery
  6. fallback channels- command and control
quasi bough
#

Switch those two

quiet osprey
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5742)

forest fjord
worthy berry
#

Hmm

quasi bough
hexed nexus
frosty dawn
#

How do i share a screenshot on here?

quasi bough
fathom swanBOT
meager tangle
#

Hey, does anyone know if it's normal to feel a little bit lost with the Intro to Cyber Threat Intelligence room? I've been following the path in order (and did the Cybersecurity 101 path before this) but I feel like I missed something somewhere because I'm kinda lost once task 3 got to the scenario ๐Ÿ˜ตโ€๐Ÿ’ซ

#

Yeaaah, I'm extremely lost now. This room was making plenty of sense but once it brought up the scenario in task 3, I feel like I missed a room or two somehow... might just call it for the night, honestly

meager tangle
#

Decided to try watching a video walkthrough on "Intro to Cyber Threat Intel" in hopes that it'd help me focus a bit more on the scenario but it looks like the room has been changed since this video came out ~1 year ago? The text in the tasks is completely different from what's there now ๐Ÿคจ

#

Maybe this is why I was so confused, the room had to have changed in the last week or so because I only took a few days off from learning and the earlier tasks have completely unfamiliar text in them. It's like a Mandela effect or something... going crazy NotLikeThis

thorny rock
#

Mate itโ€™s totally normal to feel lost doing anything

#

On thm

#

If your not lost at some point your not learning

#

I have a friend on here who I will bring in to this community he is really good and can help us

#

I just realised this group is massive with loads of resources and people like 0day he is really cool that guy is an inspiration

humble mica
#

hey is the site not working my machine having issues loading

light iron
#

Hey guys I'm mew to this server

#

Can anyone teach me hacking

quasi bough
light iron
#

Thanks

#

I'm really interested in learning ethical hacking

meager tangle
#

Quick question, with STIX (Structured Threat Information Expression), the current room says it's a JSON format for describing threat context. Does that mean I'm going to want to learn JSON? I know what it is and I know very basic web development tools/formats/languages/etc but JSON is beyond what I know at the moment

meager tangle
#

And man, I've tried on four separate days to get through the Intro to Cyber Threat Intel room and every time, I get to task 3 and start zoning out. As I mentioned elsewhere, I'm understanding the concepts but this practical scenario makes me feel like I've missed something, somewhere ๐Ÿ˜ตโ€๐Ÿ’ซ

cold dock
#

Hello guys! Hope you doing well ๐Ÿ˜Š
I stuck on ItsyBitsy room, Kibana just not loading. I try multiple times using VPN and Attackbox, but getting same message "Kibana server is not ready yet"

vital lodge
# meager tangle And man, I've tried on four separate days to get through the Intro to Cyber Thre...

I've also recently got into the SOC level 1 path and am also finding it hard to stay focused.

It just seems very verbose and a lot of technical words which I'm unfamiliar with I guess. I got through the frameworks and just completed the Intro to Cyber Threat Intel, but yh a lot of re-reading due to zoning out and most of it just not entirely going in. Just hoping the important content sticks when I actually start having to use it

meager tangle
snow belfry
meager tangle
# snow belfry I usually take notes it helps. I also use the pomodoro method to stay focused. ...

Appreciate the tips! I take notes in Obsidian but generally copy-paste sections of interest or else it'd take me forever to get through a single room ๐Ÿ˜… As for Pomodoro, I've heard some about that but haven't looked into it, I'll definitely be checking that during my studies for the ISC2 CC and other certs! Music-wise, I go for ambient stuff like instrumental post-rock, as it tends to help me focus. Hadn't considered doing the blocks of time, though! Thanks again, will definitely try some of these!

hazy kettleBOT
#

Gave +1 Rep to @snow belfry (current: #3078 - 1)

cold dock
#

Hello everyone!
Guys, can I 100% complete SOC path if some modules, like capstone challenge, contains SOC Simulator rooms?

quasi bough
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5825)

balmy path
#

Hello, I'm having issues with a stable connection to the server in the network miner room. The room crashes on me and goes slow at other times.

meager tangle
#

In the Yara room, did anyone else notice how the room says "you're not expected to use this tool in this room" when talking about Loki, yet you're definitely required to use it on several occasions? ๐Ÿคจ

tropic dragon
#

hello, Can you help me about Practice Analysis of Cyber Kill Chain?

humble mica
#

hello im doing tryhackme windonws event log task 5 can someone tell me whast wrong wiht this

#

get-winevent -logname security -filterxpath '*system/provider[@name="wlms"]' and '*system/timecreated[*2020-12-15T01:09:08.940277500Z"]'

#

it seems right to me but won fit in anser

quasi bough
fathom swanBOT
knotty coral
#

I am starting SOC lv1 path of someone want to join my the journey they can dm me

oak creek
#

Having problems verifying account

quasi bough
tropic dragon
nocturne cave
#

Hey everyone! ๐Ÿ˜
Hope youโ€™re all doing great!
Iโ€™ve recently started studying for SOC Level 1 and right now Iโ€™m exploring the Unified Kill Chain module, super interesting stuff so far!
Iโ€™d love to connect with others who are also getting into cybersecurity or already on this journey. Letโ€™s learn together, share insights, and support each other along the way.
Feel free to reach out, letโ€™s grow in this field together!

willow anchor
#

Room/Azure ||should be free|| why when clicked it directed me to ||pay for premium|| NotLikeThis

karmic laurel
#

Didnโ€™t see anyone post about it in August but the CTF in cyber threat intelligence Friday Overtime appears to be broken. VM returns a 502 bad gateway upon opening

quasi bough
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5866)

tropic dragon
#

Can you explain how to do the test " Summit" of Cyber defence frameworks

orchid merlin
#

in the "Sysmon room" im supposed to copy that into the answers but its impossible to copy anything is it normal ? is there any way to copy

golden knoll
#

Hey guys i started this path a week ago and i finished the intro to SOC and pyramid of pain is anyone on the cyber kill chain if so how is it going?

orchid merlin
quasi bough
quasi bough
orchid merlin
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 5892)

simple oyster
#

Hi guys

#

can someone help me. Why is my snort not generating alerts and log

#

I can;t attach an image

#

sudo snort -c /etc/snort/snort.conf -v -A full -l /var/log/snort

the above command run the snort but it will not generate a alert and log file with data inside

#

"sudo snort -v -A full -l /var/log/snort -c /etc/snort/snort.conf" another command that I run to capture the traffic, unfortunately alert file and snort log is not generating. Pls help

#

I can't upload photo

simple oyster
#

all goods now. I need to create a custom rule first before an alert will be generated

timber jewel
#

hi community! i have an issue with the last question in this room tryhackme.com/room/fridayovertime. even though i found it, it says it's the wrong answer. what i have to do?

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

mild egret
#

Damn, Redline is killing me with the Attackbox/RDP

rugged seal
#

hey yall I'm decoding a base64 pdf but it seems like I have the wrong format, can someone help?

rugged seal
graceful cobalt
graceful cobalt
#

is there someone who can help please?

teal vector
# graceful cobalt is there someone who can help please?

The malware file u can see when scanning it is trying to make a connection to its own server to control the system at the ip u can find in the scan so to stop it u have to put in a firewall rule that blocks the outgoing traffic (egress) to that ip so that the malware cant connect to the attackers ip

graceful cobalt
hazy kettleBOT
#

Gave +1 Rep to @teal vector (current: #3157 - 1)

teal vector
graceful cobalt
left thunder
turbid palm
#

Good day everyone, I was doing this exercise and after filling all the answers. The response is saying " At least one of them is incorrect".

And I got them right. Pls help

#

This exercise is under Cyber kill chain and it the last exercise to done there

quasi bough
cold dock
muted galleon
#

hi everyone, iam having troubles with the vm's on a firefox web browser. I load up the vm (windows vms exclusively for some reason) and it keeps right clicking without me right clicking, leading to me being unable to use the vm properly.

Im not sure why this happens, and if it's even on my end i would be happy to get some help from anybody

Thanks guyssssssssss goodluckkk

#

It is the tryhackme ui rightclick, not the firefox normal right click if that makes sense. The glitched right click only shows "paste" whilst the firefox right click allows me to copy, search with google gemini etc...

I feel like maybe i should submit a ticket ๐Ÿ’€

vital lodge
native viper
#

exactly! I usually ssh into the machine whenever I have issues

errant oar
#

hey everyone, currently working on the benign room in the SIEM section, was wondering if anyone who is experienced and has done the room already could possibly meet up and go through the room with me. After doing the investigating with splunk room, i had to google a lot for help, because i was unaware of how to really search for things and didn't know what each eventid classified as.

Trying to build up the skills and knowledge to know how to navigate and what to look for when trying to answer these questions instead of just searching for the answers on google.

smoky oyster
#

.

north breach
#

Hi everyone,
Iโ€™ve just started the SOC Level 1 path on TryHackMe, but I feel a bit lost. Iโ€™m not sure if this is the best place to start, or if thereโ€™s a better path for beginners. Could anyone guide me on the right starting point? Any advice would be really appreciated! ๐Ÿ™

#

Also, Iโ€™d love to hear how you started your own journey on this path. Any advice would mean a lot!

hushed wedge
tulip river
#

helo i am solving SOC level 1
Osquery: The Basics
i am stuck in task 5 question 5 its correct answer is Wireshark 3.6.8 64-bit but there is no space to type bit i also tried x64 it doesnot work
and also in task 6 question 4 its answer is 214 but it is not accepting
can any one help me plaese

sinful vigil
# tulip river helo i am solving SOC level 1 Osquery: The Basics i am stuck in task 5 question...

Hi, the answers dont get accepted cause theyre wrong. This vid from John Hammond should help ๐Ÿ™‚ https://youtu.be/YpmGZseJbJY

https://jh.live/tryhackme || Learn cybersecurity with TryHackMe! Discount code 'JH10THM' will save 10% off the monthly, annual or student plan. You can get started with the osquery room and their SOC Level 1 learning path here: https://jh.live/thm-osquery

๐Ÿ”ฅ YOUTUBE ALGORITHM โžก Like, Comment, & Subscribe!
๐Ÿ™ SUPPORT THE CHANNEL โžก https...

โ–ถ Play video
tiny turret
native viper
#

I just did the Summit Room's Challenge and all I can say is WOW!! Is that what real life SOC looks like? Daunting but absolutely interesting!!

rigid solstice
#

Hey Guys,

Last question in the sysmon room "What C2 is the adversary utilizing in Investigation 4?" I got the answer correct it was the name of something that couldn't really be avoided when working with another question "Trying not to spoil anything". I don't know if I arrived at the write answer correctly though as I just saw the name. Is there a way to identify C2s in event viewer with sysmon?

tight berry
#

Hi is anyone familiar with the Monday Monitor room? Is there supose to be a split view VM? Because when I start the machine no split view shows checkout the attached pic. Thanks

native viper
mighty hemlock
#

Is anyone facing the same problem in OpenCTI where the target machine isn't producing any ip address

hushed wedge
ivory flint
quasi bough
random osprey
#

Hi, the velociraptor app (SOC1 Path) isnt' starting. Does anyone have the same problem? I have started the velociraptor server in the terminal, opened chrome and clicked the velociraptor link. Then I added the creds and it's loading, but no login possible. Please help

hushed wedge
random osprey
hazy kettleBOT
#

Gave +1 Rep to @hushed wedge (current: #9 - 987)

random osprey
#

Testing the velociraptor vm again:

16:30 MESZ

  1. start: abortion!
  2. start: abortion!
  3. Start: starting - ok! Then: Instance termination
    Unfortunately, your instance has been automatically terminated. Please re-start a new one. To learn more about why this happens, please refer to.
  4. Followed the instructions the the info page for Instance Termination. Deactivated all Firefox Plugins!
    New Start: Yep running! 16:56, 17:11 Instance Termination

It's impossible for me to use this vm.
I followed the rules from the info page for Instance Termination and deactivated all my firefox plugins - no success.

please fix all the SOC1 VMs

hushed wedge
hushed wedge
random osprey
#

yes, europe/ireland

hushed wedge
# random osprey yes, europe/ireland

thanks, Europe is just like for me
sometimes I have the impression there are more problems with VMs dying in US-East than in Europe
all I can see right now is that sometimes Velociraptor works and sometimes it does not, and I do not know what to do about that
maybe you want to take up the offer from Blackout (THM Staff) here: #site-support message
otherwise, you have the option of turning to THM Support which works by email

hazy kettleBOT
#

Gave +1 Rep to @random osprey (current: #2105 - 2)

fathom swanBOT
#
TryHackMe's Email

TryHackMe's support email address.

random osprey
hazy kettleBOT
#

Gave +1 Rep to @hushed wedge (current: #9 - 992)

burnt gust
#

Hello, I'm unable to run the traffic-generator file in the Snort room. When I run the file and select an action, the terminal gives the error:

Error constructing proxy for org.gnome.Terminal:/org/gnome/Terminal/Factory0: Error calling StartServiceByName for org.gnome.Terminal: Timeout was reached

main charm
#

Yo, for info, i had the same problems with Velociraptor VM, shuting down after few minutes, even after desiabling addons with Fox or Brave.. Then i changed location setting from EU to US, since then, working so far.

native viper
#

To the admins please update this room (threatinteltools) as the domain for that IP has changed. I had to look at someone's previous work to get past that point.

karmic laurel
#

I apologize if this has been covered already I do not get on this discord frequently anymore

#

How is it possible to get a certificate of completion for the course if THM charges 1200 to use the three SOC simulator labs

#

You can do phishing unfolding but hooks, upload and black cat all require an advanced sub

native viper
#

Am I doing something wrong guys?

#

the answer format is a single digit but the word count for strings says 627

tepid hill
tepid hill
rugged seal
#

It asked how many strings used to flag the file not which string was used

digital prairie
#

hi everyone ,im stuck on pyramid of pain task 4, last answer ......Provide the redirected website for the shortened URL using a preview: https://tinyurl.com/bw7t8p4u

digital prairie
#

nvm, i found it

karmic laurel
tepid hill
# karmic laurel Yes the $1200 plan

Hmm.. haven't done the path myself so I can't say for sure. However, there is a plan to make the SOC simulator available to regular subscribers

hazy kettleBOT
#

Gave +1 Rep to @native viper (current: #2118 - 2)

raven pawn
#

i don't think this rooms is working properly Threat Intelligence Tools

#

Thunderbird Mail app is not working it all

raven pawn
#

this room should be look up ,task 6 need to be updated

latent birch
#

Hye

#

hey

#

I'm on SOC level 1, but unable to solve the last part of the Cyber kill chain

#

Can anyone help out

#

Add each item on the list in the correct Kill Chain entry-form on the Static Site Lab:

exploit public-facing application
data from local system
powershell
dynamic linker hijacking
spearphishing attachment
fallback channels

#

Also in the MISP room, im unable to open the VM

#

There appears to be an error there .

inland obsidian
latent birch
#

anyone else facing issue while accessing vms?

safe field
raven pawn
vague cave
ivory sedge
#

How are you, I would like someone to help me know how to answer the questions, I always have error messages that I am not respecting the rules

hasty gazelle
raven pawn
#

do any one have problem whit this room Snort Challenge - The Basics???

#

task 2

tired nimbus
#

Hey everyone ! Happy to be part of this group!

native viper
atomic pendant
#

Hello everyone, I was in the Windows Event Log room and got stuck on the first question. The question is: What is the Event ID for the earliest recorded event? I sorted the events, but I still got 4104, which seems to be wrong. Has anyone else faced a similar issue?

#

Anyone ?

native viper
# raven pawn task 2

Hey there, I just concluded the task 2 and the instruction was to run a shell script at a given directory. I did not encounter any errors in the process but if you can be specific about the issues you faced, I may be able to help

white vortex
#

Holy shit i cant do this no more I need Some help.

In the MITRE Room Task 4 last question:

"Which Detection ID would you implement to monitor suspicious cloud logon activity in your organization's environment?"

What is the answer?

Because...

AN1503
AN1504
AN1505
AN1506

DET0546

T1078
T1078.004

these are all wrong.

I may be stupid.

But its the only question left im stuck on this for like almost 1 hour now.

indigo monolith
#

Same situation im in... the answer should be det0546, but its not accepting. Possibly a bug with thm platform?

static widget
#

Yes I am stuck in it for the last hour

static widget
white vortex
languid estuary
#

AN-1206โ€” Suspicious Cloud Login
OR
AN-1207: Suspicious Cloud Logon (Valid Accounts: Cloud Accounts โ€” T1078.004)
based on chatGPT but not accepting neither one of them

Update:
also could be : "Behavioral Detection of Remote Cloud Logins via Valid Accounts " based on the enterprise level
AN0017, AN0018, AN0019, AN0020 but not accepting these also

pallid crag
#

I have the same problem. Last open question.

white vortex
static widget
languid estuary
#

@vagrant ledge @astral cedar @normal kettle anyone from the original creators of the room can give us a hint?!

static widget
#

Yea and also this question is new too cuz it's not in old walkthroughs also

white vortex
#

Its fixed guys

#

easy to find now, idk if im allowed to post the answer here

#

2+ hours of trying and then it was actually a bug damn

astral cedar
#

Apologies for the confusion. The room was updated today, and it seems MITRE recently (in the last couple of days) deprecated the previous DS series of Data Sources, which the previous question and answer were based on. It has been updated to reflect the new Detection Strategies DT. Thanks for the info ๐Ÿ™‚

hazy kettleBOT
#

Gave +1 Rep to @astral cedar (current: #149 - 64)

atomic pendant
#

Hello guys have you guys completed windows event logs room?

#

Anyone ?

eager crown
hazy kettleBOT
#

Gave +1 Rep to @astral cedar (current: #146 - 65)

median arrow
#

Hello everyone, I am taking the soc level 1 course. I have a question: in the soc level 1 classroom, when I complete all 9 rooms in soc1, will I be provided with a certificate of completion of the soc level 1 classroom, or do I have to register for the final certificate exam in that classroom to complete the room?

proven river
median arrow
proven river
true sphinx
raven pawn
#

im stuck here guys

#

Windows Event Logs task 5

#

i already respond all question except the first 2

#

this was what i put on the power shell vm for find the answer to the anothers question

#

and its saying the its wrong

#

Get-WinEvent -LogName Application -FilterXPath โ€˜*/System/Provider[@Name=โ€WLMSโ€] and */System/TimeCreated[@SystemTime=โ€2020โ€“12โ€“15T01:09:08.940277500Zโ€]โ€™

#

do im missing something or there is a error on that room ?

#

and for the question #2 i put this Get-WinEvent -LogName Security -FilterXPath โ€˜*/EventData/Data[@Name=โ€TargetUserNameโ€]=โ€Samโ€ and */System/EventID=4720โ€™

shrewd zephyr
#

Has to soc1 program just been changed/updated?

#

I was almost complete with the program yesterday at 72%. Now today I'm only at 31%,

proper meteor
iron drum
#

oh

#

interesting

shrewd zephyr
#

@proper meteor

#

@proper meteor Thanks

hazy kettleBOT
#

Gave +1 Rep to @proper meteor (current: #324 - 26)

raven pawn
#

for be honest the original was pretty good but i think that one have some content for soc level 2

#

like more advance resource , just my opinion maybe wrong , but still thinking the it was good content

dim island
#

Yeah Literally me this morning too, it just changed completely ๐Ÿ˜…. I was on the third section it was network traffic

fast prairie
#

Hey everyone!
To help you stay ahead in the fast-changing world of cybersecurity, we're thrilled to announce that the updated SOC Level 1 Analyst Path is now live! ๐Ÿš€

The updated path includes:

  • โœจ 9 new modules and 38 new rooms
  • ๐Ÿงฉ Lots of content improvements
  • ๐Ÿ… 9 new collectible badges

This major update fully modernizes the path to focus on the core skills required for today's SOC Level 1 analysts, explaining how a SOC is organized, how the analyst role aligns with emerging threats, and how to apply these skills across real-world scenarios. We have also adjusted overly complex forensic content and expanded coverage across all SOC domains, check out the blogpost for more details. We can't wait for you to explore everything we have built!

Migration notice:
You might have experienced some temporary issues when accessing or progressing through the SOC Level 1 path while we roll out the update. Please refer to the updated URLs below:

Both the current and new SOC Level 1 paths will have a certificate of completion and remain available in Paths until the end of the year, but if you've just started your journey - we recommend jumping straight into the new path for the best experience!

Thanks for being with us as we continue to grow and improve, we can't wait for you to dive in and see what's new! ๐ŸŽ‰

proper meteor
# raven pawn for be honest the original was pretty good but i think that one have some conten...

Yeah, the original SOC Level 1 path was great, really taught some fantastic skills. The feedback from the rooms and the modules was great. However, when reviewing the path and talking with our business customers on the expectations they have for an L1 in their teams we saw the need to improve. Some topics did not get enough coverage and some topics were relevant more for a senior role than an level 1.

We talked to lots of our customers, got feedback from them in terms of what they expect someone coming into an L1 position to have, and really focused on that to perform this major rebuild of the path. Really think this is a huge upgrade to the path, and I hope when you look at it and even talk to people currently in SOC roles, you see how great an upgrade this is.

grim folio
slow moat
#

I agree, looking at the new rooms, I don't feel that it goes in-depth on certain topics.

proper meteor
# grim folio Even though I'm happy for adding new relevant rooms but still I feel that this N...

We're really focusing on skills required for the SOC L1 role. We think we've covered it at the level for this role, but if you think we missed the mark on some topics let me know and we can look at improving it. If anything, when I look at the old path, there are 8 modules, the upgraded path has 14 modules! We had worried we covered too much, but we really wanted to try and teach everything required. Also, in the old path, if you look at the Digital Forensics and Incident Response module for example, although I absolutely love that module, I think if you ask a SOC analyst if lots of that module was relevant they would say no (at least the ones we talked to agreed). We're now moving up and into the SOC L2 path, looking at that, and refreshing. There are some topics that got moved from the L1 into the L2.

What topics do you think should be added?

slow moat
#

idk, but it feels a bit off. I think this is just because its new and I need more time exploring the new rooms a bit. At first I noticed the new module for windows security monitoring, it tackled event logs but they removed the windows event logs room that was in the old DFIR module. So looking at a beginner standpoint I would be a bit lost.

#

but hey, can't really say not until I've completed all of them. Thanks to the team who worked hard to make this happen. Lowkey excited to learn this stuff

sharp gyro
#

i think the overall path makes more sense now with it being SOC level 1, but i do agree it feels as though there isnโ€™t enough depth. the original path went in to way more detail with a lot of df tools, a lot of which arenโ€™t even covered at all now. doesnโ€™t seem a bad change, just looks a bit too simple.

proper meteor
# slow moat idk, but it feels a bit off. I think this is just because its new and I need mor...

I'm very open to feedback so if you think something should be covered just ping me. I can't remember the reasons we didn't include that specific room, I think it was that it was an older room which some outdated info but I may be wrong.

Yeah, we did work hard, and we hope we hit the mark. The intention is that this path will give people a better chance of getting a job in a SOC or improving their skills for those currently in the role. We really tried hard to make it relevant to the role of working in a SOC.

slow moat
hazy kettleBOT
#

Gave +1 Rep to @proper meteor (current: #317 - 27)

proper meteor
proper meteor
grim folio
grim folio
#

Removing whole DFIR is a sensible decision, but removing sysinternals, sysmon, osquery, wazuh , zeek a bit disappointing

tropic flower
proper meteor
tropic flower
proper meteor
proper meteor
proper meteor
tropic flower
#

Now I have Phish Hunter

tropic flower
#

You took my Checkmark (I understand why), but did not put the Progress % back? @proper meteor

proper meteor
tropic flower
#

I should obviously be seeing some progress

proper meteor
# tropic flower yes I'm referring to the updated path there's no % listed

Ah, now I understand. That's strange. You had previously completed the SOC L1 path. It did previously show a tick, but now on the updated path, it's not showing anything even though you have lots of room complete. I'll go checking, thanks for reporting it. I wonder if it's something that it doesn't see you registered on that path anymore, so it thinks you've never joined it?

hazy kettleBOT
#

Gave +1 Rep to @tropic flower (current: #2131 - 2)

tropic flower
#

I've never joined Web Fundamentals, Web Aplication Pentesting, Red Teaming, SOC Level 2, or Advanced Endpoint... yet they have %'s

#

I imagine I don't have a % next to AWS is becuase even the free ourses are locked behind an additional paywall so I've not completed any rooms that would count towards it

proper meteor
#

Makes sense. It will probably be tomorrow before we get to look at what is happening.

tropic flower
#

Thank you, haven't noticed anything else wonky yet.

silver juniper
#

I was wondering what happened. 88% finished with the old path I guess I'll finish it up and then finish the new one right after

tropic flower
# silver juniper I was wondering what happened. 88% finished with the old path I guess I'll finis...

I might do that as well, re-earn my old certificate, then burn the new version. I noted a number of the newer courses reflect in both legacy and new, so you should be making progress in both doing either. It also looks like a number of legacy courses that are in the new path, had slight adjustments as I had completed all these rooms before but now show as 97% or 99% done. May not take long or much effort to re-knock it out anyway.

#

lol in the image above one such lists as 78% done that's almost a quarter....

true sphinx
native viper
#

I think I prefer the old one because I'm looking to get into DF & IR and the legacy path covered it to some extent. I believe this modification was done with our best interests in mind nevertheless

static widget
native viper
static widget
native viper
#

I meant by next year, It's just about 2 months away

tropic flower
# native viper I meant by next year, It's just about 2 months away

I wouldn't expect rooms to disappear, they in fact appear to have added content to several of the older rooms, moved some content around, and even modified text in at least one older room where you could only provide the "No answer needed" click after turning on the VM, then reset said button. You just aren't going to have the legacy path to use a guide to hunt those rooms down after then.

tropic flower
fast prairie
proper meteor
shut cedar
#

hi having issue with SOC L1 Alert Reporting task 4

#

THM{nice_attempt_faking_microsoft_support} should be answer but in the box it looks like this THM{nice_att_empt_fakin_g_mi_croso_ft_su}

#

not sure if Im stupid or the input box is setup wrong

floral current
#

I am also having trouble in SOC L1 reporting task 4. I tried escalating to L2 for the flag and itโ€™s not working

shut cedar
#

im skipping this ill come back later

mental dawn
#

I'm enjoying the updated learning path so far.

misty mauve
#

@floral current when you escalate the status should be in progress and not closed

silver oxide
#

Hi im having an issue with one of the task from the new path it never happen before and even the Echo IA agree with my answer idk where to escalte this issue. Also idk why i cant paste an image of it so the room is "SOC Metrics and Objectives" on task 3 "triage Metrics" the second question Imagine a scenario where an employee was lured into running data stealer malware.

  1. The SOC team received the "Connection to Redline Stealer C2" alert after 12 minutes.
  2. One of the L1 analysts on shift moved the alert to In Progress 10 minutes later.
  3. After 6 minutes, the alert was escalated to L2, who spent 35 minutes cleaning the malware.
    Provide the MTTD, MTTA, and MTTR via comma as your answer (e.g. 10,20,30).
    My answer was 12,22,63 and idk if im wrong or not cause even the Echo bot agrees with my aswers. Hope someone can help with it ๐Ÿ˜„
misty mauve
#

@silver oxide yes your answer is wrong. What helped me get the right answer was looking at the picture that had the time lines for MTTD , MTTA, MTTR drawn out

wet sedge
wet sedge
true sphinx
native viper
silver oxide
#

Ty guys for the replys ๐Ÿ˜„

raven pawn
#

do some one know why i cant luch the phising simulatyor ?

#

and im in us east

native viper
#

change your region under Manage Account

proper meteor
mental dawn
wet sedge
frail hull
frail hull
proper meteor
atomic pendant
#

Guys do you feel that some of the rooms in the soc 1 (old) have missing logs ?

atomic pendant
#

?

fallow ferry
#

soc simulator Phishing Unfolding. work fine, then saved progress, next day resume all pages work but the alert page show the above error.

vagrant ledge
vague cave
#

Am I allowed to post a screenshot of said SOC1 scenario and ask to explain why the numbers 12,10,51 and how do you actually calculate the given time from triage metrics in the example given?

atomic pendant
#

ohh cant share the screenshot lol

tribal eagle
#

Okay I'm feeling kinda dumb. I'm doing the Intro to Phishing Soc Simulator but the AI says my reports aren't detailed enough. Is there like a list of everything we are suppose to include to make it more detailed. I don't know if I missed something or what.

rugged seal
#

In snapped phishing line room, I can't get the url for Zoe Duncan correctly for some reason. I copy paste the url into cyber chef and it is not correct?

fallow ferry
rugged seal
#

turns out for some reason the link worked when I restart the machine

#

at first it was giving me an error and I took that initial link and defang it

#

but I restart the machine and the link worked and yeah

fallow ferry
fallow ferry
rugged seal
atomic pendant
rugged seal
#

@vague cave I hope this makes sense

#

I also struggled a bit but I read it again and it makes sense

atomic pendant
vague cave
hazy kettleBOT
#

Gave +1 Rep to @rugged seal (current: #3252 - 1)

median arrow
#

Hello everyone, let me ask you, are there many jobs in soc in your country currently recruiting, and which companies will prioritize soc? I am currently in Vietnam and soc jobs in Vietnam are quite diverse but they will not prioritize interns much.

ocean rapids
#

.

eager crown
#

Is it me or the Splunk:Exploring SPL room is a bit wonky atm? None of the searches for Task 4 are working.

atomic pendant
eager crown
# atomic pendant I have been asking same stuff from the past 1 week it happened with me on 2 diff...

Sometimes, they fix the bug without noticing us, so it's worth going back to those rooms that you have issues with to check if it's fixed. It happened to me in the MITRE and Phishing tool room. I still have the Windows log events and Sysmon room to go back to. If they haven't fixed whatever is wrong with it, I'll just move to different rooms. I still have so many unfinished/ not started rooms to go through.

rugged seal
rugged seal
vale saffron
#

Hey guys, i'm actually at 50% of the Soc L1 path, feel free to text me to study/train together or stay in touch for help, working sessions or whatever !

vale saffron
#

Lets go i texted you

dim juniper
#

@vale saffron hey i am new in the this field and want to learn .
Want help for where to start

native viper
#

start from the pre-security path

vast stone
#

Not sure whether I'm being an idiot, but the firewall logs in sentinel for the Soc simulator don't seem to... contain any useful info? All I'm being provided is the time it was generated and the datasource, there's no way to tell what the log is

vague cave
#

@rugged seal the answer to the question in the SOC Triage Metrics room still doesn't make any sense to me. Why would it be 51 instead of 63?

latent nebula
# vague cave <@622301023108857858> the answer to the question in the SOC Triage Metrics room ...

Let's say the incident happened at 10 am but SOC received the alert 12 mins after the incident happened which will be 10.12 am.

Remember, SOC L1 received the alert at 10.12 am (and from here MTTR counting starts).
After 10 mins, i.e. at 10.22 am SOC L1 analyst moved the alert to 'In progress'.
After 6 mins, i.e. at 10.28 am alert is escalated to SOC L2 analyst.
After 35 mins, i.e. at 11.03 am, SOC L2 finished his work.

So, MTTR is from 10.12 am to 11.03 am which is 51mins.

vague cave
hazy kettleBOT
#

Gave +1 Rep to @latent nebula (current: #3252 - 1)

digital pier
vague cave
# digital pier is this talking about mean time to repair?

Yeah sounds like it. but I have to argue that it is wrong because the MTTD, MTTA and MTTR is actually 63 minutes, not 51. I just spoke to an experienced SOC friend who has been in the field for 8 / 9 years now and he has explained to me it should be from the start to the end - fire started to fire extinguished as an example used by him.

#

Lol he just corrected himself and said if THM is going on the NIST scale, it's correct

digital pier
#

so 51 is correct?

vague cave
digital pier
#

and what's the NIST scale?

vague cave
#

let me find it for you

digital pier
#

thx

vague cave
digital pier
#

Thanks so much

#

this helps a lot

vague cave
#

@digital pier I love your bio, it's funny

digital pier
#

Thanks inspired by my friend

vagrant ledge
vagrant ledge
hazy kettleBOT
#

Gave +1 Rep to @vagrant ledge (current: #101 - 88)

vast stone
#

Seemingly everyone else is doing it in Splunk so maybe I'm better off just switching over

fallow ferry
vast stone
sleek torrent
#

should i post every room that i completed in thm on linkedin or would that be too much?

forest horizon
#

Hi. Quick question, I'm trying to complete the updated SOC Analyst L1 path. Done everything except the File and Hash Threat Intel room. Managed todo everything but the only thing holding me back is the question "When was the first time the file was recorded in the wild? (Answer Format: YYYY-MM-DD HH:MM:SS UTC)" whenever I input the the right answer, it keeps saying "Uh-oh! The answer you provided may not be in English. Please review it and try again". Any ideas?

tropic flower
forest horizon
# tropic flower You do you, whatever you want, your situation may be different as well, as in if...

Hi. Quick question, I'm trying to complete the updated SOC Analyst L1 path. Done everything except the File and Hash Threat Intel room. Managed todo everything but the only thing holding me back is the question "When was the first time the file was recorded in the wild? (Answer Format: YYYY-MM-DD HH:MM:SS UTC)" whenever I input the the right answer, it keeps saying "Uh-oh! The answer you provided may not be in English. Please review it and try again". Any ideas?

tropic flower
hazy kettleBOT
#

Gave +1 Rep to @tropic flower (current: #1607 - 3)

forest horizon
#

Has anyone done the updated SOC Analyst L1 path?

misty mauve
forest horizon
fallow ferry
forest horizon
hazy kettleBOT
#

Gave +1 Rep to @fallow ferry (current: #113 - 83)

hazy kettleBOT
#

Gave +1 Rep to @tropic flower (current: #1289 - 4)

vale saffron
#

Hello blue team, starting my day with the Network Security Chapter ! Good luck to everyone

runic coral
#

Has Yara been removed from the new updated soc level 1 pathway?

native viper
#

Yeah. Iโ€™m glad I did it in the old path though

runic coral
forest horizon
fallow ferry
forest horizon
#

I've done everything else in that room barring that error.

fallow ferry
#

what exactly the question you having issue with? can you copy and paste the question here

forest horizon
#

When was the first time the file was recorded in the wild? (Answer Format: YYYY-MM-DD HH:MM:SS UTC).

#

Whenever I input the timestamp it keeps coming up as an error.

#

Error: Uh-oh! The answer you provided may not be in English. Please review it and try again.

fallow ferry
#

which task number the question is?

forest horizon
#

Task 5, Q3

fallow ferry
#

which one these you are using

forest horizon
#

First Submission. There was no First Seen In the Wild when I went onto VirusTotal.

fallow ferry
#

above is from VirusTotal under Details tab

forest horizon
#

I'm on there, but I don't see "First Seen In The Wild". There's 4 instead of 5.

#

Found it now. I was using the wrong hash.

#

Done it.

vale saffron
#

I'm doing the Data Exfiltration Monitoring, such a great room

vagrant ledge
vale saffron
hazy kettleBOT
#

Gave +1 Rep to @vagrant ledge (current: #100 - 89)

vale saffron
#

2 little questions if you don't mind

#

In Task 6 (Data Exfil via HTTP), you mention the beaconing method, why "followed by large uploads" ? if sending by small request to be low and slow why changing and suddently sending large chunks ?

#

And second question how can i see/export the data text ASCII out of that view ? hard to read + can't copy from here but i didn't find any other place where it's displayed

swift bay
#

Wait, the legendary @fallow ferry is on here??? Your videos have gotten me unstuck from countless binds. Thank you for doing what you do!

hazy kettleBOT
#

Gave +1 Rep to @fallow ferry (current: #111 - 84)

pale dirge
#

Guys did anyone used sentinel in introduction to phishing ?

#

seems like its completly useless

proper meteor
swift bay
# vale saffron

Try the "...as C String" option in that right-click menu. I think that's what I did.

pale dirge
hazy kettleBOT
#

Gave +1 Rep to @swift bay (current: #622 - 11)

swift bay
#

Somebody says "es-oh-see" instead of "sock", lol

obsidian prism
#

is SOC simulator only for business?

vague cave
#

I have a problem here that needs clarification. Will post screenshots with spoiler tag. Why does it ask for 2 IP's defanged but it's the same IP repeated and I found a 3rd, why was this not counted in the Phishing Analysis Tools room? Really gave me a hard time copying and pasting which meant that I needed to manually add everything instead.

#

Spoilered screenshots.

vague cave
vale saffron
#

I don't understand your question tbh

#

You went on the text report right ?

#

In Network activities you see all the connections done by the malware, with a reputation tag for each

#

in the list there is 2 with "Malicious" tags (the second one apears two times because he's call by 2 differents PID but the IP/domain is the same)

#

Use cyberchef to defange them and let's go ? or i'm missing smthng

vale saffron
#

Hello everybody

#

It looks like the file names in picture and i the explainations about line 2 and 3 are not matching no ? Room Living Off The Land Attack Task4

iron drum
#

Uh i took a break and now i am back i see soc level 1 legacy path i have done it 70% and new one 31% so should i complete the legacy or switch to new one?

hasty gazelle
vale saffron
fast prairie
hazy kettleBOT
#

Gave +1 Rep to @vale saffron (current: #3262 - 1)

vale saffron
#

nice thanks

vale saffron
#

File And Hash Threat Intel room, Task 4:
Which other process was spawned according to the process tree?

I found the answer on a walkthrough, I still don't get in on hybrid-analysis.com

(https://hybrid-analysis.com/sample/2672b6688d7b32a90f9153d2ff607d6801e6cbde61f509ed36d0450745998d58/690730dafbc9f27cfb0c2277)

swift bay
native viper
#

after losing streaks multiple times I finally hit this milestone

native viper
#

Thx!

obsidian prism
#

can anyone help me with this? i'm doing Elastic ELK room, it gives me 502 Bad gateway when i try to visit the ELK Instance...

pale dirge
#

ELK room after splunk room ?

obsidian prism
obsidian prism
#

and the configuration file is the newest

native viper
#

I suggest you terminate the machine, refresh the thm page, and restart the attached machine

obsidian prism
#

i mean exactly

pale dirge
#

it's not working after upddate

#

When I was trying to do it few days ago it didn't have any logs

native viper
#

It does, i completed it yesterday

pale dirge
#

really ?

#

ok so I have to go back to it

obsidian prism
#

oh wait, it's working now, but not a few minutes ago

#

thanks all

vale saffron
#

Hello,

IP And Domain Threat Intel (Task 4)
Using search.censys.io, identify the TLS certificate fingerprint for the IP address.

Need an update I guess, answer changed on censys.

lyric oasis
calm comet
# vale saffron Same, i get stopped at 98% ahah

Curious to know what you guys ended up doing. The new version seems to focus a lot more on methodology instead of specific tooling like the legacy one. Debating on just finishing the legacy one since I was at 78% and shot down to 40% on the new one.

rugged seal
#

I'm in the snort room and I made rule in the local.config files

#

why did this happen?

calm comet
calm comet
#

Im looking at my notes from that room, on my end I have a semi colon at the end of the sid, as well as a "rev:1;" that follows the SID. That seemed to have got me by

#

It also looks like I was running Snort with sudo privileges which might help

calm comet
# rugged seal

If I had to pick anything I listed above, it would be that you are missing the ";" that is supposed to follow the SID. I dont think the rev or sudo privs are a necessity.

rugged seal
#

I rewrite the rules again

calm comet
#

Same error?

rugged seal
#

yep

calm comet
#

Oh you are also missing a ":" in front of the first SID

#

You have sid100001 is should be sid:1000001

rugged seal
#

ayyyyy

#

it ran

#

thank you :DDD

#

my dumbass forgot the ":"

calm comet
#

Niceeeee

rugged seal
#

I have been struggling with this for so long

calm comet
#

Yeah I remember I kept forgetting colons and semi colons during the Snort rooms. It can be a pain but its pretty rewarding once you get through all of the tasks.

wet sedge
#

75% through this learning path. And on day 73 on THM! Itโ€™s exciting to see these concepts becoming clearer and sharper in my mind.

nova roost
vale saffron
visual rune
#

Does anybody know the answer to this and how to find out spl query for this question. How many log events are captured by the user Maleena? @lost kernel

calm comet
calm comet
rugged seal
#

does anyone struggle to run splunk in the attack box?

hushed goblet
hushed goblet
teal wadi
#

One message removed from a suspended account.

pale dirge
#

can u give link to the room

teal wadi
#

One message removed from a suspended account.

pale dirge
#

THM{nice_attempt_faking_microsoft_support}

teal wadi
#

One message removed from a suspended account.

#

One message removed from a suspended account.

pale dirge
#

this is flag from the next task

#

I mean 4

teal wadi
#

One message removed from a suspended account.

pale dirge
#

are u in good task for sure ?

teal wadi
#

One message removed from a suspended account.

pale dirge
#

this one

teal wadi
#

One message removed from a suspended account.

pale dirge
#

np

calm comet
#

Do you guys do practice labs outside of the learning tracks? If so, how do you guys know which practice labs you would be able to do and what not?

half mica
#

Hello!
I am scoping out courses to obtain my CYSA+ certification. I've seen SOC Level1 path is useful for hands-on training. How much material does this path contain to be ready for the CYSA+ exam?

calm comet
obsidian prism
#

can someone help me?

#

can't connect to the server

#

i am using vpn and doing exactly what the challenge guides me

#

server not found is the reponse i got

deft chasm
#

have you tried different vpn servers?

obsidian prism
#

how can i try different, i only have 1 config file for premium account

supple ridge
#

Hello TryHackMe team / moderators,
I am having an issue with the "IP and Domain Threat Intel" room, Task 4.
The SHA256 TLS certificate fingerprint for the IP 85.188.1.133, taken from Censys, is:
5ea8e6046bdabaa8e23a1a012c01d1be5ccd42c66ef2577a59f3b3f0f056d12e
However, TryHackMe keeps rejecting it with the message:
"The answer you provided may not be in English."
I tried typing it manually, ensuring no spaces or extra characters, but it still fails.
Could you please check and fix this task?
Thank you very much!

vivid lantern
#

Windows Threat Detection 1 and 3 target machines are not usable...they're on a constant loop of logging in and out - gets you in for a few seconds, then reverts to the "applying settings" blue screen and so on...that's from the browser, through VPN and RDP it just kicks you out, and same thing you can connect back where you were at, only to get kicked out again...anybody else came accross something like this and figured out what the issue is? Tried them from 2 separate machines, 1 linux and 1 windows, with the same result...

wet sedge
vivid lantern
#

Must be something on their end then...especially since I had no issues with the 2nd challenge...connected just fine through both methods.

sleek dove
#

Mondaymonitor room givem VM doesnt work with the given rev proxy url. it works if i use http://<ip>.. room suggests https:// annd rev proxy url.. the other issue is room suggests i run a saved query in wazuh but that saved query doesnt return a result even after i change the time frames

rugged seal
rugged seal
#

I think they are having issues with their servers again

ivory geode
supple ridge
#

Thanks, youโ€™re right

magic fulcrum
#

Hi everyone. Is anyone else having trouble with the ItsyBitsy room? I can't access Kibana, and I've been trying for a while now.

flat scarab
#

hi everyone IP and Domain Threat Intel room have a problem in task 4, third question the fingerprint is out-dated. needs to be updated

eager crown
wind cobalt
#

Splunk101 room has outdated VPN_Logs file (also named differently + file on attackbox and direct download are different), can't complete the lesson. Introduction to EDR earlier in the path also is having issues where the "open site" is missing information needed to give an answer.

Anyone else experiencing this?

slim rain
#

Hey folks! If anyone can tell me why I cant get the right answer in Alert Triage With Splunk > Task 2 > Question 2 that would be great! It is a single digit number and I have legitimately tried every number. Anyone else dealing with this too?

chilly bolt
#

Hello TryHackMe team / moderators,
I am having an issue with the "IP and Domain Threat Intel" room, Task 4.
The SHA256 TLS certificate fingerprint for the IP 85.188.1.133, taken from Censys, is:
5ea8e6046bdabaa8e23a1a012c01d1be5ccd42c66ef2577a59f3b3f0f056d12e
However, TryHackMe keeps rejecting it with the message:
"The answer you provided may not be in English."
I tried typing it manually, ensuring no spaces or extra characters, but it still fails.
Could you please check and fix this task?
Thank you very much!

toxic dove
hazy kettleBOT
#

Gave +1 Rep to @chilly bolt (current: #3292 - 1)

chilly bolt
hazy kettleBOT
#

Gave +1 Rep to @toxic dove (current: #453 - 16)

toxic dove
hazy kettleBOT
#

Gave +1 Rep to @chilly bolt (current: #2158 - 2)

chilly bolt
hazy kettleBOT
#

Gave +1 Rep to @toxic dove (current: #435 - 17)

raven pawn
#

Detecting Web DDoS room , for some reason on the attached vm the Splunk instance its not working and its necessary for answer the question on task 5.....

fast prairie
hazy kettleBOT
#

Gave +1 Rep to @raven pawn (current: #3294 - 1)

hazy kettleBOT
#

Gave +1 Rep to @fast prairie (current: #501 - 14)

hushed goblet
vale saffron
#

SOC Level 1 donnnnne

#

hehehe what is the next move

gritty vapor
#

Please my VMware isnโ€™t connecting and this is delaying me very frustrating . Splunk ainโ€™t opening elastic same

scenic turtle
#

Hi everyone, I finished some rooms in the soc level 1 path and I want to add thoses in my GitHub portfolio. Iโ€™m I allow to create writeups of the rooms, giving information about the questions, answers and some content in the room?

vale saffron
#

Yes of course = Dunno but a lot of people do it so I guess it's ok

sly quarry
#

Why is the answer wrong?

vale saffron
little ivy
#

Hello, for "Data Exfiltration Detection" room, specifically Task 4, the answer of "Which local IP sent the maximum number of suspicious requests?" is not 192.168.1.104 but ||192.168.1.103|| somehow, even though .104 sends more requests. Is there something I have missed perhaps?

vagrant ledge
little ivy
hazy kettleBOT
#

Gave +1 Rep to @vagrant ledge (current: #99 - 90)

hasty quest
#

Finally got to Windows Threat Detection 1 room. Btw there's a typo in the question, it asks to run www.zoom.com file. However there's www.skype.com file which may be confusing to users

#

Room link

#

Also, thank you for the incredible remake!

trail epoch
#

if someone morrocan here

fast prairie
hazy kettleBOT
#

Gave +1 Rep to @hasty quest (current: #586 - 12)

wet sedge
tardy spoke
#

Hello, how is it possible to complete the SOC path if some of the module requires B2B?. I have a premium though. Thank you!

hollow temple
#

Hello,
In the SOAR room in Task 4, shouldn't be "Contains URLs or attachments" instead of "Contains URLs of attachments" inside the playbook image example?

frail hull
cyan spoke
#

Guys, do yโ€™all think learning programming/coding is important for cybersecurity?

noble plaza
maiden pebble
#

Do basics and have an idea what's going on in the program

dim island
#

Anybody in here from the Pittsburgh area?

worn brook
#

Is there anyone from Bulgaria ?

kindred veldt
#

Good evening! I'm working on tasks in a Windows security monitoring room, and the Windows virtual machine in each room is very unstable. It freezes for 10 minutes, directories won't open, and neither restarting the virtual machine nor restarting the room helps. Has anyone else encountered this, or is it just me?

fast prairie
kindred veldt
#

There is also constant reconnection

#

The internet is definitely stable and no such issues were encountered on machines running Linux VMs

proper meteor
#

I don't know if this is your issue but I saw similar things when I was playing around with my VM region. If I move the region to a location far from where I'm located, things got quite sluggish.

violet edge
#

Need someone to tutor me๐Ÿฅน

wet sedge
#

Just finished the SOC 1!

calm ermine
#

Iโ€™m having a problem with the Splunk: The Basics room. I canโ€™t access Splunk because Firefox requires SSL/TLS after entering the machineโ€™s address. Is this Splunk instance running over HTTP? How am I supposed to open it?

raven pawn
#

Windows Threat Detection 2 task 5,,,, the question Which domain does the malware exfiltrate the data to? the script its no generating the dns query alert (event id 22) and its need it for answering the question...........

pale dirge
#

ye I had this problem just a moment ago

#

I just looked for the answer on youtube, and other guys had sysmon22 in thei events

#

I think something is wrong whith it

raven pawn
mild turret
#

guys please who has issues with his/her VM because for a while now can't access any VM

raw obsidian
#

Hi I am currently doing SOC Level 1 :Core SOC Solutions : Splunk: The Basics , I am stuck , I cannot seem to open splunk in the attack box , I started attackbox and opened firefox and entered :http://10.49.178.149:8000: but it just says unable to connect, can anyone help how to start splunk

ripe anvil
#

what is the http error code?

raw obsidian
#

im not sure it just says , "Firefox can't establish a connection to the server at 10.49.178.149:8000." , i am just trying to open splunk and the chatbot told me to open firefox in attackbox and type in ":http://10.49.178.149:8000/" and it should open splunk

ripe anvil
#

okay. give the target machine time to load up

#

splunk instances usually take 5-7mins to load up

raw obsidian
#

yeah i've been trying for past 2 hours , is there no icon in attack box to access splunk or thats right way via the firefox browser and typing in ":http://10.49.178.149:8000/"

ripe anvil
#

what is the ip of your attack box instance?

#

also there is some issue with instances today, where multiple people aren't able to access them properly. might be worth taking a break

#

I took some time off and went back to the instances after issues with my rooms

raw obsidian
#

this is my attack box ip 10.49.105.89

#

it just says unable to connect, alright i will give it a try after some hours, thanks

raw obsidian
#

ok sorry, where do i look for the target machine IP? the chatbot says its on top of the attackbox screen but that only shows the attackbox ip and not the target box ip

chilly bolt
#

Someone doing the exercise Tempest Incident?

#

my mind go to explod

little ivy
chilly bolt
tropic dragon
#

Do you reset SOC 1? I have practicing 100% path but now see 50% path. thm ๐Ÿ’ฏ

astral cedar
high marsh
#

My Analyst VM is lagging, it flickers black then wallpaper then black

tropic dragon
hazy kettleBOT
#

Gave +1 Rep to @astral cedar (current: #143 - 67)

high marsh
#

How to fix

high marsh
#

changed my browsers, it works now.

turbid robin
#

Are all SOC simulation behind the thm business service or subscription?

raven pawn
turbid robin
native viper
#

Guys I hit a snag here, I'm trying to answer this question but it seems I'm missing something

#

I used the wireshark filter: tls.handshake.extensions_server_name == "accounts.google.com"

#

I only got one result. but it seems the answer is meant to be a 2 digit number

native viper
#

Oh I got it, they are asking for the frame number not the number of the packet hehe

green ether
#

Hello - I'm doing the SOC L1 Path - just saying.
If someone fell a need to voice-chat I am open to talk.

green ether
#

catch me then

chilly bolt
#

Hello, this exercise from SOC1, Boogeyman 3, is not working

proper meteor
idle bone
#

Hello, i got a little problem
The second question in task 6 of the unified kill chain room, i answered it correctly but it's still having a space remaining and I'm pretty sure i typed the correct the answer

proper meteor
idle bone
proper meteor
proper meteor
chilly bolt
lime raft
#

HELP

#

What is the netstat parameter in MS Windows that displays the executable associated with each active connection and listening port?

raven pawn
#

on the room File and Hash Threat Intel task 3 question number 2 need to be updated virus total its already showing a different treat label to what ever the question is ....

#

i googole and it used to be this the answer trojan.graftor/flystudio

proper meteor
hazy kettleBOT
#

Gave +1 Rep to @raven pawn (current: #2230 - 2)

heady dawn
#

In room ip and domain threat intel question 4 part 3 , its asking for the tls fingerprint from censys.io , I have answered every other question but its not accepting the one I have found is there something I am missing.

proper meteor
heady dawn
heady dawn
hazy kettleBOT
#

Gave +1 Rep to @proper meteor (current: #314 - 29)

proper meteor
# heady dawn Thanks

Just tested there and it accepted the answer in the hint(ending in d12e). Could be something to do with the quotes? The accepted answer doesn't need them?

hazy kettleBOT
#

Gave +1 Rep to @proper meteor (current: #309 - 30)

cyan brook
#

Hello, I have a question about SOC Level 1. I was taking the path until I came across SOC Simulator: Upload and Conquer, which is a B2B SOC simulator. To obtain the path certificate, do I also need to complete this activity?

raven pawn
#

is there away the we can have access to the simulator whit out having a business plan ?

#

room IP and Domain Threat Intel on soc level 1 patch,,,, task#3 question 1 it need to be updated or correct the correct answered don't match whit what you find on the website .......

quasi bough
raven pawn
surreal osprey
#

I was in the SOC Level 1 Learning path and working on the Phishing Prevention room in the Phishing Analysis module and saw that something is not quite right. Its in the Task 5 about the S/MIME and it says about the public key cryptography in a opposite way.

chilly bolt
quasi bough
proper meteor
proper meteor
proper meteor
proper meteor
#

@surreal osprey The team has done an update on the text and added more clarity.

ancient lark
#

Does anyone know which ".json" file is correct for the PS ECLIPSE room? This room is for using Splunk to investigate ransomware activity.

river fable
#

anyone need help?

balmy bramble
#

is SOC level 1 free throughout or do i need premium for some modules ?

spare chasm
#

should spam emails in SIEM simulators be classed as true positive or false positive?

narrow gull
#

@spare chasm Define your โ€œpositiveโ€ clearly: What counts as a security incident in your SIEM simulation?

rose rover
#

Hi all, in SOC Metrics and Objectives > Triage Metrics > second question is telling me 12, 22, 41 is wrong. How?

full berry
native viper
#

So just look at it carefully again and you'll figure it out

hazy kettleBOT
#

Gave +1 Rep to @full berry (current: #3486 - 1)

hexed crow
#

Hi,
Iโ€™m a SOC Level 1 trainee focusing on Blue Team skills (log analysis, SIEM, incident response).
Iโ€™m looking for a beginner-friendly team to learn together and participate in CTFs (Blue/Forensics).
Goal is learning + consistency, not just winning

hazy kettleBOT
#

Gave +1 Rep to @native viper (current: #1168 - 5)

magic elm
#

Hello everyone! I have almost completed the SOC Level 1 path, I wanted to ask what is the best way to added what you have done in your resume. Has there been a wording that has brought more success and how do you add the quantitative aspect?

void rain
#

has anyone been able to successfully do the Log Analysis with Siem room successfully? The splunk link never seems to come up. I've tried 3 times over the last few hours (while doing other things)

Error is where I've seen it on other rooms prior to fully spinning up: 502 Bad Gateway

It just never seems to come up

native viper
void rain
vocal mesa
#

Suppose in 1 - 2 weeks I can begin with the SOC 1 course
Are there a lot of walktrough and/or challenges I can do to get better on the THM platform

void rain
vocal mesa
#

yep

void rain
#

that will be enough for the SOC Level 1 path

vocal mesa
#

am now at the offensive security tooling and have to do some metasploit challenges

fast prairie
hazy kettleBOT
#

Gave +1 Rep to @void rain (current: #17 - 589)

void rain
hasty gazelle
#

Hi everybody! Happy New Year! I just saw that this link is not working in the 'SOC Level 1' path, specifically at the 'IDS Fundamentals' room. The link that is not working is the one redirecting us to the 'Network Concepts' which is a prerequisite. Here are two snapshots. I hope we all have an excellent and super-productive year, completing an enormous number of rooms in this brand-new 2026.

hallow mantle
#

xin chร o tแบฅt cแบฃ mแปi ngฦฐแปi. chรบc mแปซng nฤƒm mแป›i

void rain
river fable
#

anyone needs help?

fast prairie
hazy kettleBOT
#

Gave +1 Rep to @hasty gazelle (current: #3504 - 1)

pulsar turtle
#

Edit: never mind, finally managed to get it to run and not crash. Thank you

hasty gazelle
hazy kettleBOT
#

Gave +1 Rep to @fast prairie (current: #496 - 15)

hasty quest
vocal mesa
#

With the phishing SoC challenge
Is there a good way I can see the data of the report after I decide that it is false or positive

#

?

native viper
#

hey guys, in the Web Security Monitoring room under Detecting DDos, we're supposed to do this simulation but it's only available for thm business. Does this mean I won't get the SOC L1 cert even after finishing it? (due to not completing this challenge?

proper meteor
proper meteor
quaint apex
#

Hello guys I am new in SOC I have basic knowledge of the networking SIEM and other things like IDS,IPS and Firewall.
Did anyone have have road map and is their any Qradar version with low storage requirement?

fast prairie
hazy kettleBOT
#

Gave +1 Rep to @fast prairie (current: #474 - 16)

vocal mesa
#

How can I make it work that the table uses the filtered data :

hasty gazelle
#

Hi. For info. This link is not working. https://tryhackme.com/room/owasptop102021
It is part of the prerequisites for the room 'Detecting Web Attacks' (https://tryhackme.com/room/detectingwebattacks) in the 'SOC Level 1' path.

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

TryHackMe

Explore web attacks and detection methods through log and network traffic analysis.

hasty gazelle
vocal mesa
#

Thanks

#

I made a visual on the date range and then I can filter it on action and got the right answer ๐Ÿ™‚

#

now soar on the menu ๐Ÿ™‚

fast prairie
hazy kettleBOT
#

Gave +1 Rep to @hasty gazelle (current: #2276 - 2)

low niche
#

How's it going everyone. I'm relatively new (been in school for a cybersec op bachelor's for 2 years now though). Just started the SOC level 1 section. Its been really good. Wish I had tried out the site sooner really great experience.

#

Anywho. Yeah I joined the discord because it has been really fun and I just wanted to see the kind of stuff other people have been doing in it lol

vocal mesa
#

@low niche have fun

vocal mesa
#

Why is this answer wrong

vocal mesa
#

no - one ???

wanton vector
#

Sometimes its a bug

vocal mesa
#

yep, tried that several times

wanton vector
vocal mesa
#

yep, there is the same answer everywhere

#

getting crazy, tried yet again and now the answer is right

#

HTM platform is wierd

#

@wanton vector thanks for the effort to help me

hazy kettleBOT
#

Gave +1 Rep to @wanton vector (current: #1184 - 5)

lyric trout
#

Hey everyone. Fellow SAL-1 learner here. I'm attempting to see who won the prizes from the AOC2025...more specifically, those SAL1 fee certs. Where can I find that info???

vocal mesa
#

@lyric trout welcome

proper meteor
vocal mesa
#

@proper meteor cannot wait

#

may we have a hint ??

vocal mesa
#

IM stuck at phising-line room question 6
Where I have to find the sha256 sum of the root-kit
and as hint I get use enumeration
But how can I use for example gobuster when there are no wordlists installed on the attackbox ?

tight sphinx
#

Hi, has anyone done the SOC Metrics and objectives module?

#

I'm stuck at core metrics task 2: FPR rate if only 10 out 0f 50 alerts appear rea threats
According to theory FPR = false positive / total alerts
I entered the answer and it's wrong

vocal mesa
#

How did you calculate the answer ??

#

@tight sphinx

tight sphinx
#

@vocal mesa sorry forgot to edit the message. Initially my logic was flawed, I skipped a step

vocal mesa
#

NP

happy that you solved it

tight sphinx
#

@vocal mesa Thanks :)

fathom swanBOT
#
Pong!
API Latency

122ms

Client Ping

158ms

vocal mesa
#

Can someone help me figure out how to solve this question

What is the total number of the "TCP Connect" scans?

WireShark : traffic analysis room

tight sphinx
full ice
#

They say use:

tcp.flags.syn==1 and tcp.flags.ack==0 and tcp.window_size > 1024

I dont quite understand why "tcp.window_size > 1024" is important, it could be to set the limit greater than to every 1024 viewed packet.

glacial vigil
#

I have a problem when working on the course in part 4: Practical: Defend FakeBank when I click view site I can't find the answer, can you help me with the answer?

quaint apex
#

Hello guys,
I am stucked in SOC L1 Alert reporting
The question is
What flag did you receive after correctly escalating the alert from the previous task to L2?
Note:If you correctly escalated the alert earlier,just edit the elart and click "save" again
MY ANSWER IS
THM{nice_attempt_faking_microsoft_support}
But it says incorrect answer I search on internet and medium.com website blog also show this answer.
CAN ANYONE PLEASE HELP ME IN THIS QUESTION

vocal mesa
full ice
vocal mesa
#

I did but this do not give a lot of more info :

The filter 'tcp.window_size <= 1024' is used to capture TCP SYN packets with a window size of 1024 bytes or less. This may help identify connections that are potentially limited in bandwidth or resources, which can be indicative of specific network conditions or configurations. It's useful in distinguishing between high-capacity and low-capacity connections during analysis. Make sure to review the task details for more insights.
full ice
vocal mesa
#

no hurry

vocal mesa
#

pff, the wireshark advanced filtering is hard

vocal mesa
#

may I have a hint on the question in red

low harbor
#

Hey ive seen the mail about SOC L1 getting an upgrade. Im about to start the path. Should i start now or will there be updates that i should wait for?

native viper