Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

419 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

TryHackMe Badge

β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—
β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β•šβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β•šβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•
β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ•— β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•  β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• 
β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘  β•šβ–ˆβ–ˆβ•”β•    β•šβ–ˆβ–ˆβ•”β•  
β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•   β–ˆβ–ˆβ•‘      β–ˆβ–ˆβ•‘   
β•šβ•β•  β•šβ•β•β•šβ•β•  β•šβ•β•β•β•β•šβ•β•β•β•β•β•    β•šβ•β•      β•šβ•β•  

SOC Analyst in Training Β· Blue Team Β· TryHackMe Top 5%


TryHackMe Rank Rooms SOC LinkedIn


β”Œβ”€β”€(andyyγ‰Ώkali)-[~/Cybersecurity-Writeups]
└─$ whoami

  Andrew D Souza     | Final-year BCA Student

β†’ Target Role        : SOC Analyst L1
β†’ Focus              : Blue Team Β· Threat Detection Β· Incident Response
β†’ Currently On       : THM SOC Level 1 (Splunk, Detection Engineering)
β†’ Certifications     : Google Cybersecurity Professional Certificate (in progress)
β†’ End Goal           : Cloud Security Engineer

What This Repository Is

This is my structured cybersecurity learning journal β€” every room I complete on TryHackMe gets documented here as a write-up.

Not just what I did, but why it matters in a real SOC environment.

Each write-up follows a consistent format:

  • Key findings
  • Hands-on activities
  • SOC Analyst relevance table
  • Key takeaways

"If you can't explain it simply, you don't understand it well enough."


Stats

Metric Value
Global Rank Top 5%
Title [0x9][MAGE]
Active Streak 46+ days
Rooms Completed 106+
Write-ups Actively updated

Why This Maps to SOC Work

A few direct lines from lab to job floor:

  • Log Fundamentals + SIEM β†’ triaging alerts, spotting anomalies in Splunk before they escalate
  • Wireshark + TCPdump + Nmap β†’ reading traffic to confirm or rule out a suspected compromise
  • Incident Response + Digital Forensics β†’ following an IR lifecycle from detection through containment
  • Active Directory + Windows fundamentals β†’ understanding the environment most SOC alerts originate from

Repository Structure

Cybersecurity-Writeups/
β”‚
β”œβ”€β”€  README.md
β”œβ”€β”€  attacks-and-defenses/
β”‚   β”œβ”€β”€ cryptography/
β”‚   β”œβ”€β”€ eternal-blue/
β”‚   β”œβ”€β”€ exploitation-basics/
β”‚   β”œβ”€β”€ metasploit/
β”‚   └── password-attacks/hydra/
β”œβ”€β”€  computer-fundamentals/
β”œβ”€β”€  cybersecurity/
β”œβ”€β”€  google-cybersecurity-professional-cert/
β”œβ”€β”€  linux/
β”œβ”€β”€  malware-analysis/
β”œβ”€β”€  network-concepts/
β”œβ”€β”€  os-basics/
β”œβ”€β”€  soc-security-operations-center/
β”‚   β”œβ”€β”€ blue-team-fundamental/
β”‚   β”œβ”€β”€ digital-forensics/
β”‚   β”œβ”€β”€ edr/
β”‚   β”œβ”€β”€ ids/
β”‚   β”œβ”€β”€ incident-response/
β”‚   β”œβ”€β”€ log/
β”‚   β”œβ”€β”€ nmap/
β”‚   β”œβ”€β”€ ping/
β”‚   β”œβ”€β”€ siem/
β”‚   β”œβ”€β”€ soc-level-1/
β”‚   β”œβ”€β”€ splunk/
β”‚   β”œβ”€β”€ tcpdump/
β”‚   β”œβ”€β”€ threat-intelligence/
β”‚   β”œβ”€β”€ vulnerability-scanning/
β”‚   └── wireshark/
β”œβ”€β”€  software-basics/
β”‚   β”œβ”€β”€ javascript/
β”‚   └── python/
└──  web-security/
    β”œβ”€β”€ burp-suite/
    β”œβ”€β”€ gobuster/
    └── sqlmap/

Completed Rooms

SOC & Blue Team

Room Difficulty Write-up
SOC Fundamentals Easy βœ…
Security Principles Easy βœ…
Log Fundamentals Easy βœ…
Incident Response Easy βœ…
Digital Forensics Easy βœ…
SIEM Basics / Splunk Basics Easy βœ…
Introduction to EDR Easy βœ…
IDS Fundamentals Easy βœ…
Threat Intelligence: Pyramid of Pain Easy βœ…
Defensive Security Intro Easy βœ…
Operating System Security Easy βœ…
Become a Defender Easy βœ…

Network Traffic Analysis

Room Difficulty Write-up
Wireshark Easy βœ…
TCPdump Easy βœ…
Nmap Easy βœ…
Vulnerability Scanning Easy βœ…

Networking

Room Difficulty Write-up
OSI Model Easy βœ…
Intro to LAN Easy βœ…
DNS in Detail Easy βœ…
HTTP in Detail Easy βœ…
Networking Core Protocols Easy βœ…
Networking Secure Protocols Easy βœ…
How Websites Work Easy βœ…
Firewall Fundamentals Easy βœ…

Cryptography & Attacks

Room Difficulty Write-up
Hashing Basics Easy βœ…
Cryptographic Concepts Easy βœ…
Hydra Easy βœ…
Metasploit (Intro / Exploitation / Meterpreter) Easy βœ…
EternalBlue Easy βœ…

Web Security

Room Difficulty Write-up
Web Application Basics Easy βœ…
JavaScript Essentials Easy βœ…
Burp Suite Basics Easy βœ…
Gobuster Basics Easy βœ…
SQLMap Basics Easy βœ…
OWASP Top 10 Easy βœ…

Linux

Room Difficulty Write-up
Linux Fundamentals Part 1-3 Easy βœ…
Linux CLI Basics Easy βœ…
Linux Shell Easy βœ…

Windows

Room Difficulty Write-up
Windows Fundamentals 1-3 Easy βœ…
Windows CLI / Command Line / PowerShell Easy βœ…
Active Directory Basics Easy βœ…

Malware Analysis

Room Difficulty Write-up
CAPA the Basics Easy βœ…
CyberChef the Basics Easy βœ…
FLARE-VM the Basics Easy βœ…
REMnux Getting Started Easy βœ…

SOC Skills Map

SKILL                    TOOLS & CONCEPTS COVERED
─────────────────────────────────────────────────────────
Log Analysis         β†’   Log Fundamentals, SIEM, Splunk
Network Analysis     β†’   Wireshark, TCPdump, Nmap
Threat Detection     β†’   SIEM, EDR, IDS, Alert Triage
Threat Intelligence  β†’   Pyramid of Pain, IOC Analysis
Malware Analysis     β†’   CAPA, CyberChef, FLARE-VM, REMnux
Digital Forensics    β†’   Evidence Handling, Autopsy
Cryptography         β†’   Hashing (MD5/SHA), Hydra
Web Security         β†’   Burp Suite, Gobuster, SQLMap, OWASP Top 10
OS Hardening         β†’   Linux, Windows, Active Directory
Incident Response    β†’   IR Lifecycle, Containment, Recovery

Tools & Platforms

Kali Linux TryHackMe Wireshark Linux Windows GitHub Nmap Python Cisco SIEM Splunk Enterprise Wazuh Microsoft Sentinel Elastic ELK Burp Suite SQLMap OWASP Hydra Metasploit


Disclaimer

All write-ups are created for educational purposes only. All activities are performed inside legal, controlled lab environments provided by TryHackMe. No real systems were targeted. Always hack ethically.


╔══════════════════════════════════════════════════════╗
β•‘           BUILT IN PUBLIC. LEARNING OUT LOUD.        β•‘
β•‘                                                      β•‘
β•‘   Every commit is a step closer to the SOC floor.    β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

Andrew D'Souza (Andyy)

TryHackMe LinkedIn GitHub

Releases

Packages

Used by

Contributors