Skip to main content
All CollectionsSOC SIM
How to Use TryHackMe SOC SIM
How to Use TryHackMe SOC SIM

This is a guide on how to use TryHackMe SOC SIM

Blackout avatar
Written by Blackout
Updated over a week ago

How Do I Access SOC SIM?

To access the SOC SIM head over to here and select “Launch Simulator”

How Do I Start a Scenario?

To start a scenario, press start on one of the following scenarios:

You will be prompted with this screen, whilst the VM and simulator load:

Once this has fully loaded, you will be prompted with this screen:

How Do I Assign An Alert?

To assign an alert, select “Alert Queue” which is on the left of the screen:

Once you are in the alert you will have a few alerts pop up, depending on which scenario you are doing. Here you will be able to see all the alerts that have came in so far. You can click the drop down arrow to expand the alert and look at more information on how the alert came in:

To assign the alert, press the head icon on the right side to assign it to the “Assigned Alert”

Your alert will now show up in “Assigned Alert(s)”

How Do I Write A Case Report?

Once you have assigned alerts, you will be able to write a case report. The write case report is above the assigned alert

You will get a prompt to choose whether it’s a “True Positive” or “False Positive”

  • True Positive (TP): The system correctly detects and alerts on an actual threat

  • False Positive (FP): The system incorrectly flags something as a threat that isn’t one

Once selected one of the options, you will be moved to this screen, where you will be able to fill out the details of the alert and can choose to escalate the alert:

Once you have filled out your report with the details, you can hit “Submit and close alert”

After you have closed the alert out, you will be sent back to alert queue to look at more alerts and repeat the same process

How Do I Finish the Scenario?

You will need to identify all the true positive alerts to pass the scenario.

Passed:

You will get this screen once you have identified all True Positives and it will look like this:

Failed:

If you fail the scenario, you will get this screen if you ran out of time or was unable to identify all True Positives:

Having Issues?

Contact [email protected] to resolve any issues you may have with the SOC SIM

Are you an existing B2B or EDU customer and still have questions?
Please reach out to your Customer Success Manager or Technical Support for assistance.

Interested in Learning if TryHackMe is Right for Your Organization?
Contact us at [email protected] to explore how TryHackMe could benefit your organization. Alternatively, you can book a meeting directly with our Sales team:

Did this answer your question?