root@thehacksparrow:~/writeups$ SYSTEM ONLINE
root@sparrow:~/writeups$ cat file-and-hash-threat-intel.md
// Blue Team & SOC

File and Hash Threat Intel

23 Oct 2024 · 10 min read · user access
File and Hash Threat Intel is an Easy-difficulty Blue Team room on TryHackMe aimed at SOC analysts. You step into the shoes of an L1 analyst who must triage suspicious binaries flagged by EDR and decide, in under 60 minutes, whether they are benign or malicious. The walkthrough teaches how to spot deceptive filenames, compute file hashes on Windows, and enrich the investigation with VirusTotal, MalwareBazaar, and Hybrid Analysis, mapping behavior to MITRE ATT&CK.
PlatformTryHackMe
CategoryBlue Team & SOC
DifficultyEasy
RoomFile and Hash Threat Intel

Task 1 — Introduction

No questions. The room sets the scene: you are an L1 analyst and several binaries have been flagged by EDR tooling. Your job is to analyze them and determine whether they are benign or malicious within a 60-minute window, mirroring the real pressure of a SOC shift.

🔒 Free account required

This is USER ACCESS content — free to unlock, no payment. The rest of the write-up (and everything else at this level) opens up once you're signed in.

Create a free account