root@thehacksparrow:~/writeups$ SYSTEM ONLINE
root@sparrow:~/writeups$ cat linux-threat-detection-1.md
// Blue Team & SOC

Linux Threat Detection 1

5 Apr 2025 · 9 min read · root access
Linux Threat Detection 1 is a Blue Team room focused on detecting Linux attacks through log analysis. It walks through three initial-access vectors: SSH password brute forcing, exploitation of a web service vulnerable to command injection, and process-tree analysis with auditd to reconstruct the execution chain.

Room facts

PlatformTryHackMe
CategoryBlue Team & SOC — Threat Detection / Log Analysis
DifficultyMedium
RoomLinux Threat Detection 1
Before this room it helps to have completed Linux Logging for SOC (common Linux log sources), to know the basics of the MITRE ATT&CK framework (tactics and techniques), and to be comfortable with the basic Linux CLI.
🔒 Clearance required

This content is Root Access only. Everything else on the site — the free tier, the whole public library — stays open.

See Root Access plans

No account? Create one free then upgrade from your console.