root@sparrow:~/writeups$ cat linux-threat-detection-1.md
// Blue Team & SOC
Linux Threat Detection 1
5 Apr 2025
· 9 min read
· root access
Linux Threat Detection 1 is a Blue Team room focused on detecting Linux attacks through log analysis. It walks through three initial-access vectors: SSH password brute forcing, exploitation of a web service vulnerable to command injection, and process-tree analysis with auditd to reconstruct the execution chain.Room facts
| Platform | TryHackMe |
| Category | Blue Team & SOC — Threat Detection / Log Analysis |
| Difficulty | Medium |
| Room | Linux Threat Detection 1 |
Before this room it helps to have completed Linux Logging for SOC (common Linux log sources), to know the basics of the MITRE ATT&CK framework (tactics and techniques), and to be comfortable with the basic Linux CLI.
Linux Threat Detection 1 es una sala de tipo Blue Team centrada en detectar ataques a Linux mediante análisis de logs. Recorre tres vectores de acceso inicial: fuerza bruta contra SSH, explotación de un servicio web vulnerable a inyección de comandos y análisis del árbol de procesos con auditd para reconstruir la cadena de ejecución.Ficha
| Plataforma | TryHackMe |
| Categoría | Blue Team & SOC — Threat Detection / Log Analysis |
| Dificultad | Medium |
| Room | Linux Threat Detection 1 |
Antes de esta sala conviene haber completado Linux Logging for SOC (fuentes de logs habituales en Linux), tener nociones del framework MITRE ATT&CK (tácticas y técnicas) y manejar la CLI básica de Linux.
🔒 Clearance required
This content is Root Access only. Everything else on the site — the free tier, the whole public library — stays open.
See Root Access plansNo account? Create one free then upgrade from your console.
🔒 Nivel de acceso insuficiente
Este contenido es solo para Root Access. Todo lo demás del sitio — el nivel gratuito, toda la biblioteca pública — sigue abierto.
Ver planes de Root Access¿Sin cuenta? Crea una gratis y luego mejora desde tu consola.