Home › SOC‑Simulator

The SOC‑Simulator: practise as you would in a security team

In the SOC‑Simulator an alert comes up on your screen, and you have to decide what to do now. This page explains in simple terms what a SOC is, how a case proceeds and what is measured along the way. And it shows where your teacher is involved.

Try it out · takes one minute

An alert has come in. What do you do?

This is what the work looks like: a message lands in the queue, and you decide whether there is a real attack behind it or a false alarm. That is exactly what you practise in the SOC‑Simulator – there with real tools, here just to look at.

Medium Login from an unusual country ALRT-4471
Time
03:14, Berlin local time
Source IP
41.203.88.17 — Nigeria
Result
Login successful, first attempt
Device
never seen before with this account
Afterwards
14 mailbox rules created, all of them forward mail

From the company documentation: Nordwerk GmbH, mechanical engineering. Sites in Germany and Poland only. The field staff travel within Europe. Trips to Africa are not planned.

Your verdict in the Case Report:

The real simulator runs in the browser, with an embedded SIEM and an Analyst VM. Some of the scenarios are open without payment too, in a limited version — so you can take a look beforehand. TryHackMe is an independent company; the simulator does not belong to us, we teach with it. To the SOC‑Simulator at TryHackMe →

How you practise here

Here the work of a security team is done, not described

Many training programmes funded with a Bildungsgutschein teach with slides, practice exercises and an exam at the end. With us, from week 24 you work for seven weeks in the SOC‑Simulator by TryHackMe, with real tools and real alerts. We cannot say for the whole market whether other providers do this too.

Teaching with slides

  • Slides and practice exercises
  • One certification at the end
  • The work of a security team is described

This is how we teach

  • Seven weeks of shifts in the simulator, from week 24
  • Three certifications along the way: SEC0, SEC1, SAL1
  • The work of a security team is done – with real tools, real alerts and a metric that measures your speed

We cannot judge whether another training programme works in a similar way. There are several hundred approved providers in Germany, and we have not seen every curriculum.

The framework around it

A shift in the security team, from 8:00 to 16:00

The alert you have just seen was one of many. This is what the day it belongs to looks like – and this is exactly the day you practise in the simulator, week after week.

08:00

Handover from the night shift

What is still open, what was escalated, what to look out for today.

08:14

The first alert lands in the queue

Exactly the one from above. You assign it to yourself – from this moment the clock is running.

That was your test
08:16

Checking what really happened

The account logs in the SIEM. Checking the IP address in the Analyst VM. Looking up in the Documentation where the company actually has sites.

08:31

The Playbook says what to do now

There is a fixed procedure for every type of alert – as in real security teams. You follow it instead of guessing.

08:44

Case Report and escalation

True Positive. You write down what you found and pass the case on to the next level. Time so far: 30 minutes.

MTTR 00:30
until 16:40

The next alert. And the one after that.

Some are done in two minutes, others take an hour. Most are false alarms – spotting them is the real skill.

MTTRMean Time to Resolve – how quickly you reach a decision
Accuracywhether your decision is correct, not just how fast it came
Pointsthe simulator adds the two together
As a teamyou can also work through a shift together

What you'll work with

Six areas, as in a real security team

These are not names we made up – this is what the areas are called in the simulator, and they have similar names in the profession.

Dashboard

The overview

How many alerts are open, what is urgent, how the team compares.

Alert Queue

The queue

This is where the alerts come in. You take one, and from then on you are responsible for it.

SIEM

The logs

The search system across all events. Who logged in and when, which computer sent data where.

Analyst VM

Your own computer

A sealed-off workstation with tools – among other things, to check addresses and files without picking up an infection.

Documentation

The company file

What this company does, where it has sites, which software is normal there. Without that you cannot judge an alert.

Playbooks

The fixed procedure

A set path for every type of alert. This is how real security teams work – so that nobody improvises in an emergency.

Where the simulator comes from. The SOC‑Simulator is a product of TryHackMe. TryHackMe is an independent company and a third-party brand; it is not part of the CYBERSQUAD Akademie. We use the platform as a learning tool in our lessons.

Have a look yourself. Some of the scenarios are open without payment too, in a limited version. If you want to know whether this kind of work suits you, you can try it out there before you register with us. To the SOC‑Simulator →

The exams come from there too. SEC0, SEC1 and SAL1 are run by TryHackMe, not by us. You can fail – anyone who does not pass the first time gets a second attempt, free of charge. The final certificate for the training programme is issued by us – our own provider certificate, with the approval number of the programme.

And what we do not promise. We are a training provider, not a job placement service. We cannot promise you a job. What we do: teach you the craft and practise job applications with you.

The simulator is part of the training programme “AI-Driven Security Operations Specialist”. The start is planned for Monday, 2 November 2026 – for that we need a minimum number of registrations. If too few people register, we will postpone the start by two to four weeks and let you know straight away.

Honest answers

This is what almost everyone asks us about the simulator

Short answers to the questions that come up again and again in our consultations.

Do I need prior knowledge to work with it?
No. The training programme starts from zero. By the time you sit in the simulator for the first time, you will have a good five months of basics behind you: computers, networks, security work.
Is this a computer game?
No. There are points and a leaderboard within the group, that is true. But the tasks themselves are real steps of the job: checking alerts, deciding, writing a report, closing the case.
Do I have to practise alone in the evenings?
No. Lessons take place live from Monday to Friday. The training programme has no self-study parts that you have to work through alone at home.
Is everything in English?
Lessons are in German, and your instructor explains in German. You need to understand and speak German well enough to follow the lessons — we do not require a particular level. Parts of the practice platform and of the specialist materials are in English. The technical terms in them are part of the job, and everyone learns them from scratch, native speakers included.
Do I need a powerful computer?
No. The simulator runs in the browser. We provide the laptop and the headset. You need a quiet place and a stable internet connection.
What happens if I get a case wrong?
That is exactly what a practice environment is for. Nothing breaks, no company is harmed. The case is reviewed, your instructor goes through it with you, and then the next one comes.
Do I get a certificate for the simulator?
Not for the simulator itself. At the end of Phase 4 there is the SAL1 exam at TryHackMe. Anyone who passes it receives that certification in addition. The final qualification of the training programme is the CYBERSQUAD Akademie's own provider certificate.

Two minutes. Then you know which rule applies to you.

Three questions, no sign-up and no obligation.

Marsí · WhatsApp Appointment · 1 click