Home › SOC‑Simulator
The SOC‑Simulator: practise as you would in a security team
In the SOC‑Simulator an alert comes up on your screen, and you have to decide what to do now. This page explains in simple terms what a SOC is, how a case proceeds and what is measured along the way. And it shows where your teacher is involved.
Try it out · takes one minute
An alert has come in. What do you do?
This is what the work looks like: a message lands in the queue, and you decide whether there is a real attack behind it or a false alarm. That is exactly what you practise in the SOC‑Simulator – there with real tools, here just to look at.
- Time
- 03:14, Berlin local time
- Source IP
- 41.203.88.17 — Nigeria
- Result
- Login successful, first attempt
- Device
- never seen before with this account
- Afterwards
- 14 mailbox rules created, all of them forward mail
From the company documentation: Nordwerk GmbH, mechanical engineering. Sites in Germany and Poland only. The field staff travel within Europe. Trips to Africa are not planned.
Your verdict in the Case Report:
Correct — True Positive
Close, but not quite — it is a True Positive
Three things together settle this case: the login at 3 in the morning from a country where the company does not operate; a device that has never been seen before with this account; and immediately afterwards 14 forwarding rules in the mailbox. Each one on its own could be explained. Together it is an account takeover — and the rules make sure the attacker keeps reading the mail.
The thinking is right: a lot of what looks unusual is harmless. But here three unusual signs come together — 3 in the morning, a country with no link to the company, a device never seen before. And then the 14 forwarding rules right afterwards. That is not a coincidence, that is an account takeover.
In the simulator you then write the Case Report and decide whether the case gets escalated. One of the things measured is how long you take to reach a solution — this metric is called MTTR, Mean Time to Resolve.
The real simulator runs in the browser, with an embedded SIEM and an Analyst VM. Some of the scenarios are open without payment too, in a limited version — so you can take a look beforehand. TryHackMe is an independent company; the simulator does not belong to us, we teach with it. To the SOC‑Simulator at TryHackMe →
How you practise here
Here the work of a security team is done, not described
Many training programmes funded with a Bildungsgutschein teach with slides, practice exercises and an exam at the end. With us, from week 24 you work for seven weeks in the SOC‑Simulator by TryHackMe, with real tools and real alerts. We cannot say for the whole market whether other providers do this too.
Teaching with slides
- Slides and practice exercises
- One certification at the end
- The work of a security team is described
This is how we teach
- Seven weeks of shifts in the simulator, from week 24
- Three certifications along the way: SEC0, SEC1, SAL1
- The work of a security team is done – with real tools, real alerts and a metric that measures your speed
We cannot judge whether another training programme works in a similar way. There are several hundred approved providers in Germany, and we have not seen every curriculum.
The framework around it
A shift in the security team, from 8:00 to 16:00
The alert you have just seen was one of many. This is what the day it belongs to looks like – and this is exactly the day you practise in the simulator, week after week.
Handover from the night shift
What is still open, what was escalated, what to look out for today.
The first alert lands in the queue
Exactly the one from above. You assign it to yourself – from this moment the clock is running.
That was your testChecking what really happened
The account logs in the SIEM. Checking the IP address in the Analyst VM. Looking up in the Documentation where the company actually has sites.
The Playbook says what to do now
There is a fixed procedure for every type of alert – as in real security teams. You follow it instead of guessing.
Case Report and escalation
True Positive. You write down what you found and pass the case on to the next level. Time so far: 30 minutes.
MTTR 00:30The next alert. And the one after that.
Some are done in two minutes, others take an hour. Most are false alarms – spotting them is the real skill.
What you'll work with
Six areas, as in a real security team
These are not names we made up – this is what the areas are called in the simulator, and they have similar names in the profession.
The overview
How many alerts are open, what is urgent, how the team compares.
The queue
This is where the alerts come in. You take one, and from then on you are responsible for it.
The logs
The search system across all events. Who logged in and when, which computer sent data where.
Your own computer
A sealed-off workstation with tools – among other things, to check addresses and files without picking up an infection.
The company file
What this company does, where it has sites, which software is normal there. Without that you cannot judge an alert.
The fixed procedure
A set path for every type of alert. This is how real security teams work – so that nobody improvises in an emergency.
Where the simulator comes from. The SOC‑Simulator is a product of TryHackMe. TryHackMe is an independent company and a third-party brand; it is not part of the CYBERSQUAD Akademie. We use the platform as a learning tool in our lessons.
Have a look yourself. Some of the scenarios are open without payment too, in a limited version. If you want to know whether this kind of work suits you, you can try it out there before you register with us. To the SOC‑Simulator →
The exams come from there too. SEC0, SEC1 and SAL1 are run by TryHackMe, not by us. You can fail – anyone who does not pass the first time gets a second attempt, free of charge. The final certificate for the training programme is issued by us – our own provider certificate, with the approval number of the programme.
And what we do not promise. We are a training provider, not a job placement service. We cannot promise you a job. What we do: teach you the craft and practise job applications with you.
The simulator is part of the training programme “AI-Driven Security Operations Specialist”. The start is planned for Monday, 2 November 2026 – for that we need a minimum number of registrations. If too few people register, we will postpone the start by two to four weeks and let you know straight away.
Honest answers
This is what almost everyone asks us about the simulator
Short answers to the questions that come up again and again in our consultations.
Do I need prior knowledge to work with it?
Is this a computer game?
Do I have to practise alone in the evenings?
Is everything in English?
Do I need a powerful computer?
What happens if I get a case wrong?
Do I get a certificate for the simulator?
Two minutes. Then you know which rule applies to you.
Three questions, no sign-up and no obligation.