How Attackers Scan Networks: Network Discovery Detection | TryHackMe SOC Level 1 2025

Опубликовано: 05 Июнь 2026
на канале: WireDogSec
630
22

In this walkthrough of the TryHackMe – Network Discovery Detection room, we explore how attackers perform reconnaissance, how they scan networks, and how SOC analysts detect this activity using logs and network‑security tooling.
According to the room outline, this module covers internal vs external scanning, horizontal vs vertical scanning, and the mechanics of discovery techniques such as ping sweeps, TCP SYN scans, and UDP scans. It also includes hands‑on detection using firewall logs, CSV exports, and Zeek/Kibana analysis.
🔍 What you’ll learn:
• What network discovery is and why attackers perform it
• How to distinguish internal vs external scanning
• How to identify horizontal vs vertical scans in logs
• How ping sweeps, SYN scans, and UDP scans appear in traffic
• How to analyze Zeek logs and Kibana dashboards for reconnaissance
• How SOC analysts detect early‑stage attacker activity
🚀 Try it yourself:
https://tryhackme.com/room/networkdis...
FOR EDUCATIONAL PURPOSES ONLY
👍 Like, comment, and subscribe to ‪@wiredogsec‬ for more SOC, blue‑team, and network‑security walkthroughs.

#TryHackMe #NetworkDiscovery #Reconnaissance #SOCAnalyst #BlueTeam #NetworkSecurity #CyberSecurityTraining #WireDogSec