I signed up for my first SIEM CTF 🔍
Officially enrolled in Operation Cymbal: Cold Room, a free community CTF from Google Cloud Security x Hack The Box ✅
🧊 The scenario
A company collapses after 3 breaches that look unrelated. Your job: figure out what really happened.
🛠️ What you actually do
→ Investigate logs inside Google SecOps (a real enterprise SIEM)
→ Separate attacker activity from normal noise
→ Rebuild each intrusion from start to finish
→ File findings that hold up
💡 Why I'm doing it
I'm a data analyst moving into SOC work. Finding what doesn't belong in data is what I already do. This is the same skill, pointed at attacks.
📅 The details
• Virtual, Oct 29 to Nov 1
• 72 hours to play
• Free, but registration needs approval
• Registration closes Oct 22
Save this if you're breaking into cybersecurity too, and tell me: have you ever done a CTF? 👇🏽
The tool changes, the question doesn't. 💜
#cybersecurity #blueteam #SOCanalyst #womenincybersecurity #learninpublic
Participating in a SIEM capture-the-flag (CTF) event for the first time was an eye-opening experience that truly deepened my understanding of security operations. Operation Cymbal: Cold Room challenged me to analyze three seemingly unrelated breaches in a simulated enterprise environment using Google SecOps, which is a powerful Security Information and Event Management (SIEM) tool widely used in the industry. Navigating through hours of log data to differentiate between benign activities and malicious intrusions felt a lot like detective work, and I quickly realized how crucial this skill is for any SOC analyst. The CTF scenario placed me in the shoes of a cybersecurity expert tasked with untangling a complex attack chain — from the initial compromise to lateral movement and finally data exfiltration. What made this experience invaluable is that it closely mirrored real-world incident investigations, emphasizing the importance of methodical log analysis and evidence preservation. Beyond the technical skills, the event reinforced the necessity of clear documentation and reporting. Creating findings that stand up to scrutiny is something I hadn’t appreciated before. The collaborative community environment of the CTF also encouraged sharing insights and learning from others, which is essential when breaking into cybersecurity. For those considering jumping into a similar challenge, my advice is to focus on honing your log analysis and pattern recognition skills, since spotting what doesn’t belong can quickly become second nature. Additionally, participating in free virtual CTFs like this one is a fantastic way to gain hands-on experience in a low-risk setting, build confidence, and broaden your understanding of security operations. Overall, Operation Cymbal not only bolstered my technical skill set but also gave me a real sense of what working as a SOC analyst entails. For anyone moving from data analytics into cybersecurity, this type of targeted practice bridges the gap beautifully, making complex enterprise security concepts accessible and engaging.
