6 Real Problems I Solved While Building My SOC Homelab
Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment
Recently TryHackMe revamped its SOC Analyst Level 1 (SOC L1) learning path, adapting its contents to more real-life tasks and expected knowledge for the role. In this article I highlight some changes, summarize interesting new content, and emphasize key takeaways from the newly completed rooms in the SOC L1, SOC Team Internals module.
In general, we now see extended content related to endpoint and network threats, SOC operations & SIEM triage, and the deliberate omission of some digital forensics topics (such as memory forensics) which have been moved to more advanced paths. This aligns more closely with real-world expectations for a SOC Level 1 analyst.
In addition to the background knowledge given in the Cyber Security 101 and existing SOC Fundamentals modules, this new module offers a quick dive into the Security Analyst L1 role: from the fundamentals to the detailed information about day-to-day tasks, the most important contributions and responsibilities of the SOC team; including protecting people and systems, understanding the tasks of more advanced roles, and how the SOC team operates altogether.
This module deserves a special place in this article since it bridges the gap between “what tools you learn” and “how a SOC actually works”.
Contents include:
Why this is important: This is core “entry-level SOC analyst” work: monitoring, triaging and escalating — not deep forensic investigation. The new path emphasizes exactly that.
Contents include:
Contents include:
This module provides an introduction to the major tools and technologies: Endpoint Detection & Response (EDR), Security Information & Event Management (SIEM), and Security Orchestration, Automation & Response (SOAR).
This is critical because it gives context to how alerts are generated, triaged and managed in a real SOC setting — rather than just learning a tool in isolation.
The new path refines the module around frameworks like MITRE ATT\&CK, which gets its own room updated, emphasizing those techniques that security analysts use most. In its room, it moves away from a tooling overload towards practical application and day-to-day usage of ATT\&CK.
A dedicated room focused on network packet analysis and how to detect attacks. The content appears streamlined, focusing on Wireshark and NetworkMiner, and less on less-used tools (e.g., T-shark).
A new set of rooms intended to provide Security Analysts with the “what, why and how” to identify network scans, lateral movement, exfiltration etc. This gives practical use cases for what you learned in the previous “Traffic Analysis” module.
Another new set of rooms aimed at teaching how to protect a company’s web assets by identifying web attacks, web shells and web DDoS patterns. With web-applications being major targets this is a very timely inclusion.
Windows gets its own module, which now includes:
Also a new set of rooms, specifically aimed at investigating Linux systems through logs and detection of malicious activity — again including three Threat Detection rooms.
This module adds an important foundation: a theoretical refresher of different kinds of malware and includes analysis, detection and actions when facing malware. It gives you enough context to recognize malware behavior in SOC operations.
An intro to cyber threat intelligence (CTI) becomes its own module, including rooms on how to leverage threat intelligence to detect, investigate and defend against adversaries.
“Here I miss tool rooms like the cool and useful OpenCTI … Perhaps we may also get a specialized Cyber Threat Intelligence (CTI) Analyst path at some point.”
In addition to the basics of Splunk and Elastic Stack (ELK) covered in Core SOC Solutions, the new path introduces a specialized module dedicated to SIEM deepening: log analysis and alert triage in both Splunk and Elastic are covered. This reflects the real world, where triage analysts spend a lot of time working in the SIEM, correlating logs from endpoints, network, and other sensors.
These essential practices mimicking real life scenarios remain part of the path. These challenges are the final test before getting your SOC Level 1 Path Completion Certification.
Please note: The contents of these challenges are interesting, really good for practical training as a SOC or Blue Team focused learner, but they are not directly oriented to be a preparation or a stepping stone for the Security Analyst Level 1 (SAL1) certification exam, since they are different kind of exercises and using other tooling. So even if you pass them, consider them additional learning and keep in mind the other expectations the SAL1 test may have for you.
I’m genuinely excited to see this update in an almost totally renewed SOC L1 learning path. Although I lost around 10% of my prior progress (as other users may have noted too), my completed rooms and my previous point-count are kept, and I’ve gained the chance to deepen my knowledge in fields that matter most for my future role — guided by TryHackMe’s team of experts.
The path now feels much more aligned with the skills that hiring managers expect from a real-world SOC analyst. As the blog says: it’s “more practical, structured and relevant to real job requirements than ever before.”
| [TryHackMe | Introducing the Revamped SOC Level 1 Learning Path](https://tryhackme.com/resources/blog/introducing-the-revamped-soc-level-1-learning-path) |
And also from users’ perspective:
“It feels significantly closer to what a real junior SOC analyst does on the job today.”
The MasterMinds Media | Motasem Hamdan](https://motasem-notes.net/tryhackme-soc-level-1-what-changed-in-2025/)
If you’re not a total beginner in cybersecurity (let’s say you already hold a certification like me), I still encourage you to go at least partially through their rooms in the Pre-Security and Cyber Security 101 paths; they can provide very valuable refreshers about security roles, SIEM and networking fundamentals. And if you feel you already know most of it, browse through their contents anyway , you may be surprised that there’s something new you just learnt.
Do you want to know how to study and pass TryHackMe’s SOC L1 related Security Analyst Level 1 — SAL1 Certification? Check my other article