The new TryHackMe SOC Level 1 Path

The new TryHackMe SOC Level 1 Path

in

The new TryHackMe SOC Level 1 Path

Now getting ready for the job got even better

Recently TryHackMe revamped its SOC Analyst Level 1 (SOC L1) learning path, adapting its contents to more real-life tasks and expected knowledge for the role. In this article I highlight some changes, summarize interesting new content, and emphasize key takeaways from the newly completed rooms in the SOC L1, SOC Team Internals module.

In general, we now see extended content related to endpoint and network threats, SOC operations & SIEM triage,  and the deliberate omission of some digital forensics topics (such as memory forensics) which have been moved to more advanced paths. This aligns more closely with real-world expectations for a SOC Level 1 analyst.


Blue Team Introduction Module

In addition to the background knowledge given in the Cyber Security 101 and existing SOC Fundamentals modules, this new module offers a quick dive into the Security Analyst L1 role: from the fundamentals to the detailed information about day-to-day tasks, the most important contributions and responsibilities of the SOC team; including protecting people and systems, understanding the tasks of more advanced roles, and how the SOC team operates altogether.


SOC Team Internals

This module deserves a special place in this article since it bridges the gap between “what tools you learn” and “how a SOC actually works”.

SOC L1 Alert Triage and Reporting Rooms

Contents include:

  • Anatomy of alerts: what composes an alert, what relevant information to use to identify it.
  • Alert prioritization: how to filter and sort alerts by importance.
  • Alert triage: how to investigate an alert, and basics of distinguishing a false positive from a true positive.
  • Alert reporting: using the “5 Ws” (Who, What, When, Where, Why).
  • Alert escalation: why you escalate, when and to whom.
  • SOC communication: who you reach out to and in which situations.

Why this is important: This is core “entry-level SOC analyst” work: monitoring, triaging and escalating — not deep forensic investigation. The new path emphasizes exactly that.

SOC Workbooks and Lookups Room

Contents include:

  • Asset & Identity Inventories: having a clear understanding of who operates what and where in the company.
  • Using network diagrams: understanding the structure of the network you’re investigating.
  • Using workbooks: How and why they are used, and how they are structured for common investigation tasks (e.g., a phishing email, a PowerShell command, a network connection).

SOC Metrics and Objectives

Contents include:

  • Relevant SOC metrics and their calculation: alert count, false positive rate, alert escalation rate, threat detection rate.
  • Relevant triage metrics, their calculation and how to improve them: SOC team availability, Mean Time to Detect (MTTD), Mean Time to Acknowledge (MTTA), Mean Time to Respond (MTTR).

Core SOC Solutions

This module provides an introduction to the major tools and technologies: Endpoint Detection & Response (EDR), Security Information & Event Management (SIEM), and Security Orchestration, Automation & Response (SOAR).

This is critical because it gives context to how alerts are generated, triaged and managed in a real SOC setting — rather than just learning a tool in isolation.


Cyber Defense Frameworks

The new path refines the module around frameworks like MITRE ATT\&CK, which gets its own room updated, emphasizing those techniques that security analysts use most. In its room, it moves away from a tooling overload towards practical application and day-to-day usage of ATT\&CK.


Network Traffic Analysis

A dedicated room focused on network packet analysis and how to detect attacks. The content appears streamlined, focusing on Wireshark and NetworkMiner, and less on less-used tools (e.g., T-shark).


Network Security Monitoring

A new set of rooms intended to provide Security Analysts with the “what, why and how” to identify network scans, lateral movement, exfiltration etc. This gives practical use cases for what you learned in the previous “Traffic Analysis” module.


Web Security Monitoring

Another new set of rooms aimed at teaching how to protect a company’s web assets by identifying web attacks, web shells and web DDoS patterns. With web-applications being major targets this is a very timely inclusion.


Windows Security Monitoring

Windows gets its own module, which now includes:

  • The previous room “Windows Logging for SOC”, teaching you which Windows components to check and what to look for during investigations.
  • Additional “Threat Detection” rooms (three of them) teaching how to detect different malicious activities on Windows hosts.

Linux Security Monitoring

Also a new set of rooms, specifically aimed at investigating Linux systems through logs and detection of malicious activity — again including three Threat Detection rooms.


Malware Concepts for SOC

This module adds an important foundation: a theoretical refresher of different kinds of malware and includes analysis, detection and actions when facing malware. It gives you enough context to recognize malware behavior in SOC operations.


Threat Analysis Tools

An intro to cyber threat intelligence (CTI) becomes its own module, including rooms on how to leverage threat intelligence to detect, investigate and defend against adversaries.

“Here I miss tool rooms like the cool and useful OpenCTI … Perhaps we may also get a specialized Cyber Threat Intelligence (CTI) Analyst path at some point.”


SIEM Triage for SOC

In addition to the basics of Splunk and Elastic Stack (ELK) covered in Core SOC Solutions, the new path introduces a specialized module dedicated to SIEM deepening: log analysis and alert triage in both Splunk and Elastic are covered. This reflects the real world, where triage analysts spend a lot of time working in the SIEM, correlating logs from endpoints, network, and other sensors.


SOC Level 1 Capstone Challenges

These essential practices mimicking real life scenarios remain part of the path. These challenges are the final test before getting your SOC Level 1 Path Completion Certification.

Please note: The contents of these challenges are interesting, really good for practical training as a SOC or Blue Team focused learner, but they are not directly oriented to be a preparation or a stepping stone for the Security Analyst Level 1 (SAL1) certification exam, since they are different kind of exercises and using other tooling. So even if you pass them, consider them additional learning and keep in mind the other expectations the SAL1 test may have for you.


In conclusion

I’m genuinely excited to see this update in an almost totally renewed SOC L1 learning path. Although I lost around 10% of my prior progress (as other users may have noted too), my completed rooms and my previous point-count are kept, and I’ve gained the chance to deepen my knowledge in fields that matter most for my future role — guided by TryHackMe’s team of experts.

The path now feels much more aligned with the skills that hiring managers expect from a real-world SOC analyst. As the blog says: it’s “more practical, structured and relevant to real job requirements than ever before.”

[TryHackMe Introducing the Revamped SOC Level 1 Learning Path](https://tryhackme.com/resources/blog/introducing-the-revamped-soc-level-1-learning-path)

And also from users’ perspective:

“It feels significantly closer to what a real junior SOC analyst does on the job today.”
The MasterMinds Media | Motasem Hamdan](https://motasem-notes.net/tryhackme-soc-level-1-what-changed-in-2025/)


If you’re not a total beginner in cybersecurity (let’s say you already hold a certification like me), I still encourage you to go at least partially through their rooms in the Pre-Security and Cyber Security 101 paths;  they can provide very valuable refreshers about security roles, SIEM and networking fundamentals. And if you feel you already know most of it, browse through their contents anyway ,  you may be surprised that there’s something new you just learnt.


Final thoughts and insights

  • The shift from tool-focused to workflow/context-focused is meaningful. Learning how a SOC actually operates (roles, triage, escalation, metrics) is as important as learning the tools.
  • The inclusion of broader asset types (Linux, web applications) reflects the reality that SOC analysts increasingly monitor diverse environments.
  • Removing or reducing deep-forensics content (which is less typical for Tier 1 analyst roles) is a smart alignment to job expectations.
  • From a recruiter/employer viewpoint, a candidate who can say “I completed the SOC L1 path on TryHackMe” will likely stand out more because it aligns with real triage workflows, rather than extensive tooling.

Do you want to know how to study and pass TryHackMe’s SOC L1 related Security Analyst Level 1 — SAL1 Certification? Check my other article