6 Real Problems I Solved While Building My SOC Homelab
Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment
TryHackMe recently released a significantly updated version of its SOC Level 2 learning path, replacing the previous curriculum with a much broader and more modern one.
As someone currently working through the new path while building my skills toward a career in security operations, I found the changes particularly interesting. They are not simply a matter of adding a few new rooms or updating some tools. They reflect a broader change in what we should expect from a SOC analyst as security operations become more complex, more automated and increasingly influenced by AI.
That is why I wanted to look at the new path not simply as a learner, but from the perspective of someone trying to understand what “job ready” actually means for the next generation of SOC analysts.
The old SOC Level 2 path was already a substantial blue-team curriculum. It covered advanced Splunk and Elastic, detection engineering, threat hunting, threat emulation, incident response and malware analysis. The new path keeps much of that foundation, but the structure feels considerably more aligned with the actual responsibilities of an L2 analyst.
One of the clearest examples is that the new path starts with an introduction to the SOC L2 role itself, including L2 alert triage and report writing. That may sound like a relatively small change, but I think it is significant.
An L1 analyst is often working from alerts: something triggered, investigate it, determine whether it is malicious and escalate when necessary.
At L2, the investigation becomes deeper. You may receive an escalated incident and need to establish what happened, determine the scope, correlate evidence from different sources, identify the attack path and communicate your conclusions. That difference in mindset is important.
The new curriculum appears to recognise that being an L2 analyst is not simply about knowing more tools than an L1 analyst. It is about being able to conduct a more complete investigation.
Some of the most interesting additions are Active Directory, Microsoft 365 and Entra ID, AWS security monitoring, Wazuh and osquery. These are not random technologies; they represent the environments from which modern SOC analysts increasingly have to collect evidence.
An investigation might involve a suspicious authentication event in Entra ID, activity on an endpoint, an unusual PowerShell process, network traffic associated with the host and cloud activity that helps establish what the attacker did next. That means the analyst needs to understand how different sources of telemetry fit together.
The new path moves much further in this direction than the legacy version:
For me, this is one of the strongest signs that the new path is trying to model the modern SOC rather than simply teach a collection of security tools.
Another change I find particularly relevant is the stronger emphasis on detection engineering. The new curriculum covers detection-rule development, Sigma, threat hunting, detection engineering with Snort and even AI and automation in detection engineering.
This reflects something that is becoming increasingly difficult to ignore: the analyst of the future will not necessarily spend the entire day manually investigating alerts.
Automation, AI-assisted analysis, better detections and improved telemetry can reduce the amount of repetitive work involved in SOC operations. That does not make analytical skills less important. In some ways, it makes them more important.
If automation handles more of the straightforward work, analysts need to be increasingly capable of dealing with the cases that require judgement. This is one reason I find the evolution from L1 toward L2 particularly interesting.
The question is gradually moving from “Can you recognise this alert?” toward “Can you investigate this situation and determine what is actually happening?”
The new curriculum also expands the ecosystem around the investigation itself. Cyber Threat Intelligence now has its own section, including MISP and OpenCTI, while advanced traffic analysis introduces Snort, Zeek, Zui and packet analysis.
These additions make sense when viewed together:
The individual technologies are useful, but I think what is more important is the relationship between them.
The new path ends with a dedicated SOC Level 2 Capstone Challenges section, including investigations based on scenarios such as Volt Typhoon, Servidae, the APIWizards breach and Conti.
This is important because there is a big difference between completing individual training exercises and being able to combine what you have learned.
Learning Splunk, threat hunting, network analysis, CTI, malware analysis and incident response separately is useful. The real challenge is knowing when to use each of them during the same investigation. That is much closer to the problem an L2 analyst faces in a real SOC.
For someone building a portfolio, these types of investigations can also provide excellent opportunities to demonstrate analytical thinking rather than simply listing another completed course.
The new path is not simply “the old path plus more” and the malware-analysis section is a good example.
The legacy curriculum went quite deeply into subjects such as x86 architecture, assembly, Windows internals, PE headers, debugging and anti-reverse-engineering techniques. The new path retains static malware analysis, YARA, scripting analysis and other useful malware-related material, but places less emphasis on low-level reverse engineering.
I don’t see that as necessarily a weakness. Malware Analyst is more often a specialization that branches out from SOC L2 to SOC L3/DFIR/threat intelligence/detection engineering.
It makes sense if the objective is to prepare someone for SOC L2 rather than to train a malware reverse engineer. An L2 analyst may need to determine whether a sample is malicious, understand its behaviour, extract indicators and connect it to the wider investigation without necessarily spending hours debugging it at assembly level.
The change illustrates something important about this update: the new path is not necessarily more advanced in every individual subject; it is more targeted toward the actual L2 role.
This is where I think we need to be careful, so let me be clear about it. Completing the new path can provide a strong technical foundation for an L2 position, but it cannot provide something a learning platform cannot provide: production experience.
A real SOC involves noisy telemetry, incomplete data, business impact, SLAs, customer expectations, escalation procedures, shift handovers and decisions where the correct answer is not always obvious.
Current SOC L2 vacancies still frequently ask for previous SOC, IT or security experience, sometimes several years of it. The new path therefore shouldn’t be interpreted as a shortcut around experience requirements.
What it does provide is something different: an opportunity to systematically develop many of the technical capabilities that employers associate with the role. And for someone trying to move into cybersecurity, that distinction matters.
This question is particularly relevant to me because I am currently working through the path myself. The changes became interesting to me precisely because I am learning them and can already see how relevant some of the new material is to the direction in which security operations appears to be moving. For people at the same stage, I think the message is quite encouraging, but also quite demanding.
The traditional entry-level SOC route has often been described as learning networking and security fundamentals, becoming familiar with a SIEM, learning alert triage and then applying for L1 positions.
Those fundamentals remain essential, but the industry is changing.
As organisations adopt more automation, AI-assisted security operations, cloud services, identity platforms and increasingly sophisticated detection capabilities, it is reasonable to ask whether the long-term value of a junior analyst will increasingly depend on the ability to investigate more complicated situations rather than simply process large numbers of basic alerts.
That is one reason I think the new SOC L2 path is worth paying attention to even for people who are still targeting their first SOC position. You don’t necessarily need to be an L2 analyst today to start developing L2 thinking.
I would also be careful about treating the completion certificate itself as a major recruiting credential. A recruiter who is familiar with cybersecurity may understand what TryHackMe represents, but a general HR recruiter may not know how difficult or relevant a particular learning path is. That makes it different from something such as Security+, which has much broader recognition.
The value of the path, and especially in the job market nowadays, is therefore likely to be stronger when applied to a practical case such as completing an investigation and writing about it, or using your new knowledge in your own documented homelab.
Also, it could be prove useful as a complementary addition, combined with other evidence. For example, a candidate could demonstrate Security+ for foundational knowledge, a practical certification such as BTL1 or SAL1, SIEM experience through Splunk, hands-on work through a homelab, and then use the SOC L2 path to demonstrate continued progression into more advanced areas.
At that point, the path is no longer just another certificate: it becomes part of a larger story.
This distinction is important, since completing the SOC Level 2 learning path and validating your skills by passing the Security Analyst Level 2 certification are not the same thing.
While the learning path demonstrates that you completed the training curriculum, SAL2 is intended to assess whether you can actually apply advanced SOC skills in practical scenarios. For that reason, I expect SAL2 to carry a different type of weight with technical hiring managers than the learning-path certificate itself.
It is also worth remembering that newer certifications take time to establish market recognition. Security+ has been known to recruiters for years. A newer certification has to build its reputation among employers and practitioners. So I wouldn’t expect SAL2 to suddenly replace the value of established certifications.
Instead, I see SAL2 as potentially becoming a useful practical signal for people who want to demonstrate that they can operate beyond basic SOC fundamentals.
For me, the most interesting aspect of this update is what it tells us about the direction of the SOC analyst role.
The old curriculum already taught advanced blue-team skills. The new curriculum places considerably more emphasis on identity, cloud, enterprise environments, cross-domain investigation, CTI, network telemetry, detection engineering, automation and professional reporting.
That combination tells us the analyst is increasingly expected to understand the environment rather than simply the alert, and as AI and automation take over more repetitive analytical tasks, that may become even more important. If machines can increasingly identify obvious anomalies, enrich alerts and perform parts of the initial investigation, the human analyst’s value increasingly shifts toward judgement, investigation, correlation, understanding business context and explaining what happened. That is where L2 becomes interesting.
I think the new TryHackMe SOC Level 2 path is a meaningful improvement over the legacy version, not because every individual topic is more advanced, but because the overall curriculum is more closely aligned with the way modern SOC investigations are actually performed.
The additions of Active Directory, Microsoft 365 and Entra ID, AWS, CTI, advanced network analysis, Wazuh, detection engineering and integrated capstone investigations make the path considerably more relevant to someone trying to develop toward an L2 role.
It doesn’t eliminate the experience gap, and I wouldn’t advise anyone to claim that completing it makes them an experienced SOC L2 analyst.
But I do think it raises an important question for people entering the field:
Should we still think of “entry level” cybersecurity as simply learning the fundamentals, or should we already be developing the deeper analytical skills that will make us valuable as the role evolves?
For me, the new SOC Level 2 path is a good example of why the answer may be changing.
I’m currently working through it myself, alongside my homelab and practical investigations, and that is precisely why I found the update worth discussing. The more I progress through it, the more I see it not simply as another learning path, but as an indication of where the SOC analyst role may be heading.