Lab Overview

Field Detail
Platform TryHackMe
Room URL tryhackme.com/room/socroleinblueteam
Category SOC / Blue Team
Status ✅ Completed
Points Earned 64
Tasks Completed 6
GitHub File labs/tryhackme/rooms/soc-role-blue-team.md
Live Website tryhackme.html

Room Objective

Discover security roles and learn how to advance your SOC career, starting from the L1 analyst. The room deepens understanding of the SOC team structure, defines the responsibilities of each role across the defensive lifecycle, and maps out realistic career progression paths from junior analyst to senior positions.


Methodology / Approach

Worked through each task sequentially, building on the foundational SOC knowledge from Junior Security Analyst Intro. Focused on understanding the full scope of what a SOC team does collectively, how each role contributes to the defence mission, and what a realistic analyst career journey looks like through the TryHackMe SOC Level 1 path.


Walkthrough

Key Concepts Covered

SOC team roles — detailed breakdown:

Role Shift Work? Core Function When Involved
L1 Analyst (Junior) Yes — 24/7 Initial alert triage, monitoring, first-line investigation Every shift
Senior Analyst (L2) Yes Complex case handling, mentoring L1 analysts, escalation decisions When L1 escalates
SOC Engineer No Tool maintenance, alert configuration, detection rule building Ongoing, not shift-based
SOC Manager No Reporting to top management, team coordination, process ownership Ongoing
Incident Responder On demand Major incident response, forensics, containment Only during significant incidents

Career progression paths from SOC L1: