August 14, 2026
TryHackMe’s New SOC Level 1 Path: What Changed and Why It Matters
Getting ready for a real SOC analyst job just got better

By Citadel Cybersec
9 min read
Originally published on November 10, 2025
TryHackMe has revamped its SOC Analyst Level 1 (SOC L1) learning path, adapting the content to better reflect real-world tasks and the knowledge expected from an entry-level Security Operations Center analyst.
After going through the newly updated path, I wanted to highlight some of the biggest changes, summarize the most interesting new content, and share my key takeaways — especially from the new SOC Team Internals module.
Overall, the revamped path puts much more emphasis on:
- Endpoint and network threat detection
- SOC operations and alert triage
- SIEM-based investigation
- Incident escalation and reporting
- Understanding how a SOC team actually operates
At the same time, some deeper digital forensics topics — such as memory forensics — have been reduced or moved to more advanced learning paths.
In my opinion, this is a positive change because it brings the SOC Level 1 path closer to what an entry-level SOC analyst is actually expected to do.
Blue Team Introduction
In addition to the background knowledge provided by the Cyber Security 101 and existing SOC Fundamentals modules, the new Blue Team Introduction module provides a focused introduction to the Security Analyst Level 1 role.
It covers everything from the fundamentals of the role to the day-to-day responsibilities of a SOC team, including:
- Protecting people, systems, and organizational assets
- Understanding the responsibilities of different SOC roles
- Knowing when and why analysts escalate incidents
- Understanding how the different members of a SOC work together
This is an important addition because cybersecurity learning can sometimes become heavily focused on tools without explaining the operational context in which those tools are actually used.
SOC Team Internals
This module deserves a special mention because it helps bridge the gap between "the tools you need to learn" and "how a SOC actually works."
For anyone preparing for their first SOC analyst role, I think this is one of the most valuable parts of the revamped path.
SOC L1 Alert Triage and Reporting
The rooms cover several fundamental activities that entry-level SOC analysts are expected to perform.
What you learn
- Anatomy of alerts: Understanding what makes up an alert and which information is relevant during an investigation.
- Alert prioritization: Learning how to filter and prioritize alerts based on their importance and potential impact.
- Alert triage: Investigating alerts and understanding the basics of distinguishing false positives from true positives.
- Alert reporting: Using the 5 Ws — Who, What, When, Where, and Why — to document findings.
- Alert escalation: Understanding why, when, and to whom an alert should be escalated.
- SOC communication: Knowing who to contact and how to communicate information effectively during an investigation.
Why this matters
This is core entry-level SOC analyst work.
Monitoring, triaging, documenting, communicating, and escalating are often much more representative of a Tier 1 SOC analyst's daily responsibilities than performing deep forensic investigations.
The new path puts much greater emphasis on exactly these skills.
SOC Workbooks and Lookups
Another useful addition is the focus on workbooks, inventories, and organizational context.
What you learn
- Asset and identity inventories: Understanding who operates what systems and where those systems are located within the organization.
- Network diagrams: Understanding the structure of the environment you're investigating.
- SOC workbooks: Learning how and why workbooks are used and how they can support common investigation scenarios.
Examples include investigations involving: Phishing emails, PowerShell commands, Network connections and Endpoint activity
This is the kind of contextual knowledge that can make an analyst much more effective when working with alerts.
SOC Metrics and Objectives
The path also introduces important SOC metrics and explains how they can be calculated and improved.
Some of the metrics covered include: Alert count, False positive rate, Alert escalation rate, Threat detection rate, SOC team availability, Mean Time to Detect (MTTD), Mean Time to Acknowledge (MTTA), Mean Time to Respond (MTTR).
Understanding these metrics gives learners a better idea of how SOC performance is measured beyond simply "how many alerts did we investigate?"
Core SOC Solutions
This module introduces some of the major technologies used in modern security operations:
- Endpoint Detection and Response (EDR)
- Security Information and Event Management (SIEM)
- Security Orchestration, Automation and Response (SOAR)
This is particularly useful because it provides context for how alerts are generated, investigated, and managed in an actual SOC environment.
Rather than learning a security tool in isolation, learners start to understand where that tool fits into the wider SOC workflow.
Cyber Defense Frameworks
The revamped path also refines its coverage of cybersecurity frameworks, particularly MITRE ATT&CK.
The MITRE ATT&CK content has been updated to focus more heavily on techniques that security analysts are likely to encounter and use during day-to-day investigations.
The emphasis feels less like a catalog of tools and techniques and more like a practical introduction to how analysts can use ATT&CK to understand attacker behavior and map observed activity to known techniques.
Network Traffic Analysis
The path now includes a dedicated focus on network packet analysis and detecting attacks through network traffic.
The content appears more streamlined, with a stronger focus on practical tools such as: Wireshark and NetworkMiner.
There is also less emphasis on tools that are less commonly used in a typical entry-level SOC workflow, such as TShark.
This makes the module feel more focused on the practical skills an aspiring analyst needs to develop.
Network Security Monitoring
The new Network Security Monitoring content takes the concepts from traffic analysis and applies them to practical detection scenarios.
The rooms focus on identifying activities such as: Network scanning, Lateral movement, Data exfiltration and Suspicious network behavior.
This is an important progression. First, you learn how to analyze traffic. Then, you learn how that analysis can be used to identify malicious activity.
That connection between technical knowledge and detection use cases is exactly what I like about the new structure.
Web Security Monitoring
Web applications are major targets for attackers, so the addition of dedicated Web Security Monitoring content is a very timely improvement.
The new rooms focus on detecting and investigating web-based attacks, including: Web attacks, Web shells and Web-based DDoS patterns.
This broadens the scope of the path beyond traditional endpoint monitoring and reflects the reality of modern environments, where SOC teams may need to monitor everything from employee laptops to internet-facing applications.
Windows Security Monitoring
Windows now receives its own dedicated security monitoring module.
It includes the previous Windows Logging for SOC room, which teaches learners which Windows components and logs to examine during investigations.
The module also adds three Threat Detection rooms focused on detecting different types of malicious activity on Windows hosts.
For aspiring SOC analysts, this is particularly relevant because Windows environments generate a huge amount of security telemetry and are frequently targeted by attackers.
Linux Security Monitoring
Linux also gets dedicated coverage.
The new Linux Security Monitoring content focuses on investigating Linux systems using logs and detecting malicious activity.
Like the Windows section, it includes three Threat Detection rooms.
I think this is a welcome addition because SOC analysts increasingly have to deal with heterogeneous environments rather than purely Windows-based networks.
Malware Concepts for SOC
The Malware Concepts for SOC module provides an important theoretical foundation.
It covers different types of malware and introduces concepts around: Malware analysis, Malware detection, Recognizing malicious behavior and Responding to malware-related incidents.
The goal isn't necessarily to turn a SOC Level 1 analyst into a malware reverse engineer.
Instead, it provides enough context to understand what malware can do, recognize suspicious behavior, and know what actions may be appropriate when malware is detected.
Threat Analysis Tools
Cyber Threat Intelligence (CTI) now receives its own dedicated module.
The content introduces how threat intelligence can be used to:
- Detect adversary activity
- Investigate suspicious behavior
- Understand threats
- Support defensive operations
One thing I personally miss here is a deeper look at platforms such as OpenCTI.
Perhaps we'll eventually see a dedicated Cyber Threat Intelligence Analyst learning path as well.
That would be an interesting addition to the TryHackMe ecosystem.
SIEM Triage for SOC
One of the most important additions, in my opinion, is the dedicated SIEM Triage for SOC module.
The Core SOC Solutions module already introduces platforms such as Splunk and Elastic Stack (ELK).
The new SIEM-focused module goes further, with dedicated content around: Log analysis, Alert investigation, SIEM-based triage, Splunk investigations and Elastic investigations.
This is highly relevant to real-world SOC work: a Tier 1 analyst can spend a significant amount of time working inside the SIEM, correlating information from endpoints, network devices, authentication systems, and other security sensors.
Learning how to perform that type of investigation is therefore much more valuable than simply knowing how to navigate a particular SIEM interface.
SOC Level 1 Capstone Challenges
The capstone challenges remain an essential part of the path.
They provide practical scenarios that simulate real-world SOC and Blue Team situations and act as a final practical test before completing the SOC Level 1 Path Completion Certification.
However, there is an important distinction worth mentioning.
The capstone challenges are excellent practical exercises for someone learning SOC and Blue Team skills, but they should not be considered a direct preparation path for the Security Analyst Level 1 (SAL1) certification exam.
The two use different types of exercises and different tooling. So, even after completing the capstone challenges, keep in mind that the SAL1 certification has its own expectations and preparation requirements.
What Do I Think of the New SOC Level 1 Path?
Overall, I'm genuinely excited about the update.
The SOC L1 learning path feels almost completely renewed, and I think the changes move it in the right direction.
I personally lost around 10% of my previous progress after the update, as other users have also noted. However, my completed rooms and previous point count were retained.
More importantly, I gained the opportunity to deepen my knowledge in areas that matter for my future role, guided by TryHackMe's updated learning structure and content.
The path now feels much more aligned with the skills hiring managers expect from an entry-level SOC analyst.
As TryHackMe describes it, the revamped path is:
"More practical, structured and relevant to real job requirements than ever before."
You can read TryHackMe's announcement here:
TryHackMe — Introducing the Revamped SOC Level 1 Learning Path
And from the learner community, The MasterMinds Media / Motasem Hamdan described the updated path as:
"It feels significantly closer to what a real junior SOC analyst does on the job today."
The MasterMinds Media — TryHackMe SOC Level 1: What Changed?
Should You Complete the Other TryHackMe Paths First?
If you're completely new to cybersecurity, the obvious recommendation is to start with the foundational material.
But even if you're already familiar with cybersecurity — or already hold a certification — I would still recommend going through at least parts of the Pre-Security and Cyber Security 101 paths.
Why?
Because they provide useful refreshers on topics such as:
- Networking fundamentals
- Security concepts
- SIEM fundamentals
- Cybersecurity roles
- Common attack techniques
And even when you think you already know the material, it's worth browsing through the rooms.
You might be surprised by the occasional concept, technique, or explanation that you haven't encountered before.
My Key Takeaways
After going through the revamped path, several changes stand out to me.
1. The focus is shifting from tools to workflows
This is probably the biggest improvement.
Knowing how to use Splunk, Wireshark, or an EDR platform is useful — but understanding why you're using the tool, what you're looking for, and what you do with the result is even more important.
A SOC analyst needs to understand the workflow:
Alert → Triage → Investigation → Documentation → Escalation → Response
The new path puts much more emphasis on that process.
2. The scope reflects modern environments
The inclusion of Windows, Linux, networks, and web applications reflects the reality of modern enterprise environments.
SOC analysts can't assume that everything they investigate will come from a single operating system or security platform.
3. Less deep forensics makes sense for Tier 1
Reducing or moving some advanced digital forensics topics — such as memory forensics — to more advanced paths makes sense to me.
Those are valuable skills, but they aren't necessarily the core responsibilities of an entry-level SOC analyst.
4. Practical detection matters
The new Threat Detection rooms across Windows, Linux, network, and web security make the path feel much more practical.
Instead of simply learning what a technology is, learners increasingly get to practice detecting malicious activity using it.
5. The path better reflects what employers are looking for
From a recruiter or employer perspective, a candidate who can demonstrate that they understand SOC workflows, alert triage, SIEM investigation, escalation, and detection may stand out more than someone who has simply completed a long list of individual tool-based rooms.
The real value is not just saying: "I know Splunk." It's being able to say: "I understand how a SOC uses a SIEM to investigate, prioritize, document, and escalate security alerts." That's a much more meaningful skill.
Final Thoughts
The revamped TryHackMe SOC Level 1 path is, in my opinion, a significant improvement.
It moves away from simply teaching a collection of cybersecurity tools and puts greater emphasis on how those tools and technologies fit into a real SOC operation.
For someone trying to break into cybersecurity, this is exactly the direction I would like to see from an entry-level learning path.
You still need to build hands-on experience, understand networking and operating systems, practice investigation, and develop strong analytical and communication skills.
But as a structured learning path for understanding what a junior SOC analyst actually does, the new SOC L1 path is considerably more practical and relevant.
And if you're planning to pursue the Security Analyst Level 1 (SAL1) certification, remember that completing the SOC L1 learning path is only part of the journey.
If you'd like to know how I prepared for and passed TryHackMe's Security Analyst Level 1 (SAL1) certification, check out my other article:
How I Passed TryHackMe's Security Analyst Level 1 (SAL1): A Practical Study Guide