← Back to list

TryHackMe: SOC in Blue Team — Where Security Operations Fits

https://tryhackme.com/room/socroleinblueteam

SHASHANK M B in InfoSec Write-ups · 2026-08-20 12:57 · 81 claps · 4.3 min read
#security-operation-center #blue-team #cyber-forensics #digital-threats #information-security
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

TryHackMe: SOC in Blue Team — Where Security Operations Fits

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.

https://tryhackme.com/room/socroleinblueteam

When we talk about cybersecurity, we often focus on attacks, vulnerabilities, and penetration testing. But once an attack happens, who detects it, investigates it, and responds?

That is where the Blue Team and, more specifically, the Security Operations Center (SOC) come in.

I recently completed the SOC Role in Blue Team room on TryHackMe, which helped me understand where the SOC fits within an organization’s security structure, what different defensive teams do, and how a SOC career can evolve.

Where Does the SOC Fit?

A typical large organization may have a security hierarchy like:

CEO → CISO → Security Departments → Security Teams

The CISO (Chief Information Security Officer) is responsible for aligning cybersecurity with the organization’s business requirements.

Under the security function, different teams may have different responsibilities:

  • Red Team — Offensive security, penetration testing, and finding weaknesses.
  • GRC — Security policies, risk management, and regulatory compliance.
  • Blue Team — Defensive security, monitoring, detection, and response.

The exact structure depends on the organization’s size and security requirements.

The Blue Team

The Blue Team is responsible for defending the organization’s systems, networks, applications, and data.

Instead of trying to exploit systems, the Blue Team focuses on questions such as:

Can we detect an attack? Can we investigate it? Can we contain it before it causes serious damage?

The Blue Team can include several specialized functions, including SOC analysts, security engineers, incident responders, threat hunters, forensic analysts, and threat intelligence analysts.

SOC: The First Line of Defense

The Security Operations Center (SOC) acts as the central operational hub for security monitoring.

A simplified SOC workflow looks like:

Telemetry → Detection → Alert → Triage → Investigation → Escalation/Response

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.

A SOC receives security data from sources such as:

  • SIEM
  • EDR
  • Firewalls
  • IDS/IPS
  • Authentication systems
  • Servers and endpoints
  • Network devices
  • Cloud platforms

The objective isn’t simply to generate alerts. The analyst needs to determine whether an alert represents a real security threat.

SOC Roles

L1 Analyst: Performs initial alert triage, investigates basic events, identifies false positives, and escalates complex cases.

L2 Analyst: Performs deeper investigation of advanced or suspicious incidents.

Security Engineer: Maintains and configures security technologies such as SIEM and EDR and helps improve detection capabilities.

SOC Manager: Oversees the SOC team, processes, operations, and overall performance.

For example, an analyst might see:

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.

The analyst correlates logs, examines the affected account or endpoint, checks the timeline, and determines whether the activity is legitimate or malicious.

When the SOC Needs More Help

Not every incident can be handled by the SOC alone.

For major or complex incidents, organizations may involve a Cyber Incident Response Team (CIRT/CSIRT/CERT).

CIRT teams can include specialists in:

  • Digital forensics
  • Malware analysis
  • Threat intelligence
  • Threat hunting
  • Incident response

For example, if an attacker compromises an endpoint and begins moving laterally across the network, the SOC may detect the activity and escalate it to incident response specialists for containment and deeper investigation.

This creates a simple relationship:

SOC → Detects and investigates

CIRT → Handles major incidents and response

Forensics → Determines what happened

Threat Intelligence → Provides attacker and threat context

Specialized Defensive Roles

As organizations become larger, security responsibilities become more specialized.

Some examples include:

Digital Forensics Analyst — Investigates disk, memory, and other digital evidence.

Threat Intelligence Analyst — Tracks threat actors, campaigns, indicators, and emerging threats.

AppSec Engineer — Integrates security into the software development lifecycle.

Threat Hunter — Proactively searches for suspicious activity that existing detections may have missed.

Security Engineer — Designs and maintains defensive security infrastructure.

These roles often require deeper specialization, but SOC experience can provide a strong foundation.

SOC L1 → Where Can You Go?

For many people, SOC L1 is an entry point into cybersecurity.

A typical progression might look like:

SOC L1 → SOC L2 → SOC L3 / Senior Analyst

But the path doesn’t have to remain within SOC operations.

You can move toward:

Threat Hunting | Incident Response | Digital Forensics | Threat Intelligence | Detection Engineering | Security Engineering | SOC Management

The important part is to use the early SOC experience to understand how real-world attacks, security controls, and investigations work.

Internal SOC vs MSSP

Another important distinction is between an internal SOC and an MSSP (Managed Security Services Provider).

An internal SOC protects its own organization.

For example:

A bank’s SOC monitors and protects the bank’s infrastructure.

An MSSP provides security services to multiple customers.

An MSSP analyst may monitor environments belonging to dozens of different organizations.

This means an MSSP environment can expose analysts to a much wider variety of technologies and incidents, while an internal SOC usually provides deeper knowledge of one organization’s environment.

The Bigger Picture

The SOC is not an isolated team.

It is part of a larger defensive ecosystem:

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.

The goal of all these functions is the same:

Detect threats → Understand them → Respond effectively → Improve the defenses

Final Takeaway

The biggest takeaway from the TryHackMe SOC Role in Blue Team room is that a SOC analyst is much more than someone who monitors dashboards.

The SOC is often the first operational layer of defense, connecting security telemetry with investigation and response.

Starting at SOC L1 can also provide exposure to a wide range of cybersecurity concepts and open paths into specialized areas such as incident response, threat hunting, digital forensics, threat intelligence, and security engineering.

For someone starting a Blue Team career, the fundamental mindset is simple:

Monitor. Detect. Investigate. Respond. Improve.

That is where the SOC fits into the Blue Team.

Disclaimer: Images are AI-generated and may contain inaccuracies. Content and concepts are based on TryHackMe; credit belongs to the original creators and owners.


메타데이터
post_id
efdede8e41fe
slug
soc-in-blue-team-where-security-operations-fits-efdede8e41fe
url
https://medium.com/@shashank.mb.rao/soc-in-blue-team-where-security-operations-fits-efdede8e41fe
canonical_url
https://medium.com/@shashank.mb.rao/soc-in-blue-team-where-security-operations-fits-efdede8e41fe
author_url
https://medium.com/@shashank.mb.rao
status
ok
fetched_at
2026-08-30 00:50:25