TryHackMe: SOC in Blue Team — Where Security Operations Fits
https://tryhackme.com/room/socroleinblueteam
TryHackMe: SOC in Blue Team — Where Security Operations Fits

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.
When we talk about cybersecurity, we often focus on attacks, vulnerabilities, and penetration testing. But once an attack happens, who detects it, investigates it, and responds?
That is where the Blue Team and, more specifically, the Security Operations Center (SOC) come in.
I recently completed the SOC Role in Blue Team room on TryHackMe, which helped me understand where the SOC fits within an organization’s security structure, what different defensive teams do, and how a SOC career can evolve.
Where Does the SOC Fit?
A typical large organization may have a security hierarchy like:
CEO → CISO → Security Departments → Security Teams
The CISO (Chief Information Security Officer) is responsible for aligning cybersecurity with the organization’s business requirements.
Under the security function, different teams may have different responsibilities:
- Red Team — Offensive security, penetration testing, and finding weaknesses.
- GRC — Security policies, risk management, and regulatory compliance.
- Blue Team — Defensive security, monitoring, detection, and response.
The exact structure depends on the organization’s size and security requirements.
The Blue Team
The Blue Team is responsible for defending the organization’s systems, networks, applications, and data.
Instead of trying to exploit systems, the Blue Team focuses on questions such as:
Can we detect an attack? Can we investigate it? Can we contain it before it causes serious damage?
The Blue Team can include several specialized functions, including SOC analysts, security engineers, incident responders, threat hunters, forensic analysts, and threat intelligence analysts.
SOC: The First Line of Defense
The Security Operations Center (SOC) acts as the central operational hub for security monitoring.
A simplified SOC workflow looks like:
Telemetry → Detection → Alert → Triage → Investigation → Escalation/Response

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.
A SOC receives security data from sources such as:
- SIEM
- EDR
- Firewalls
- IDS/IPS
- Authentication systems
- Servers and endpoints
- Network devices
- Cloud platforms
The objective isn’t simply to generate alerts. The analyst needs to determine whether an alert represents a real security threat.
SOC Roles
L1 Analyst: Performs initial alert triage, investigates basic events, identifies false positives, and escalates complex cases.
L2 Analyst: Performs deeper investigation of advanced or suspicious incidents.
Security Engineer: Maintains and configures security technologies such as SIEM and EDR and helps improve detection capabilities.
SOC Manager: Oversees the SOC team, processes, operations, and overall performance.
For example, an analyst might see:

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.
The analyst correlates logs, examines the affected account or endpoint, checks the timeline, and determines whether the activity is legitimate or malicious.
When the SOC Needs More Help
Not every incident can be handled by the SOC alone.
For major or complex incidents, organizations may involve a Cyber Incident Response Team (CIRT/CSIRT/CERT).
CIRT teams can include specialists in:
- Digital forensics
- Malware analysis
- Threat intelligence
- Threat hunting
- Incident response
For example, if an attacker compromises an endpoint and begins moving laterally across the network, the SOC may detect the activity and escalate it to incident response specialists for containment and deeper investigation.
This creates a simple relationship:
SOC → Detects and investigates
CIRT → Handles major incidents and response
Forensics → Determines what happened
Threat Intelligence → Provides attacker and threat context
Specialized Defensive Roles
As organizations become larger, security responsibilities become more specialized.
Some examples include:
Digital Forensics Analyst — Investigates disk, memory, and other digital evidence.
Threat Intelligence Analyst — Tracks threat actors, campaigns, indicators, and emerging threats.
AppSec Engineer — Integrates security into the software development lifecycle.
Threat Hunter — Proactively searches for suspicious activity that existing detections may have missed.
Security Engineer — Designs and maintains defensive security infrastructure.
These roles often require deeper specialization, but SOC experience can provide a strong foundation.
SOC L1 → Where Can You Go?
For many people, SOC L1 is an entry point into cybersecurity.
A typical progression might look like:
SOC L1 → SOC L2 → SOC L3 / Senior Analyst
But the path doesn’t have to remain within SOC operations.
You can move toward:
Threat Hunting | Incident Response | Digital Forensics | Threat Intelligence | Detection Engineering | Security Engineering | SOC Management
The important part is to use the early SOC experience to understand how real-world attacks, security controls, and investigations work.
Internal SOC vs MSSP
Another important distinction is between an internal SOC and an MSSP (Managed Security Services Provider).
An internal SOC protects its own organization.
For example:
A bank’s SOC monitors and protects the bank’s infrastructure.
An MSSP provides security services to multiple customers.
An MSSP analyst may monitor environments belonging to dozens of different organizations.
This means an MSSP environment can expose analysts to a much wider variety of technologies and incidents, while an internal SOC usually provides deeper knowledge of one organization’s environment.
The Bigger Picture
The SOC is not an isolated team.
It is part of a larger defensive ecosystem:

Disclaimer: This image is AI-generated for illustrative purposes and may contain inaccuracies. Any existing concepts or factual content represented belong to their respective original owners.
The goal of all these functions is the same:
Detect threats → Understand them → Respond effectively → Improve the defenses
Final Takeaway
The biggest takeaway from the TryHackMe SOC Role in Blue Team room is that a SOC analyst is much more than someone who monitors dashboards.
The SOC is often the first operational layer of defense, connecting security telemetry with investigation and response.
Starting at SOC L1 can also provide exposure to a wide range of cybersecurity concepts and open paths into specialized areas such as incident response, threat hunting, digital forensics, threat intelligence, and security engineering.
For someone starting a Blue Team career, the fundamental mindset is simple:
Monitor. Detect. Investigate. Respond. Improve.
That is where the SOC fits into the Blue Team.
Disclaimer: Images are AI-generated and may contain inaccuracies. Content and concepts are based on TryHackMe; credit belongs to the original creators and owners.
메타데이터
- post_id
- efdede8e41fe
- slug
- soc-in-blue-team-where-security-operations-fits-efdede8e41fe
- url
- https://medium.com/@shashank.mb.rao/soc-in-blue-team-where-security-operations-fits-efdede8e41fe
- canonical_url
- https://medium.com/@shashank.mb.rao/soc-in-blue-team-where-security-operations-fits-efdede8e41fe
- author_url
- https://medium.com/@shashank.mb.rao
- status
- ok
- fetched_at
- 2026-08-30 00:50:25