# Senior Security Analyst Intro (TryHackMe)

Challenge on TryHackMe: **Senior Security Analyst Intro**

## Journey to Senior

## **Journey to Senior**

Ready to take the next step beyond Level 1? The natural progression is to the SOC Level 2 analyst role, where juniors grow into experienced, decision-making team members. This room serves as a roadmap for getting there: the technical skills, the broader toolkit, and the new challenges and responsibilities to expect. You'll also learn how to develop a senior mindset and prepare for even more advanced roles. Let's get started!

![Illustration of a woman climbing stairs toward a gold award medal, with arrows reading More Skills, More Challenges, and More Responsibility, showing career growth.](https://cdn-images.tryhackme.com/user-uploads/678ecc92c80aa206339f0f23/room-content/678ecc92c80aa206339f0f23-1782912588518.png align="center")

## **Today, You Will Learn**

*   How middle-senior responsibilities differ from junior ones
    
*   Which skills you'd need, and how to prepare for promotion
    
*   What a typical day as a SOC Level 2 analyst looks like
    

## New Role, New Duties

## **SOC Level 2 Definition**

The Level 2 analyst is a natural progression from Level 1: a middle- or senior-level technical role responsible for investigating escalated alerts and responding to threats. As Level 2, you are expected to excel at log analysis and take over basic engineering and incident response tasks. In addition, you should have strong soft skills to mentor juniors, take initiative, and properly communicate with different teams.

![Skill comparison chart for L1 and L2 SOC analysts across Log Analysis, Engineering, DFIR, Communication, Initiative, and Mentorship, scored 0 to 100.](https://cdn-images.tryhackme.com/user-uploads/678ecc92c80aa206339f0f23/room-content/678ecc92c80aa206339f0f23-1779721838619.svg align="center")

*Typical expectations for L1 and L2 analysts from 0 to 100*

## **New Tasks and Duties**

Your schedule will typically be split between shift-based triage of escalated alerts (your core duty) and a range of supportive tasks. We'll cover L2 triage in the next room, but the supportive side of the role can be quite broad. Unless your company has a dedicated L3 position and DFIR team, you may take on lots of senior duties as an L2, for example:

*   Build new detection rules and run threat hunting exercises
    
*   Cooperate with the IT team to configure the network securely
    
*   Respond to infections: clean malware and rotate credentials
    
*   Participate in, or even lead IR in case of a major intrusion
    
*   And, of course, triage complex alerts escalated by Level 1
    

## **Importance of Soft Skills**

The biggest difference between L1 and L2 is not in technical knowledge, but in the soft skills: responsibility, attitude, and mindset. You will need to mentor juniors and help them grow alongside you, take initiative and lead discussions, communicate effectively within the team and externally, and much more! In the next few rooms, you will learn more about the teamwork and mentorship aspects of the L2.

### Answer the questions below

Should you improve **tech**, **soft**, or **both** skills to become L2? `Both`

## Fun of Being SOC L2

## **Fun of Being SOC L2**

We've talked about the duties of Level 2, but what about the benefits? Beyond the higher salary, you'll have a chance to broaden your worldview and grow in different areas: mentorship and leadership, closer cooperation with management, incident handling, engineering tasks, and much more. The role should push you out of your comfort zone and stop you from becoming a narrow specialist, incapable of doing anything beyond your favorite task:

![Quadrant chart plotting skill breadth against depth, with categories Surface Explorer, Perfect Level 2, Not Ready Yet, and One-Tool Guru, for assessing analyst readiness.](https://cdn-images.tryhackme.com/user-uploads/678ecc92c80aa206339f0f23/room-content/678ecc92c80aa206339f0f23-1781692390272.svg align="center")

## **Incident Handling**

You'll deal with the most interesting cases, attacks that are too complex for L1 to investigate: infostealers that bypassed prevention, supply chain attacks, insider threats, Active Directory intrusions, and so on. You'll also move beyond SIEM\-only triage and start doing on-host investigations, network and malware analysis, and even some OSINT. There, you'll:

*   Learn how to respond to attacks using EDR or a regular CLI
    
*   See the world beyond SIEM: host, cloud, and network points of view
    
*   Observe the same attacks you read about in threat reports and blogs
    

![News article headline reading Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account.](https://cdn-images.tryhackme.com/user-uploads/678ecc92c80aa206339f0f23/room-content/678ecc92c80aa206339f0f23-1778542450265.png align="center")

*As an L2, you often handle the incident first and find it in the news only a day later.*

## **Engineering Tasks**

Only large MSSPs can afford fully analytical L2 roles. Most companies merge L2 duties with detection engineering, SIEM maintenance, and security automation. That's actually great, because the more "side" tasks you take on, the wider your worldview becomes. The broad experience you build here is vital for your growth. Some tasks you can expect:

*   Simulate an attack and build a detection rule to cover it
    
*   Dig deeper into how SIEMs and EDRs work internally
    
*   Automate a routine task and make your team's life easier
    

![A big Splunk SPL query for Azure sign-in logs using streamstats and haversine math to detect impossible travel between login locations within a 24 hour window.](https://cdn-images.tryhackme.com/user-uploads/678ecc92c80aa206339f0f23/room-content/678ecc92c80aa206339f0f23-1778542450404.png align="center")

*Have you wondered how most SIEM rules work? As L2, you'll find out!*

## **General Security Tasks**

You will dig deeper into how the company operates and what parts of it are covered by SOC. Expect more opportunities to work with IT on patching vulnerabilities, tightening policies, and securing public services. Occasionally, you will help the compliance team, analyze pentest results, or even run red teaming exercises yourself. The skills you can build here:

*   Learn about corporate processes and the daily life of other departments, especially IT
    
*   Discover enterprise software such as SAP, Salesforce, Jira, Stripe, and the M365 suite
    
*   Explore new security domains: pentesting, compliance, DevOps, AppSec, and more
    

![PingCastle Password Policies report showing a weak Default Domain Policy with complexity off, passwords never expiring, minimum length 6, and history of 1.](https://cdn-images.tryhackme.com/user-uploads/678ecc92c80aa206339f0f23/room-content/678ecc92c80aa206339f0f23-1778537083698.png align="center")

*By cooperating with IT, you will better understand how companies are breached.*

### Answer the questions below

Does exploring new security areas help you grow? (Yea/Nay) `Yea`

## L1 vs L2 Mindset Shift

## **Sense of Responsibility**

Level 2 isn't just a technical step up, it's a mindset shift. As a senior, you take responsibility for your team and for the security posture of the whole organization. You can't say "it's not my fault" after a ransomware attack, because everyone now expects ownership from you, not excuses. And the first rule of the senior mindset is simple: never ignore a security concern, whether it was raised by you or someone else.

![Illustration of a large concrete dam holding back water, with a visible vertical crack running down its center.](https://cdn-images.tryhackme.com/user-uploads/678ecc92c80aa206339f0f23/room-content/678ecc92c80aa206339f0f23-1779386212077.png align="center")

*Whenever you see a security crack, raise the alarm, even if it's not your fault*

**Scenario**

*One of the L1 mentioned that we haven't seen any alerts from the servers for two weeks.*  
*In the past, the servers regularly generated False Positives due to IT team actions.*

*   **Junior mindset**: No logs means no alerts, and no alerts means less work to do.
    
*   **Senior mindset**: No alerts for weeks is not OK. Something is wrong with the logging.
    

The senior must be 100% sure that the critical servers are well monitored. They would work with engineers to identify the root cause of the issue, run a hunt to detect log tampering attempts, and ensure the team is better prepared next time.

## **Attacker Mindset**

It is recommended that L2 have some red teaming experience because the more you understand how attacks occur, the easier it is to understand the adversary's behavior and predict their next steps. Combined with knowledge of MITRE and the Cyber Kill Chain, the attacker's mindset will help you read between the lines and run your investigations much more quickly and in a more organized way.

![Jigsaw puzzle illustration tracing an attack path through connected pieces: a green lock and user, an orange network node, and a red cloud exfiltration icon.](https://cdn-images.tryhackme.com/user-uploads/678ecc92c80aa206339f0f23/room-content/678ecc92c80aa206339f0f23-1779386212087.png align="center")

*Thinking like an attacker helps you complete the attack puzzle:*  
*What happened before the alert, and what's coming next*

**Scenario**

*An alert fires for a PowerShell command spawned by the IIS web server.*  
*The command is a simple "whoami". No more commands are seen afterward.*

*   **Junior mindset**: The command is safe, this is likely expected web server activity.
    
*   **Senior mindset**: Looks like a test of a web shell. Malicious commands will follow later.
    

Even if the command is safe, the senior would first assume breach and then spend time on deep log analysis or even forensics to prove that it was not a test before the full-scale attack, but rather the expected activity of a web server.

### Answer the questions below

What mindset helps you see and predict how incidents unfold? `Attacker Mindset`

## Your Day as Level 2

## **Challenge**

Open the static site by clicking the **View Site** button below. You will start from a SIEM interface and go through a daily routine of the L2 analyst: triage of escalated alerts, rule development and tuning, and responding to urgent threats. Follow the instructions in the app and get your flag.

View Site

**Note**: For best experience, open the app in full screen mode.

### Answer the questions below

What flag did you get after completing the challenge? `THM{much_more_than_alert_redacted}`

````python
```Double-Extension File Creation```
index=windows EventCode=11 TargetFilename IN(*.pdf.exe, *.pdf.lnk, ...)
| table _time host user Image TargetFilename
````

````python
```Double-Extension File Creation```
index=windows EventCode=11 TargetFilename IN(*.pdf.exe, *.pdf.lnk, ...)
NOT TargetFilename IN(C:\\Program Files\\TryHackMeToolkit\\*)
| table _time host user Image TargetFilename
````

![](https://cdn.hashnode.com/uploads/covers/5f4a98085ee1ba597542e097/8c69c5fb-c7a7-4452-a9dc-cd3f1d7ff4ea.png align="center")

## Next Steps

## **Preparing for Promotion**

In this room, you have learned the duties and opportunities of the L2 role. Next, we'd suggest:

| **#** | **Goal** | **Suggestions** |
| --- | --- | --- |
| 1 | Gain SOC technical skills |  |

*   Complete the [SOC Level 2 Analyst](https://tryhackme.com/path/outline/soclevel2) path
    
*   Try yourself in different blue challenges
    
*   Monitor how L2 in your company operate
    

<table style="min-width: 75px;"><colgroup><col style="min-width: 25px;"><col style="min-width: 25px;"><col style="min-width: 25px;"></colgroup><tbody><tr><td colspan="1" rowspan="1"><p>2</p></td><td colspan="1" rowspan="1"><p>Build up attacker's mindset</p></td><td colspan="1" rowspan="1"><p></p></td></tr></tbody></table>

*   Complete rooms from the [Red Teaming](https://tryhackme.com/path/outline/redteaming) path
    
*   Analyze historical incidents your company faced
    
*   Read cyber news, especially technical threat reports
    

<table style="min-width: 75px;"><colgroup><col style="min-width: 25px;"><col style="min-width: 25px;"><col style="min-width: 25px;"></colgroup><tbody><tr><td colspan="1" rowspan="1"><p>3</p></td><td colspan="1" rowspan="1"><p>Broaden security awareness</p></td><td colspan="1" rowspan="1"><p></p></td></tr></tbody></table>

*   Discover how other teams in your company work
    
*   Volunteer for an engineering task (e.g., fix a rule)
    
*   Ask to be involved in the Incident Response tasks
    

<table style="min-width: 75px;"><colgroup><col style="min-width: 25px;"><col style="min-width: 25px;"><col style="min-width: 25px;"></colgroup><tbody><tr><td colspan="1" rowspan="1"><p>4</p></td><td colspan="1" rowspan="1"><p>Validate acquired skills</p></td><td colspan="1" rowspan="1"><p></p></td></tr></tbody></table>

*   Consider passing a practical SOC or IR certification
    
*   For example, check out TryHackMe's [SAL2](https://tryhackme.com/certification/security-analyst-level-2/details) certification  
    (Evaluates both hard and soft skills across 12 domains)
    

  
See you in the next room!
