root@thehacksparrow:~/writeups$ SYSTEM ONLINE
root@sparrow:~/writeups$ cat soc-l2-alert-triage.md
// Blue Team & SOC

SOC L2 Alert Triage

15 Mar 2023 · 11 min read · user access
Overview — A room on the SOC Level 2 path centred on the core L2 responsibility: picking up an alert that L1 has already triaged and escalated, then performing the deeper log analysis, verdict-making, and advanced response actions that L1 cannot do alone. The idea running through the whole room is that L1 optimises for triage speed while L2 optimises for triage quality and depth. It closes with a hands-on challenge around a fake Claude Desktop installer that actually delivers an infostealer.
PlatformTryHackMe
CategoryBlue Team & SOC
DifficultyEasy
RoomSOC L2 Alert Triage

L1 versus L2

Before diving into the tasks it helps to pin down the role difference the room repeats throughout:

AspectLevel 1Level 2
TriggerNew security alertEscalated alert
FocusQuick alert triage within SLADeeper log analysis and response
ToolsTicketing system + SIEMWider range of SOC and IT tools
ResponseQuarantine a file, approve a SOAR playbookManually clean malware, disable users, isolate hosts
🔒 Free account required

This is USER ACCESS content — free to unlock, no payment. The rest of the write-up (and everything else at this level) opens up once you're signed in.

Create a free account