root@sparrow:~/writeups$ cat soc-l2-alert-triage.md
// Blue Team & SOC
SOC L2 Alert Triage
15 Mar 2023
· 11 min read
· user access
Overview — A room on the SOC Level 2 path centred on the core L2 responsibility: picking up an alert that L1 has already triaged and escalated, then performing the deeper log analysis, verdict-making, and advanced response actions that L1 cannot do alone. The idea running through the whole room is that L1 optimises for triage speed while L2 optimises for triage quality and depth. It closes with a hands-on challenge around a fake Claude Desktop installer that actually delivers an infostealer.
| Platform | TryHackMe |
| Category | Blue Team & SOC |
| Difficulty | Easy |
| Room | SOC L2 Alert Triage |
L1 versus L2
Before diving into the tasks it helps to pin down the role difference the room repeats throughout:
| Aspect | Level 1 | Level 2 |
|---|---|---|
| Trigger | New security alert | Escalated alert |
| Focus | Quick alert triage within SLA | Deeper log analysis and response |
| Tools | Ticketing system + SIEM | Wider range of SOC and IT tools |
| Response | Quarantine a file, approve a SOAR playbook | Manually clean malware, disable users, isolate hosts |
Resumen — Room de la ruta SOC Level 2 centrado en la responsabilidad central de un analista L2: recoger una alerta que L1 ya ha triado y escalado, y realizar el análisis de logs profundo, la emisión de veredicto y las acciones de respuesta avanzadas que L1 no puede ejecutar por sí solo. La idea clave que atraviesa todo el room es que L1 optimiza la velocidad del triaje mientras L2 optimiza la calidad y la profundidad. Cierra con un reto práctico sobre un falso instalador de Claude Desktop que en realidad entrega un infostealer.
| Plataforma | TryHackMe |
| Categoría | Blue Team & SOC |
| Dificultad | Easy |
| Room | SOC L2 Alert Triage |
L1 frente a L2
Antes de entrar en las tareas conviene fijar la diferencia de roles que el room repite una y otra vez:
| Aspecto | Level 1 | Level 2 |
|---|---|---|
| Disparador | Nueva alerta de seguridad | Alerta escalada |
| Foco | Triaje rápido dentro del SLA | Análisis de logs y respuesta profundos |
| Herramientas | Sistema de tickets + SIEM | Abanico más amplio de herramientas SOC e IT |
| Respuesta | Poner un fichero en cuarentena, aprobar un playbook SOAR | Limpiar malware a mano, deshabilitar usuarios, aislar hosts |
🔒 Free account required
This is USER ACCESS content — free to unlock, no payment. The rest of the write-up (and everything else at this level) opens up once you're signed in.
Create a free account🔒 Registro gratuito requerido
Esto es contenido de nivel USER ACCESS — se desbloquea gratis, sin pago. El resto del writeup (y todo lo demás de este nivel) se abre en cuanto inicies sesión.
Crear una cuenta gratis