
How I Passed TryHackMe — Security Analyst Level 1 (SAL1) on My Second Attempt!

TryHackMe launched their first professional certification on 25 February 2025: a blue team certification named Security Analyst Level 1 (SAL1). The naming convention is deliberately similar to BTL1, and both target entry-level security jobs. TryHackMe states in their FAQ that no prior education, certification, or work experience is required, which makes it one of the most accessible certifications in the space. The most interesting aspects, however, are how they marketed it and the exam format itself, but before that, let's cover pricing.

There are two pricing models:
- Non-premium users: £299, includes 2 exam attempts plus 3 months of THM Premium.
- Active premium subscribers: £255, exam only (2 attempts).
Theoretically, you could buy 1 month of premium at £12 first to qualify for the £255 price, saving £32 total, though I'm not sure if that model actually works in practice.

I am not a fan of how this certification is marketed. TryHackMe branded SAL1 as "The defensive certification that gets you hired": a claim that implies every certified holder will land a job, which is simply not true. A certification can prepare you with the skills; it cannot guarantee employment. Unless a firm explicitly commits to hiring SAL1-certified candidates, "get you hired" is aspirational at best and misleading at worst. The more accurate framing would be "skill-ready", not "job opportunity."

TryHackMe also published a comparison table against three other blue team certifications (BTL1, CDSA, and CySA+), which generated significant backlash from the community. Let's break down why:
- Job-ready SOC experience: TryHackMe is genuinely the only platform (at the time of writing, March 2025) that integrates a real SOC simulation into the exam with live alert triage. This criterion is legitimately theirs to claim.
- Brand trusted by millions: Note the word "Brand": they're comparing the platform's brand recognition, not the certification's recognition. These are very different things.
- Entry level: This is the most debatable column. CySA+ officially recommends a minimum of 4 years of hands-on experience, while the other certifications on the table (including SAL1) have no stated prerequisites. It's a fair point, but framing it as a head-to-head win is a stretch.
Certifications earn recognition through time and trust. Even if Fortune 500 companies trust TryHackMe's platform, whether they trust the SAL1 certification specifically is a different matter, and only time will tell. You can verify this yourself by searching "SAL1" or "Security Analyst Level 1" on LinkedIn.

There is also no "breakthrough" into cybersecurity: you're already in if you're willing to engage. If you encounter gatekeeping in one community, find another. There are plenty of cybersecurity communities that will genuinely help you.
With that said, let's talk about the exam itself.

The exam consists of 5 stages: identity verification, then 80 Multiple Choice Questions (MCQ), followed by SOC Simulation 1 and SOC Simulation 2 in sequence, and finally your result. There is no final report to write, but you do write a case report for each ticket as you close alerts inside the simulation.


The exam runs for 24 hours and requires a minimum of 750 / 1000 to pass. Here's the score breakdown:

Sections must be completed in order: you must finish the MCQ before starting Simulation 1, and Simulation 1 before Simulation 2. Each simulation generates alerts over time in a real SOC environment.


The SOC simulator generates alerts gradually: you'll use a Splunk SIEM to investigate each one and decide: True Positive (TP) or False Positive (FP)? If it's a TP, does it need to be escalated? Note that this is the same SOC simulator feature TryHackMe sells to business subscribers. Free and premium users can only practice on the "Phishing Unfolding" free simulation.

You also have access to TryDetectThis (TryHackMe's custom threat intelligence platform) on the analyst VM for reputation checks (file, hash, IP, domain). Do not expect VirusTotal results here; TryDetectThis is a custom tool specific to the exam environment.

TryHackMe provides a recommended learning path, practice rooms, and a free SOC simulator. My personal recommendation: do all the Splunk modules and challenges until you feel comfortable pivoting between different data sources and IOC types.


SAL1 comes with a 3-year validity period, similar to CompTIA and EC-Council certifications, and to newer OffSec certifications like OSCP+. However, since SAL1 is TryHackMe's first certification, the renewal process isn't clearly defined yet, keep an eye on how they handle this and what renewal fees, if any, will look like.
Attempt 1: Failed

I started my first attempt on launch day (25 February 2025), confident I'd pass. I had never used TryHackMe's SOC simulator before, so I tried it briefly to get a feel for the interface.

After identifying all the True Positives, the practice simulation ended and a results screen appeared. Without reading the feedback for each ticket, which I absolutely should have done, I jumped straight into the exam.

Clicking "Start Exam" triggers ID verification via Onfido: you'll need a webcam for face recognition and a physical ID. After that, you agree to the exam terms, watch a briefing video, and Section 1 begins.
The 80 MCQs weren't too hard for anyone who studied the recommended path. They cover fundamentals: security concepts, networking, NIST IR process, Cyber Kill Chain, and SOC methodology. I finished Section 1 and went directly into Sections 2 and 3 without any break, which was a mistake.
Unlike the free "Phishing Unfolding" simulation where you close all TP alerts within 30 minutes, the exam simulation generates alerts over time. You wait for alerts to appear: it genuinely simulates a real SOC shift. The total number of tickets is shown once Section 1 is complete, but you only need to close all TP alerts to finish each simulation.
After 3 hours and 20 minutes, I finished all three sections. Section 3 was shorter but more challenging than Section 2.

I failed. My SOC simulation scores on both sections were below the passing threshold, and I deserved it.

Breaking it down: each SOC simulation is worth 400 points: 150 for incident classification, 150 for escalation decisions, and 100 for the case report (AI-graded in real time as you close each alert). Reading the AI feedback afterward, I clearly failed to cover 5Ws+H (What, Where, When, Why, Who, and How) thoroughly enough, and I hadn't read the documentation carefully, which meant I missed important context about the environment, TP/FP criteria, and escalation requirements.
Between Attempts: Preparation

SAL1 has a 3-day cooling period before you can use your retake. The exam package includes 1 retake, so I planned to sit it again the following Saturday once I was fully rested and prepared.

I practiced more with the SOC simulator and studied how the AI grades case reports. I noticed that AI feedback is only provided for True Positive alerts: FPs don't generate report scores.

I went back and read the case reports I'd written during the first attempt. I had been overconfident and lazy: I overlooked the AI's feedback entirely during the exam, which might have helped me course-correct and pass on the first try.
Attempt 2: Passed
On Saturday, after breakfast (or lunch?), I retook the exam. The MCQs felt harder this time: if Attempt 1 was slightly easier than CySA+, Attempt 2 was harder. After finishing Section 1, I started Section 2 immediately. I got the same SOC simulation as before, which let me go deeper than my first attempt, and I noticed a crucial detail I had missed entirely the first time around.
For the case reports this time, I wrote very thorough reports covering everything I found. It took 1 hour and 40 minutes to close all TP alerts in Section 2. The mental exhaustion was real, so I took a 6-hour break before tackling Section 3. Section 3 was a different simulation, also 1 hour and 40 minutes.

I passed with 959 / 1000: full marks on both classification and escalation, and case report scores above 80 on both simulations.

The certificate is issued immediately upon passing and includes the expiration date.
SAL1 nailed the SOC simulation experience. Replicating a real SOC environment in an exam, where alerts trickle in over time and you have to triage them with Splunk, is genuinely innovative and I haven't seen another certification do it this way.
That said, the AI case-report grading still needs work. The main issue is transparency: I wish you could see exactly which parts of your report scored well and which didn't, not just during the exam, but also in the free SOC simulator practice mode. This would help candidates understand what the AI actually values, improving the learning loop and building trust in the grading system.
From TryHackMe's perspective, AI grading makes perfect sense. It scales to handle any number of simultaneous exam sitters without needing human graders, and it delivers results immediately. The challenge is convincing the community that the grades are fair, and right now, many people (including several of my friends) are skeptical.
I'd also love to see TryDetectThis integrated directly into the SOC alert panel, so you can paste IPs, hashes, and domains without switching to a separate analyst VM tab. A small UX improvement that would reduce friction considerably.
Finally, I'll be honest: this exam is not truly entry level, at least not by the standards of my country. The depth of case report writing expected (covering full 5Ws+H and environment context) goes well beyond what a typical SOC L1 analyst is expected to produce. Maybe TryHackMe is deliberately setting a higher bar. If so, say so explicitly.
- Read the documentation thoroughly before triaging any alerts. Understand the criteria for TP vs. FP, and the escalation requirements for each alert type. Missing these will cost you heavily.
- Read each alert's details and description carefully. Understand how it was triggered before you start your investigation.
- Do not underestimate the MCQ section. It's straightforward but covers a wide range (NIST IR process, Cyber Kill Chain, networking fundamentals, SOC workflows) and breadth is what catches people off guard.
- Treat the case report as a bonus multiplier: if you nail classification and escalation, your report score tips you over the line. If you're borderline on classification, a strong report can save you.
- Practice case report writing with Phishing Unfolding (the free SOC simulation). Study the AI feedback on each closed alert and iterate: understand what the AI rewards.
- Cover 5Ws+H in every case report: What happened, Where it occurred, When, Why it's significant, Who is involved, and How it was carried out. Go beyond what's visible on the ticket.
- Skip FP alerts: the simulation only completes when all TP alerts are closed. Spending time investigating a FP beyond ruling it out is wasted time.
- This is a 24-hour exam. Plan your schedule. You do not have to do everything in one sitting, and you shouldn't. Take real breaks. Mental exhaustion degrades both your triage accuracy and your report quality, which compounds against you.
- If you don't have access to TryHackMe's full SOC simulator, practice alert triage on LetsDefend: they offer over 100 free alerts (15/month for free users). The experience isn't identical, but it exposes you to different alert types and playbooks.
- Stay hydrated and keep snacks nearby. Seriously.

Overall: TryHackMe's SOC simulation is a genuinely great exam format. I hope other vendors take note. The AI grading needs more transparency and tuning. The marketing is dishonest and will push away people who would otherwise be interested. And the difficulty level is set higher than "entry level" in practice, which TryHackMe should be upfront about.
I learned from TryHackMe when I was a college student, and so have many others. That legacy deserves honesty and integrity in how they present new products. Let's build a good-hygiene cybersecurity community.
Peace out~ ✌️