Defensive SecurityBeginner~6 months

Blue Team

Defend organizations through monitoring, detection, incident response, and security operations.

10 Topics

Key concepts

3 Levels

Beginner to Advanced

6 Tools

Curated for this track

8 Questions

Test yourself

About this track

Detection, response, and the operations that make them work.

Blue team work is where security meets operations. The job is to see what is happening across an estate, decide quickly what matters, and respond before an intrusion becomes an incident — repeatedly, under alert volume that never stops.

This track covers the SOC toolchain from the analyst's seat outward: SIEM query fluency, endpoint telemetry, triage discipline, and then the engineering work of writing detections that fire on attacker behaviour rather than on easily-changed indicators.

It rewards pairing with an offensive track. The best detection engineers know precisely what the attack looks like from the other side.

Key topics

10 topics grouped into three modules, in the order you should meet them.

  1. 01

    Visibility

    4 topics
    • 1.

      SIEM Operations

      Ingestion, normalisation, and writing queries that answer a real question.

    • 2.

      Threat Hunting

      Starting from a hypothesis instead of waiting for an alert to arrive.

    • 3.

      Incident Response

      The formal cycle — prepare, detect, contain, eradicate, recover, review.

    • 4.

      Log Analysis

      Knowing which log answers which question, and what each source silently omits.

  2. 02

    Detection & hunting

    4 topics
    • 5.

      Endpoint Detection

      EDR telemetry, process trees, and what the agent cannot see.

    • 6.

      Security Monitoring

      Coverage, alert fatigue, and the tuning that keeps a queue survivable.

    • 7.

      Vulnerability Management

      Prioritising by exploitability and exposure rather than by CVSS alone.

    • 8.

      Threat Intelligence

      Turning external reporting into detections that fire in your environment.

  3. 03

    Response & engineering

    2 topics
    • 9.

      SOC Operations

      Shift handover, runbooks, and the process discipline that makes a team scale.

    • 10.

      Detection Engineering

      Building rules on attacker behaviour so they survive a changed hash or domain.

What you'll be able to do

  • Triage an alert queue and justify what you escalated and what you closed
  • Write SIEM queries that answer an investigative question, not just return rows
  • Build behavioural detections mapped to MITRE ATT&CK techniques
  • Run an incident from detection through to a written post-incident review