Blue Team
Defend organizations through monitoring, detection, incident response, and security operations.
10 Topics
Key concepts
3 Levels
Beginner to Advanced
6 Tools
Curated for this track
8 Questions
Test yourself
About this track
Detection, response, and the operations that make them work.
Blue team work is where security meets operations. The job is to see what is happening across an estate, decide quickly what matters, and respond before an intrusion becomes an incident — repeatedly, under alert volume that never stops.
This track covers the SOC toolchain from the analyst's seat outward: SIEM query fluency, endpoint telemetry, triage discipline, and then the engineering work of writing detections that fire on attacker behaviour rather than on easily-changed indicators.
It rewards pairing with an offensive track. The best detection engineers know precisely what the attack looks like from the other side.
Key topics
10 topics grouped into three modules, in the order you should meet them.
- 01
Visibility
4 topics- 1.
SIEM Operations
Ingestion, normalisation, and writing queries that answer a real question.
- 2.
Threat Hunting
Starting from a hypothesis instead of waiting for an alert to arrive.
- 3.
Incident Response
The formal cycle — prepare, detect, contain, eradicate, recover, review.
- 4.
Log Analysis
Knowing which log answers which question, and what each source silently omits.
- 1.
- 02
Detection & hunting
4 topics- 5.
Endpoint Detection
EDR telemetry, process trees, and what the agent cannot see.
- 6.
Security Monitoring
Coverage, alert fatigue, and the tuning that keeps a queue survivable.
- 7.
Vulnerability Management
Prioritising by exploitability and exposure rather than by CVSS alone.
- 8.
Threat Intelligence
Turning external reporting into detections that fire in your environment.
- 5.
- 03
Response & engineering
2 topics- 9.
SOC Operations
Shift handover, runbooks, and the process discipline that makes a team scale.
- 10.
Detection Engineering
Building rules on attacker behaviour so they survive a changed hash or domain.
- 9.
What you'll be able to do
- Triage an alert queue and justify what you escalated and what you closed
- Write SIEM queries that answer an investigative question, not just return rows
- Build behavioural detections mapped to MITRE ATT&CK techniques
- Run an incident from detection through to a written post-incident review