Training pathways
01 Blue Team
Defensive Security
See the signal. Understand the system. Act with evidence.
Learn how defenders collect telemetry, investigate alerts, validate incidents and improve controls across endpoints, identity, network and cloud-connected services.
Discuss this pathwayRoles within this pathway
Where this capability can take shape
- 01SOC Analyst
- 02Cyber Security Analyst
- 03Security Monitoring Analyst
- 04Incident Responder
- 05Threat Hunter
- 06Detection Engineer
- 07Vulnerability Analyst
- 08Endpoint Security Analyst
Practical capability
What you work through
Windows event logging and endpoint telemetry
SIEM searches, dashboards and correlation
Network traffic and packet analysis
Alert triage and incident scoping
Threat hunting and detection tuning
Containment, recovery and lessons learned
The precise sequence is adapted to prior experience, available hardware and the role outcome being pursued.
How practice works
A scenario should force more than one correct command.
- Observe
Establish what the environment is doing before deciding what is wrong.
- Reason
Form a testable explanation based on architecture, evidence and risk.
- Act
Configure, test, investigate or communicate the response required by the role.
- Defend
Explain the decision, its limitations and what should happen next.
No pathway works alone