Program Overview
What makes this track serious and market-ready
This track has been repositioned to feel less generic and more operational. The focus is on log visibility, SIEM usage, ATT&CK mapping, detection logic, endpoint investigation, and response communication so learners can build a more credible blue-team profile.
Blue-team fundamentals tied to real analyst workflows
Log and telemetry interpretation before tool dependence
Detection, investigation, and response sequencing
Case-based practice for SOC and IR readiness
Skills and Stack
Tools, workflows, and execution skills you will build
Threat monitoring
Log analysis
SIEM workflows
Alert triage
Endpoint visibility
ATT&CK mapping
Incident reporting
Blue-team reasoning
Program Syllabus
Detailed modules built for practical depth and role readiness
This syllabus is structured so students can see exactly how the track advances from blue-team foundations into monitoring, detection logic, triage workflows, and response communication.
- Module-wise progression from SOC fundamentals into practical detection workflows
- Hands-on telemetry review, SIEM practice, and investigation-oriented lab tasks
- Revision and analyst-ready preparation aligned with defensive security interviews
This version of the syllabus is built to feel more serious for competitive learners. It focuses on analyst thinking, telemetry interpretation, and operational response instead of a shallow overview of blue-team buzzwords.
- Threat, risk, and control language
- Blue-team operating model
- Security telemetry basics
- Analyst documentation discipline
- Windows and Linux event sources
- Sysmon and endpoint telemetry concepts
- Network traffic basics for defenders
- Telemetry collection blind spots
- Important log fields and parsing logic
- Hunting suspicious sequences in logs
- Correlation thinking for investigations
- Noise versus signal in analyst work
- Splunk, Wazuh, and ELK overview
- Detection dashboards and saved searches
- Basic alert logic creation
- Triage workflow inside a SIEM
- Indicators of compromise and behavior patterns
- Email, endpoint, and authentication alert review
- Severity and escalation logic
- Initial containment thinking
- Using MITRE ATT&CK in analysis
- Threat intel sources and enrichment
- Adversary technique mapping
- Improving analyst context during incidents
- Investigation sequencing
- Containment, eradication, and recovery basics
- Stakeholder communication
- Post-incident notes and reporting
- Log-based case walkthroughs
- Suspicious endpoint scenario review
- Mini detection exercises
- Interview-facing analyst explanations
Career Readiness
Roles, deliverables, and hiring preparation
Target roles
- SOC Analyst
- Blue Team Associate
- Security Monitoring Analyst
- Detection Operations Associate
Output you build
- Triage worksheet
- SIEM investigation notes
- ATT&CK mapped incident summary
- Blue-team lab evidence pack