Blue Team Level 1
MotiGraph
Track

Blue Team Level 1

The defensive foundation: an integrated Security+, BTL1 and SC-200 preparation path, from cybersecurity fundamentals to working a SOC on the Microsoft security stack.

26 Courses
108 Lessons
120 Hours
16 Weeks
Beginner Level
  • Security+
  • BTL1
  • SC-200
  • SOC
  • SIEM
  • Microsoft Sentinel
  • Defender
  • Incident Response
About This Track

What You Are Signing Up For

This is the blue-team route, and it teaches the other half of the discipline: not how to break in, but how to see it happen and stop it. You start with the fundamentals that Security+ covers — the concepts, the network, threats and identity, cryptography and endpoint and network security — then move into security operations proper: monitoring, SIEM, log analysis and alert triage the way BTL1 measures. The last third is the Microsoft defensive stack that SC-200 targets: Sentinel, Defender, and KQL to hunt through the telemetry. It is heavy on practical labs — Wireshark, Windows and Linux logs, a live SIEM, phishing and IOC investigations, MITRE ATT&CK mapping — and it ends with a full SOC investigation run the way an analyst runs one.

  • One continuous route across Security+, BTL1 and SC-200 — fundamentals to a working SOC analyst.
  • Built around the tools a SOC actually uses: a SIEM, Microsoft Sentinel and Defender, and KQL.
  • Fourteen practical labs, from packet analysis to a full incident investigation.
  • Ends with a complete SOC investigation, triaged, hunted and reported.

What You Will Be Able to Do

  • Explain cybersecurity fundamentals, threats, identity and cryptography.
  • Analyse network traffic and read Windows and Linux logs for signal.
  • Work a SIEM: ingest, search, and triage alerts.
  • Hunt through telemetry with KQL in Microsoft Sentinel.
  • Investigate phishing, IOCs and malware at a triage level.
  • Map activity to MITRE ATT&CK and drive a SOC investigation workflow.
  • Run incident response and write a professional incident report.
  • Operate Microsoft Sentinel and Defender as a junior SOC analyst.

Requirements

  • Basic IT and networking familiarity.
  • Comfort with Windows and Linux at a basic level, or the willingness to build it.
  • No prior security experience required.
  • A machine that can run virtual labs.

Who It Is For

  • Beginners in cyber security.
  • IT and Computer Science students.
  • IT and system administrators.
  • Network engineers.
  • Anyone wanting to enter a SOC.
  • Junior security analysts.
  • Anyone moving from IT into the blue team.

This is a preparation and training track. It builds the knowledge and practical skills the Security+, BTL1 and SC-200 paths are built on, but it does not award those certifications: their official exams and requirements are set by CompTIA, Security Blue Team and Microsoft respectively, and are separate. All practical work is carried out in authorised, isolated lab environments only.

Skills

What You Will Learn

Security Foundations (Security+)

  • Cybersecurity fundamentals and the CIA triad
  • Networking and security protocols
  • Threats, vulnerabilities and attacks
  • Identity and access management
  • Cryptography and PKI
  • Endpoint and network security

Security Monitoring & SIEM

  • Security monitoring concepts
  • SIEM fundamentals and log ingestion
  • Log analysis across Windows and Linux
  • Alert triage and prioritisation
  • KQL fundamentals for hunting

Microsoft Defensive Stack (SC-200)

  • Microsoft Sentinel: workspace, analytics and hunting
  • Microsoft Defender across the stack
  • Windows security and telemetry
  • Linux security and logging

Detection & Response (BTL1)

  • IOC investigation and threat intelligence
  • Phishing and malware triage
  • Detection engineering and MITRE ATT&CK
  • Incident response and the SOC investigation workflow
  • Incident reporting to a professional standard
Hands On

What You Will Build

Every project below is yours to keep and to show. By the end you have a portfolio, not a certificate alone.

Practical Labs

  • Wireshark traffic analysis
  • Windows event logs and Linux logs
  • SIEM investigation and Microsoft Sentinel
  • Microsoft Defender and KQL queries
  • Phishing investigation and IOC hunting
  • Malware triage and MITRE ATT&CK mapping
  • Incident response and SOC alert triage

Final Investigation

  • A full SOC investigation from alert to report
  • Triage, correlation, IOC hunting and containment
  • A professional incident report and handover

Graduation Project

You finish with a full SOC investigation run the way an analyst runs one: an alert arrives, and you triage it, correlate the surrounding telemetry, hunt for indicators of compromise across the logs and the SIEM, map what you find to MITRE ATT&CK, decide on containment, and write it all up as a professional incident report a team could act on. It ties together everything the three certifications cover into one piece of work you can show.

The Roadmap

Your Path Through This Track

Blue Team Level 1 roadmap
The Route

Course by Course

26 modules · 108 lessons. Open any module to see what is inside it.

  1. 01 Security+ Foundation Cybersecurity Fundamentals Beginner 5 lessons 4 hours

    The vocabulary and the mental model a defender works from. What information security actually protects, the CIA triad, the kinds of threat and control, and where a security operations centre sits in all of it.

    • Security+
    • Fundamentals
    • CIA Triad
    • Information security and the CIA triad
    • Threats, vulnerabilities, risks and controls
    • Security control types
    • The role of a SOC and a defender
    • Governance, risk and compliance basics
    Open course
  2. 02 Security+ Networking and Security Protocols Beginner 5 lessons 5 hours

    You cannot defend traffic you do not understand. The network stack, the protocols you will meet on every alert, and the secure and insecure versions of each, so a log line means something.

    • Security+
    • Networking
    • TCP/IP
    • The OSI model and TCP/IP
    • Ports, services and common protocols
    • DNS, HTTP, HTTPS and TLS
    • Secure versus insecure protocols
    • Reading a connection from a log line
    Open course
  3. 03 Security+ Threats, Vulnerabilities and Attacks Beginner 5 lessons 5 hours

    The catalogue of what a defender is defending against. Threat actors and their motives, attack types across the network, host and application, and the social-engineering techniques that remain the most reliable way in.

    • Security+
    • Threats
    • Attacks
    • Threat actors and motives
    • Network and host attacks
    • Application attacks
    • Malware types
    • Social engineering
    Open course
  4. 04 Security+ Identity and Access Management Beginner 4 lessons 4 hours

    Who is allowed to do what, and how that is proven. Authentication and authorisation, multi-factor authentication, directory services and the account-related events that fill a SOC queue.

    • Security+
    • IAM
    • MFA
    • Authentication, authorisation and accounting
    • MFA and single sign-on
    • Directory services and their events
    • Account activity worth investigating
    Open course
  5. 05 Security+ Cryptography and PKI Beginner 4 lessons 4 hours

    How data is kept confidential and verified, and what a defender needs to know about it. Symmetric and asymmetric encryption, hashing, certificates and PKI, and the failures that turn up in alerts.

    • Security+
    • Cryptography
    • PKI
    • Symmetric and asymmetric encryption
    • Hashing and digital signatures
    • Certificates and PKI
    • Crypto failures in security events
    Open course
  6. 06 Security+ Endpoint Security Beginner 4 lessons 4 hours

    The host as a defended surface. Endpoint protection and hardening, the telemetry an endpoint produces, and the baseline that makes an anomaly visible.

    • Security+
    • Endpoint
    • Hardening
    • Endpoint protection and hardening
    • Endpoint telemetry
    • Baselining normal behaviour
    • Recognising endpoint anomalies
    Open course
  7. 07 Security+ Network Security Beginner 4 lessons 5 hours

    Defending the network itself. Firewalls, segmentation and zero-trust concepts, VPNs and secure access, and the network telemetry a SOC watches.

    • Security+
    • Firewall
    • Segmentation
    • Firewalls and segmentation
    • Zero trust concepts
    • VPNs and secure remote access
    • Network telemetry and anomalies
    Open course
  8. 08 Security+ · BTL1 Security Monitoring Beginner 5 lessons 5 hours

    The shift from concepts to operations. What a SOC monitors, the data sources it draws on, and how monitoring turns a stream of events into the alerts an analyst acts on.

    • Security+
    • BTL1
    • Monitoring
    • What a SOC monitors
    • Security data sources
    • From events to alerts
    • Monitoring dashboards
    • False positives and tuning concepts
    Open course
  9. 09 BTL1 · SC-200 SIEM Fundamentals Beginner 4 lessons 5 hours

    The tool at the centre of a SOC. What a SIEM does, how logs are ingested, parsed and normalised, and how correlation rules turn scattered events into a single meaningful alert.

    • BTL1
    • SC-200
    • SIEM
    • What a SIEM does
    • Log ingestion, parsing and normalisation
    • Correlation rules
    • Searching a SIEM
    Open course
  10. 10 SC-200 Microsoft Sentinel Intermediate 5 lessons 7 hours

    The cloud-native SIEM at the heart of SC-200. Workspaces and data connectors, analytics rules and incidents, workbooks and hunting — enough to work Sentinel the way a SOC analyst does.

    • SC-200
    • Sentinel
    • Cloud SIEM
    • Workspaces and data connectors
    • Analytics rules
    • Incidents in Sentinel
    • Workbooks and visualisation
    • Hunting in Sentinel
    Open course
  11. 11 SC-200 Microsoft Defender Intermediate 4 lessons 5 hours

    The detection and response side of the Microsoft stack. Defender across endpoint, identity and cloud, the alerts it raises, and how they feed the same investigation a SOC runs in Sentinel.

    • SC-200
    • Defender
    • XDR
    • Defender across endpoint, identity and cloud
    • Reading and triaging Defender alerts
    • Connecting Defender to Sentinel
    • Automated response actions
    Open course
  12. 12 SC-200 · BTL1 Windows Security Beginner 4 lessons 5 hours

    The operating system a defender sees most. The Windows security model, the event logs that matter, and the account, process and logon events that carry the signal of an attack.

    • SC-200
    • Windows
    • Event Logs
    • The Windows security model
    • Security-relevant event logs
    • Logon and account events
    • Process events and attacker behaviour
    Open course
  13. 13 BTL1 Linux Security Beginner 4 lessons 4 hours

    The other operating system in the estate. The Linux security model, its logs and audit framework, and the signal an attacker leaves on a compromised host.

    • BTL1
    • Linux
    • Logs
    • The Linux security and permission model
    • Linux logs and the audit framework
    • Suspicious activity on a host
    • Mapping Linux events to attacks
    Open course
  14. 14 BTL1 Log Analysis Intermediate 4 lessons 5 hours

    Turning raw logs into findings. Reading logs across sources, correlating them into a story, and separating the one line that matters from the thousands that do not — the daily work of a SOC analyst.

    • BTL1
    • Logs
    • Analysis
    • Reading logs across sources
    • Correlating events into a story
    • Signal versus noise
    • Documenting a finding from logs
    Open course
  15. 15 BTL1 Alert Triage Intermediate 4 lessons 4 hours

    The first decision an analyst makes on every alert: is it real, how bad, and what next. A repeatable triage method that turns a queue of alerts into ranked, actioned findings.

    • BTL1
    • Triage
    • SOC
    • A repeatable triage method
    • Judging severity and priority
    • Escalate, close or investigate
    • Recording a triage decision
    Open course
  16. 16 BTL1 IOC Investigation Intermediate 4 lessons 4 hours

    Indicators of compromise as the thread you pull. What the different indicator types are, how to hunt one across the estate, and how one confirmed indicator expands into the scope of an incident.

    • BTL1
    • IOC
    • Investigation
    • Indicator types
    • Hunting an indicator across the estate
    • From one indicator to incident scope
    • Recording and sharing indicators
    Open course
  17. 17 BTL1 Threat Intelligence Intermediate 4 lessons 4 hours

    Context that makes an alert mean more. What threat intelligence is, the difference between strategic, operational and tactical, and how to enrich an indicator so a triage decision is informed.

    • BTL1
    • Threat Intel
    • Levels of threat intelligence
    • Enriching an indicator
    • Judging source reliability
    • Applying intelligence to triage
    Open course
  18. 18 BTL1 Phishing Analysis Intermediate 4 lessons 4 hours

    The most common alert a SOC works. Reading email headers and structure, analysing links and attachments safely, and deciding the verdict and the response.

    • BTL1
    • Phishing
    • Email
    • Email headers and message structure
    • Analysing links and attachments safely
    • Reaching a verdict
    • Containment and user response
    Open course
  19. 19 BTL1 Malware Analysis Fundamentals Intermediate 4 lessons 5 hours

    Enough analysis to triage, not to reverse engineer. Static and dynamic triage concepts in a safe environment, the artefacts malware leaves, and when to hand off to a specialist.

    • BTL1
    • Malware
    • Triage
    • Static and dynamic triage concepts
    • Handling a sample safely
    • Malware artefacts on a host
    • When to escalate
    Open course
  20. 20 BTL1 Incident Response Intermediate 4 lessons 5 hours

    What happens once an alert becomes an incident. The response lifecycle, containment, eradication and recovery, and the analyst role at each stage.

    • BTL1
    • Incident Response
    • The incident response lifecycle
    • Containment, eradication and recovery
    • The analyst role during a response
    • Preserving evidence
    Open course
  21. 21 BTL1 · SC-200 Detection Engineering Intermediate 4 lessons 5 hours

    Writing the detections a SOC runs on. Turning a technique into a detection rule, testing it against real and benign activity, and tuning it so it fires on the attack and not on the business.

    • BTL1
    • SC-200
    • Detection
    • From technique to detection rule
    • Testing a detection
    • Tuning to reduce false positives
    • Maintaining detections over time
    Open course
  22. 22 SC-200 KQL Fundamentals Intermediate 4 lessons 4 hours

    The query language of the Microsoft security stack. KQL syntax, filtering and summarising, joining tables, and building the queries that hunt through Sentinel and Defender data.

    • SC-200
    • KQL
    • Hunting
    • KQL syntax, filtering and summarising
    • Joining tables
    • Building a hunting query
    • Reading and adapting queries
    Open course
  23. 23 BTL1 MITRE ATT&CK Intermediate 4 lessons 4 hours

    The shared language of attacker behaviour. Tactics, techniques and procedures, mapping an observed activity to the framework, and using it to find the gaps in a detection coverage.

    • BTL1
    • MITRE ATT&CK
    • Tactics, techniques and procedures
    • Mapping activity to ATT&CK
    • Reasoning about detection coverage
    • Communicating in ATT&CK terms
    Open course
  24. 24 BTL1 SOC Investigation Workflow Intermediate 4 lessons 4 hours

    How the pieces fit into one repeatable flow. From an alert through triage, enrichment, correlation and scoping to a decision, run the way a shift actually runs it.

    • BTL1
    • SOC
    • Workflow
    • The full investigation flow
    • Enrich, correlate and scope
    • Reaching and recording a decision
    • Shift handover
    Open course
  25. 25 BTL1 Incident Reporting Intermediate 3 lessons 3 hours

    The deliverable that survives the incident. Writing a clear incident report — summary, timeline, findings, impact and recommendations — that a manager and an engineer can both act on.

    • BTL1
    • Reporting
    • Summary and timeline
    • Findings, impact and recommendations
    • Writing for two audiences
    Open course
  26. 26 Capstone Final SOC Investigation Intermediate 4 lessons 7 hours

    The whole track in one investigation. An alert arrives, and you triage it, correlate the telemetry, hunt indicators across the SIEM, map to ATT&CK, decide containment, and write the incident report an analyst hands over.

    • Capstone
    • SOC
    • Investigation
    • The alert and initial triage
    • Correlation and IOC hunting
    • ATT&CK mapping and containment
    • The incident report and handover
    Open course
After the Track

Roles This Track Prepares You For

  • SOC Analyst — L1
  • Junior Security Analyst
  • Security Operations Analyst
  • Cybersecurity Analyst
  • Incident Response Junior
  • Threat Monitoring Analyst
  • SIEM Analyst — Junior
  • Blue Team Junior
  • Security Monitoring Analyst
Same Diploma

Other Tracks in This Diploma

Red Team Level 1 Red Team Level 1 Track Beginner

Red Team Level 1

The complete offensive-security foundation: an integrated CEH, eJPT and OSCP+ preparation path, from cybersecurity fundamentals to OSCP-level practical pentesting.

  • Ethical Hacking
  • Penetration Testing
  • CEH
  • eJPT
  • OSCP+
  • Active Directory
  • Linux
  • Windows
  • One continuous route across CEH, eJPT and OSCP+ — not three disconnected courses.
  • Sixty to seventy percent hands-on labs, in authorised training environments only.
  • Real depth where OSCP+ demands it: Active Directory, privilege escalation, pivoting and reporting.
  • Ends with a full corporate pentest and a professional written report.
Red Team Level 2 Red Team Level 2 Track Advanced

Red Team Level 2

The jump from penetration tester to red team operator: an integrated CRTP, PNPT and CRTO preparation path across enterprise Active Directory, professional network engagements, Command & Control and OPSEC.

  • Red Team
  • Active Directory
  • Cobalt Strike
  • C2
  • CRTP
  • PNPT
  • CRTO
  • Adversary Simulation
  • One continuous route across CRTP, PNPT and CRTO — enterprise AD, professional engagements and C2.
  • Seventy percent hands-on in enterprise AD, internal network and C2 labs.
  • Real red team tradecraft: Cobalt Strike, C2 infrastructure, OPSEC and detection awareness.
  • Ends with a full enterprise adversary simulation across a multi-domain forest.
Red Team Level 3 Red Team Level 3 Track Advanced

Red Team Level 3

The expert tier: an integrated OSEP, OSWE and OSED preparation path across advanced evasion, white-box web exploitation and Windows user-mode exploit development — the three specialisations that together map to OSCE3.

  • Advanced Evasion
  • Exploit Development
  • Web Exploitation
  • Reverse Engineering
  • OSEP
  • OSWE
  • OSED
  • OSCE3
  • Three real specialisations, not three variations: advanced evasion, web exploit development and binary exploit development.
  • Seventy-five percent hands-on across Windows internals, source-code review and exploit-development labs.
  • White-box web work: read the source, find the bug, write the exploit, reach RCE.
  • Windows user-mode exploit development: reverse engineering, DEP and ASLR bypass, custom shellcode.
  • Ends with three separate expert assessments, one for each of OSEP, OSWE and OSED.
Certified

Certificates You Can Earn

Finish your course and receive an accredited MotiGraph certificate you can add to your CV and share with employers.

MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample