Blue Team Level 2
MotiGraph
Track

Blue Team Level 2

The advanced defensive route: an integrated CySA+, BTL2 and GCIA preparation path across security analytics, advanced incident response, threat hunting and network forensics.

32 Courses
126 Lessons
144 Hours
18 Weeks
Advanced Level
  • CySA+
  • BTL2
  • GCIA
  • Threat Hunting
  • Digital Forensics
  • Network Forensics
  • Incident Response
  • SOC
About This Track

What You Are Signing Up For

This is the second defensive level, and it moves from working a SOC queue to leading an investigation. You go deep on security analytics and threat detection the way CySA+ measures, then advanced blue-team incident response and threat hunting from BTL2, and finally the network security monitoring and forensics that GCIA is built on — packet analysis, IDS/IPS, DNS and traffic analysis, and full network forensics. It is heavy on labs: PCAP investigation, C2 traffic detection, malware traffic analysis, Windows event analysis, EDR investigation and a full incident response. It ends with a complete network forensics case and a final blue-team assessment.

  • One route across CySA+, BTL2 and GCIA — analytics, advanced IR and network forensics.
  • Deep network security monitoring: packet analysis, IDS/IPS, DNS, C2 and malware traffic.
  • Advanced threat hunting and detection engineering, not just alert triage.
  • Ends with a full network forensics investigation and a blue-team assessment.

What You Will Be Able to Do

  • Perform security analytics and advanced threat detection.
  • Run the incident response lifecycle and lead an investigation.
  • Hunt threats proactively and map to advanced MITRE ATT&CK.
  • Investigate Windows, Linux and network forensics artefacts.
  • Analyse packets, IDS/IPS alerts, DNS and HTTP traffic.
  • Detect command and control and lateral movement in traffic.
  • Investigate malware traffic and advanced phishing.
  • Write a professional forensics and incident report.

Requirements

  • Blue Team Level 1, or equivalent SOC experience.
  • A good base in networking, Windows/Linux and a SIEM.
  • Comfort reading logs and working alerts.
  • This is an advanced track — it builds on Level 1.

Who It Is For

  • SOC analysts at L1.
  • Security analysts and incident responders.
  • Threat hunters and network security analysts.
  • Blue team professionals.
  • Graduates of Blue Team Level 1.

This is a preparation and training track. It builds the knowledge and practical skills the CySA+, BTL2 and GCIA paths are built on, but it does not award those certifications: their official exams and requirements are set by CompTIA, Security Blue Team and GIAC respectively, and are separate. All practical work is carried out in authorised, isolated lab environments only.

Skills

What You Will Learn

Security Analytics (CySA+)

  • Advanced security operations
  • Threat detection and analysis
  • Vulnerability management
  • Security analytics
  • Advanced threat intelligence

Advanced Blue Team (BTL2)

  • Advanced SIEM operations and log analysis
  • Detection engineering
  • Threat hunting and advanced MITRE ATT&CK
  • Incident response lifecycle and investigation
  • Endpoint detection and response

Network Forensics (GCIA)

  • Packet analysis and network security monitoring
  • IDS/IPS analysis
  • DNS, HTTP/HTTPS and TCP/IP deep analysis
  • Malware traffic and command-and-control detection
  • Digital, Windows, Linux and network forensics

Investigation & Reporting

  • Advanced KQL and querying
  • Advanced phishing investigation
  • Threat hunting operations
  • Incident and forensics reporting
Hands On

What You Will Build

Every project below is yours to keep and to show. By the end you have a portfolio, not a certificate alone.

Practical Labs

  • Advanced Wireshark and PCAP investigation
  • Network forensics and IDS/IPS alerts
  • DNS investigation and HTTP traffic analysis
  • C2 traffic detection and malware traffic analysis
  • Windows event analysis and SIEM threat hunting
  • EDR investigation and IOC correlation
  • Threat intelligence enrichment and MITRE ATT&CK mapping

Final Investigations

  • A full network forensics investigation
  • A full incident response investigation
  • A final blue-team assessment across the three certifications

Graduation Project

You finish with two full investigations and an assessment: a complete network forensics case worked from packet capture to a documented conclusion, a full incident response investigation run end to end, and a final blue-team assessment that draws on the analytics, hunting and forensics skills the three certifications cover. Each is documented the way a professional report is written.

The Roadmap

Your Path Through This Track

Blue Team Level 2 roadmap
The Route

Course by Course

32 modules · 126 lessons. Open any module to see what is inside it.

  1. 01 CySA+ Foundation Advanced Security Operations Intermediate 4 lessons 4 hours

    Where Level 2 begins: running security operations as a discipline, not a queue. Operational maturity, metrics, and how an analyst contributes to a programme rather than only closing tickets.

    • CySA+
    • Security Operations
    • Operational maturity and metrics
    • The analyst in a security programme
    • Operational data flows
    • Coverage and gaps
    Open course
  2. 02 CySA+ Threat Detection and Analysis Intermediate 4 lessons 5 hours

    The core CySA+ skill: detecting a threat from the data and analysing it to a conclusion. Behavioural and signature detection, anomaly analysis, and turning a detection into a understood event.

    • CySA+
    • Detection
    • Analysis
    • Behavioural and signature detection
    • Anomaly analysis
    • Correlating across sources
    • Documenting a detection
    Open course
  3. 03 CySA+ Vulnerability Management Intermediate 4 lessons 4 hours

    Finding weakness before an attacker does. Vulnerability scanning, scoring and prioritisation, and the management lifecycle that turns a scan into remediation that actually happens.

    • CySA+
    • Vulnerability Management
    • Vulnerability scanning
    • Scoring and prioritisation
    • The remediation lifecycle
    • Risk reduction with limited resources
    Open course
  4. 04 CySA+ Security Analytics Intermediate 4 lessons 4 hours

    Using data to find what rules miss. Statistical and behavioural analytics, baselining, and the analytics techniques that surface a slow, quiet attack a signature never catches.

    • CySA+
    • Analytics
    • Statistical and behavioural analytics
    • Baselining normal
    • Surfacing slow and quiet activity
    • Communicating an analytics finding
    Open course
  5. 05 CySA+ · BTL2 Advanced Threat Intelligence Intermediate 4 lessons 4 hours

    Intelligence that drives detection and hunting. The intelligence lifecycle, adversary profiling, and turning intelligence into detections and hunt hypotheses rather than a feed nobody reads.

    • CySA+
    • BTL2
    • Threat Intel
    • The intelligence lifecycle
    • Adversary profiling
    • Intelligence into detections and hunts
    • Judging and weighting sources
    Open course
  6. 06 BTL2 Advanced SIEM Operations Advanced 4 lessons 5 hours

    Running a SIEM at a level beyond searching it. Data onboarding and normalisation at scale, advanced correlation, content management, and keeping a SIEM useful as it grows.

    • BTL2
    • SIEM
    • Data onboarding and normalisation at scale
    • Advanced correlation content
    • SIEM content management
    • Performance as the SIEM grows
    Open course
  7. 07 BTL2 Advanced Log Analysis Advanced 4 lessons 5 hours

    Reading logs at the depth an investigation needs. Correlating across many sources, reconstructing a sequence of events, and spotting the tampering and gaps that reveal an attacker covering tracks.

    • BTL2
    • Log Analysis
    • Correlating across many sources
    • Reconstructing an event sequence
    • Spotting tampering and gaps
    • Building a timeline from logs
    Open course
  8. 08 BTL2 Detection Engineering Advanced 4 lessons 5 hours

    Building detections as a discipline. A detection development lifecycle, testing against adversary emulation, measuring efficacy, and managing detections as code that a team maintains.

    • BTL2
    • Detection Engineering
    • The detection development lifecycle
    • Testing against adversary emulation
    • Measuring detection efficacy
    • Detections as maintained content
    Open course
  9. 09 BTL2 Threat Hunting Advanced 4 lessons 5 hours

    Looking for the attacker no alert fired on. Hypothesis-driven hunting, building a hunt from intelligence or a technique, and turning a successful hunt into a permanent detection.

    • BTL2
    • Threat Hunting
    • Hypothesis-driven hunting
    • Building and running a hunt
    • Confirming with evidence
    • From hunt to detection
    Open course
  10. 10 BTL2 MITRE ATT&CK Advanced Advanced 4 lessons 4 hours

    ATT&CK as an operational tool, not a poster. Building coverage maps, driving purple-team style validation, and prioritising detection work by the techniques that matter to your estate.

    • BTL2
    • MITRE ATT&CK
    • Building a coverage map
    • Validating detections against techniques
    • Prioritising by relevance
    • Communicating posture
    Open course
  11. 11 BTL2 Incident Response Lifecycle Advanced 4 lessons 5 hours

    Response led, not just performed. The full lifecycle from preparation to lessons learned, coordinating an investigation, and the decisions that limit damage while preserving evidence.

    • BTL2
    • Incident Response
    • Preparation to lessons learned
    • Coordinating an investigation
    • Containment versus evidence
    • The lessons-learned review
    Open course
  12. 12 BTL2 Incident Investigation Advanced 4 lessons 5 hours

    Working an incident to its root. Scoping the compromise, following the attacker across hosts, establishing the timeline and the entry point, and answering the questions a report must close.

    • BTL2
    • Investigation
    • Scoping the compromise
    • Following an attacker across hosts
    • Timeline and entry point
    • Answering the core questions
    Open course
  13. 13 GCIA · BTL2 Digital Forensics Fundamentals Advanced 4 lessons 4 hours

    The discipline behind an evidence-grade investigation. Forensic principles, evidence handling and chain of custody, imaging, and the difference between finding something and proving it.

    • GCIA
    • Forensics
    • Forensic principles and handling
    • Chain of custody
    • Imaging and integrity
    • Finding versus proof
    Open course
  14. 14 GCIA Windows Forensics Advanced 4 lessons 4 hours

    Reconstructing what happened on a Windows host from what it left behind. The registry, event logs, execution artefacts and user activity, correlated into a timeline of the attack.

    • GCIA
    • Windows Forensics
    • Registry and event log forensics
    • Execution and user-activity artefacts
    • Correlating into a timeline
    • Attacker versus user activity
    Open course
  15. 15 GCIA Linux Forensics Advanced 4 lessons 4 hours

    The same discipline on Linux. Filesystem and log forensics, persistence and account artefacts, and reconstructing an intrusion on a server from the traces it left.

    • GCIA
    • Linux Forensics
    • Filesystem and log forensics
    • Persistence and account artefacts
    • Reconstructing a server intrusion
    • A Linux forensic timeline
    Open course
  16. 16 GCIA Network Forensics Advanced 4 lessons 4 hours

    The investigation that lives in the traffic. Working from captured packets and flow data, reconstructing sessions and transferred files, and proving what crossed the wire.

    • GCIA
    • Network Forensics
    • Investigating from packets and flow
    • Reconstructing sessions and transfers
    • Extracting artefacts from traffic
    • Proving what crossed the wire
    Open course
  17. 17 GCIA Packet Analysis Advanced 4 lessons 5 hours

    Reading the wire packet by packet, the foundational GCIA skill. Wireshark in depth, dissecting protocols, following streams, and recognising the shape of an attack in the raw traffic.

    • GCIA
    • Packet Analysis
    • Wireshark
    • Wireshark in depth
    • Dissecting protocols
    • Following streams
    • Attack patterns in traffic
    Open course
  18. 18 GCIA Network Security Monitoring Advanced 4 lessons 5 hours

    Monitoring the network as a defended system. NSM data types, sensor placement, and building the visibility that lets a defender see an intrusion in the traffic before the endpoint does.

    • GCIA
    • NSM
    • NSM data types
    • Sensor placement
    • Building network visibility
    • Detecting an intrusion from network data
    Open course
  19. 19 GCIA IDS/IPS Analysis Advanced 4 lessons 4 hours

    The systems that flag the traffic, and how to work their output. How IDS and IPS detect, reading and writing signatures, and triaging an IDS alert to a verdict.

    • GCIA
    • IDS
    • IPS
    • How IDS and IPS detect
    • Reading and writing signatures
    • Triaging an IDS alert
    • Tuning to reduce noise
    Open course
  20. 20 GCIA DNS Security Analysis Advanced 4 lessons 4 hours

    The protocol attackers hide inside. Reading DNS traffic, recognising tunnelling and exfiltration, and spotting the algorithmically generated domains that malware calls home to.

    • GCIA
    • DNS
    • Reading DNS traffic
    • DNS tunnelling and exfiltration
    • Algorithmically generated domains
    • Investigating a suspicious lookup
    Open course
  21. 21 GCIA HTTP/HTTPS Traffic Analysis Advanced 4 lessons 4 hours

    The web traffic that carries most of an attack. Reading HTTP requests and responses, what TLS does and does not hide, and recognising web-based delivery and beaconing in the flow.

    • GCIA
    • HTTP
    • HTTPS
    • Reading HTTP requests and responses
    • What TLS hides and reveals
    • Web-based delivery
    • Spotting beaconing
    Open course
  22. 22 GCIA TCP/IP Deep Analysis Advanced 4 lessons 4 hours

    The stack at the level GCIA tests. Header fields and their meaning, connection behaviour and anomalies, fragmentation and evasion, and reading a session from its packets alone.

    • GCIA
    • TCP/IP
    • Header fields and their meaning
    • Connection behaviour and anomalies
    • Fragmentation and evasion
    • Reconstructing a session
    Open course
  23. 23 GCIA Malware Traffic Analysis Advanced 4 lessons 4 hours

    Identifying malware by how it talks. Recognising the traffic signatures of common families, extracting indicators from a capture, and reconstructing an infection from the network alone.

    • GCIA
    • Malware Traffic
    • Malware traffic signatures
    • Extracting indicators from a capture
    • Reconstructing an infection
    • Producing indicators for detection
    Open course
  24. 24 GCIA · BTL2 Command and Control Detection Advanced 4 lessons 5 hours

    Finding the channel an attacker controls a compromise through. C2 patterns across HTTP, DNS and TLS, beaconing and jitter, and detecting a channel designed to blend in.

    • GCIA
    • C2 Detection
    • C2 patterns across protocols
    • Beaconing and jitter
    • C2 versus benign automation
    • Building a detection for a channel
    Open course
  25. 25 BTL2 Advanced Phishing Investigation Advanced 4 lessons 4 hours

    Phishing worked to the campaign behind it. Analysing a payload chain, attributing a campaign from its infrastructure, and scoping who else was targeted across the estate.

    • BTL2
    • Phishing
    • Analysing a payload chain
    • Attributing a campaign
    • Scoping who was targeted
    • Producing campaign indicators
    Open course
  26. 26 BTL2 · SC-200 Endpoint Detection and Response Advanced 4 lessons 5 hours

    Working an EDR as an investigation tool. The telemetry an EDR provides, hunting and responding from the console, and reconstructing what happened on a host from its process tree.

    • BTL2
    • EDR
    • EDR telemetry
    • Hunting and responding from the console
    • Reconstructing a process tree
    • Containing a host
    Open course
  27. 27 SC-200 · BTL2 Advanced KQL and Querying Advanced 4 lessons 4 hours

    KQL beyond the basics. Advanced operators and functions, time-series and join techniques, and writing efficient hunting queries that run over large data without timing out.

    • SC-200
    • KQL
    • Advanced operators and functions
    • Time-series and multi-join queries
    • Query optimisation
    • A reusable query library
    Open course
  28. 28 BTL2 Threat Hunting Operations Advanced 4 lessons 5 hours

    Hunting as a repeatable programme, not a one-off. Planning a hunt cycle, running it across the estate, measuring outcomes, and feeding results back into detections and coverage.

    • BTL2
    • Threat Hunting
    • Planning a hunt cycle
    • Running a hunt across the estate
    • Measuring outcomes
    • Feeding results into coverage
    Open course
  29. 29 BTL2 · GCIA Incident and Forensics Reporting Advanced 3 lessons 3 hours

    The report that stands up to scrutiny. Structuring a forensics and incident report, presenting evidence and a defensible timeline, and writing findings that survive review.

    • BTL2
    • GCIA
    • Reporting
    • Structuring the report
    • Evidence and a defensible timeline
    • Fact versus interpretation
    Open course
  30. 30 BTL2 Advanced SOC Investigation Advanced 4 lessons 5 hours

    A multi-source investigation run to completion. Pulling endpoint, network and SIEM data into one picture, resolving conflicting evidence, and reaching a defensible conclusion under time pressure.

    • BTL2
    • SOC
    • Correlating endpoint, network and SIEM
    • Resolving conflicting evidence
    • A defensible conclusion
    • Working under time pressure
    Open course
  31. 31 GCIA Capstone Full Network Forensics Lab Advanced 3 lessons 5 hours

    The network-forensics half of the finals. A full case worked from a packet capture: reconstructing the intrusion, extracting evidence and indicators, and documenting a defensible conclusion.

    • GCIA
    • Lab
    • Network Forensics
    • The capture and initial analysis
    • Reconstructing the intrusion
    • Evidence, indicators and conclusion
    Open course
  32. 32 Capstone Final Blue Team Assessment Advanced 4 lessons 7 hours

    The whole level in one assessment. An incident that spans analytics, hunting and forensics: detect it, investigate it across endpoint and network, hunt the scope, and deliver a professional report drawing on all three certifications.

    • Capstone
    • CySA+
    • BTL2
    • GCIA
    • Detection and scoping
    • Endpoint and network investigation
    • Hunting the full scope
    • The professional report
    Open course
After the Track

Roles This Track Prepares You For

  • SOC Analyst — L2
  • Security Operations Analyst
  • Cybersecurity Analyst
  • Incident Response Analyst
  • Threat Hunter
  • Network Security Analyst
  • Detection Engineer — Junior
  • Security Monitoring Specialist
  • Digital Forensics Analyst — Junior
  • Blue Team Analyst
Same Diploma

Other Tracks in This Diploma

Red Team Level 1 Red Team Level 1 Track Beginner

Red Team Level 1

The complete offensive-security foundation: an integrated CEH, eJPT and OSCP+ preparation path, from cybersecurity fundamentals to OSCP-level practical pentesting.

  • Ethical Hacking
  • Penetration Testing
  • CEH
  • eJPT
  • OSCP+
  • Active Directory
  • Linux
  • Windows
  • One continuous route across CEH, eJPT and OSCP+ — not three disconnected courses.
  • Sixty to seventy percent hands-on labs, in authorised training environments only.
  • Real depth where OSCP+ demands it: Active Directory, privilege escalation, pivoting and reporting.
  • Ends with a full corporate pentest and a professional written report.
Red Team Level 2 Red Team Level 2 Track Advanced

Red Team Level 2

The jump from penetration tester to red team operator: an integrated CRTP, PNPT and CRTO preparation path across enterprise Active Directory, professional network engagements, Command & Control and OPSEC.

  • Red Team
  • Active Directory
  • Cobalt Strike
  • C2
  • CRTP
  • PNPT
  • CRTO
  • Adversary Simulation
  • One continuous route across CRTP, PNPT and CRTO — enterprise AD, professional engagements and C2.
  • Seventy percent hands-on in enterprise AD, internal network and C2 labs.
  • Real red team tradecraft: Cobalt Strike, C2 infrastructure, OPSEC and detection awareness.
  • Ends with a full enterprise adversary simulation across a multi-domain forest.
Red Team Level 3 Red Team Level 3 Track Advanced

Red Team Level 3

The expert tier: an integrated OSEP, OSWE and OSED preparation path across advanced evasion, white-box web exploitation and Windows user-mode exploit development — the three specialisations that together map to OSCE3.

  • Advanced Evasion
  • Exploit Development
  • Web Exploitation
  • Reverse Engineering
  • OSEP
  • OSWE
  • OSED
  • OSCE3
  • Three real specialisations, not three variations: advanced evasion, web exploit development and binary exploit development.
  • Seventy-five percent hands-on across Windows internals, source-code review and exploit-development labs.
  • White-box web work: read the source, find the bug, write the exploit, reach RCE.
  • Windows user-mode exploit development: reverse engineering, DEP and ASLR bypass, custom shellcode.
  • Ends with three separate expert assessments, one for each of OSEP, OSWE and OSED.
Certified

Certificates You Can Earn

Finish your course and receive an accredited MotiGraph certificate you can add to your CV and share with employers.

MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample