Blue Team Level 3
MotiGraph
Track

Blue Team Level 3

The expert defensive tier: an integrated GCFA, GCIH and GCED preparation path across advanced digital forensics, incident handling, threat hunting and enterprise defense.

36 Courses
136 Lessons
143 Hours
18 Weeks
Advanced Level
  • GCFA
  • GCIH
  • GCED
  • Digital Forensics
  • DFIR
  • Threat Hunting
  • Enterprise Defense
  • Memory Forensics
About This Track

What You Are Signing Up For

This is the final defensive level, and it turns an analyst into a specialist. GCFA takes forensics to depth — memory, filesystem, timeline and artefact analysis, malware and rootkit investigation, and full threat hunting. GCIH covers incident handling and the hacker techniques a responder must recognise across the attack lifecycle: command and control, lateral movement, credential attacks, privilege escalation and post-exploitation. GCED steps back to enterprise defense — security architecture, defense-in-depth, hardening and the defensive posture across endpoint, network, application and cloud. It is heavily practical: Windows memory forensics, digital evidence analysis, APT investigation, advanced threat hunting and full incident response. It ends with two complete investigations and an expert assessment.

  • One route across GCFA, GCIH and GCED — forensics, incident handling and enterprise defense.
  • Deep digital forensics: memory, filesystem, timeline, registry and artefact analysis.
  • The full attack lifecycle from a defender view: C2, lateral movement, credentials, privilege escalation.
  • Ends with a full forensics case, a full incident response, and an expert assessment.

What You Will Be Able to Do

  • Perform advanced digital forensics across memory, disk and network.
  • Investigate malware, rootkits and persistence to root cause.
  • Handle an incident across the full attack lifecycle.
  • Recognise and detect C2, lateral movement and credential attacks.
  • Hunt an APT and analyse post-exploitation activity.
  • Design enterprise defense: architecture, defense-in-depth and hardening.
  • Defend endpoint, network, application and cloud.
  • Deliver a professional forensics and incident report.

Requirements

  • Blue Team Level 2, or equivalent senior SOC experience.
  • Strong forensics, incident response and networking foundations.
  • Comfort across Windows, Linux and enterprise environments.
  • This is an expert track — it builds on Levels 1 and 2.

Who It Is For

  • SOC analysts at L2 or L3.
  • Senior security analysts and incident responders.
  • Digital forensics analysts and threat hunters.
  • Detection engineers and security engineers.
  • Blue team professionals specialising further.
  • Graduates of Blue Team Level 2.

This is a preparation and training track. It builds the knowledge and practical skills the GCFA, GCIH and GCED paths are built on, but it does not award those certifications: their official exams and requirements are set by GIAC and are separate. All practical work is carried out in authorised, isolated lab environments only.

Skills

What You Will Learn

Incident Handling (GCIH)

  • Advanced blue team operations
  • Advanced incident response and handling methodology
  • Hacker techniques and the attack lifecycle
  • Advanced threat intelligence
  • Post-exploitation analysis

Digital Forensics (GCFA)

  • Windows, Linux and file-system forensics
  • Windows memory forensics
  • Timeline, registry and artefact analysis
  • Browser and user artefacts
  • Malware, rootkit and persistence investigation

Threat Hunting & Detection

  • Advanced threat hunting and APT investigation
  • Command-and-control analysis
  • Lateral movement and credential-attack detection
  • Privilege-escalation detection
  • Advanced detection engineering

Enterprise Defense (GCED)

  • Enterprise security architecture and defense-in-depth
  • Security controls and hardening
  • Endpoint, network and application defense
  • Cloud security defense
  • Security automation
Hands On

What You Will Build

Every project below is yours to keep and to show. By the end you have a portfolio, not a certificate alone.

Practical Labs

  • Windows memory forensics and digital evidence analysis
  • File-system forensics and Windows registry investigation
  • Network forensics and malware investigation
  • APT investigation and advanced threat hunting
  • Full incident response and post-exploitation investigation
  • SIEM investigation and endpoint detection and response
  • MITRE ATT&CK mapping, detection engineering and forensics reporting

Expert Investigations

  • A full digital forensics investigation
  • A full incident response investigation
  • A final expert blue-team assessment across the three certifications

Graduation Project

You finish with two complete investigations and an expert assessment: a full digital forensics case worked from evidence to conclusion, a full incident response investigation run across the attack lifecycle, and a final expert blue-team assessment that draws on the forensics, incident-handling and enterprise-defense skills the three certifications cover. Each is documented to a professional standard a court or a board could read.

The Roadmap

Your Path Through This Track

Blue Team Level 3 roadmap
The Route

Course by Course

36 modules · 136 lessons. Open any module to see what is inside it.

  1. 01 GCIH Foundation Advanced Blue Team Operations Advanced 4 lessons 4 hours

    Where the expert level begins: leading defensive operations, not participating in them. Programme maturity, coordinating detection and response, and the operational judgement a senior defender brings.

    • GCIH
    • Blue Team Operations
    • Leading defensive operations
    • Coordinating detection and response
    • Senior operational judgement
    • Programme maturity
    Open course
  2. 02 GCIH Advanced Incident Response Advanced 4 lessons 4 hours

    Response at the level GCIH measures. Handling a major incident under pressure, coordinating across teams, and making the containment and eradication decisions that shape the outcome.

    • GCIH
    • Incident Response
    • Handling a major incident
    • Coordinating across teams
    • Containment and eradication decisions
    • Managing stakeholders in a crisis
    Open course
  3. 03 GCIH Incident Handling Methodology Advanced 4 lessons 4 hours

    The structured method behind consistent handling. Preparation, identification, containment, eradication, recovery and lessons learned, applied as a repeatable discipline rather than improvisation.

    • GCIH
    • Methodology
    • The six-step handling method
    • Consistency under pressure
    • Documenting each phase
    • Improving the method
    Open course
  4. 04 GCIH Hacker Techniques and the Attack Lifecycle Advanced 4 lessons 4 hours

    A defender has to know the attack to detect it. The full attack lifecycle from reconnaissance to actions on objectives, the techniques at each stage, and the defensive signal each one leaves.

    • GCIH
    • Attack Lifecycle
    • The full attack lifecycle
    • Techniques at each stage
    • Attack to defensive signal
    • Detection at each stage
    Open course
  5. 05 GCIH · GCFA Advanced Threat Intelligence Advanced 4 lessons 4 hours

    Intelligence that drives an expert investigation. Adversary tracking, campaign attribution, and using intelligence to anticipate an attacker rather than only react to them.

    • GCIH
    • GCFA
    • Threat Intel
    • Adversary tracking
    • Campaign attribution
    • Anticipating an attacker
    • Intelligence into hunts and forensics
    Open course
  6. 06 GCFA Foundation Digital Forensics Fundamentals Advanced 4 lessons 4 hours

    Forensics at expert depth, starting with the principles that make evidence hold. Forensic soundness, acquisition and integrity, and the analytical mindset a court-grade investigation demands.

    • GCFA
    • Forensics
    • Forensic soundness and integrity
    • Acquisition and imaging
    • A court-grade analytical mindset
    • Planning an investigation
    Open course
  7. 07 GCFA Windows Forensics Advanced 4 lessons 4 hours

    Deep Windows disk forensics. The full set of execution, access and account artefacts, correlated to answer exactly what ran, when, and by whom on a compromised host.

    • GCFA
    • Windows Forensics
    • Execution and access artefacts
    • Account and authentication artefacts
    • Correlating into a narrative
    • Defending the conclusion
    Open course
  8. 08 GCFA Windows Memory Forensics Advanced 4 lessons 5 hours

    The evidence that only exists in RAM. Acquiring and analysing a memory image, recovering processes, network connections, injected code and credentials, and catching what disk forensics never sees.

    • GCFA
    • Memory Forensics
    • Acquiring and analysing a memory image
    • Recovering processes and network state
    • Detecting injected and hidden code
    • Recovering credentials from memory
    Open course
  9. 09 GCFA Linux Forensics Advanced 4 lessons 4 hours

    Expert forensics on Linux servers. Filesystem, log and memory artefacts, persistence mechanisms, and reconstructing a server compromise to root cause.

    • GCFA
    • Linux Forensics
    • Disk, log and memory artefacts
    • Persistence mechanisms
    • Reconstructing to root cause
    • A defensible Linux timeline
    Open course
  10. 10 GCFA File System Forensics Advanced 4 lessons 4 hours

    Below the files, into the filesystem itself. How NTFS and common filesystems store data and metadata, recovering deleted and hidden data, and reading the filesystem structures that outlive an attacker cleanup.

    • GCFA
    • File System
    • How filesystems store data and metadata
    • Recovering deleted and hidden data
    • Reading filesystem structures
    • Detecting anti-forensic tampering
    Open course
  11. 11 GCFA Timeline Analysis Advanced 4 lessons 4 hours

    The technique that ties an investigation together. Building a super-timeline from many artefact sources, resolving what happened in what order, and reading the story of an intrusion from time itself.

    • GCFA
    • Timeline
    • Building a super-timeline
    • Resolving event order
    • Reading an intrusion from time
    • Presenting a timeline
    Open course
  12. 12 GCFA Registry and Artifact Analysis Advanced 4 lessons 4 hours

    The Windows registry as an evidence store. The keys that record execution, persistence and user activity, and reading them into the record of what an attacker did.

    • GCFA
    • Registry
    • Forensically valuable registry keys
    • Execution and persistence evidence
    • User-activity artefacts
    • Registry evidence to a timeline
    Open course
  13. 13 GCFA Browser and User Artifacts Advanced 3 lessons 3 hours

    What the user did, from what the applications remembered. Browser history and downloads, application artefacts, and reconstructing user activity relevant to an incident.

    • GCFA
    • User Artifacts
    • Browser history and downloads
    • Application-level artefacts
    • Reconstructing user activity
    Open course
  14. 14 GCFA Network Forensics Advanced 4 lessons 4 hours

    Forensics from the wire at expert depth. Full session and file reconstruction from capture, correlating network evidence with host artefacts, and proving movement across the estate.

    • GCFA
    • Network Forensics
    • Session and file reconstruction
    • Correlating network with host
    • Proving movement across the estate
    • Documenting network findings
    Open course
  15. 15 GCFA Malware Investigation Advanced 4 lessons 4 hours

    Investigating malware to understand an incident, short of full reverse engineering. Behavioural analysis in a sandbox, extracting capabilities and indicators, and answering what the malware did on the host.

    • GCFA
    • Malware
    • Behavioural analysis in a sandbox
    • Extracting capabilities and indicators
    • What it did on the host
    • Feeding findings into detection
    Open course
  16. 16 GCFA Rootkit and Persistence Analysis Advanced 4 lessons 4 hours

    Finding what is designed not to be found. Rootkit techniques and their traces, the full range of persistence mechanisms, and detecting a foothold built to survive a reboot and a cleanup.

    • GCFA
    • Rootkit
    • Persistence
    • Rootkit techniques and traces
    • Enumerating persistence mechanisms
    • Detecting a hidden foothold
    • Confirming eradication
    Open course
  17. 17 GCFA · GCIH Advanced Threat Hunting Advanced 4 lessons 4 hours

    Hunting a capable adversary who is trying not to be found. Hypotheses grounded in forensics and intelligence, hunting across host and network at depth, and confirming a quiet compromise.

    • GCFA
    • Threat Hunting
    • Hypotheses from forensics and intelligence
    • Hunting across host and network
    • Confirming a quiet compromise
    • Hunt into detection and forensics
    Open course
  18. 18 GCFA · GCIH APT Investigation Advanced 4 lessons 4 hours

    Investigating an adversary who stays. The patient, multi-stage tradecraft of an advanced persistent threat, tracking it across the estate, and scoping a long-running compromise.

    • GCFA
    • GCIH
    • APT
    • Advanced persistent tradecraft
    • Tracking an actor across the estate
    • Scoping a long-running compromise
    • Coordinating a large investigation
    Open course
  19. 19 GCIH Command and Control Analysis Advanced 4 lessons 4 hours

    Understanding the channel to break it. C2 frameworks and their traffic and host traces, decoding a channel, and cutting an attacker off without tipping them off too early.

    • GCIH
    • C2
    • C2 framework traces
    • Analysing a channel to its function
    • Planning a coordinated disruption
    • Detections for the channel
    Open course
  20. 20 GCIH Lateral Movement Detection Advanced 4 lessons 4 hours

    Catching an attacker moving between hosts. The techniques of lateral movement, the traces they leave on source and target, and building detections that fire on movement without drowning in admin activity.

    • GCIH
    • Lateral Movement
    • Lateral movement techniques
    • Traces on source and target
    • Building detections for movement
    • Movement versus admin activity
    Open course
  21. 21 GCIH Credential Attack Detection Advanced 4 lessons 4 hours

    Detecting the theft and abuse of credentials. Credential dumping, pass-the-hash and ticket attacks from the defender view, and the events that reveal them.

    • GCIH
    • Credentials
    • Credential dumping and abuse
    • Pass-the-hash and ticket attacks
    • The events that reveal them
    • Detections for credential attacks
    Open course
  22. 22 GCIH Privilege Escalation Detection Advanced 3 lessons 3 hours

    Catching an attacker gaining rights they should not have. Common escalation techniques on Windows and Linux from the defender view, and the signal each one produces.

    • GCIH
    • Privilege Escalation
    • Common escalation techniques
    • The signal escalation produces
    • Detections and coverage priority
    Open course
  23. 23 GCIH · GCFA Post-Exploitation Analysis Advanced 4 lessons 4 hours

    What an attacker does once inside, seen from the evidence. Discovery, collection, staging and exfiltration from the defender view, and reconstructing the objective of a compromise.

    • GCIH
    • GCFA
    • Post-Exploitation
    • Recognising post-exploitation activity
    • Reconstructing discovery and collection
    • Detecting staging and exfiltration
    • Determining the objective
    Open course
  24. 24 GCED Foundation Enterprise Security Architecture Advanced 4 lessons 4 hours

    Stepping back from the incident to the design. How a defensible enterprise is architected, where controls sit, and how architecture decisions shape what an attacker can and cannot do.

    • GCED
    • Architecture
    • A defensible enterprise architecture
    • Placing controls where they matter
    • Attack surface by design
    • Assessing an architecture
    Open course
  25. 25 GCED Defense-in-Depth Advanced 3 lessons 3 hours

    Layered defense so no single failure is fatal. Building overlapping controls, understanding where layers reinforce and where they merely duplicate, and measuring real depth.

    • GCED
    • Defense in Depth
    • Designing overlapping layers
    • Reinforcement versus duplication
    • Measuring depth and single points of failure
    Open course
  26. 26 GCED Security Controls and Hardening Advanced 4 lessons 4 hours

    Reducing what an attacker can use. Systematic hardening of systems and services, applying benchmarks, and verifying that a control actually does what it claims.

    • GCED
    • Hardening
    • Systematic hardening
    • Applying benchmarks
    • Verifying a control
    • Hardening versus usability
    Open course
  27. 27 GCED Endpoint Security Advanced 3 lessons 3 hours

    Defending the endpoint as a system. Layered endpoint controls, application control and EDR as prevention, and making the host a hard target rather than a soft landing.

    • GCED
    • Endpoint
    • Layered endpoint controls
    • Application control and EDR as prevention
    • Reducing endpoint attack surface
    Open course
  28. 28 GCED Network Defense Advanced 4 lessons 4 hours

    The network as a defended and monitored system. Segmentation and zero trust in practice, egress control, and designing a network an attacker cannot move freely across.

    • GCED
    • Network Defense
    • Segmentation and zero trust in practice
    • Egress control
    • Constraining lateral movement
    • Monitoring built into the network
    Open course
  29. 29 GCED Application Security Defense Advanced 3 lessons 3 hours

    Defending the applications the business runs on. The defensive controls around an application, monitoring it for abuse, and reducing the attack surface a web app presents.

    • GCED
    • Application Security
    • Defensive controls around an application
    • Monitoring for abuse
    • Reducing application attack surface
    Open course
  30. 30 GCED Cloud Security Defense Advanced 4 lessons 4 hours

    Defending the environment most estates now run in. The cloud shared-responsibility model, identity and configuration as the new perimeter, and monitoring a cloud estate for attack.

    • GCED
    • Cloud
    • The shared-responsibility model
    • Identity and configuration as perimeter
    • Monitoring a cloud estate
    • Reducing cloud attack surface
    Open course
  31. 31 GCED Security Automation Advanced 3 lessons 3 hours

    Scaling defense with automation. SOAR concepts, automating repetitive response, and the judgement of what to automate and what a human must still decide.

    • GCED
    • Automation
    • SOAR
    • SOAR and automation concepts
    • Automating a repetitive response
    • What to automate, and keeping it auditable
    Open course
  32. 32 GCED · GCFA Advanced Detection Engineering Advanced 4 lessons 4 hours

    Detection engineering at an enterprise scale. Coverage strategy across the attack lifecycle, engineering high-fidelity detections, and running detection as a measurable programme.

    • GCED
    • BTL2
    • Detection Engineering
    • Coverage strategy across the lifecycle
    • Engineering high-fidelity detections
    • Measuring and reporting coverage
    • Detection as a programme
    Open course
  33. 33 GCFA · GCIH Threat Hunting Operations Advanced 4 lessons 4 hours

    Running hunting as an expert-level programme feeding forensics and defense. Planning and measuring hunts at scale, and closing the loop between a hunt, a detection and a hardening change.

    • GCFA
    • Threat Hunting
    • A hunting programme at scale
    • Planning and measuring enterprise hunts
    • Closing the loop to detection and hardening
    • Reporting outcomes to leadership
    Open course
  34. 34 GCFA Capstone Full Digital Forensics Investigation Advanced 3 lessons 5 hours

    The forensics finals. A complete case worked from evidence acquisition through memory, disk and timeline analysis to a documented, defensible conclusion about what happened and how.

    • GCFA
    • Capstone
    • Forensics
    • Acquisition and triage
    • Memory, disk and timeline analysis
    • Conclusion and the forensic report
    Open course
  35. 35 GCIH Capstone Full Incident Response Investigation Advanced 3 lessons 5 hours

    The incident-handling finals. A major incident handled across the full attack lifecycle: detection, scoping, containment, eradication and recovery, with the tradecraft recognised at each stage.

    • GCIH
    • Capstone
    • Incident Response
    • Detection and scoping
    • Containment, eradication and recovery
    • The incident report and debrief
    Open course
  36. 36 Capstone Final Expert Blue Team Assessment Advanced 4 lessons 6 hours

    The whole level in one assessment. A sophisticated, multi-stage compromise: detect it, hunt its full scope, forensicate the key hosts, handle the incident, and recommend the enterprise-defense changes that would have stopped it.

    • Capstone
    • GCFA
    • GCIH
    • GCED
    • Detection and full-scope hunting
    • Forensics on the key hosts
    • Incident handling and enterprise recommendations
    • The final report
    Open course
After the Track

Roles This Track Prepares You For

  • Senior SOC Analyst
  • SOC Analyst — L3
  • Incident Response Analyst
  • Digital Forensics Analyst
  • DFIR Analyst
  • Threat Hunter
  • Detection Engineer
  • Cyber Defense Analyst
  • Security Operations Engineer
  • Senior Security Analyst
  • Blue Team Specialist
Same Diploma

Other Tracks in This Diploma

Red Team Level 1 Red Team Level 1 Track Beginner

Red Team Level 1

The complete offensive-security foundation: an integrated CEH, eJPT and OSCP+ preparation path, from cybersecurity fundamentals to OSCP-level practical pentesting.

  • Ethical Hacking
  • Penetration Testing
  • CEH
  • eJPT
  • OSCP+
  • Active Directory
  • Linux
  • Windows
  • One continuous route across CEH, eJPT and OSCP+ — not three disconnected courses.
  • Sixty to seventy percent hands-on labs, in authorised training environments only.
  • Real depth where OSCP+ demands it: Active Directory, privilege escalation, pivoting and reporting.
  • Ends with a full corporate pentest and a professional written report.
Red Team Level 2 Red Team Level 2 Track Advanced

Red Team Level 2

The jump from penetration tester to red team operator: an integrated CRTP, PNPT and CRTO preparation path across enterprise Active Directory, professional network engagements, Command & Control and OPSEC.

  • Red Team
  • Active Directory
  • Cobalt Strike
  • C2
  • CRTP
  • PNPT
  • CRTO
  • Adversary Simulation
  • One continuous route across CRTP, PNPT and CRTO — enterprise AD, professional engagements and C2.
  • Seventy percent hands-on in enterprise AD, internal network and C2 labs.
  • Real red team tradecraft: Cobalt Strike, C2 infrastructure, OPSEC and detection awareness.
  • Ends with a full enterprise adversary simulation across a multi-domain forest.
Red Team Level 3 Red Team Level 3 Track Advanced

Red Team Level 3

The expert tier: an integrated OSEP, OSWE and OSED preparation path across advanced evasion, white-box web exploitation and Windows user-mode exploit development — the three specialisations that together map to OSCE3.

  • Advanced Evasion
  • Exploit Development
  • Web Exploitation
  • Reverse Engineering
  • OSEP
  • OSWE
  • OSED
  • OSCE3
  • Three real specialisations, not three variations: advanced evasion, web exploit development and binary exploit development.
  • Seventy-five percent hands-on across Windows internals, source-code review and exploit-development labs.
  • White-box web work: read the source, find the bug, write the exploit, reach RCE.
  • Windows user-mode exploit development: reverse engineering, DEP and ASLR bypass, custom shellcode.
  • Ends with three separate expert assessments, one for each of OSEP, OSWE and OSED.
Certified

Certificates You Can Earn

Finish your course and receive an accredited MotiGraph certificate you can add to your CV and share with employers.

MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample