Roadmap
Blue Team Foundations
Detection and response basics: logging you can trust, reading traffic, triaging alerts, and writing the timeline that survives review.
Prerequisites
- Linux and Windows administration basics
Who it is for
SOC newcomers, sysadmins, developers owning production
Outcome: You can tell whether an alert corresponds to real activity, build a timeline from logs and captures, and say what you do not know.
Stages
Work them in order the first time. Ticking a stage only records your own progress, in this browser.
Stored in this browser only. No account, no sync.
Telemetry inventory
What is logged, where, at what fidelity and retention.
1 weekLearn
- Endpoint, network, identity, cloud control plane
- Clock accuracy as a prerequisite
Host state and memory
Processes, connections, services, and the value of a capture over a guess.
1–2 weeksTraffic triage
Beacons, handshakes, cleartext credentials, unusual destinations.
1 weekToolsWiresharkDetection logic and noise
Writing a rule you can defend, and tuning what you cannot.
1–2 weeksLearn
- False-positive budget
- Testing a rule against benign behaviour
ToolsNucleiBuild and supply chain posture
What runs in production, from where, and how you would know.
1 weekResponse practice
Drills, timelines, evidence handling, communication under pressure.
ongoingLearn
- Tabletop exercises
- Evidence integrity
ToolsVolatility 3
Tools in this path
Each tool page carries installation steps, commands and the errors you will hit.