Skip to content

Roadmap

Blue Team Foundations

Detection and response basics: logging you can trust, reading traffic, triaging alerts, and writing the timeline that survives review.

Beginner → Intermediate6 stages8–10 weeks

Prerequisites

  • Linux and Windows administration basics

Who it is for

SOC newcomers, sysadmins, developers owning production

Outcome: You can tell whether an alert corresponds to real activity, build a timeline from logs and captures, and say what you do not know.

Stages

Work them in order the first time. Ticking a stage only records your own progress, in this browser.

Progress0 / 60%

Stored in this browser only. No account, no sync.

  1. Telemetry inventory

    What is logged, where, at what fidelity and retention.

    1 week

    Learn

    • Endpoint, network, identity, cloud control plane
    • Clock accuracy as a prerequisite
  2. Host state and memory

    Processes, connections, services, and the value of a capture over a guess.

    1–2 weeks
  3. Traffic triage

    Beacons, handshakes, cleartext credentials, unusual destinations.

    1 week
  4. Detection logic and noise

    Writing a rule you can defend, and tuning what you cannot.

    1–2 weeks

    Learn

    • False-positive budget
    • Testing a rule against benign behaviour
    ToolsNuclei
  5. Build and supply chain posture

    What runs in production, from where, and how you would know.

    1 week
  6. Response practice

    Drills, timelines, evidence handling, communication under pressure.

    ongoing

    Learn

    • Tabletop exercises
    • Evidence integrity

Tools in this path

Each tool page carries installation steps, commands and the errors you will hit.