Blue Team Level 1 Introduction
Introduction Statement
I recently began the Blue Team Level 1 (BTL1) Certification and want to document my learnings. It is a wonderful pathway to get hands-on experience in the role of a SOC Analyst.
First and foremost, I will not share specifics, screenshots, or any direct content to respect their Terms and Policy. All notes will be written at a high-level and conceptually.
Domains Covered
The BTL1 certification covers several core domains that are essential for anyone looking to build a strong foundation in defensive security. These areas reflect the day-to-day responsibilities of a SOC analyst and blue teamer:
- Security Fundamentals — Core concepts such as the CIA triad, threat actors, and the basics of networking and operating systems.
- Phishing Analysis — Identifying and analyzing phishing emails, suspicious attachments, and malicious links.
- Threat Intelligence — Understanding indicators of compromise (IOCs), threat actors, and how to apply intelligence to detection.
- Digital Forensics — Collecting and analyzing artifacts from endpoints and logs to understand what happened during an incident.
- Incident Response — Following a structured approach to detect, analyze, contain, and recover from security incidents.
- Log Analysis — Parsing and interpreting logs from firewalls, endpoints, and other security tools to find anomalies.
- SIEM — Using Security Information and Event Management platforms to correlate events and detect threats.
Why I'm Excited
I'm genuinely excited to go through the BTL1 program because it focuses on practical, hands-on skills rather than just theory. As someone building a home lab and actively working toward a SOC analyst role, this certification aligns perfectly with the areas I want to grow in — from analyzing phishing attempts to responding to incidents in a structured way.
I look forward to documenting what I learn along the way and using these notes as a reference for my future work in blue teaming.