Junior

Blue Team Level 1 (BTL1)

Lessons available in 9 languages with native text-to-speech (beta)

BTL1 is designed to train technical defenders that are capable of defending networks and responding to cyber incidents. The skills and tools you’ll learn in this course will be directly applicable to a range of security roles, and are actively used by defenders around the world.

Skills you'll gain

ATT&CK
Autopsy
Browser History Capturer
CyberChef
Browser History Viewer
DeepBlueCLI
DomainTools
Event Viewer
FTK Imager
JumpList Explorer
KAPE
Linux CLI
MISP
OpenCTI
PECmd
PhishTool
PowerShell
ProcDump
Scalpel
Sigma
Splunk
TheHive5
URL2PNG
VirusTotal
Volatility
WannaBrowser
Windows File Analyzer
Wireshark
Digital Forensics
Threat Intelligence
Phishing Analysis
SIEM
Incident Response
PICERL
Case Management
Cyber Kill Chain
Active DIrectory

Blue Team Level 1 (BTL1)

BTL1 is designed to train technical defenders that are capable of defending networks and responding to cyber incidents. The skills and tools you’ll learn in this course will be directly applicable to a range of security roles, and are actively used by defenders around the world.

Recommended experience

0-2 years experience

Estimated time to complete

approximately 30 hours to complete

On-demand access

Complete in 4 months

Training and exam price

£399.00 GBP

NICE Mapping

Cyber Defense Analyst

60% Topics, 60% Knowledge, 67% Ability

View Course Content Try Demo

Who is the course for?

BTL1 is perfect for security enthusiasts or professionals that want to develop their practical defensive cyber skills. Roles that we believe would benefit from this course include:

  • Students/IT Personnel
  • Security Analysts
  • Incident Responders
  • Threat Intelligence Analysts
  • Forensics Analysts

Whilst our content is aimed primarily at entry-level or junior roles, read our course syllabus to see if BTL1 is the right choice for you or your team! 

Why choose BTL1?

BTL1 is designed to train technical defenders that are capable of defending networks and responding to cyber incidents. Below are some examples of the skills and experience you will gain.

  • Analyzing and responding to phishing attacks
  • Performing forensics investigations to collect and analyze digital evidence
  • Using a SIEM platform to investigate malicious activity
  • Log and network traffic analysis including malware infections
  • Conducting threat actor research
  • … And much more

The skills and tools you’ll learn in this course will be directly applicable to a range of security roles, and are actively used by defenders around the world.

Security Fundamentals

26 topics

3 quizzes

What you'll learn

This section covers the basics of information security, building a foundation for the rest of the course.

Lessons

  • Introduction to Security Fundamentals
  • Soft Skills
  • Security Controls
  • Networking 101
  • Management Principles

Skills you'll gain

Blue Team Roles
Soft Skills
Physical Security
Network Security
Endpoint Security
Email Security
Networking 101
OSI Model
Network Devices
Management Principles
Risk
Policies and Procedures
Compliance
Active DIrectory

Phishing Analysis

Threat Intelligence

Digital Forensics

Security Information and Event Monitoring

Incident Response

BTL1 Exam Preparation

Course Authors

Photo of Joshua Beaman

Joshua Beaman

Academic Board

Unsure if BTL1 is right for you?

Frequently asked questions

Are there any exam entry requirements? If so, what are they?

No, there are no entry requirements for the exam. You can take the exam whenever you feel ready, however we strongly recommend you complete all the labs, as they are designed to prepare you for the practical exam.

What are the prerequisites for enrolling in this certification?

BTL1 is suitable for security enthusiasts or professionals looking to develop practical defensive cyber skills. Ideal candidates include students, IT personnel, security analysts, incident responders, threat intelligence analysts, and forensics analysts. The course is primarily aimed at entry-level or junior roles and is designed to train technical defenders capable of protecting networks and responding to cyber incidents. The skills and tools taught are directly applicable to various security roles and are widely used by defenders globally.

How long does it take to complete the certification?

Completing the BTL1 certification typically takes between 40 to 50 hours. However, the actual time may vary based on your prior knowledge of the course materials, your working speed, and the amount of time you can dedicate. Everyone's pace is different, so you might complete it more quickly or take a bit longer.

What's included in the price?

The price includes 4 months of on-demand access to 330+ lessons, videos, activities, and quizzes, along with 23 browser labs providing 100 hours of access. You'll also get one 24-hour practical incident response exam with immediate grading and feedback, and one free exam resit voucher (additional resits can be purchased for each). Detailed feedback is provided for all exams to help you improve. Upon passing, you'll receive lifetime BTL1 certification, digital and printed certificates, a Credly digital badge, a silver challenge coin (or gold if scoring 90%+ on the first attempt), and a laptop sticker.

Does the cost of the course include all resources needed to pass the exam?

Yes, there is nothing in the exam that hasn't been covered in the course, or without clear instructions being provided. The exam features a select subset of the tools covered in the course, similar to real incident response engagements. On average 70% of students pass on their first attempt. Over 99% of students that use their free retake pass the exam.

How long is the access?

Individual Students: Once you purchase BTL1, it will immediately appear in your account. You will then be free to start the course whenever you want. Corporate Clients: Purchased licenses can be issued at any time within 12 months from the purchase date, providing you the flexibility to start the training when your team is ready. After gaining access to the course, you have 4 months on-demand access to the training material.

Are there any discounts available?

A 10% discount is available to verified students that are actively studying with an established educational institute. There are also discounts available to military personnel, first responders, and veterans. Read more here: https://support.securityblue.team/hc/en-gb/articles/11802106331164-Discounts-for-Students-and-Service-Members . Corporate discounts are available based on the number of licenses purchased.