Security Blue Team Level 1 (BTL1) Training
Become a certified Blue Team defender. This hands-on course teaches essential SOC and Incident Response skills, covering forensics, SIEM analysis (Splunk), phishing defense, and MITRE ATT&CK concepts.
Certified Blue Team Level 1 (BTL1)
Course Overview
BTL1 is designed to train technical security defenders capable of defending networks and responding to cyber incidents. The comprehensive skills and tools learned are directly applicable to a range of operational security roles (SOC, Incident Response, Forensics) and are actively used by defenders around the world. The course emphasizes practical application across multiple security domains.
Course Outline
- Module 1: Security Fundamentals
- Soft Skills for Security Professionals
- Security Controls Overview
- Networking 101 (TCP/IP, Common Protocols)
- Security Management Principles
- Active Directory Fundamentals
- Module 2: Phishing Analysis
- Types of Phishing Emails (Spear, Whale, Vishing, etc.)
- Tactics and Techniques Used by Threat Actors
- Investigating a Phishing Email (Headers, URLs, Attachments)
- Analyzing Phishing Artifacts
- Taking Defensive Actions and Reporting
- Phishing Response Challenge
- Module 3: Threat Intelligence
- Threat Actors and Advanced Persistent Threats (APTs)
- Operational Threat Intelligence (TTPs and Incident Validation)
- Tactical Threat Intelligence (IOCs and Automated Blocking)
- Strategic Threat Intelligence (Risk and Executive Reporting)
- Module 4: Digital Forensics
- Forensics Fundamentals and Chain of Custody
- Digital Evidence Collection Techniques
- Windows Investigations (Registry, Event Logs, Pre-fetch)
- Linux Investigations (Log Files, Users, Shell History)
- Memory Analysis With Volatility
- Disk Analysis With Autopsy (File System and Artefact Analysis)
- Module 5: Security Information and Event Monitoring (SIEM)
- Logging and Log Aggregation Principles
- Correlation and Alerting Concepts
- Using Splunk SIEM for Investigation and Querying
- Module 6: Incident Response
- Preparation Phase and Documentation
- Detection and Analysis Phase (Triage)
- Case Management and Documentation
- Containment, Eradication, and Recovery Phase
- Lessons Learned and Reporting
- Introduction to the MITRE ATT&CK Framework
Intended Audience
- IT Personnel
- Security Analysts
- Incident Responders
- Threat Intelligence Analysts
- Forensics Analysts
Prerequisites
1–2 years security experience
Follow-On Courses
Related training topics
Justify your training
Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.
Sample training request letter
Subject: Request for Defensive Cyber & Blue Teaming training from Applied Technology Academy
[Decision Maker Name],
I'm writing to request time and budget approval to complete Applied Technology Academy's course, Security Blue Team Level 1 (BTL1) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.
Course Description
Become a certified Blue Team defender. This hands-on course teaches essential SOC and Incident Response skills, covering forensics, SIEM analysis (Splunk), phishing defense, and MITRE ATT&CK concepts. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners. The course combines instructor-led training with practical exercises, real-world examples, and computer-based activities designed to reinforce job-relevant skills. It also includes formal hands-on labs for applied, learn-by-doing practice in a live environment.
Course Objectives
Once I've completed the course, I'll have job-ready skills in defensive cyber & blue teaming that I can apply immediately to our work.
Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.
Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.
Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in defensive cyber & blue teaming. Additional course information is available at https://appliedtechnologyacademy.com/centri-training/security-blue-team-level-1-btl1-training/.
Thank you for your consideration,
[Your Name]
Related Defensive Cyber & Blue Teaming courses
Design training around your team, not the other way around.
Talk to a training advisor about private cohorts, funding paths and program management.