Centri Authorized Training

Security Blue Team Level 1 (BTL1) Training

Become a certified Blue Team defender. This hands-on course teaches essential SOC and Incident Response skills, covering forensics, SIEM analysis (Splunk), phishing defense, and MITRE ATT&CK concepts.

LevelIntermediate
Duration4 Days
Experience1-2 year: Security Operations
Average Salary$110,000
LabsYes

Certified Blue Team Level 1 (BTL1)

Course Overview

BTL1 is designed to train technical security defenders capable of defending networks and responding to cyber incidents. The comprehensive skills and tools learned are directly applicable to a range of operational security roles (SOC, Incident Response, Forensics) and are actively used by defenders around the world. The course emphasizes practical application across multiple security domains.

Course Outline
  • Module 1: Security Fundamentals
    • Soft Skills for Security Professionals
    • Security Controls Overview
    • Networking 101 (TCP/IP, Common Protocols)
    • Security Management Principles
    • Active Directory Fundamentals
  • Module 2: Phishing Analysis
    • Types of Phishing Emails (Spear, Whale, Vishing, etc.)
    • Tactics and Techniques Used by Threat Actors
    • Investigating a Phishing Email (Headers, URLs, Attachments)
    • Analyzing Phishing Artifacts
    • Taking Defensive Actions and Reporting
    • Phishing Response Challenge
  • Module 3: Threat Intelligence
    • Threat Actors and Advanced Persistent Threats (APTs)
    • Operational Threat Intelligence (TTPs and Incident Validation)
    • Tactical Threat Intelligence (IOCs and Automated Blocking)
    • Strategic Threat Intelligence (Risk and Executive Reporting)
  • Module 4: Digital Forensics
    • Forensics Fundamentals and Chain of Custody
    • Digital Evidence Collection Techniques
    • Windows Investigations (Registry, Event Logs, Pre-fetch)
    • Linux Investigations (Log Files, Users, Shell History)
    • Memory Analysis With Volatility
    • Disk Analysis With Autopsy (File System and Artefact Analysis)
  • Module 5: Security Information and Event Monitoring (SIEM)
    • Logging and Log Aggregation Principles
    • Correlation and Alerting Concepts
    • Using Splunk SIEM for Investigation and Querying
  • Module 6: Incident Response
    • Preparation Phase and Documentation
    • Detection and Analysis Phase (Triage)
    • Case Management and Documentation
    • Containment, Eradication, and Recovery Phase
    • Lessons Learned and Reporting
    • Introduction to the MITRE ATT&CK Framework
Intended Audience
  • IT Personnel
  • Security Analysts
  • Incident Responders
  • Threat Intelligence Analysts
  • Forensics Analysts
Prerequisites

1–2 years security experience

Follow-On Courses

Related training topics

Get approved to attend

Justify your training

Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.

Sample training request letter

Subject: Request for Defensive Cyber & Blue Teaming training from Applied Technology Academy

[Decision Maker Name],

I'm writing to request time and budget approval to complete Applied Technology Academy's course, Security Blue Team Level 1 (BTL1) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.

Course Description
Become a certified Blue Team defender. This hands-on course teaches essential SOC and Incident Response skills, covering forensics, SIEM analysis (Splunk), phishing defense, and MITRE ATT&CK concepts. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners. The course combines instructor-led training with practical exercises, real-world examples, and computer-based activities designed to reinforce job-relevant skills. It also includes formal hands-on labs for applied, learn-by-doing practice in a live environment.

Course Objectives
Once I've completed the course, I'll have job-ready skills in defensive cyber & blue teaming that I can apply immediately to our work.

Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.

Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.

Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in defensive cyber & blue teaming. Additional course information is available at https://appliedtechnologyacademy.com/centri-training/security-blue-team-level-1-btl1-training/.

Thank you for your consideration,
[Your Name]

Design training around your team, not the other way around.

Talk to a training advisor about private cohorts, funding paths and program management.

Request a Quote Call 800.674.3550