Junior

Blue Team Level 1 (BTL1)

Lessons available in 9 languages with native text-to-speech (beta)

BTL1 is our leading certification for building practical blue team capability and improving security operations performance. It develops operation-ready skills for detecting, investigating, and responding to real-world cyber incidents.

 

The certification helps organisations reduce onboarding time, improve triage accuracy, and increase consistency in incident handling. By standardising core investigative skills, BTL1 develops hands-on skills and reduces dependency on senior analysts for routine tasks.

 

More than 10,000 professionals have earned BTL1 over the past five years, contributing to a global community of over 150,000 learners across 80+ countries. It is widely recognised for developing Tier 1 SOC capability.

Skills Your Team Will Gain

ATT&CK
Autopsy
Browser History Capturer
CyberChef
Browser History Viewer
DeepBlueCLI
DomainTools
Event Viewer
FTK Imager
JumpList Explorer
KAPE
Linux CLI
MISP
OpenCTI
PECmd
PhishTool
PowerShell
ProcDump
Scalpel
Sigma
Splunk
TheHive5
URL2PNG
VirusTotal
Volatility
WannaBrowser
Windows File Analyzer
Wireshark
Digital Forensics
Threat Intelligence
Phishing Analysis
SIEM
Incident Response
PICERL
Case Management
Cyber Kill Chain
Active DIrectory

Blue Team Level 1 (BTL1)

Recommended experience

0-2 years experience

Estimated time to complete

approximately 30 hours to complete

On-demand access

Complete in 4 months

Contact Sales

NICE Mapping

Cyber Defense Analyst

60% Topics, 60% Knowledge, 67% Ability

View Course Content Download brochure

Who is the course for?

BTL1 is designed to bridge the skills gap for organisations looking to strengthen SOC performance and analyst capability. It provides the practical foundation required for:

 

  • New Hires & IT Transitions: Reduce onboarding time and accelerate SOC readiness
  • SOC Analysts (Tier 1): Improve triage accuracy, investigation and escalation quality
  • Incident Response Teams: Strengthen operational first-response capability 
  • Threat Intelligence & Forensics Analysts: Build foundational investigation skills aligned to SOC workflows

Why choose BTL1?

SOC teams use BTL1 to standardise Tier 1 performance, speed up onboarding, and reduce reliance on senior analysts for routine triage, improving team consistency and audit and reporting readiness. 

 

Build a Defender Skillset

BTL1 develops practical, transferable skills across core security operations areas. Key highlights include: 

  • Phishing Mitigation - Investigate and respond to email threats
  • Digital Forensics - Collect and analyze digital evidence
  • SIEM Mastery – Using tools to investigate malicious activity
  • Traffic & Log Analysis - Analyze logs and network traffic to identify threats and malware
  • Threat Profiling - Research threat actors to support proactive defense

Security Fundamentals

35 topics

3 quizzes

What Your Team Will Learn

This section covers the basics of information security, building a foundation for the rest of the course.

Lessons

  • Introduction to Security Fundamentals
  • Soft Skills
  • Security Controls
  • Networking 101
  • Management Principles
  • Active Directory

Skills Your Team Will Learn

Blue Team Roles
Soft Skills
Physical Security
Network Security
Endpoint Security
Email Security
Networking 101
OSI Model
Network Devices
Management Principles
Risk
Policies and Procedures
Compliance
Active DIrectory

Phishing Analysis

Threat Intelligence

Digital Forensics

Security Information and Event Monitoring

Incident Response

BTL1 Exam Preparation

Course Authors

Photo of Joshua Beaman

Joshua Beaman

Photo of Sabastian Hague

Sabastian Hague

Ready to strengthen your team's capabilities?

To find out more about how your SOC is operating take our SOC Leaders Maturity Assessment and gain a clear picture of your SOC’s effectiveness in minutes.

Our maturity assessment benchmarks your capabilities, identifies gaps, and delivers a personalized report with prioritized actions to strengthen your security operations.