
Blue Team Level 1 (BTL1)
Lessons available in 9 languages with native text-to-speech (beta)
BTL1 is our leading certification for building practical blue team capability and improving security operations performance. It develops operation-ready skills for detecting, investigating, and responding to real-world cyber incidents.
The certification helps organisations reduce onboarding time, improve triage accuracy, and increase consistency in incident handling. By standardising core investigative skills, BTL1 develops hands-on skills and reduces dependency on senior analysts for routine tasks.
More than 10,000 professionals have earned BTL1 over the past five years, contributing to a global community of over 150,000 learners across 80+ countries. It is widely recognised for developing Tier 1 SOC capability.
Skills Your Team Will Gain
Blue Team Level 1 (BTL1)
Recommended experience
0-2 years experience
Estimated time to complete
approximately 30 hours to complete
On-demand access
Complete in 4 months
NICE Mapping
Cyber Defense Analyst
60% Topics, 60% Knowledge, 67% Ability
Who is the course for?
BTL1 is designed to bridge the skills gap for organisations looking to strengthen SOC performance and analyst capability. It provides the practical foundation required for:
- New Hires & IT Transitions: Reduce onboarding time and accelerate SOC readiness
- SOC Analysts (Tier 1): Improve triage accuracy, investigation and escalation quality
- Incident Response Teams: Strengthen operational first-response capability
- Threat Intelligence & Forensics Analysts: Build foundational investigation skills aligned to SOC workflows
Why choose BTL1?
SOC teams use BTL1 to standardise Tier 1 performance, speed up onboarding, and reduce reliance on senior analysts for routine triage, improving team consistency and audit and reporting readiness.
Build a Defender Skillset
BTL1 develops practical, transferable skills across core security operations areas. Key highlights include:
- Phishing Mitigation - Investigate and respond to email threats
- Digital Forensics - Collect and analyze digital evidence
- SIEM Mastery – Using tools to investigate malicious activity
- Traffic & Log Analysis - Analyze logs and network traffic to identify threats and malware
- Threat Profiling - Research threat actors to support proactive defense
Security Fundamentals
35 topics
3 quizzes
What Your Team Will Learn
Lessons
- Introduction to Security Fundamentals
- Soft Skills
- Security Controls
- Networking 101
- Management Principles
- Active Directory
Skills Your Team Will Learn
Phishing Analysis
Threat Intelligence
Digital Forensics
Security Information and Event Monitoring
Incident Response
BTL1 Exam Preparation
Ready to strengthen your team's capabilities?
To find out more about how your SOC is operating take our SOC Leaders Maturity Assessment and gain a clear picture of your SOC’s effectiveness in minutes.
Our maturity assessment benchmarks your capabilities, identifies gaps, and delivers a personalized report with prioritized actions to strengthen your security operations.
