Intermediate

Blue Team Level 2 (BTL2)

Lessons available in 9 languages with native text-to-speech (beta)

BTL2 is our advanced certification for building deeper investigative and analytical skills in security operations teams. It focuses on complex attack scenarios and equips professionals with the skills needed to detect, analyse, and respond to advanced threats.

 

It’s designed to improve detection depth, strengthen investigation quality, and mature incident response across security operations, providing a clear development path for analysts.

Skills Your Team Will Gain

SIEM
Threat Hunting
Malware Analysis
Vulnerability Management
YARA
yarGen
String
BinText
Resource Hacker
ProcDOT
Process Monitor
PowerShell
Bash
Strings
pestudio
CAPA
PDFid
pdf-parser
OfficeMalScanner
CyberChef
Malwoverview
AutoRuns
TCPView
Regshot
VirusTotal
Hybrid Analysis
GRR
Velociraptor
KAPE
JumpList Explorer
Windows File Analyzer
PECmd
Chainsaw
Wireshark
tshark
RITA
DeTT&CT
ATT&CK Navigator
ATT&CK
OpenVAS
Nmap
Nmap NSE
Nikto
WPScan
Report Writing
Adversary Emulation
Threat Modelling
Threat Intelligence

Blue Team Level 2 (BTL2)

Recommended experience

2+ years' experience

Estimated time to complete

approximately 50 hours to complete

On-demand access

Complete in 5 months

Contact Sales
View Course Content Download brochure

Who is the course for?

BTL2 is designed for professionals with existing experience in security operations who are looking to advance their technical capability, including:

 

  • Mid–Senior Security Analysts  
  • Mid–Senior Incident Responders  
  • Security Consultants  
  • DFIR Specialists  
  • Threat Hunters  
  • Malware Analysts

Why choose BTL2?

BTL2 is designed for practitioners working in security environments who want to develop more advanced skills. It focuses on real-world scenarios that reflect modern attack techniques and evolving threats.

 

The certification helps teams improve detection coverage, reduce risk exposure, and respond more effectively to complex threats building an advanced defender skill set.
 

  • Vulnerability Management - Identify, analyse, prioritise, and remediate vulnerabilities to reduce risk 
  • Malware Analysis - Conduct static and dynamic analysis to gather indicators of compromise and understand behavior 
  • Adversary Emulation - Simulate attacker activity to identify SIEM detection gaps and improve visibility 
  • Threat Hunting - Perform hunts across systems and at scale to detect adversaries post-breach

Malware Analysis

107 topics

4 quizzes

17 labs

What Your Team Will Learn

This section will develop your understanding of malware analysis, and will teach you how to use a range of tools to perform static and dynamic analysis on portable executables, portable documents, and Microsoft Office document filetypes.

Lessons

  • Introduction to Malware Analysis
  • Setting up a Malware Analysis Home Lab
  • Static Malware Analysis
  • Dynamic Malware Analysis
  • Windows Internals
  • Assembly Language
  • Reverse Engineering - C Code Constructs
  • Advanced Analysis
  • Different Malware Types
  • Malware Analysis Practice

Skills Your Team Will Learn

Malware Analysis
YARA
yarGen
String
BinText
Resource Hacker
ProcDOT
Process Monitor
PowerShell
Bash
Strings
pestudio
CAPA
PDFid
pdf-parser
OfficeMalScanner
CyberChef
Malwoverview
AutoRuns
TCPView
Regshot
VirusTotal
Hybrid Analysis
Wireshark
Static Analysis
Dynamic Analysis
OSINT

Threat Hunting

Advanced SIEM

Vulnerability Management

BTL2 Exam Preparation

Course Authors

Photo of Joshua Beaman

Joshua Beaman

Photo of Sabastian Hague

Sabastian Hague

Ready to strengthen your team's capabilities?

To find out more about how your SOC is operating take our SOC Leaders Maturity Assessment and gain a clear picture of your SOC’s effectiveness in minutes.

Our maturity assessment benchmarks your capabilities, identifies gaps, and delivers a personalized report with prioritized actions to strengthen your security operations.