Blue Team and Defense

The SOC, the SIEM, detection engineering, and response.

6 guides

The blue team is the side that keeps the lights on. Blue team work is watching, detecting, investigating, and responding. It is where most people start a security career, because it is where most of the jobs are.

These guides cover the parts of defense you will actually touch on the job: the security operations center and how it is staffed, the SIEM and the logs that feed it, endpoint detection and response, writing detections that fire on real behavior instead of noise, running an incident from first alert to written report, and hunting for the things no alert caught.

Weeks 8 and 9 of the mentorship are built around this work. You learn Splunk and then use it to reconstruct a full intrusion from log data.

Learn This at HackRange

If you want to work in a SOC, the fastest proof you can offer an employer is an investigation you ran yourself and wrote up clearly. That is exactly what Week 9 of the mentorship asks you to do.