01 — Modules
Blue Team
The defensive side: log collection, correlation rules, incident investigation and reporting. More than half of the course is lab exercises that simulate a real SOC shift.
First lesson is free
Duration
6 months
Level
Beginner → intermediate
Format
Offline / online
Group
8–12 students
Who it's for
IT support, network and system administrators
What you will achieve
- →Collect and analyze logs on a real SOC shift
- →Build a SIEM on ELK/Wazuh and create dashboards and reports
- →Write detection rules with Sigma and MITRE ATT&CK
- →Investigate an incident and complete containment and the report
Tools
WiresharkSysmonELKWazuhSigmaMITRE ATT&CK
Modules
M01Network and protocol basicsReading TCP/IP, DNS, HTTP traffic; hunting for anomalies with Wireshark.
M02Linux and Windows telemetrySystem logs, Sysmon, audit policies, useful event IDs.
M03SIEM setupCollection, parsing, dashboards and reports on ELK / Wazuh.
M04Detection rulesSigma rules, coverage mapping against MITRE ATT&CK, false-positive management.
M05Incident responseTriage, escalation, containment steps, writing the incident report.
M06Capstone projectA full investigation of a simulated incident and a defense report.