Cybersecurity — Blue Team (Defensive Security)

Cybersecurity — Blue Team (Defensive Security)

The Cybersecurity Blue Team course is a hands-on program focused on defending information systems, detecting threats, and responding to security incidents. You will learn security fundamentals, log analysis, SIEM concepts, endpoint and network monitoring, vulnerability identification, incident response workflows, and basic hardening practices through real-world scenarios and practical labs. This course prepares learners for roles such as SOC Analyst, Blue Team Analyst, and Junior Cybersecurity Specialist.

Duration4 months
Start Date2026-02-22
Schedule2 times per week
FormatHYBRID

Üstünlüklərimiz

Professional Mentors

Guidance and support from experienced specialists

Practical Learning

Not just theory — hands-on experience through real projects

Modern Technologies

Python, AI, web development and other trending fields

Career Support

CV preparation, interview simulations and access to job opportunities

Curriculum

0

Module 1 — Security Fundamentals & Blue Team Architecture

  • 1.• Computer network basics — network types & topologies, devices, TCP/IP stack, core protocols (ICMP/ARP/DHCP/DNS, HTTP/HTTPS), IPv4/IPv6, subnetting • Operating systems overview — Linux fundamentals (CLI, filesystem, permissions & ownership, user/group management, package management) and Windows fundamentals • Programming & scripting essentials — foundations for tooling and automation • Cybersecurity basics & Blue Team overview — core security concepts, SOC structure and the Blue Team's role
0

Module 2 — Security Engineering

  • 1.• Blue Team lab setup & network monitoring — directory/identity services (domain environment), firewall & network segmentation • Web & perimeter defense (WAF, IDS/IPS) — web application security & common vulnerabilities, web application firewalls, intrusion detection/prevention (signature-based detection, rule creation, threat-feed integration) • SIEM deployment & log management — log collection, normalization, centralized storage, retention • Endpoint monitoring & IR tooling (EDR/XDR) — endpoint agents/sensors, endpoint detection & response capabilities • Blue Team workflows & ticketing — case management and workflow orchestration
0

Module 3 — Incident Response

  • 1.• Incident response fundamentals • IR process & phases deep dive — preparation → detection → containment → eradication → recovery → lessons learned • Network traffic & packet analysis (×2 lessons) • SIEM log analysis & attack simulation (×2 lessons) — event correlation, pattern/anomaly detection, real-time investigation • Malicious email & phishing analysis • Malicious office document analysis • Malicious PDF analysis • Threat hunting fundamentals — hypothesis-driven and indicator/TTP-based hunting • Introduction to digital forensics — evidence types (volatile/non-volatile), chain of custody, acquisition • Memory forensics & analysis • Disk forensics & DLP — file-system analysis (FAT/NTFS/EXT) and Data Loss Prevention fundamentals
0

Module 4 — Threat Detection & Automation.Threat Intelligence

  • 1.• Threat detection planning & attack simulation • Detection engineering (×3 lessons) — writing and tuning detection rules, reducing false positives • Introduction to SOAR & automation — SOAR vs. SIEM vs. EDR, key components, use cases & benefits • Automation basics & playbook design • Response workflows — automated response, integrating automation with threat-intelligence feeds • Full-cycle detection & response • Threat intelligence fundamentals & threat-actor analysis — TI types (strategic/tactical/operational), TTP mapping • OSINT techniques & threat-intelligence platforms — OSINT/HUMINT/TECHINT collection, platform & feed integration, applying intel to detection, IR and recovery

Our Top Graduates

Bu kurs üçün hələ məzun məlumatı əlavə olunmayıb.

Our Teachers

No teachers found in this category.

Market Salaries

1500 AZN

Junior
0-1 year experience

2600 AZN

Middle
1–3 years experience

4200+ AZN

Salary Plus Icon
Senior
3+ years experience

Frequently Asked Questions

  • idtech is a modern learning ecosystem providing education in technology, programming, and digital skills.

  • You can register by filling out the form in the 'Apply' section on our website.

  • Our courses are suitable for both beginners and those looking to deepen their expertise.

  • Yes, lessons are available both online and in classrooms.

Cybersecurity — Blue Team (Defensive Security) | Cybersecurity Course — IDTECH