Blue Team Study Notes — Priority Topics

For the Blue Team side, it's worth taking detailed notes on the highlighted topics below — you'll be coming back to these concepts constantly, so having your own written reference will save you a lot of time later.
Yellow = Core — foundational, know it well Teal = Supporting — important context, know at a working level Plain text = Background — good general awareness

Click any topic to see why it matters — several also expand with the actual commands, paths, or workflow you'd use.

General Approach

Cyber Defense Frameworks

Cyber Threat Intelligence

Network Security and Traffic Analysis

Endpoint Security Monitoring

Security Information and Event Management

Digital Forensics and Incident Response

Phishing


BTL1 Course Content

Section 1 - Introduction

Section 2 - Security Fundamentals

Blue Team Roles & Soft Skills

Security Controls

Networking 101

Management Principles

Active Directory

Section 3 - Phishing Analysis

This entire section is core — one of the most heavily used skillsets in day-to-day Blue Team work.

Types of Phishing / Tactics & Techniques

Investigating a Phishing Email

Analyzing Artifacts

Defensive Actions & Reporting

Section 4 - Threat Intelligence

Section 5 - Digital Forensics

Forensics Fundamentals

Digital Evidence Collection

Windows & Linux Investigations

Memory & Disk Analysis

Section 6 - SIEM

Section 7 - Incident Response

MITRE ATT&CK Framework (end of Section 7)

Practice Boxes

All of it is core — the closest hands-on practice to real Blue Team work. Make sure to complete every one of these.

TryHackMe - Cyber Defense C3 (extra practice)

Timeline / Note-taking Method