LP
  • About
    • Untitled
  • CERTIFICATIONS
    • 🟦Passing the Blue Team Level 1
    • 🟥Passing the CySA+
  • homelabs
    • 📕A Simple Active Directory VM Lab Set Up (Work in Progress)
    • Ⓜ️Metasploitable 3 for VMware Workstation
    • 📦Metasploitable 3 for VirtualBox
Powered by GitBook
On this page
  • Why BTL1?
  • 24-Hour Incident Response Exam
  • Preparation
  • Supplemental Resources
  • Autopsy
  • Splunk
  • MITRE ATT&CK Framework
  • Conclusion

Was this helpful?

  1. CERTIFICATIONS

Passing the Blue Team Level 1

Covering about my Blue Team Level 1 certification course and exam experience

PreviousUntitledNextPassing the CySA+

Last updated 2 years ago

Was this helpful?

Why BTL1?

24-Hour Incident Response Exam

I sat the exam for 8.5 hours and passed with an 80%. Won't be able to cover much detail about the exam because of NDA, but It was a fun one. I'd say it was the best certification exam I have ever taken.

Preparation

I used up 40 out of the 100 hours of lab time provided by the course. Redoing the labs, taking notes, and trying to understand why and how the techniques and tools are used helped me pass the exam. Approaching the course with the mindset of "I'm here to learn" instead of just trying to get the cert as fast as possible also helped me relax.

I also used external materials (see below) to better understand the topics that I wasn't strong at.

Supplemental Resources

These were the additional resources I used to get more practice in areas that I was weak at:

Autopsy

Splunk

MITRE ATT&CK Framework

Conclusion

I found this certification exam and training course to be the best of its kind. The course content was comprehensive and in-depth, and the practical labs were engaging and informative. I believe that the value of this certification will only increase over time, as it is well-suited for those who are interested in the technical aspects of blue teaming, such as network defense, digital forensics, and incident response. I would highly recommend this certification exam and training course to anyone who is looking to advance their career in cybersecurity.

I was in need of a more practical and in-depth course to fill in my lack of technical knowledge in blue team, specifically SOC Analyst role. After , the certification only fulfilled the theoretical aspect of blue team. It was a mile-wide and inch-deep quality of knowledge I gained after passing it. Luckily, I stumbled upon one of 's stream, where he was talking about the BTL1, how it is basically the "OSCP for blue team". A certification with a practical 24-hour incident response exam. I was convinced.

🟦
passing the CySA+
Day Cyberwox
TryHackMe | Autopsy
TryHackMe | Disk Analysis & Autopsy
Free access to Splunk with BOTSv1 data
Free video course covering the basics of the MITRE ATT&CK Framework
Blue Team Level 1 (BTL1)
Tracked my exam duration using Toggl