Blue Team Analyst | Ingress Academy
Create account & apply
NETWORK SECURITY & ETHICAL HACKING · INTERMEDIATE LEVEL

Blue Team Analyst

The Blue Team Analyst ( program is a 4-month hands-on cybersecurity training course focused on Security Operations Center (SOC) activities and cyber defense. Participants develop practical skills in security monitoring, log analysis, digital forensics, phishing investigation, threat intelligence, incident response, and detection engineering. Through real-world case studies, lab exercises, and simulated SOC environments, learners gain the knowledge required to detect, investigate, and respond to cyber threats while preparing for the Blue Team Level 1 certification exam

Intermediate16 weeks128 hoursOn-site
Your selected course will be carried into Ingress Portal.
YOUR LEVEL
BeginnerIntermediateAdvancedExpert
WHAT YOU WILL BE ABLE TO DO

The skills you will have by the end of this course.

  • Upon successful completion of this program, participants will be able to:
  • Monitor and analyze security events using SIEM platforms.
  • Investigate Windows and Linux logs to identify suspicious activity.
  • Perform endpoint investigations and basic digital forensics analysis.
  • Analyze phishing emails, malicious URLs, and suspicious attachments.
  • Use threat intelligence and MITRE ATT&CK techniques to support investigations.
  • Detect and investigate security incidents across networks and endpoints.
  • Create detection rules and reduce false positives in security monitoring tools.
  • Conduct end-to-end incident investigations and produce professional security reports.
  • Prepare for the Blue Team Level 1 (BTL1) certification exam and entry-level SOC Analyst roles.
CONDENSED SYLLABUS

See the structure without reading a textbook.

Modules stay collapsed for quick scanning. Open any module to inspect its topics.

01IT & Cybersecurity Essentials Refresh1 lesson+

Networking basics (IP, DNS, ports), OS basics, logging, SIEM overview, attack lifecycle

02SOC & SIEM Fundamentals1 lesson+

SOC roles, SIEM architecture, log ingestion, log sources

03Windows Authentication Logs1 lesson+

Event ID 4624, 4625, 4648, və digər windows logları, log fields analizi

04Linux Logs & Privilege Indicators1 lesson+

auth.log, syslog, sudo activity, command traces

05Process Analysis1 lesson+

Process tree, parent-child relationship

06Command-line Investigation1 lesson+

PowerShell, CMD, Bash, encoded commands

07Forensics Basics1 lesson+

Artifacts (Windows/Linux), timeline

08Persistence & Anti-Forensics1 lesson+

Scheduled tasks, autoruns, log deletion

09DNS & Network Analysis1 lesson+

DNS queries, domain reputation, beaconing

10Phishing Analysis1 lesson+

Email headers, sender analysis

11URL & Attachment Analysis1 lesson+

Obfuscation, malicious docs

12Threat Intelligence1 lesson+

IOC vs TTP, MITRE ATT&CK

13Incident Response Basics1 lesson+

IR lifecycle, triage

14Lateral Movement1 lesson+

RDP, SMB, credential abuse

15Detection Engineering1 lesson+

SIEM/XDR rules, FP reduction

16Exam Preparation1 lesson+

Full simulation

UPCOMING GROUPS

Choose the cohort you can actually attend.

Only current, open groups are shown.

STARTS

To be announced

On-site
Schedule
To be announced
Format
On-site
Duration
16 weeks · 128 hours
Language
Confirm with advisor
Join the next cohort waitlist
CONTEXTUAL PROOF
“The program helped me connect individual skills into the way real teams design, build and deliver software.”

See real graduate stories from the Ingress community.

Explore graduate results
APPLICATION THROUGH INGRESS PORTAL

Your course stays selected while you create your account.

We use one Portal account for applications, assessments and future learning progress. You will not need to email your details or select the training again.

Questions first? Talk to an advisor
  1. 01

    Create or sign in to your Portal accountYour contact details stay connected to one student profile.

  2. 02

    Confirm your application detailsBlue Team Analyst is preselected.

  3. 03

    Submit your applicationThe admissions team receives it immediately and can follow up from the Portal.

SELECTED TRAININGBlue Team AnalystOn-site

Continue in Ingress Portal Already registered? The Portal will let you sign in instead.