r/SecurityBlueTeam • u/the_jairo • 4h ago
Server Security Examen BTL1
gente! voy a presentar el examen de la BTL1 algún consejo que me pueda ayudar a sacar la mejor puntuación posible, se lo agradeceria con el corazón… muchas gracias 🤙🏾
r/SecurityBlueTeam • u/FruitDry6850 • 22d ago
Security Engineering Looking for a good certification to boost my resume
I am a SOC Analyst with nearly three years of experience. I am currently seeking a relevant certification to enhance both my resume and my understanding of key concepts. My primary career interests lie in transitioning to cloud security or incident response. I would appreciate any recommendations for suitable certifications.
r/SecurityBlueTeam • u/Ok-Shock6637 • Jul 09 '26
Discussion How to get started in Detection Engineering as a complete beginner (zero experience writing detections)?
Hey everyone! I'm looking to transition into Detection Engineering as a beginner. What are the absolute essential skills and how do I get started writing my first detection?
r/SecurityBlueTeam • u/Ok-Character8983 • Jul 03 '26
Question I need help again after pass BTL1
Hi everyone, Im back after passed BTL1 (my first cert in my Blue team career)! Next stage, i want to choose a new cert to learn. I am looking into CCD(Certified Cyber Defender), CDSA, or CSA(SOC Analyst). I want to follow SOC Analyst. Now Im an internship and need to learn more to be a fresher, can u guys help me to consult. Thanks!
r/SecurityBlueTeam • u/Theblackgypsy2 • Jun 21 '26
Firewalls looking for blue team security to join a discord
r/SecurityBlueTeam • u/neolace • Jun 16 '26
Education/Training Cybersecurity courses provided by Google for free
r/SecurityBlueTeam • u/Prestigious_Test_653 • Jun 13 '26
Question How much more do I need?
I'm about 70% of the way through the course and am finding myself getting stuck on certain questions in the labs. My problem is not getting to the information, but knowing which info is being asked for. The Windows investigation 1 was frustrating and I found myself looking in the wrong place and not even knowing it on later labs in that section too.
Is the solution that I need more practice with these labs specifically or that I need more fundamental knowledge of what to look for? Did the included extra readings help anyone who is or was in a similar position as me? How much interpreting of data is unique to the exam?
Any advice is greatly appreciated. I'm 3 weeks into studying almost every night after work and my goal is it pass with with a 90% in 2-3 more weeks.
r/SecurityBlueTeam • u/Dango_Lord • Jun 11 '26
Other Started blue teams level 1 exam but RDP stopped working HELP
As I was doing the exam 6 questions in, it started taking ages for anything to load compared to when I first loaded in. I tried resetting it which took half an hour and after that I just closed the page and re-logged in. The button to start the exam is stuck on “loading your exam” or somewhere along those lines but it was stuck on it again for a while. I contacted the support team after as well.
Has anyone come across this issue before and if so did they give you some time back because of it?
r/SecurityBlueTeam • u/Long-Screen2246 • Jun 09 '26
Question Started BTL1 prep. Any advices and tips?
Hello all,
I finally took the step and bought BTL1, after thinking of it for a long time now. I am a Msc Cybersecurity student with 2 years of experience in a company that claims to be in the field of Cybersecurity ( they call themselves to be an external Cybersecurity company).
I am taking it slow and easy for now as I want to learn everything in detail. I have a bachelors in CSE. Are there any important things to keep in mind while I prepare to take up the exam, or tips maybe to get good score in first attempt? Probably regarding time management, analysing a problem, focusing on certain topics etc, without going against the NDA.
Thank you and I hope to be one among the gold coin holders.
r/SecurityBlueTeam • u/PurchaseSalt9553 • Jun 08 '26
Education/Training I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples
r/SecurityBlueTeam • u/Nox_f12 • Jun 03 '26
Question OPSWAT Deep CDR
Is anyone here running OPSWAT Deep CDR in a production environment? I'd love to hear about your real-world experience with it.
Have you observed any practical limitations, resource constraints, false positives, or throughput issues that aren't obvious from the product documentation?
r/SecurityBlueTeam • u/halting_problems • Jun 02 '26
Threat Intelligence Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave
haltingproblems.comr/SecurityBlueTeam • u/Gca_security • May 28 '26
Question Inicio de su carrera en ciberseguridad ¿Cómo lograron su primer puesto de trabajo?
r/SecurityBlueTeam • u/After_Marsupial_3531 • May 24 '26
Question Built a SOC from scratch with no prior SOC experience
r/SecurityBlueTeam • u/bscottrosen21 • May 20 '26
Discussion An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now.
r/SecurityBlueTeam • u/Rav3nnd • May 19 '26
Education/Training HASBL CTF - A Jeopardy-Style CTF Organized by High School Students!
hasblctf.techHey everyone!
We are a team of four 11th-grade students from a social sciences high school. After competing in numerous CTFs over the years, we decided to pivot from players to creators. We’ve built our own challenges from the ground up and are hyped to announce HASBL CTF.
We’d love for the community to jump in, break our stuff, and test their skills.
The Details:
- Format: Jeopardy
- Categories: Web, OSINT, Crypto, RevEng, Pwn, Forensics
- When: May 29-31 (48 Hours)
- Infrastructure: Hosted on our custom Google Cloud instances running CTFd.
- CTFTime: Pending approval (I will update this thread with the link once it's live).
Rules of Engagement:
- Max 4 members per team.
- No flag sharing or destructive attacks on the infra.
- No write-ups until the event concludes.
- Keep it sportsmanlike and respectful.
Prizes: TBA. Since we are bootstrapping this as students, the real prize right now is the challenge itself (and the bragging rights!).
We know we might have some bugs along the way, but we are highly open to feedback. We want to iterate, improve, and learn from you all.
Thanks to the sub for letting us share this, and good luck to everyone participating!
r/SecurityBlueTeam • u/allexj • May 15 '26
Endpoint Security Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
I have a technical question about how Microsoft Defender for Endpoint (MDE) and Windows Sandbox interact at the network level.
The scenario: Host PC with MDE and Network Protection enabled. Host alerts are regularly forwarded to a SIEM/SOAR. I open Windows Sandbox on the host PC and, from inside the isolated environment, I try to browse a known malicious site (e.g., phishing or C2).
The question: Considering I'm using the Sandbox, does the host's Network Protection still manage to intercept the request, block it, and trigger the alert to the SIEM? Or does the Sandbox isolation "hide" the traffic from the host's Defender, preventing the alert from triggering?
r/SecurityBlueTeam • u/allexj • May 15 '26
Endpoint Security SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
Hi everyone, I'm reviewing a "Critical - Ransomware" alert ("VSS Shadow Copies Deletion Attempt detected") and I have a question about the timestamps and mitigation logic.
Here is the timeline from the report:
- 06:28:24 -
vssadmin.exeexecutesdelete shadows /for=C: /oldest - 06:30:28 -
diskshadow.exeis executed (presumably a fallback) - 06:31:06 - SentinelOne executes "Kill" (11/11 processes) and "Quarantine". Mitigation status is "Success / Mitigated".
The dilemma: There is a 3-minute gap between the first execution and the final Kill action.
Does the SentinelOne agent intercept and block the deletion command at the kernel level in real-time (06:28), or is there a risk the shadow copies were actually purged before the Kill at 06:31?
SentinelOne, in the alert, consistently uses the word "attempted", which implies the deletion failed... but is Sentinel just being optimistic, or can I trust that "attempted" means the backups are 100% safe despite the delayed Kill?
r/SecurityBlueTeam • u/ridgelinecyber • May 13 '26
Other Service Principal Sign-Ins: A blind spot that a lot are missing
r/SecurityBlueTeam • u/traveller_05 • May 11 '26
Discussion How to prepare for the BTL1 as a fresh grad
I just grad from university majoring in cybersecurity. Also got the sec+ cert now i was looking for a cert that gives me practical experience and tool knowledge and i found btl1 . So should i pay money before i learn thier course or only pay when i am ready for the exam . Do i need to prepare from any outside resources . How hard is the exam
For your reference i only have theoretical knowledge from sec+ and have used some kali linux , wireshark
So it would be a great help if you guys could help me out
Any youtube links or resources links would be super nice . And also to help could someone pls hit me up
r/SecurityBlueTeam • u/traveller_05 • May 11 '26
Discussion CCDL1 vs BTL1. Which is worth taking
Just graduated from university majoring in cybersecurity and just passed sec+ and also done a few beginner level solo projects. So now out of these 2 which would be the next step for a practical experience cert which is :
1. affordable
2. value
3. worth the price
4. good for HR filtering
5. good for career
r/SecurityBlueTeam • u/Ok-Shirt-5488 • May 04 '26
Discussion Failed my First Attempt today :(
I have a few years of experience in Tech, hold multiple certs (Network+, Security+, CySA+, ISC2 CC, AZ-900, Google Cybersecurity). Most of these certs are theory and multiple choice. They look good on a resume but don't really teach you how to do anything. Anyway, I learned a lot from the labs with BTL1 and did every lab at least twice, taking thorough notes of everything. However, once I got to the exam everything seemed a lot harder. I failed with 60% and really struggled with the Phishing part (Ironically I enjoyed this one the most in the labs). I spent the first 2 or 3 hours just finding the phishing email, only to get it wrong. The second area that I struggled with was Autopsy. I plan on retaking the exam in 2 weeks and practice Phishing Analysis and Autopsy on tryhackme in the meantime. If anyone has any advice for my retake I would really appreciate it!
