Learning pathDefensive Operations

Blue Team Operations

Learn monitoring, detection and incident response, and how to protect systems.

  • Courses7
  • Lessons84

About this path

Learn to monitor systems, detect attacks and respond to incidents, the work of a Blue Team and a Security Operations Center (SOC). The path starts with Linux, then covers network defense, malware, cloud security and connected devices.

Courses in this path

From beginner to advanced

  1. Linux Basics

    Start Linux from zero: the command line, users, services, networking and Bash scripts.

    Beginner53 lessonsFree preview
  2. Malware Threats and Defensive Basics

    Understand malware and how to defend against it, including AI-assisted threats.

    Beginner to intermediate5 lessonsFree preview
  3. Network Defense Essentials

    Understand sniffing and DoS attacks, and defend networks with monitoring and firewalls.

    Beginner to intermediate10 lessonsFree preview
  4. Mobile, Wireless and IoT Security

    Protect wireless networks, mobile devices and IoT from common attacks.

    Beginner to intermediate9 lessonsFree preview
  5. Certified SOC Analyst

    Build core SOC analyst skills in threat monitoring, log and SIEM analysis, incident detection, triage, and response across security operations workflows.

    Coming soonView course
  6. Security+

    Develop foundational cybersecurity skills across threats, vulnerabilities, secure architecture, security operations, identity, access, risk, and incident response.

    Coming soonView course
  7. Cloud and Container Security Fundamentals

    Learn the risks of cloud and containers, and how controls and encryption protect them.

    Intermediate7 lessonsFree preview
All learning paths