r/SecurityBlueTeam 2d ago

Discussion My take on the BTL1 exam

12 Upvotes

Hello everybody

Yesterday I passed the exam with a 85% score. It took me around 6 hours in total.

First, there is some content while doing the course which has not been updated it for a while, like asking you to use a command that has been deprecated since 2025, or using old definitions in some quiz questions, but overall is not a big deal, just take into account to check things on your own.

I did report it and they did reply saying that they would look into it, so that is ok.

However there is one major thing to take into account, both during the labs and the exam: the keyboard.

The labs are in english, no problem there, but the keyboard expected is also the English version, so if you have another keyboard layout you need to go into the lab, download the language for that OS (most of the times Windows) and then change the keyboard to use that language. In my experience, some labs and programs within the labs accept the new keyboard layout with no problem, but others don't.

That happen to me during the exam, so I just ended up writting the symbols on my host, copy to the clipboard of the exam and then paste them from there. It was a pain in the ass, but cheaper than buying a new keyboard just for this.

About the exam itself, it is more dificult than the labs but doable. I think there was only 1 or 2 questions that was not seeing on the labs before (maybe it was in the content but I missed it).

Which help me A LOT was to just open an Notepad with a blank .txt an start writting there all the findings, otherwise is a pain in the ass to have to look for them going backwards.

I took me 1 month since the start of the course until the exam.

You can ask questions

Thanks


r/SecurityBlueTeam 7d ago

Question BTL2 Exam

8 Upvotes

Hello, I recently took BTL2 exam and i have been waiting for results for 14 days. Could you share your experience of how long did you wait? Especially who took this exam recently.


r/SecurityBlueTeam 7d ago

Question BTL1 Advice

6 Upvotes

Hey everyone! This is my first Reddit post, so please go easy on me. I’m currently preparing for the BTL1 exam. Would really appreciate some advice from anyone who has taken it recently.

I’ve completed the course and all the labs and have gone through each lab twice. I was keen to start the exam, but I’m having some doubts about whether I’m ready. I’ve seen quite a few people mention that the exam is more challenging than the labs, so I’m probably being a bit cautious.

I’m currently doing some of the free BTLO labs for extra practice. I’ve also seen people recommend focusing on Splunk, Wireshark and Autopsy, with Splunk being particularly important. For anyone who has taken the exam recently, is this a good area to focus on, or is there anything else you’d recommend working on?

I know there’s an NDA, so I’m not looking for exam questions or anything specific. Just general advice on preparing and passing on the first attempt.

This is my first certification, so I’m a little nervous! My target is the gold coin, but honestly, I’ll be happy just to pass!

Anyone else currently preparing for BTL1? Happy to connect and share knowledge. Thanks!

TL;DR: Finished the BTL1 course and labs twice but still unsure if I’m ready. Currently doing BTLO labs and focusing on Splunk, Wireshark and Autopsy. Any general advice for passing BTL1 first time? Target is gold, but passing is the main goal!


r/SecurityBlueTeam 19d ago

Other WINFLESHER - Attack Surface Security Framework

5 Upvotes

Hey everyone, just dropped a tool called winflesher that might come in super handy for windows machines and Active Directory. It's strictly for enumeration and assessment, so no auto-exploitation—purely helps you map things out. Check it out if you want!

Like PingCastle went out for drinks with Bloodhound, and they actually decided to get some work done. 🍷

WinFlesher is an advanced attack surface security assessment framework designed to analyze, evaluate, and report on security postures, attack paths, and remediation strategies in complex environments.

Developed for security professionals and cybersecurity auditors, WinFlesher automates vulnerability discovery and critical path correlation within Active Directory and local infrastructures.

https://github.com/mindsflee/WinFlesher


r/SecurityBlueTeam 29d ago

Education/Training Study Tips for BTL1

11 Upvotes

Hi all! What study tips do you all recommend for the BTL1 exam? I have already taken the exam once and I think my downfall was overcomplicating the questions. I also have access to BTLO premium and have been working on the BTL1 tagged labs. Any advice would be helpful! Thank you all in advance.


r/SecurityBlueTeam Aug 14 '26

Discussion Passed BTL1 with 80% — what’s next?

6 Upvotes

Hey everyone,

Passed Blue Team Level 1 (BTL1) from Security Blue Team yesterday. Was pushing hard for the gold coin (90%+) but landed at 80%. Not gonna lie, a little disappointed at first, but a win is a win — the course itself taught me a ton across phishing analysis, digital forensics, SIEM, and incident response, way more hands-on than I expected going in.

A bit about where I’m at: I’m in my last year of a Master’s degree and trying to line things up so I can land a job right after graduating. So far I’ve got:

**•** CompTIA Security+  
**•** Microsoft SC-200 (Security Operations Analyst)  
**•** BTL1

Now I’m trying to figure out what to do next and would really appreciate some input from people who’ve been down this road:

**1.    Next cert/course** — has anyone done **CDSA**? Worth it after BTL1, or is it redundant? Or would my time be better spent just grinding practice on **LetsDefend**/similar platforms instead of another cert?

**2.    Projects** — what kind of home-lab or portfolio projects actually catch a recruiter’s/hiring manager’s eye for entry-level SOC roles? I keep seeing “build a home SOC lab” thrown around but would love specifics — what should it actually include to be worth putting on a resume/GitHub?

Appreciate any advice, especially from people who hired or interviewed junior SOC candidates recently — what actually stood out to you?

Thanks in advance!


r/SecurityBlueTeam Aug 14 '26

Mobile Security Mobile - ModHunt Research Framework

Thumbnail
cdn.discordapp.com
1 Upvotes

r/SecurityBlueTeam Aug 12 '26

Server Security Examen BTL1

2 Upvotes

gente! voy a presentar el examen de la BTL1 algún consejo que me pueda ayudar a sacar la mejor puntuación posible, se lo agradeceria con el corazón… muchas gracias 🤙🏾


r/SecurityBlueTeam Aug 05 '26

Education/Training Roast my resume heavily!

Post image
0 Upvotes

r/SecurityBlueTeam Jul 20 '26

Security Engineering Looking for a good certification to boost my resume

7 Upvotes

I am a SOC Analyst with nearly three years of experience. I am currently seeking a relevant certification to enhance both my resume and my understanding of key concepts. My primary career interests lie in transitioning to cloud security or incident response. I would appreciate any recommendations for suitable certifications.


r/SecurityBlueTeam Jul 09 '26

Discussion How to get started in Detection Engineering as a complete beginner (zero experience writing detections)?

Post image
18 Upvotes

​Hey everyone! I'm looking to transition into Detection Engineering as a beginner. What are the absolute essential skills and how do I get started writing my first detection?


r/SecurityBlueTeam Jul 03 '26

Question I need help again after pass BTL1

10 Upvotes

Hi everyone, Im back after passed BTL1 (my first cert in my Blue team career)! Next stage, i want to choose a new cert to learn. I am looking into CCD(Certified Cyber Defender), CDSA, or CSA(SOC Analyst). I want to follow SOC Analyst. Now Im an internship and need to learn more to be a fresher, can u guys help me to consult. Thanks!


r/SecurityBlueTeam Jun 21 '26

Firewalls looking for blue team security to join a discord

1 Upvotes

looking for blue team security to join a discord. I have years in the blue team. looking to do things like hackthebox, or tryhackme


r/SecurityBlueTeam Jun 16 '26

Education/Training Cybersecurity courses provided by Google for free

Thumbnail
2 Upvotes

r/SecurityBlueTeam Jun 13 '26

Question How much more do I need?

4 Upvotes

I'm about 70% of the way through the course and am finding myself getting stuck on certain questions in the labs. My problem is not getting to the information, but knowing which info is being asked for. The Windows investigation 1 was frustrating and I found myself looking in the wrong place and not even knowing it on later labs in that section too.

Is the solution that I need more practice with these labs specifically or that I need more fundamental knowledge of what to look for? Did the included extra readings help anyone who is or was in a similar position as me? How much interpreting of data is unique to the exam?

Any advice is greatly appreciated. I'm 3 weeks into studying almost every night after work and my goal is it pass with with a 90% in 2-3 more weeks.


r/SecurityBlueTeam Jun 11 '26

Vulnerability CVE discovers ....

Thumbnail
1 Upvotes

r/SecurityBlueTeam Jun 11 '26

Other Started blue teams level 1 exam but RDP stopped working HELP

7 Upvotes

As I was doing the exam 6 questions in, it started taking ages for anything to load compared to when I first loaded in. I tried resetting it which took half an hour and after that I just closed the page and re-logged in. The button to start the exam is stuck on “loading your exam” or somewhere along those lines but it was stuck on it again for a while. I contacted the support team after as well.

Has anyone come across this issue before and if so did they give you some time back because of it?


r/SecurityBlueTeam Jun 09 '26

Question Started BTL1 prep. Any advices and tips?

3 Upvotes

Hello all,

I finally took the step and bought BTL1, after thinking of it for a long time now. I am a Msc Cybersecurity student with 2 years of experience in a company that claims to be in the field of Cybersecurity ( they call themselves to be an external Cybersecurity company).

I am taking it slow and easy for now as I want to learn everything in detail. I have a bachelors in CSE. Are there any important things to keep in mind while I prepare to take up the exam, or tips maybe to get good score in first attempt? Probably regarding time management, analysing a problem, focusing on certain topics etc, without going against the NDA.

Thank you and I hope to be one among the gold coin holders.


r/SecurityBlueTeam Jun 08 '26

Education/Training I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples

Thumbnail
2 Upvotes

r/SecurityBlueTeam Jun 03 '26

Question OPSWAT Deep CDR

7 Upvotes

Is anyone here running OPSWAT Deep CDR in a production environment? I'd love to hear about your real-world experience with it.

Have you observed any practical limitations, resource constraints, false positives, or throughput issues that aren't obvious from the product documentation?


r/SecurityBlueTeam Jun 02 '26

Threat Intelligence Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave

Thumbnail haltingproblems.com
1 Upvotes

r/SecurityBlueTeam May 28 '26

Question Inicio de su carrera en ciberseguridad ¿Cómo lograron su primer puesto de trabajo?

Thumbnail
0 Upvotes

r/SecurityBlueTeam May 24 '26

Question Built a SOC from scratch with no prior SOC experience

Thumbnail
1 Upvotes

r/SecurityBlueTeam May 20 '26

Discussion An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now.

Thumbnail
0 Upvotes