BTL1 Study Plan
Phishing, forensics, threat intel, SIEM and incident response in one practical defender cert. A free, day-by-day BTL1 schedule built from the official Blue Team Level 1 (formerly Security Blue Team) syllabus, scaled to your exam date and weekly hours.
- Approx. cost
- Check vendor
- Difficulty
- ♥♥♥♥♥
- Study time
- about 114h
- Start level
- Beginner
> How long does BTL1 take?
The plan assumes about 114 study hours. Here is how that stretches across different weekly schedules.
| Hours per week | Time to finish |
|---|---|
| 5 hours | about 23 weeks (5.3 months) |
| 10 hours | about 12 weeks (2.8 months) |
| 15 hours | about 8 weeks (1.8 months) |
| 20 hours | about 6 weeks (1.4 months) |
| 30 hours | about 4 weeks (0.9 months) |
> BTL1 exam format
Centri · Blue Team Level 1 (formerly Security Blue Team)
- One practical 24-hour incident response exam, graded with immediate feedback
- Task-based questions answered from your own investigation. Candidates report 20 tasks and a 70% pass mark
- One free resit voucher included with the course
- Course includes about 4 months of on-demand access and browser-based labs
- No formal prerequisites; 0 to 2 years of experience suggested. Certified for life
> BTL1 syllabus and study hours
Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.
Security Fundamentals
Soft skills, controls, networking and Active Directory basics.
- Soft Skills & Management Principles2h · learn
- Security Controls1h · learn
- Networking 1012h · learn
- Active Directory Fundamentals2h · learn
Phishing Analysis
Take a suspicious email apart and respond.
- Introduction to Emails & Phishing1h · learn
- Types of Phishing & Attacker Tactics1h · learn
- Analysing URLs, Attachments & Artifacts3h · learn
- Phishing Defensive Measures1h · learn
- Phishing Report Writing & Lessons Learned1h · learn
- Phishing Response Challenge2h · lab
Threat Intelligence
Know who is attacking and what they leave behind.
- Threat Actors & APTs1h · learn
- Operational Threat Intelligence: TTPs & Incident Validation2h · learn
- Tactical Threat Intelligence: IOCs & Automated Blocking2h · learn
- Strategic Threat Intelligence: Risk & Executive Reporting1h · learn
Digital Forensics
Collect evidence properly and read what hosts and memory tell you.
- Forensics Fundamentals & Chain of Custody1h · learn
- Digital Evidence Collection Techniques2h · learn
- Windows Investigations (Registry, Event Logs, Prefetch)3h · learn
- Linux Investigations (Logs, Users, Shell History)2h · learn
- Memory Analysis with Volatility3h · learn
- Disk Analysis with Autopsy3h · learn
SIEM
Logs, correlation and investigating in Splunk.
- Logging & Log Aggregation Principles1h · learn
- Correlation & Alerting Concepts1h · learn
- Investigating with Splunk4h · learn
Incident Response
Prepare, triage, contain and learn.
- Incident Response Preparation & Documentation1h · learn
- Detection & Analysis (Triage)3h · learn
- Containment, Eradication & Recovery2h · learn
- Post-Incident Activity & Lessons Learned1h · learn
Training Grounds
The exam is an investigation, so investigate a lot.
- Finish every course lab20h · lab
- Extra DFIR, SIEM and phishing practice25h · lab
Final Boss Prep
Turn what you know into a workflow you can run for 24 hours.
- Build tool cheat sheets (Volatility, Autopsy, Splunk, CyberChef)6h · review
- Write an investigation workflow checklist4h · review
- Timed 24-hour mock investigation10h · review
> Where to practise for BTL1
Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:
- Blue team challenges (CyberDefenders)
- Boss of the SOC datasets (BOTS) (Splunk)
- Packet capture exercises (Malware-Traffic-Analysis)
- SOC Level 1 path (TryHackMe)
> BTL1 exam-day checklist
General logistics for exam week. The official exam guide always takes priority if it differs.
One to two weeks before
- Schedule your exam and add the start time, time zone and deadline to your calendar
- Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
- Practise the full investigation flow: phishing, forensics, threat intel, SIEM and incident response
- Answer tasks from your own investigation notes as you go
- Complete a full-length timed practice run (24 hours if you can) on your exam setup
- Finalize your note-taking setup and templates (see the notes starter below)
- Build and review your cheat sheets and command references
- Arrange time off, tell people you will be unavailable, and plan your meals ahead
- Confirm whether the exam is proctored and what ID, camera or screen sharing you need
Machine and network
- Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
- Plug in your laptop and turn off sleep, updates and notifications for the exam
- Test access to the exam platform and check any browser or device requirements
- Install and test every tool you plan to use, and check none of them are banned
- Test your screenshot hotkeys and make sure you have plenty of free disk space
Proctoring and room (if required)
- Test your webcam, microphone and screen sharing on the proctoring platform
- Clear your desk and room as the rules require, and tell housemates not to interrupt
- Confirm what is allowed at your desk (second monitor, phone, notes, paper) and follow it exactly
- Learn the rules for breaks and for leaving the camera view
- Have your ID ready and know the check-in steps
During the exam
- Sleep well the night before, and skip last-minute cramming
- Prepare food and water, and set timers for break reminders
- Read the brief and scope carefully before you touch anything
- Write notes and capture proof as you go, not at the end
- Time-box each target and move on when stuck. You can come back later
- Stop new attacks with enough time left to verify your evidence
Finishing
- Review how your results are submitted or scored so nothing is missed before you close the lab
Suggested exam-day rhythm
- Hour 0 to 0:30. Connect, confirm the VPN, read the brief and set up your notes.
- Hour 0:30 to 2. Enumerate everything first. Rank targets by points and how promising they look.
- Through the day. Work in blocks of about 90 minutes with a 10-minute break after each. Time-box each target and rotate when stuck.
- Meals. Eat real meals away from your desk roughly every 5 to 6 hours.
- Around hour 12. Decide on a sleep window of 4 to 6 hours. A rested brain spots what a tired one misses.
- Last 3 hours. Stop new attacks unless you are very close. Verify proof, collect screenshots and outline the report.
- After the hands-on part. Confirm your submission or score is recorded.
▶ Open the interactive BTL1 exam kit
The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.
> Passed BTL1 with PWN PATH
No BTL1 debriefs yet
Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.
▶ Share my debriefDebriefs are self-reported. See all pass stories.
> Recent BTL1 changes
- Site OSIR, eCPPT, eMAPT, CRTE, BTL1: Added five new certs: OSIR, eCPPT, eMAPT, CRTE and BTL1, with a new Mobile app security track on the roadmap.
> Frequently asked questions
How long does it take to prepare for BTL1?
PWN PATH builds the BTL1 plan on about 114 study hours. At 10 hours a week that is roughly 12 weeks, and at 20 hours a week roughly 6 weeks. Your own timeline depends on how much of the material you already know.
What is the BTL1 exam like?
One practical 24-hour incident response exam, graded with immediate feedback. Task-based questions answered from your own investigation. Candidates report 20 tasks and a 70% pass mark. One free resit voucher included with the course. Course includes about 4 months of on-demand access and browser-based labs. No formal prerequisites; 0 to 2 years of experience suggested. Certified for life.
How hard is BTL1?
We rate BTL1 2 out of 5. It suits beginners who want a practical, well-known first defender cert covering phishing, forensics, SIEM and incident response. None. 0 to 2 years of security experience is suggested.
How much does BTL1 cost?
Sold as a course with a bundled exam and one resit. Check Centri for current pricing. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.
What should I study first for BTL1?
Start with the "Security Fundamentals" phase: Soft Skills & Management Principles, Security Controls, Networking 101. The planner puts topics in a sensible order and scales the hours to the time you have.
What are the prerequisites for BTL1?
None. 0 to 2 years of security experience is suggested.
What should I do the week before the BTL1 exam?
Re-read the official exam guide for rules and banned tools, test your machine, network and exam platform access, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.
How should I handle breaks and sleep during the BTL1 exam?
Hour 0 to 0:30: Connect, confirm the VPN, read the brief and set up your notes. Hour 0:30 to 2: Enumerate everything first. Rank targets by points and how promising they look. Through the day: Work in blocks of about 90 minutes with a 10-minute break after each. Time-box each target and rotate when stuck. Meals: Eat real meals away from your desk roughly every 5 to 6 hours.
What should I take after BTL1?
Common next steps are OSIR, CDSA, OSDA. See the roadmap to compare them.
Is the PWN PATH study planner free?
Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.
> Plan your path
Where it leads:
More in blue team & soc:
Not sure BTL1 is right for you? Take the one-minute cert quiz.