This article explains how to approach the BTL-1 certification exam in an effective and intelligent way.
Published on March 30, 2024 by Daniele Berardinelli
training certification sbt
2 min READ
I’ve recently passed the BTL-1 exam with 100% of the score. This article is intended for those who are currently studying or considering taking the exam.
The best way to pass this exam is through practice. BTLO is a platform developed by Security Blue Team, who are also the creators of this certification.
I highly recommend purchasing the PRO version to conduct more investigations using the same tools in the exam. This platform is also very useful once certification has been achieved.
In this domain, you will learn how to identify a malicious email and how to extract artefacts.
This domain is focused more on theoretical concepts and lacks practical application. The vital focus here lies in studying the MITRE ATT&CK framework and the prevalent attack techniques.
This domain teaches gathering digital evidence and conducting investigations on Windows and Linux.
Splunk is every student’s worst nightmare. This is where many students fail, mainly because they do not get enough practice.
This domain teaches you how to respond to an incident. It is the most important because this is what you will do in the exam.
I also suggest to watch this YouTube video by Malik Girondin:
If you have any questions about the exam, please consult this page.