
CompTIA
Cisco
ISACA & governance
Offense & defense
Current syllabus·Cybersecurity
Blue Team Level 1
Build practical defensive-security capability across phishing analysis, threat intelligence, digital forensics, SIEM investigations, and incident response.
Choose a preferred plan, then confirm availability with our team.

RSAY completion certificate
Recognize your training achievement
Online or in-person
Explore delivery options below
Foundation to intermediate
Review prerequisites before choosing
6 learning modules
Topics, practice, and learning checks
BUILD SKILLS THAT MATTER
From understanding to application.
A focused learning experience that connects the concepts to decisions you make in real technical work.
Is this the right course for me? ↗What you will be able to do
- Investigate suspicious emails, URLs, attachments, and authentication evidence.
- Collect and enrich indicators using structured threat-intelligence workflows.
- Analyze endpoint, file-system, memory, and network evidence.
- Build SIEM searches, timelines, detections, and incident narratives.
- Triage, contain, document, and communicate security incidents.
Who this course is for
Aspiring blue-team analysts · Junior SOC analysts · IT professionals moving into cybersecurity · Learners seeking a practical defensive certification
INSIDE THE COURSE
Explore the syllabus.
Open a module to see its focus, a suggested practical activity, and how you will check your understanding. Exam percentages are not allocations of training hours.
Official certification reference ↗Activities are RSAY learning examples, not a promise of vendor-owned lab access. Final materials are confirmed in the cohort guide.
01Security Fundamentals
Topics in focus
Core defensive concepts, networking, common attack paths, security controls, analyst workflow, evidence, and reporting foundations.
Put it into practice
Map assets, common threats, and control gaps in a small organization's environment.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
02Phishing Analysis
Topics in focus
Email headers, sender authentication, URLs, attachments, document behavior, sandboxing, indicators, verdicts, and response recommendations.
Put it into practice
Inspect a sanitized email's headers and links, then record a phishing verdict and rationale.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
03Threat Intelligence
Topics in focus
Intelligence lifecycle, indicator enrichment, source evaluation, adversary behavior, TTP mapping, pivoting, and actionable intelligence products.
Put it into practice
Assess a sample indicator's confidence and relevance before sharing it with analysts.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
04Digital Forensics
Topics in focus
Disk and file systems, Windows artifacts, browser and user activity, memory concepts, evidence handling, timelines, and forensic interpretation.
Put it into practice
Create an evidence inventory and timeline from supplied forensic artifacts.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
05SIEM
Topics in focus
Log sources, normalization, searches, filtering, correlation, dashboards, alert triage, detection logic, investigation timelines, and case notes.
Put it into practice
Review sample event records and describe a query that would surface suspicious authentication.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
06Incident Response
Topics in focus
Preparation, classification, scoping, containment, eradication, recovery, evidence, communication, playbooks, and lessons learned.
Put it into practice
Prepare an incident handover with scope, actions taken, remaining risks, and recovery checks.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
RECOGNIZE YOUR PROGRESS
Your learning. Your achievement.
Receive an RSAY ITC completion certificate when you meet the attendance, activities, and assessment requirements published in your cohort guide.
Completion is not vendor certification
The RSAY certificate records training completion. Vendor certification requires its own exam and applicable eligibility criteria. An exam voucher is not included unless explicitly confirmed in your package.
CERTIFICATION EXAM
Know your next milestone.
- Certification / version
- Current syllabus
- Exam duration
- 24-hour practical exam
- Assessment
- Practical incident scenario
Exam policies can change. Verify current requirements with the certification provider before booking. Training does not guarantee a pass.
Review official requirements ↗MAKE ROOM FOR YOUR NEXT SKILL
Course schedule & pricing
An intensive week, evening sessions, or weekends. Explore a learning rhythm that fits your life.
Example schedules · not open cohorts
Compare three 40-hour plans. Dates, delivery, breaks, venue, and final price must be confirmed by RSAY. Choosing a plan does not book or charge you.
All times: Riyadh · UTC+3
Five-day intensive
Sunday–Thursday · 09:00–17:00
Online or in-person · venue to be confirmed5 × 8 hours = 40 hours
View every session
- 4 Oct 2026 09:00–17:00
- 5 Oct 2026 09:00–17:00
- 6 Oct 2026 09:00–17:00
- 7 Oct 2026 09:00–17:00
- 8 Oct 2026 09:00–17:00
Weekday evenings
Sunday–Wednesday · 18:00–20:00
Online or in-person · venue to be confirmed20 × 2 hours = 40 hours
View every session
- 4 Oct 2026 18:00–20:00
- 5 Oct 2026 18:00–20:00
- 6 Oct 2026 18:00–20:00
- 7 Oct 2026 18:00–20:00
- 11 Oct 2026 18:00–20:00
- 12 Oct 2026 18:00–20:00
- 13 Oct 2026 18:00–20:00
- 14 Oct 2026 18:00–20:00
- 18 Oct 2026 18:00–20:00
- 19 Oct 2026 18:00–20:00
- 20 Oct 2026 18:00–20:00
- 21 Oct 2026 18:00–20:00
- 25 Oct 2026 18:00–20:00
- 26 Oct 2026 18:00–20:00
- 27 Oct 2026 18:00–20:00
- 28 Oct 2026 18:00–20:00
- 1 Nov 2026 18:00–20:00
- 2 Nov 2026 18:00–20:00
- 3 Nov 2026 18:00–20:00
- 4 Nov 2026 18:00–20:00
Five weekends
Friday–Saturday · 09:00–13:00
Online or in-person · venue to be confirmed10 × 4 hours = 40 hours
View every session
- 9 Oct 2026 09:00–13:00
- 10 Oct 2026 09:00–13:00
- 16 Oct 2026 09:00–13:00
- 17 Oct 2026 09:00–13:00
- 23 Oct 2026 09:00–13:00
- 24 Oct 2026 09:00–13:00
- 30 Oct 2026 09:00–13:00
- 31 Oct 2026 09:00–13:00
- 6 Nov 2026 09:00–13:00
- 7 Nov 2026 09:00–13:00
Prerequisites
Review the foundation to intermediate level and intended audience. Relevant networking and operating-system knowledge helps with technical security courses; our team can assess your starting point.
Technical requirements
A computer, current browser, reliable internet, and clear audio. Software, virtual-machine requirements, and lab access are specified before registration is confirmed.
Learning schedule
The cohort guide confirms dates, breaks, live hours, self-study, activities, and assessments. Example plans on this page are illustrative until confirmed.
Measuring progress
Knowledge checks, practical activities, feedback, and a final review connect to learning outcomes. Completion criteria and assessment weights are published in the cohort guide.
Support & accessibility
Tell us about learning support or accessibility needs before enrollment. Our team can clarify attendance, complaints, privacy, and refund policies.