Skip to main content
Free resources

Complete resources, not teasers

These are extracts from the actual curriculum — the same playbooks and references our students work through. If they are useful to someone who never enrols, that is a reasonable outcome.

Email required
PlaybookBeginner

Phishing Investigation Playbook

The exact sequence an analyst follows on a reported phish: header analysis, sender infrastructure, payload handling, blast-radius scoping and the closure note. Includes the decision points where analysts most often stop too early.

30 min readGet it
Email required
GuideBeginner

60 SOC Analyst Interview Questions

Real questions from technical screens and panels, grouped by theme, with notes on what the interviewer is actually testing for — which is rarely the fact itself.

45 min readGet it
Open access
Cheat sheetIntermediate

Detection Query Cheat Sheet

The query patterns that cover most day-to-day investigation work — filtering, joining, time-windowing and aggregation — with worked examples on realistic log tables.

20 minGet it
Open access
GuideBeginner

Your First 90 Days in a SOC

What a new analyst is actually judged on, how to ask questions without burning credibility, and how to survive shift work without burning out.

25 min readGet it
Email required
Cheat sheetIntermediate

Windows Event Log Investigation Reference

The event IDs that matter during an intrusion investigation, what each one proves and does not prove, and how to assemble them into a defensible timeline.

35 minGet it
Email required
ChecklistIntermediate

Cloud Identity Hardening Checklist

Fifty checks across Azure and AWS identity, ordered by the ratio of risk reduced to effort spent, with the business objection you should expect for each.

40 minGet it
Open access
TemplateBeginner

Incident Report Template

The structure we teach for incident documentation — timeline, evidence, impact, root cause, recommendations — with an annotated worked example.

15 minGet it
Email required
TemplateAdvanced

Detection Tuning Worksheet

A structured method for taking a noisy detection from unusable to trusted without quietly deleting the signal along with the noise.

30 minGet it
Email required
ChecklistAdvanced

Identity Attack Path Review Checklist

How to walk a directory looking for the route from a standard user to full administrative control — and how to work out which of the fixes you would actually get approved.

45 minGet it
Where these come from

Extracts from the curriculum, not marketing material

Everything here is used in a live program. That is why there are no ten-item listicles and no beginner content that stops right where it gets useful.

Next cohort enrolling

Talk to someone who has done the job

Book a consultation and leave with a written plan mapped to your background and the roles you are targeting — whether or not you enrol.

Prefer email? connectbluelayersacademy@gmail.com

What the call actually is

  • 45 minutes, with a mentor rather than a sales team
  • A written recommendation you keep either way
  • An honest answer if a program is not right for you yet

We do not guarantee placement, and we will say so on the call. What we are accountable for is whether you finish able to do the work.