Skip to library

Blue Team Learn

Start with the thing you need to understand.

Browse services, ports, attacks and high-value artefacts. Each article explains what it is, how it works and what defenders should look for.

01

83 articles

Services

Understand the services that carry enterprise, cloud and industrial activity.

  • Active Directory Certificate Services
  • Active Directory Federation Services
  • Active Directory Web Services
Browse Services
02

118 articles

Ports

Look up common transport ports, the services associated with them and the limits of port-based identification.

  • Port 102: Siemens S7comm
  • Port 10250: kubelet
  • Port 10256: Kubernetes kube-proxy
Browse Ports
03

125 articles

Attacks

Learn how named attacks work, what they target and which evidence can expose them.

  • AD CS certificate abuse
  • AdminSDHolder and SDProp persistence
  • Adversary-in-the-middle phishing and cookie theft
Browse Attacks
04

51 articles

Artefacts

Recognise the files, stores, keys and tokens attackers seek after gaining access.

  • /etc/shadow
  • AD CS CA private keys and certificates
  • Application access and refresh tokens
Browse Artefacts

Curated collections

Explore a connected area

Collections bring related Services, Ports, Attacks and Artefacts together without prescribing a route or tracking progress.

90 resourcesActive Directory and Windows Identity

Understand the services, credential stores and attack paths that shape Windows enterprise identity.

183 resourcesEndpoint and DFIR

Connect endpoint behaviour, valuable local artefacts and investigation evidence across Windows, Linux and macOS.

207 resourcesNetwork and Remote Access

Move from ports and protocols to the identities, devices and attacks visible across network boundaries.

37 resourcesWeb and API Security

Follow web requests, identity tokens and application flaws from normal service behaviour to defensive evidence.

136 resourcesCloud Identity and Workloads

Understand cloud control planes, workload identities, metadata services and the credentials attackers seek.

55 resourcesContainers and Kubernetes

Connect cluster services, runtime trust, orchestration attacks and high-value container credentials.

92 resourcesLinux and macOS

Study Unix-like remote access, persistence, credential stores and investigation evidence.

25 resourcesOT and ICS

Understand industrial protocols, engineering trust and attacks that can affect a physical process.