Blue Team
The Blue Team defends an organisation's IT, detects attacks and responds to security incidents.
The Blue Team is the team that defends an organisation against attacks. This includes monitoring, detection, incident response and system hardening.
How it works
The Blue Team operates defensive tools such as SIEM, EDR and identity protection systems. It assesses Alerts, investigates incidents and contains attacks. Additionally, it maintains detection rules and performs threat hunting. It also improves system configurations. In many organisations, the SOC is the core of the Blue Team. It is supplemented by specialists from IT operations, networks and identity.
For example, an EDR reports suspicious credential access during a Red Team exercise. The Blue Team investigates the laptop and blocks the affected account. It finds the original phishing email. The team then removes this email from all mailboxes. It also adds a rule for similar lures.
What to look out for
- The Blue Team needs access to all relevant data. Missing log sources create blind spots.
- Clear permissions for containment save valuable time during an incident.
- Regular exercises with a Red or Purple Team highlight existing gaps.
- Document findings and implement them in rules and playbooks.
Roles in the Blue Team
Typical roles are SOC Analyst, Detection Engineer, Incident Responder and Threat Hunter. In smaller organisations, a few people take on multiple roles. Many companies outsource a portion of this work to a service provider. This can include around-the-clock operations.
Typical mistakes
Often, the Blue Team is so busy with Alerts that no time remains for improvements. The quality of detection then decreases over time. A second mistake is a lack of communication with IT operations. The Blue Team learns of changes only when they trigger Alerts.
How we implement it
As a SOC, we perform core tasks of the Blue Team around the clock from Switzerland. We coordinate responsibilities and handovers with your internal team.