Mind map of blue teaming, with a central node branching into twelve domains grouped into defense and response, monitoring and tools, and intelligence and governance, each listing its key subtopics.
- Attack simulation
- Detection engineering
- Threat hunting
- Continuous monitoring
- Security automation
- MITRE ATT&CK mapping
- Signature detection
- Threat intelligence
- SIEM analysis
- Behavior analysis
- Anomaly detection
- Incident identification
- Incident analysis
- Containment
- Eradication
- Recovery
- Post-incident review
- Asset discovery
- Vulnerability scanning
- Risk assessment
- Configuration hardening
- Patch management
- Security alerts
- Threat detection
- Endpoint monitoring
- Security operations center (SOC)
- Log monitoring
- Network monitoring
- Threat intelligence platforms
- Network IDS / IPS
- SIEM platforms
- EDR platforms
- SOAR platforms
- Centralized logging
- Log correlation
- Authentication logs
- System logs
- Application logs
- Network logs
- Intrusion detection system (IDS)
- Intrusion prevention system (IPS)
- Firewall monitoring
- Network traffic analysis
- DNS monitoring
- VPN monitoring
- Security policies
- Security auditing
- Security awareness training
- Risk management
- Regulatory compliance
- Identity threat detection
- Account monitoring
- Access control
- Multi-factor authentication
- Privileged access management
- Adversary tracking
- Malware analysis
- Indicators of compromise (IOC)
- Indicators of attack (IOA)
- Threat feeds
- Host intrusion detection
- Endpoint detection and response (EDR)
- Antivirus / anti-malware
- Patch management
- Device control
š¬ Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter ā









