
2020 came with plenty of surprises for everyone—COVID, social distancing, remote work—and PlainText decided to take a break from its RedTeam learning journey to pick up some BlueTeam skills.
And so it was. While scrolling through Twitter I came across a tweet from my friend Víctor García, affectionately known as Takito, talking about the #100DaysOfCode challenge. I found it super interesting—I'm someone who loves a good challenge—and I thought it would be the perfect methodology to learn BlueTeam topics. That's when I decided to apply the #100DaysOfCode rules to my own challenge: #100DaysOfBlueTeam.
The challenge basically consisted of dedicating at least 1 hour every day to learning something related to BlueTeam. You can check the rules for the original challenge here. My initial goal was to learn about threat detection, mainly in Windows environments, dive into YARA/Sigma rules, and see what else came up along the way.
On October 10, 2020, I kicked off the challenge by posting my first tweet, and I started a learning journey I don't regret one bit.
On my GitHub I shared different use cases from the things I learned during this journey, so others can use them as a reference. Honestly, by the end I realized I spent far more time understanding how to collect information, which tools I could use for different needs, and automating all those processes, than actually analyzing the information itself.
As part of these tasks I learned how to automate my labs, explored different tools for log collection, and discovered many open-source tools that are fantastic and genuinely useful for learning how to identify threats.
I know this knowledge will help me improve my overall perspective on Cybersecurity topics—knowledge I hope to apply and share going forward.
If you want to follow part of my journey, check out my GitHub #100DaysOfBlueTeam.
God bless you! Serving Christ is not a task, but a relationship. Friends of God. Jn 15:15
