Configurable role profile
Detect, decide and respond under realistic pressure.
Blue Team pathways build defensive operations capability: monitoring correlated endpoint, network, identity and application telemetry; engineering and tuning detections; triaging alerts; investigating incidents; and making containment and recovery decisions that can be reviewed afterwards. Exercises run against synthetic environments with realistic noise, so analysts practise judgement under uncertainty rather than pattern-matching a clean dataset. Evidence captures the decision and its rationale, not only the outcome.
CLIP · Blue Team role profile
Illustrative view- 01 · Mission outcomeProtect systems through monitoring, detection, investigation, containment and recovery.
- 02 · CompetenciesTelemetry · Detection engineering · Triage · Threat hunting
- 03 · Exercise activityRansomware response
- 04 · EvidenceDetection timeline with source telemetry
Team-colour terminology varies by organization
Mission intent
The role's purpose and its boundaries.
Protect systems through monitoring, detection, investigation, containment and recovery.
Core competencies
What this pathway develops.
Competencies are versioned and mapped to organizational, NICE, relevant SKKNI or custom frameworks without duplicating the underlying evidence.
- 01Telemetry
- 02Detection engineering
- 03Triage
- 04Threat hunting
- 05Response
- 06Recovery
Learning pathway
Progressive difficulty, evidence at every step.
- 01FoundationStructured learning and prerequisites.
- 02Guided labSupervised practice with checkpoints.
- 03Team labCoordination and handoffs within the role.
- 04Integrated exerciseMulti-team scenario under exercise control.
- 05AssessmentObserved performance and assessor adjudication.
In sequence: Foundation knowledge leads into a guided laboratory, then a team laboratory, then an integrated multi-team exercise, and finally an assessment that produces competency evidence.
Representative scenarios
How the pathway is exercised.
Ransomware response
Detection, containment and recovery sequencing under time pressure with leadership injects.
Identity compromise
Investigating credential misuse across identity and endpoint telemetry to establish scope.
Data-exfiltration investigation
Reconstructing an exfiltration path and preserving evidence for later review.
Tools and environments
Capability categories, not a tool list.
Specific tooling is selected per deployment after security, licence and air-gap review. The categories below describe what the pathway needs to work.
- Security analytics and log search workspaces
- Endpoint, network, identity and application telemetry sources
- Case management and collaborative investigation surfaces
Evidence of competence
What observable behaviour supports readiness.
A readiness claim for this role must trace back to these artifacts. Evidence freshness is tracked separately from current competence, so an expired record never silently counts as a current one.
How readiness is calculated- Detection timeline with source telemetry
- Investigation hypotheses and what disproved them
- Case record with actions and owners
- Containment decision and rationale
- Recovery verification evidence
Collaboration
Upstream and downstream handoffs.
No role operates alone. These are the relationships that make this pathway useful to the wider mission.
Receives emulated technique context from Purple Team validation
Escalates decisions requiring risk acceptance to Gold Team
Hands engineering defects to Yellow and Orange Team pathways
Metrics
Operational and learning measures.
What the platform can measure for this role. Targets are baselined with each organization rather than claimed in advance.
- Time to detect, acknowledge, investigate, contain and recover
- Detection coverage with false-positive context
- Evidence completeness
- Escalation and handoff quality
Map your roles to CLIP.
We will work from your approved role definitions and competency framework, not from ours.