Beginner Blue Team Training!

Beginner Blue Team Training!

🎙 John Hammond 👥 2.2M 📅 December 5, 2025 ⏱ 59 min 👁 8K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

SigmaChainsawWindows Event LogsSysmonThreat Hunting

Summary

In this live stream, John Hammond provides a beginner-oriented introduction to blue team operations, focusing on Windows log analysis and threat hunting using Sigma rules and the Chainsaw tool. He begins with announcements about Just Hacking Training (JHT), including a Cyber December discount code and upcoming courses. He emphasizes the importance of defensive security and presents the Blue Team Training Roadmap. The main demonstration involves using Chainsaw to analyze Windows event logs (EVTX files) and Sysmon telemetry to detect malicious script execution. He explains the role of Sigma rules in detecting patterns in logs and contrasts Sigma with YARA. The session includes quizzes to reinforce concepts and a practical walkthrough of setting up Chainsaw and analyzing logs. The content is practical and accessible, aimed at beginners, and highlights the value of log analysis in incident response.

136 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, hands-on instruction for beginners in blue teaming, demonstrating real-world tools and techniques. The argumentation is clear and logical, building from basic concepts to practical application. The use of quizzes and a live demo reinforces learning. The presenter’s expertise is evident, and the content is directly applicable to entry-level security operations roles.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by using established tools (Chainsaw, Sigma) and frameworks (MITRE ATT&CK) without misrepresenting them. However, it lacks formal citations or references to external sources beyond the JHT website. The title accurately reflects the content, and the presentation is well-structured. No comments were provided for analysis.

119 words

Title / Content Match

The title accurately reflects the content: a beginner-focused blue team training session covering Windows log analysis and Sigma rules.

Quality & Reliability

8/10

The video is a practical tutorial by an experienced cybersecurity educator, demonstrating hands-on use of Chainsaw and Sigma rules for Windows log analysis. The content is accurate and well-structured, though it includes promotional segments and lacks formal citations.

Key Moments

Cited Sources

  • Just Hacking Training — The presenter's training platform, mentioned as the source for courses and resources.

Concurring Sources

  • Sigma Rules — The detection language used in the video for writing rules.
  • Chainsaw — The tool demonstrated for searching Windows event logs.
  • Sysmon — Microsoft's tool for enhanced logging, mentioned in the video.

Contribution & Novelties

The video provides a beginner-friendly, practical introduction to blue teaming, specifically focusing on Windows log analysis with Chainsaw and Sigma rules. It bridges the gap between theory and practice by offering a live demonstration and quizzes. The content is original in its approach, emphasizing the use of free tools and accessible methods for log analysis.

Pour aller plus loin :

  • Sigma Rules — Official repository for Sigma rules, the detection language used in the video.
  • Chainsaw — The tool demonstrated for searching Windows event logs.
  • Sysmon — Microsoft’s Sysinternals tool for enhanced logging, mentioned in the video.

97 words

Radar Profile

The radar chart shows a balanced profile with high scores in information quantity, quality, and reliability, and a slightly lower score in technical level, indicating the content is accessible to beginners while still providing solid technical depth.

Reliability 8/10