Your defensive security training on Hack The Box just got a major upgrade

Cyber defense is not a capability that organizations and individuals can build through theory alone.

August 28, 2026

Aspiring and current analysts need structured knowledge, repeated exposure to realistic investigations, and room to practice operational workflows before their decisions affect a live environment. Meanwhile, security leaders need a consistent way to develop people across different roles and experience levels, without adding more disconnected training tools.

Following the acquisition of LetsDefend, we have significantly expanded the Blue Team offering within Hack The Box Platforms with more defensive learning, more realistic investigation scenarios, broader role coverage, and a new way to practice SOC operations

What’s new?

This is one of the largest expansions of defensive content on the HTB Enterprise Platform to date:

  • 191+ Blue Team modules, that’s almost a 6x expansion in defensive learning
  • 120+ new Sherlocks, a +70% increase in the Sherlock catalog
  • 8 supported Blue Team job roles on HTB Enterprise, doubling previous role coverage
  • New and expanded content across Cloud Security, DFIR, Malware Analysis, Detection Engineering, ICS, Threat Hunting, Threat Intelligence, Incident Response, and SOC Analysis

Together, these additions give aspiring cyber professionals and organizations more ways to develop defensive capability at every stage of the journey, from people wanting to enter the field to experienced practitioners developing specialized expertise.

If you are looking to train your defensive security team with Hack The Box, contact us here:

Visual 1 - Blog - LetsDefend Migration Blue offering expansion

New defensive learning content for every topic

This expansion also includes 191 LetsDefend courses as fully integrated HTB Academy modules. Learners can develop capabilities across cybersecurity fundamentals, cloud security, threat intelligence, threat hunting, incident response, digital forensics, malware analysis, detection engineering, and SOC operations.

We’ve also integrated 3 New Skill Paths: CompTIA Security+ Preparation, Programming for Cybersecurity, and Google Cybersecurity Certificate Preparation. These provide an additional structured route for learners building foundational defensive knowledge.

For organizations, this means defensive development can become a planned workforce program rather than a collection of unrelated courses.

Join HTB Academy and start learning for free Start building a cyber workforce development plan for your team

For teams: Build skills around the roles your team needs

Most security teams patch together a defensive curriculum from whatever’s available: a vendor course here, a certification prep guide there, some tribal knowledge passed down from senior analysts. None of it is mapped to the actual job someone is being asked to do, and a Threat Hunter ends up training on the same generic content as a SOC Manager.

We doubled the role-aligned learning paths on HTB Enterprise to fix that. The expanded Blue Team catalog now supports eight job roles, including:

  • Threat Hunter
  • SOC Manager
  • Incident Responder
  • Information Security Specialist

These roles join existing pathways for defensive practitioners, giving leaders a clearer way to align learning with workforce requirements and helping learners understand how individual skills contribute to career progression.

Develop deeper investigative judgment with 127 new Sherlocks

Understanding the concepts behind an attack matters. Recognizing the evidence, following the trail, and reaching the right conclusion under pressure is where defensive capability is tested.

Sherlocks place learners inside investigation scenarios where they must analyze evidence, reconstruct events, and determine what happened. Bringing 127 LetsDefend challenges into the Sherlock catalog grows HTB Enterprise and HTB Labs coverage by +70%, with the sharpest gains in:

  • Cloud Security: 67% more Sherlocks
  • DFIR: 58% more Sherlocks
  • Malware Analysis: 193% more Sherlocks
  • ICS: 2 new Sherlocks
  • A new Detection Engineering category with 2 Sherlocks

Visual 2 - Blog - LetsDefend Migration Blue offering expansion

 

For junior practitioners, repeated investigation builds the confidence that turns theory into instinct. For experienced analysts, the expanded catalog is a way to sharpen specialized skills and stay sharp against attack patterns they haven't seen yet.

SOC Range: Turn defensive knowledge into operational muscle memory

Sherlocks build investigative judgment. But reading evidence and reconstructing an incident is different from running the full mechanics of a live SOC shift: claiming an alert, working it under a playbook, using the right tools, documenting every decision, and closing it out.

That is the role of SOC Range, now integrated directly into the HTB Enterprise Platform.

Built on LetsDefend’s SOC simulation capability, SOC Range is a self-paced, SIEM-mimicking environment where analysts practice the day-to-day workflow of a modern Security Operations Center.

Instead of following a passive alert walkthrough, analysts work through a realistic operational process. They claim alerts from a backlog, manage active investigations, review evidence, use integrated security tools, follow alert-specific playbooks, classify findings, document their decisions, and close investigations.

The environment includes:

Integrated investigative tools: Analysts can work with Log Management, Endpoint Security, Email Security, Threat Intelligence, and sandbox-style analysis capabilities without leaving the investigation workflow.

Guided playbooks: Structured workflows help analysts develop consistent investigation habits across scenarios such as phishing, malware, and suspicious login activity.

Realistic response actions: Learners can practice containment, mailbox remediation, evidence collection, and other actions without introducing risk into a production environment.

Investigation documentation: Analysts record notes, evidence, artifacts, and decisions throughout the process, reinforcing the discipline required for effective operational reporting.

Most junior analysts often encounter realistic alerts for the first time during a live shift. SOC Range gives them a safe place to make decisions, recognize mistakes, and repeat the process before those decisions affect a real incident.

 

Threat Range: From individual readiness to team response

The progression is deliberate:

HTB Academy builds the foundations.
Role-aligned modules develop the knowledge required for defensive work.

Sherlocks deepen investigative capability.
Scenario-based challenges teach analysts how to analyze evidence and reconstruct incidents.

SOC Range builds individual operational processes.
Analysts repeatedly practice triage, investigation, tool use, containment, remediation, and documentation.

However, if you are looking for team readiness, you need an extra layer of training:

Threat Range is the training that validates coordinated team response.
Multi-user exercises test how SOC, DFIR, incident response, and threat hunting teams work together against realistic attack chains. Currently available only for HTB Enterprise customers.

Put simply, SOC Range prepares the analyst. Threat Range tests the team.

This gives organizations a connected approach to defensive workforce development.

 

 

What this means for aspiring and current defensive security professionals

  • Hands-on experience: Gain practical skills through the upcoming SOC Range, practicing real-world tasks like claiming alerts and managing investigations in a safe environment.
  • Defined learning paths: Benefit from expanded role-aligned learning that maps to specific job requirements, helping you bridge the gap between theory and practice.
  • Expanded defensive training content: Access a vastly increased library of Blue Team modules and Sherlocks, allowing for deeper exploration of topics like Cloud Security, DFIR, and Threat Hunting.

 

If you are starting your learning journey now and want to pursue a defensive security career, create an HTB Account now and start learning and training for free on HTB Labs and Academy.

What this means for security leaders

The expansion creates several practical opportunities for CISOs, security directors, and SOC managers.

Accelerate analyst onboarding

New analysts can practice alert queues, investigation workflows, playbook execution, and documentation before they face production incidents. This can help teams create a more structured path and learn to respond at machine speed in an increasingly AI-supported landscape.

Give people a clearer path to progress

Expanded job-role coverage and hands-on practice help practitioners understand what they need to develop for their current role and what capabilities they need to move forward.

Reduce defensive training sprawl

Courses, investigation challenges, individual SOC simulations, and team exercises can now form part of one connected HTB experience, with unified access and streamlined seat management through HTB Enterprise

The expansion of the HTB Blue Team offering is about more than growing a content catalog. Discover how Hack The Box Enterprise can help your organization build, practice, and strengthen defensive capabilities within a single cyber workforce development journey.

 

Receive our weekly blog digest

Megaphone icon