Jutsu Ambassadors

Every black belt
started at white.

Free. Four weeks beside an AI SOC: build a lab, attack it, investigate, and question the agents. Walk out with a White Belt and public proof.

  • 4 weeks
  • Less than 2 hours per week
  • Build in public

How it works

One hour a week for four weeks. Each week earns a stripe on your white belt, and you take one real incident from first alert to writeup — checking the AI agents’ work at every step.

  1. Week 01White belt · stripe 01
    Week 1 of 4

    Foundations

    Set up your lab machine and connect it to Jutsu, and learn the language of a SOC from zero — what an alert is, what severity means, and what an AI agent actually does.

    • A lab machine — a local VM, or a cloud instance you spin up — connected to Jutsu and streaming events
    • The SOC basics down: people, process, technology, and where the AI agents fit the workflow
    • A screenshot of your connected machine, and a prediction for week 2
    Your post prompt

    Week 1 of the Jutsu Ambassador program: I set up my first security lab and connected it to a live SOC. Post the screenshot, then answer three things. What did you build, what broke, and what did fixing it teach you?

  2. Week 02White belt · stripe 02
    Week 2 of 4

    Threat intel & detection

    Run password-spray and brute-force login attacks against your own lab, then read the alerts the AI agents enrich — IP reputation, geo, and history the raw logs never showed you.

    • A password-spray and a brute-force run against a service you control, side by side
    • Both alerts found in Jutsu, with the enrichment the AI agents added to each
    • A note on how a raw event becomes an alert — and which of the two looked more serious
    Your post prompt

    Week 2: I attacked my own lab. Show the commands you ran and the alerts they set off. What did the SOC's enrichment tell you that the raw logs did not?

  3. Week 03White belt · stripe 03
    Week 3 of 4

    Triage

    Take one alert through a real triage process — evidence, timeline, verdict — then hold your call up against the AI agent's own assessment of the same alert.

    • One alert triaged end to end: true positive, false positive, or needs more work, with reasoning you can defend
    • An investigation timeline: what happened, in what order, to which host
    • A note comparing your verdict with the AI agent's assessment — where you agreed, and where you did not
    Your post prompt

    Week 3: I ran my first alert triage. Walk through it start to finish. Where did your judgment and the AI agent's assessment line up, and where did they part ways?

  4. Week 04White belt · stripe 04
    Week 4 of 4

    The broader landscape

    Turn your verdict into an incident-response report, then zoom out — cloud security, compliance, and the hard question of how far to let an AI agent act on its own.

    • An incident-response report: containment, eradication, recovery, and lessons learned
    • Your take on the hard question — should an AI agent contain a threat automatically, or wait for a human?
    • Your published writeup, plus your Jutsu White Belt certificate and badge
    Your post prompt

    Week 4: here is my full writeup, and my White Belt. Lead with the honest version. What could you not do four weeks ago that you can do now?

That is the whole program. Four weeks, four stripes, four posts, one incident — and the White Belt they add up to.

Apply for Free

What you walk away with

By the end you have not just learned the words — SOC, triage, AI agent. You have four things that prove you practiced the work behind them.

  1. 01A real incident reportYour own triage notes, a verdict you can defend, and a full incident report — containment through lessons learned. The kind of evidence a SOC actually keeps, in a document you can hand a hiring manager.
  2. 02A public learning trailFour weekly posts that turn quiet lab work into a visible record, reshared from the Jutsu account so it reaches security people who do not know you yet.
  3. 03Your Jutsu White BeltA verifiable White Belt certificate and profile badge — a stripe for every week you finished, issued once you complete all four. An honest, introductory credential, and the first belt on a longer path.
  4. 04A way into the communityThe program is your entry point, not the end of it. Finish, and there is a path to keep going — Contributor, Advocate, and the belts beyond — with people building the future of agentic security together.

Who usually applies

Beginners who want to learn security by doing the work, not by collecting another certificate. No security job, no degree in it, and something to prove.

  • Career switchers

    You are coming from support, sales, teaching, or something else entirely, and you need proof, not another course certificate.

  • Students and new grads

    You have the theory and none of the receipts, and every job posting still asks for two years of experience.

  • IT and helpdesk pros

    You already touch the systems, you just need the security side of the work on paper and in public.

  • Certified but never hands-on

    You passed the exam, you have never triaged a real alert, and you know it shows in interviews.

What we ask in return

Five things, and none of them cost money. Two we never bend on: the weekly post that makes your work visible, and the rule that everything stays inside your own lab.

  1. 01Give it four weeks.Roughly 1 to 1.5 hours a week — a few short lessons, a video, one hands-on lab, and one thing to hand in. Everything is pre-recorded, so you take your hour whenever it suits you.
  2. 02Post on LinkedIn every week.This one is not optional. The weekly post is how four weeks of quiet lab work becomes a visible learning trail, and we hand you the prompt each week so you never face a blank box.
  3. 03Bring a machine that can run a VM.Anything that can run one virtual machine is enough — roughly 8GB of RAM and some free disk. It is the one hardware requirement, because the whole program is a hands-on lab that lives on that VM.
  4. 04Keep everything in your own lab.This is defensive training. You only ever run these tools against a lab you own — never a system you do not, and never with real company or customer data. That line does not bend.
  5. 05Question the AI, do not just trust it.The agents are fast, not infallible — they can miss evidence or overstate risk. Half the skill is checking their reasoning: treat what they conclude as a starting point, then decide for yourself.
Week 01 promptsent to you every Monday
You

About two minutes of writing.Post

We write the prompt. You write three sentences and press post. That is the whole requirement.

There is no bar to clear

No degree, no experience, no budget. If you are curious and you show up, you already qualify.

  • A degree

    We do not ask where you studied, or whether you did.

  • A security job

    Most do not have one yet. That is why they applied.

  • Prior SIEM or SOC experience

    Week 1 assumes you have never opened one in your life.

  • A budget

    The program is free, and the lab runs on the laptop you own.

Frequently Asked Questions

The things worth knowing before you fill anything in.

$whoamisecurity analyst

Come in at white belt

No stripes yet — that is the point. Everyone starts here. Put in your hour a week, earn them one at a time, and finish with a belt, a writeup, and a way into the community.

Nothing to wait for. Every week is pre-recorded, so you start the day we let you in.