Jutsu Ambassadors
Every black belt
started at white.
Free. Four weeks beside an AI SOC: build a lab, attack it, investigate, and question the agents. Walk out with a White Belt and public proof.
- 4 weeks
- Less than 2 hours per week
- Build in public
How it works
One hour a week for four weeks. Each week earns a stripe on your white belt, and you take one real incident from first alert to writeup — checking the AI agents’ work at every step.
- Week 01White belt · stripe 01Week 1 of 4
Foundations
Set up your lab machine and connect it to Jutsu, and learn the language of a SOC from zero — what an alert is, what severity means, and what an AI agent actually does.
- A lab machine — a local VM, or a cloud instance you spin up — connected to Jutsu and streaming events
- The SOC basics down: people, process, technology, and where the AI agents fit the workflow
- A screenshot of your connected machine, and a prediction for week 2
Your post promptWeek 1 of the Jutsu Ambassador program: I set up my first security lab and connected it to a live SOC. Post the screenshot, then answer three things. What did you build, what broke, and what did fixing it teach you?
- Week 02White belt · stripe 02Week 2 of 4
Threat intel & detection
Run password-spray and brute-force login attacks against your own lab, then read the alerts the AI agents enrich — IP reputation, geo, and history the raw logs never showed you.
- A password-spray and a brute-force run against a service you control, side by side
- Both alerts found in Jutsu, with the enrichment the AI agents added to each
- A note on how a raw event becomes an alert — and which of the two looked more serious
Your post promptWeek 2: I attacked my own lab. Show the commands you ran and the alerts they set off. What did the SOC's enrichment tell you that the raw logs did not?
- Week 03White belt · stripe 03Week 3 of 4
Triage
Take one alert through a real triage process — evidence, timeline, verdict — then hold your call up against the AI agent's own assessment of the same alert.
- One alert triaged end to end: true positive, false positive, or needs more work, with reasoning you can defend
- An investigation timeline: what happened, in what order, to which host
- A note comparing your verdict with the AI agent's assessment — where you agreed, and where you did not
Your post promptWeek 3: I ran my first alert triage. Walk through it start to finish. Where did your judgment and the AI agent's assessment line up, and where did they part ways?
- Week 04White belt · stripe 04Week 4 of 4
The broader landscape
Turn your verdict into an incident-response report, then zoom out — cloud security, compliance, and the hard question of how far to let an AI agent act on its own.
- An incident-response report: containment, eradication, recovery, and lessons learned
- Your take on the hard question — should an AI agent contain a threat automatically, or wait for a human?
- Your published writeup, plus your Jutsu White Belt certificate and badge
Your post promptWeek 4: here is my full writeup, and my White Belt. Lead with the honest version. What could you not do four weeks ago that you can do now?
That is the whole program. Four weeks, four stripes, four posts, one incident — and the White Belt they add up to.
Apply for FreeWhat you walk away with
By the end you have not just learned the words — SOC, triage, AI agent. You have four things that prove you practiced the work behind them.
- 01A real incident reportYour own triage notes, a verdict you can defend, and a full incident report — containment through lessons learned. The kind of evidence a SOC actually keeps, in a document you can hand a hiring manager.
- 02A public learning trailFour weekly posts that turn quiet lab work into a visible record, reshared from the Jutsu account so it reaches security people who do not know you yet.
- 03Your Jutsu White BeltA verifiable White Belt certificate and profile badge — a stripe for every week you finished, issued once you complete all four. An honest, introductory credential, and the first belt on a longer path.
- 04A way into the communityThe program is your entry point, not the end of it. Finish, and there is a path to keep going — Contributor, Advocate, and the belts beyond — with people building the future of agentic security together.
Who usually applies
Beginners who want to learn security by doing the work, not by collecting another certificate. No security job, no degree in it, and something to prove.
Career switchers
You are coming from support, sales, teaching, or something else entirely, and you need proof, not another course certificate.
Students and new grads
You have the theory and none of the receipts, and every job posting still asks for two years of experience.
IT and helpdesk pros
You already touch the systems, you just need the security side of the work on paper and in public.
Certified but never hands-on
You passed the exam, you have never triaged a real alert, and you know it shows in interviews.
What we ask in return
Five things, and none of them cost money. Two we never bend on: the weekly post that makes your work visible, and the rule that everything stays inside your own lab.
- 01Give it four weeks.Roughly 1 to 1.5 hours a week — a few short lessons, a video, one hands-on lab, and one thing to hand in. Everything is pre-recorded, so you take your hour whenever it suits you.
- 02Post on LinkedIn every week.This one is not optional. The weekly post is how four weeks of quiet lab work becomes a visible learning trail, and we hand you the prompt each week so you never face a blank box.
- 03Bring a machine that can run a VM.Anything that can run one virtual machine is enough — roughly 8GB of RAM and some free disk. It is the one hardware requirement, because the whole program is a hands-on lab that lives on that VM.
- 04Keep everything in your own lab.This is defensive training. You only ever run these tools against a lab you own — never a system you do not, and never with real company or customer data. That line does not bend.
- 05Question the AI, do not just trust it.The agents are fast, not infallible — they can miss evidence or overstate risk. Half the skill is checking their reasoning: treat what they conclude as a starting point, then decide for yourself.
We write the prompt. You write three sentences and press post. That is the whole requirement.
There is no bar to clear
No degree, no experience, no budget. If you are curious and you show up, you already qualify.
A degree
We do not ask where you studied, or whether you did.
A security job
Most do not have one yet. That is why they applied.
Prior SIEM or SOC experience
Week 1 assumes you have never opened one in your life.
A budget
The program is free, and the lab runs on the laptop you own.
Frequently Asked Questions
The things worth knowing before you fill anything in.
Come in at white belt
No stripes yet — that is the point. Everyone starts here. Put in your hour a week, earn them one at a time, and finish with a belt, a writeup, and a way into the community.
Nothing to wait for. Every week is pre-recorded, so you start the day we let you in.