Build Your Skills — Intermediate — hands-on

📖 WorkbookAdvanced🔒 Free account

Detection Engineering

Writing detection rules, YARA, Sigma, and tuning for low false positive rates.

Read →⏱ ~5 hours
📖 WorkbookIntermediate🔒 Free account

Digital Forensics & Incident Response

Evidence acquisition, chain of custody, disk and memory forensics fundamentals.

Read →⏱ ~4 hours
🧪 LabIntermediate✓ Free

IDS/IPS Detection Engineering

Snort/Suricata rule writing, tuning, and evasion-aware detection.

Start lab →⏱ 1.5 hours
📖 WorkbookIntermediate🔒 Free account

Incident Handling

Incident lifecycle, communication, containment, eradication, and post-mortems.

Read →⏱ ~4 hours
🧪 LabIntermediate✓ Free

Linux Forensics

Disk acquisition, filesystem timeline, log analysis, and bash history forensics.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

Malicious Document Analysis

Analyse malicious Office documents, PDFs, and macros with olevba and remnux.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

Memory Forensics with Volatility

Analyse infected memory dumps: find malware, C2 IPs, injected code, and creds.

Start lab →⏱ 2 hours
🧪 LabAdvanced✓ Free

Process Injection & Detection

Detect DLL injection, process hollowing, and reflective injection in EDR logs.

Start lab →⏱ 3 hours
🧪 LabIntermediate✓ Free

Threat Hunting with Elastic

Hypothesis-driven hunting in Elastic/Kibana using KQL and EQL.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

User Behavior Forensics

UEBA concepts, detecting insider threats, and anomalous account activity.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

Windows Attacks & Defense

Attack and detect common Windows attack patterns in a paired lab environment.

Start lab →⏱ 1.5 hours
🧪 LabBeginner✓ Free

YARA & Sigma for Defenders

Write YARA malware signatures and Sigma detection rules for SIEM platforms.

Start lab →⏱ 45 minutes