Defensive
Build the skills defenders actually need. SOC operations, SIEM analysis, threat hunting, incident response, digital forensics, and malware analysis.
Start Here — Foundations — no experience assumed
Network Traffic Analysis
Wireshark, tcpdump, protocol analysis, and detecting anomalies in traffic.
SOC Alert Triage with a SIEM
Work a realistic alert queue: classify, investigate, and escalate findings.
SOC Operations & SIEM
SOC workflow, alert triage, SIEM platforms, and escalation procedures.
Threat Detection with Splunk
Write SPL queries, build dashboards, and create detection rules in Splunk.
Windows Event Log Analysis
Key event IDs for logon, process creation, lateral movement, and privilege use.
Build Your Skills — Intermediate — hands-on
Detection Engineering
Writing detection rules, YARA, Sigma, and tuning for low false positive rates.
Digital Forensics & Incident Response
Evidence acquisition, chain of custody, disk and memory forensics fundamentals.
IDS/IPS Detection Engineering
Snort/Suricata rule writing, tuning, and evasion-aware detection.
Incident Handling
Incident lifecycle, communication, containment, eradication, and post-mortems.
Linux Forensics
Disk acquisition, filesystem timeline, log analysis, and bash history forensics.
Malicious Document Analysis
Analyse malicious Office documents, PDFs, and macros with olevba and remnux.
Memory Forensics with Volatility
Analyse infected memory dumps: find malware, C2 IPs, injected code, and creds.
Process Injection & Detection
Detect DLL injection, process hollowing, and reflective injection in EDR logs.
Threat Hunting with Elastic
Hypothesis-driven hunting in Elastic/Kibana using KQL and EQL.
User Behavior Forensics
UEBA concepts, detecting insider threats, and anomalous account activity.
Windows Attacks & Defense
Attack and detect common Windows attack patterns in a paired lab environment.
YARA & Sigma for Defenders
Write YARA malware signatures and Sigma detection rules for SIEM platforms.