Field-focused curricula for SOC analysts, threat hunters, and detection engineers, sourced from CrowdStrike, Red Canary, Mandiant, SANS, and MITRE. No account. No subscription. Browser-native.
LEARNING DOMAINS
/
No domains match “”.
FD
FUNDAMENTALS
Where Every Analyst Starts.
LIVE
The CIA triad, authentication and access control, cryptography basics, common attacks and the kill chain, security frameworks, risk management, and SOC operations, the vocabulary every other domain builds on.
TCP/IP fundamentals, routing and switching, DNS and TLS internals, hands-on packet analysis, abused protocols, and network detection, the networking foundation every detection is built on.
Active Directory, process and token internals, the registry, Windows event logging, common attack techniques, and AD attack detection, the OS-level knowledge behind most enterprise attacks.
Filesystem and permissions foundations, auth and syslog analysis, cron/systemd persistence, live process and network internals, shell tradecraft, and container/Docker security.
SOC tiers and shift models, alert triage and prioritization, SIEM and SOAR in practice, incident handling workflow, case management, and the metrics that measure whether a SOC is actually working.
Reading and comparing KQL/SPL/Sigma, turning a hypothesis into tested detection logic, false positive tuning, ATT&CK coverage mapping, and detection-as-code through the full rule lifecycle.
The shared responsibility model through applied detection engineering: Azure AD/Entra ID and AWS IAM attacks, cloud telemetry, and Zero Trust/CIEM/CSPM defense.
Chain of custody and order of volatility, disk and memory forensics, Windows artifacts and timeline analysis, network and mobile forensics, and anti-forensics detection and report writing.
Static and dynamic analysis, unpacking, malware tradecraft, and YARA/Sigma rule writing, from first-pass triage through detection engineering and evasion tradecraft.
AI-powered threats, prompt injection and LLM application security, AI-assisted SOC triage and threat hunting, securing AI/ML systems, and the NIST AI RMF/EU AI Act governance layer.
761 enterprise-grade questions with model answers across SOC Ops, IR, Threat Hunting, CTI, Digital Forensics, Malware Analysis, and Cloud Security, grounded in real attack scenarios.