H3AD-LEARN
SECURITY TRAINING PLATFORM
by H3AD

Learn the Methodology
Behind the Detection.

Field-focused curricula for SOC analysts, threat hunters, and detection engineers, sourced from CrowdStrike, Red Canary, Mandiant, SANS, and MITRE. No account. No subscription. Browser-native.

LEARNING DOMAINS
/
FD
FUNDAMENTALS
Where Every Analyst Starts.
LIVE
The CIA triad, authentication and access control, cryptography basics, common attacks and the kill chain, security frameworks, risk management, and SOC operations, the vocabulary every other domain builds on.
10 CHAPTERS · ~13 HRS · BEGINNER → INTERMEDIATE
OPEN FUNDAMENTALS →
NW
NETWORKING
Packets, Protocols, and Where Attacks Live.
LIVE
TCP/IP fundamentals, routing and switching, DNS and TLS internals, hands-on packet analysis, abused protocols, and network detection, the networking foundation every detection is built on.
10 CHAPTERS · ~13 HRS · BEGINNER → ADVANCED
OPEN NETWORKING →
WN
WINDOWS
Internals for Attackers and Defenders.
LIVE
Active Directory, process and token internals, the registry, Windows event logging, common attack techniques, and AD attack detection, the OS-level knowledge behind most enterprise attacks.
11 CHAPTERS · ~16 HRS · BEGINNER → ADVANCED
OPEN WINDOWS →
LX
LINUX
Auth, Logs, and Persistence on Unix.
LIVE
Filesystem and permissions foundations, auth and syslog analysis, cron/systemd persistence, live process and network internals, shell tradecraft, and container/Docker security.
8 CHAPTERS · ~12 HRS · BEGINNER → ADVANCED
OPEN LINUX →
SO
SOC OPERATIONS
Triage. Escalate. Contain.
LIVE
SOC tiers and shift models, alert triage and prioritization, SIEM and SOAR in practice, incident handling workflow, case management, and the metrics that measure whether a SOC is actually working.
8 CHAPTERS · ~11 HRS · BEGINNER → ADVANCED
OPEN SOC OPERATIONS →
TI
THREAT INTELLIGENCE
From Raw IOCs to Finished Intel.
LIVE
The intelligence cycle, IOC confidence scoring, Diamond Model actor profiling, STIX/TAXII sharing, intel-driven hunting, and CTI report writing.
8 CHAPTERS · ~11 HRS · BEGINNER → ADVANCED
OPEN THREAT INTELLIGENCE →
DE
DETECTION ENGINEERING
From Hypothesis to Production Rule.
LIVE
Reading and comparing KQL/SPL/Sigma, turning a hypothesis into tested detection logic, false positive tuning, ATT&CK coverage mapping, and detection-as-code through the full rule lifecycle.
8 CHAPTERS · ~12 HRS · BEGINNER → ADVANCED
OPEN DETECTION ENGINEERING →
TH
THREAT HUNTING
Hunt Smarter. Miss Nothing.
LIVE
The complete hunt lifecycle: hypothesis generation, PEAK, TaHiTI, data sources, KQL/Sigma/SPL, and evidence scoring with the Admiralty System.
9 CHAPTERS · ~13 HRS · BEGINNER → ADVANCED
OPEN THREAT HUNTING →
LO
LIVING OFF THE LAND
Abuse the Tools Windows Ships With.
LIVE
LOLBAS taxonomy, certutil/mshta/regsvr32/bitsadmin abuse, WMI and PowerShell techniques, and behavioral detection for defense evasion.
8 CHAPTERS · ~10 HRS · INTERMEDIATE → ADVANCED
OPEN LOLBAS →
CS
CLOUD SECURITY
Hunting in Azure, AWS, and Entra.
LIVE
The shared responsibility model through applied detection engineering: Azure AD/Entra ID and AWS IAM attacks, cloud telemetry, and Zero Trust/CIEM/CSPM defense.
8 CHAPTERS · ~11 HRS · BEGINNER → ADVANCED
OPEN CLOUD SECURITY →
IR
INCIDENT RESPONSE
Contain. Eradicate. Recover.
LIVE
The full IR lifecycle: preparation, containment strategy, eradication, recovery, and post-incident review, built around NIST and SANS PICERL.
8 CHAPTERS · ~12 HRS · BEGINNER → ADVANCED
OPEN INCIDENT RESPONSE →
DF
DIGITAL FORENSICS
Chain of Custody to Courtroom.
LIVE
Chain of custody and order of volatility, disk and memory forensics, Windows artifacts and timeline analysis, network and mobile forensics, and anti-forensics detection and report writing.
8 CHAPTERS · ~12 HRS · BEGINNER → ADVANCED
OPEN DIGITAL FORENSICS →
MA
MALWARE ANALYSIS
Static. Dynamic. Behavioral.
LIVE
Static and dynamic analysis, unpacking, malware tradecraft, and YARA/Sigma rule writing, from first-pass triage through detection engineering and evasion tradecraft.
8 CHAPTERS · ~12 HRS · BEGINNER → ADVANCED
OPEN MALWARE ANALYSIS →
AI
AI IN SECURITY
LLMs for Triage, Hunting, and Detection.
LIVE
AI-powered threats, prompt injection and LLM application security, AI-assisted SOC triage and threat hunting, securing AI/ML systems, and the NIST AI RMF/EU AI Act governance layer.
8 CHAPTERS · ~11 HRS · BEGINNER → ADVANCED
OPEN AI IN SECURITY →
IP
INTERVIEW PREP
Reasoning Shown, Not Just the Answer.
LIVE
761 enterprise-grade questions with model answers across SOC Ops, IR, Threat Hunting, CTI, Digital Forensics, Malware Analysis, and Cloud Security, grounded in real attack scenarios.
761 QUESTIONS · L1 → L3 · 8 DOMAINS LIVE
OPEN INTERVIEW PREP →
← BACK TO H3AD-SEC