H3AD-SEC · SECURITY TRAINING PLATFORM

Six Learning Domains Built for
Security Practitioners.

Threat Hunting, Living Off the Land, Threat Intelligence, SOC Operations, Malware Analysis, Cloud Security. Field-focused material sourced from CrowdStrike, Red Canary, Mandiant, SANS, and MITRE. No certification fluff. No account. No vendor lock-in.

FIELD-SOURCED METHODOLOGY BROWSER-NATIVE NO ACCOUNT REQUIRED KNOWLEDGE CHECKS KQL · SPL · SIGMA EXAMPLES
6DOMAINS PLANNED
3LIVE NOW
25CHAPTERS LIVE
34 HRSTRAINING CONTENT

An analyst who understands the hunt lifecycle catches what the ruleset misses. Every domain here starts where detection ends and works forward from adversary behavior to structured evidence.
No backend. No account. No certificate. Just the methodology, in your browser.

LEARNING DOMAINS
Domains Planned 6 Domains
Live Now 3 Live
Chapters Live 25 Chapters
Training Content 34 HRS Est.
THREAT HUNTING
LIVE
Hunt Smarter. Miss Nothing.
A field-focused curriculum built from CrowdStrike OverWatch, Red Canary, Elastic Security, and Mandiant methodologies. Eight chapters covering the complete hunt lifecycle: hypothesis generation, PEAK, TaHiTI, data sources, KQL/Sigma/SPL, evidence scoring with the Admiralty System, and advanced ML-assisted techniques.
CROWDSTRIKE OVERWATCH RED CANARY MANDIANT MITRE ATT&CK
9 CHAPTERS · ~13 HRS · BEGINNER → ADVANCED · PEAK · TAHITI · ADMIRALTY SYSTEM
OPEN THREAT HUNTING →
LIVING OFF THE LAND
LIVE
Abuse the Tools Windows Ships With.
How attackers weaponize legitimate Windows binaries, scripts, and services. Covers LOLBAS taxonomy, certutil, mshta, regsvr32, bitsadmin abuse patterns, WMI/PowerShell LOL techniques, defense evasion strategies, and behavioral detection approaches.
8 CHAPTERS · ~10 HRS · INTERMEDIATE → ADVANCED · LOLBAS · WINDOWS · DEFENSE EVASION
OPEN LOLBAS →
THREAT INTELLIGENCE
LIVE
From Raw IOCs to Finished Intel.
The complete CTI practitioner curriculum. Eight chapters covering the intelligence cycle, IOC confidence scoring, threat actor profiling with the Diamond Model, STIX 2.1 and TAXII sharing infrastructure, intel-driven hunting, malware and campaign analysis, CTI report writing, and converting intelligence into detection rules.
8 CHAPTERS · ~11 HRS · BEGINNER → ADVANCED · DIAMOND MODEL · STIX/TAXII · SIGMA · PYRAMID OF PAIN
OPEN THREAT INTELLIGENCE →
SOC OPERATIONS
PLANNED
Triage. Escalate. Contain.
Alert triage methodology, escalation frameworks, shift management, and playbook creation. Built for analysts who need to move from alert intake to resolution without second-guessing the process.
ALERT TRIAGE · ESCALATION FRAMEWORKS · SHIFT MANAGEMENT · PLAYBOOK CREATION
COMING SOON
MALWARE ANALYSIS
PLANNED
Static. Dynamic. Behavioral.
Static analysis, dynamic behavior, sandbox output interpretation, and YARA rule writing. Covers the full analysis workflow from first-pass triage through detection signature authorship.
STATIC ANALYSIS · DYNAMIC BEHAVIOR · SANDBOX OUTPUT · YARA WRITING · DETECTION SIGNATURES
COMING SOON
CLOUD SECURITY
PLANNED
Hunting in Azure, AWS, and Entra.
Azure AD attacks, AWS enumeration, cloud-native threat hunting, and CloudTrail/Entra analysis. Structured for detection engineers who need to extend coverage beyond the endpoint.
AZURE AD · AWS ENUMERATION · CLOUD-NATIVE HUNTING · CLOUDTRAIL · ENTRA ANALYSIS
COMING SOON
BUILT FOR PRACTITIONERS
01
FIELD-SOURCED
Every chapter cites real methodology. CrowdStrike OverWatch interrupted 41,000 intrusions with these techniques. Red Canary analyzed 329 billion records a day to produce these patterns. This is not hypothetical.
02
LEARN BY DOING
Every chapter ends with a knowledge check and real query examples in KQL, SPL, or Sigma. Concepts are not described. They are demonstrated with working code.
03
FREE AND OPEN
No account. No subscription. No certificate. The material is here because the community benefits when analysts are better trained. Browser-native, no tracking.
PLATFORM
BROWSER-NATIVE
ALL CONTENT
NO ACCOUNT
REQUIRED
PROGRESS TRACKING
localStorage ONLY
9 CHAPTERS
THREAT HUNTING
8 CHAPTERS
LOLBAS
OPEN ACCESS
FREE FOREVER
← BACK TO H3AD-SEC
VISITORS