Over 118 live security alerts investigated, triaged, and documented — each one mapped to known attacker behaviour and written up with full methodology. 174+ completed lab scenarios covering network forensics, malware analysis, cloud intrusions, and incident response. Everything on this site is real work, publicly linked, and verifiable.
HTB proctored certification exam covering SOC fundamentals, alert triage workflows, SIEM analysis with Splunk & Elastic, threat intelligence & IOC correlation, digital forensics, incident response, phishing analysis, malware detection, and network traffic analysis.
Hands-on certification covering five SOC domains — phishing analysis, digital forensics, threat intelligence, SIEM investigation, and incident response. Passed first attempt.
CyberDefenders certification exam covering SIEM operations, digital forensics, incident response, threat intelligence, and network/endpoint/email security across realistic SOC investigation scenarios.
One real LetsDefend alert per day, triaged out loud on camera. Structured workflow, log correlation, containment decisions — real analyst thinking documented publicly.
▶ Full CyberDefenders lab walkthroughs on YouTube — every question answered, every tool and technique explained from scratch. Endpoint forensics, malware analysis, and threat investigation.
Every alert triaged, documented, and mapped to MITRE ATT&CK. Updated daily as part of the Day N of Becoming a SOC Analyst series.
Reusable KQL detection patterns auto-extracted from KC7 lab investigations — write the writeup once, every tagged query promotes itself into a searchable reference. Capability over completion: the queries are the takeaway.
Every technique observed across labs and investigations mapped to MITRE ATT&CK Enterprise. Generated live from documented writeups — no manual curation.
Twelve investigations selected across core blue team disciplines. Hard-rated labs, real artefacts, documented methodology.
All platforms, all labs. Filter by platform, difficulty, or category. Adding new labs weekly.
Writeups are complete but locked until these labs officially retire. Reach out if you need the password.
HTB Sherlocks — DFIR investigations covering endpoint forensics, threat intelligence, network analysis, and memory forensics.
Writeups complete but locked until these sherlocks officially retire. Reach out if you need the password.
Shorter CTF-style challenges. Same platforms, less depth.