Explore paths
Learning Paths
Job-role curricula built by LearnDefend. Each path takes you from concepts to a final simulation that mirrors the real work.
Available
Start here
Start here — the core technology and security skills every other path builds on.
Cyber Foundations
TutorialThe starting point before SOC Analyst L1 — what cybersecurity actually protects, and the vocabulary every later module builds on.
Networking Fundamentals
BeginnerBuild a working mental model of how computers talk — from a single Ethernet frame to a full HTTPS request across the internet. A core-technology foundation for Cloud, DevOps, Linux, Windows, Security and Data roles alike. Recommended prior knowledge: Cyber Foundations.
Windows & Active Directory Administration
BeginnerBuild a working mental model of Windows — processes, the registry, users and permissions — then how Active Directory lets one team manage thousands of machines and identities. A core-technology foundation for IT operations, system administration, Cloud, DevOps and Security roles alike. Recommended prior knowledge: Cyber Foundations.
Scripting & Automation
BeginnerBuild a working mental model of how programs think — data, logic, functions, files — and use it to automate repetitive work reliably. A core-technology foundation for Cloud, DevOps, Data, Programming, AI and Security roles alike. Concepts are language-agnostic, shown mainly in Python. Recommended prior knowledge: Cyber Foundations.
Linux Administration
BeginnerLearn practical Linux administration end to end: the shell and filesystem, users and permissions, processes and services, packages, storage, networking and SSH, security hardening, Bash automation, and real production troubleshooting — on a browser workspace with synthetic servers.
Security operations
Detect, triage and investigate attacks — the day-to-day of a security operations centre.
SOC Analyst L1
BeginnerLearn how modern SOC analysts monitor, investigate, triage and respond to security events — by doing the work, not by memorising definitions.
SOC Analyst L2
MediumStep up from Tier-1 triage to Tier-2 depth: correlate across sources, hunt on a hypothesis, engineer and tune detections, and lead complex investigations. Recommended after completing SOC Analyst L1.
SOC Analyst L3
HardOwn the investigation, not just the alert. Scope an intrusion end to end, correlate across every source, lead a hunt, validate and tune detections without creating blind spots, and make evidence-supported escalation and closure decisions like a senior analyst. Recommended after SOC Analyst L2.
Detection Engineering
BeginnerTurning attacker behavior and telemetry into high-quality, maintainable detections — from requirements and data quality through detection logic, testing, false-positive tuning, coverage and production readiness. Tool-neutral (Sigma-style logic). Recommended prior knowledge: SOC, Threat Hunting or Malware Analysis.
Endpoint Security
BeginnerDefending endpoints end to end — architecture and attack surface, telemetry and EDR, process-lineage investigation, containment decisions, and hardening. Where telemetry, detection, forensics and response meet the real host. Recommended prior knowledge: Cyber Foundations, SOC or Detection Engineering.
Response & investigation
Contain incidents and reconstruct what happened, down to the disk and the malware.
Incident Response
BeginnerMove from a confirmed alert into structured response: validate, scope, preserve evidence, contain, eradicate, recover — and report to both engineers and executives. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
Digital Forensics (DFIR)
BeginnerReconstructing what happened from evidence — execution artifacts, registry, event logs, filesystem metadata, memory and network traces — into a defensible timeline and report. Recommended prior knowledge: Cyber Foundations or Incident Response.
Malware Analysis
BeginnerUnderstanding suspicious samples defensively — safe handling, static and dynamic analysis, behavior, persistence, network activity — and turning what a sample DOES into IOCs, ATT&CK mappings and detections. Recommended prior knowledge: Cyber Foundations or Digital Forensics.
Hunting & intelligence
Go looking for the threats no alert fired on, and turn intelligence into detection.
Threat Hunting
BeginnerProactive, hypothesis-driven investigation — finding attacker behavior the alerts missed, and turning what you find into new detections. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
Threat Intelligence
BeginnerTurning raw observations into assessed, actionable intelligence — with sourcing, structured analysis, and estimative language a decision-maker can act on. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.