Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Tutorial Beginner1 hours

Cyber Foundations

The starting point before SOC Analyst L1 — what cybersecurity actually protects, and the vocabulary every later module builds on.

Incident Triage

What you will be able to do

  • Explain what cybersecurity protects and why it is a shared responsibility, not one tool.
  • Identify digital assets, threats, attackers and defenders in a real scenario.

Units

  1. 01

    Digital & Cybersecurity Foundations

    What cybersecurity means, what a digital environment is made of, and the four ideas — asset, threat, attacker, defender — every later module assumes you already know.

    BeginnerAvailable

    Why you are learning this

    Every SOC module that follows talks about protecting assets from threat actors. This module is where those words stop being jargon and start being tools you use on purpose.

    Unit contents7
  2. 02

    Networking Foundations

    How networks actually move data — addressing, TCP/UDP and ports, DNS/DHCP/HTTP, switching and routing, and the controls that defend a network — the vocabulary every later network investigation assumes.

    BeginnerAvailable

    Why you are learning this

    Nearly every SOC and Tool Academy module that follows reads network evidence — an IP, a port, a DNS name. This module is where that evidence stops being unfamiliar.

    Unit contents9
  3. 03

    Operating Systems & Endpoint Foundations

    What an operating system actually coordinates — users, processes, services, files and network activity — on both Windows and Linux, and how that activity becomes the telemetry a SOC reviews.

    BeginnerAvailable

    Why you are learning this

    Almost every host investigation is really a question about processes, files and connections on an endpoint. This module builds the vocabulary that makes an event log readable instead of noise.

    Unit contents10
  4. 04

    Identity, Access & Cryptography

    Who a system believes you are, what it then lets you do, and how encryption, hashing and certificates protect and prove that relationship.

    BeginnerAvailable

    Why you are learning this

    Identity is the thread through nearly every investigation — a compromised account, a misused privilege, a certificate nobody trusts. This module builds that vocabulary before it is needed under pressure.

    Unit contents10
  5. 05

    Threats & Attacks

    Who attacks organizations and why, and how phishing, credential attacks, malware, network attacks, web threats and denial of service actually work at a foundational level.

    BeginnerAvailable

    Why you are learning this

    Every alert a SOC analyst triages is a suspected instance of something in this module. Recognizing the pattern is what turns a wall of alerts into a manageable queue.

    Unit contents10
  6. 06

    Security Operations Foundations

    How a SOC actually works — telemetry, logs, SIEM, detection logic, alert triage, incident response, and the frameworks analysts use to turn observations into a coordinated response.

    BeginnerAvailable

    Why you are learning this

    This is the daily operating rhythm of a real SOC seat — everything from Modules 1–5 becomes the raw material an analyst processes through this exact set of tools and steps.

    Unit contents11
  7. 07

    Modern Security & Career Exploration

    Where security extends beyond the SOC — cloud, applications, DevSecOps, Zero Trust and automation — plus a guided tour of the career fields this foundation opens the door to.

    BeginnerAvailable

    Why you are learning this

    Almost every modern organization runs cloud and web applications alongside its traditional network — and every learner eventually needs to choose which of these fields to specialize in.

    Unit contents10

Recommended next