Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

Tool Academy

Tool Academy

Learn the cybersecurity tools used on the job through guided lessons and hands-on browser labs.

Available tools

Wireshark

Beginner

Learn to inspect packets, filter traffic, follow streams and investigate suspicious network activity — hands-on, in the browser.

4 units6 hours

Splunk

Beginner

Turn a security question into a search. Learn events, fields and the SPL pipeline, then aggregate, correlate across log sources and reach an evidence-supported conclusion — hands-on, in the browser.

4 units10 hours

Elastic Security

Beginner

Investigate logs with the Elastic Stack and KQL. Learn indices, documents and fields, write Kibana Query Language to search and filter, aggregate with visualizations, and correlate an incident in Elastic Security — the same analyst reasoning as Splunk, in a second language.

4 units10 hours

Nmap

Beginner

Turn a network question into a scan. Learn hosts vs services and ports, run host discovery and service/version detection, read the open/closed/filtered states correctly, and write the analyst conclusion — on safe synthetic targets.

4 units8 hours

Sysmon

Beginner

See what happens on an endpoint. Read process creation and parent/child lineage, network and file and registry activity, tell noise from signal, and correlate events into a short attack timeline — on safe synthetic telemetry.

4 units9 hours

Windows Event Logs

Beginner

Investigate Windows from its own record. Learn the log channels and event structure, read authentication and identity events (4624/4625/4672/4740/4768/4769), follow account and system activity (4688/4720/4728/4732/7045/1102), and build an evidence-based timeline.

4 units9 hours

Sigma

Beginner

Write detections as code. Learn Sigma's structure (logsource, detection, selection, condition), express behaviour as portable rules, judge detection quality and false positives, and validate a rule against normalized events — the detection-engineering craft, tool-neutral.

4 units9 hours

YARA

Beginner

Classify files by what is inside them. Learn YARA rule anatomy (meta, strings, condition), choose reliable text and hex patterns, combine them with boolean conditions, control false positives with specificity and context, and test a rule against safe synthetic artifacts.

4 units8 hours

CyberChef

Beginner

Transform and decode data like an analyst. Learn the input→recipe→output model, the common encodings (Base64, hex, URL), how to peel layered encodings and identify the next step, and how to extract and verify indicators from a safe encoded artifact.

3 units6 hours

More tools are being prepared.