Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

Tool Path

Nmap

Turn a network question into a scan. Learn hosts vs services and ports, run host discovery and service/version detection, read the open/closed/filtered states correctly, and write the analyst conclusion — on safe synthetic targets.

BeginnerNetwork AnalysisIncident Triage

Curriculum

  1. 01

    Hosts, Services & Ports

    What Nmap answers, the difference between a host, a service and a port, and the TCP facts a scan relies on.

    Available
  2. 02

    Host Discovery & Scanning

    Find which hosts are alive, scan their ports, and read the open/closed/filtered states — including what latency and filtering tell you.

    Available
  3. 03

    Service & Version Detection

    Go beyond 'a port is open' to 'what is actually listening and which version' — and why version detail drives the defender's next move.

    Available
  4. 04

    Enumeration Workflow & Conclusions

    Put it together: choose the right scan for the question, compare hosts, spot the unusual exposed service, and write the short analyst/admin conclusion — then work real scan output.

    Available

Related learning

SOC Analyst L1