What brings you to CDK?
Choose a route for today. Switch paths any time—CDK's guides and labs work together.
From concepts to improvement
Learn a concept, build a lab, investigate evidence, then improve your defences.
Learn what each SOC capability does, where it fits, and which open-source tools can provide it.
Explore core conceptsFollow practical deployment guidance for connected and air-gapped environments.
Choose a first labCorrelate endpoint, network, and forensic records to reconstruct what happened.
Explore investigationRun bounded tests, compare expected and observed evidence, then document what should improve.
Explore security validationChoose your first lab
Choose a beginner lab by goal and setup. Each includes a practical guide and a short demonstration.
4 recommended labs
Wireshark traffic analysis
Inspect packet captures, apply display filters, and investigate malware traffic.
First result: identify suspicious traffic in a supplied packet capture.
Suricata IDS lab
Monitor network traffic, generate controlled activity, and analyse IDS alerts.
First result: generate and investigate a network detection alert.
Wazuh detection lab
Collect endpoint telemetry, investigate alerts, and test active response.
First result: collect endpoint activity and trace it through an alert.
DFIR-IRIS investigation
Create a case, organise evidence, and document a structured incident investigation.
First result: build a structured case from evidence to findings.
Watch practical CDK demonstrations
Watch a workflow, then use its companion guide to reproduce it in a safe lab.
Manage an investigation with DFIR-IRIS
Create a case, organise evidence, build a timeline, and document a supported conclusion.
Build your defensive toolkit
Already know what you need? Choose a capability to open its concepts, tools, and implementation guides.
Swipe to see more
Security monitoring
Centralise logs, detect suspicious activity, and investigate alerts.
Splunk · Wazuh · Security OnionExplore SIEM Observe and detectNetwork defence
Inspect traffic and identify malicious patterns across the network.
Suricata · Snort · Zeek · Wireshark · ZuiExplore network defence Hunt and containEndpoint visibility
Investigate process activity and collect endpoint evidence.
Velociraptor · Aurora LiteExplore EDR Triage, coordinate, automateResponse & automation
Manage investigations and automate repeatable response workflows.
TheHive · DFIR-IRIS · ShuffleExplore response & automation Acquire and reconstructDigital forensics
Preserve evidence, analyse artefacts, and reconstruct activity.
Velociraptor · DFIR tool suite coming soonExplore DFIR Test, map, improveValidation & threat frameworks
Emulate adversary behaviour, measure controls, and communicate coverage.
MITRE Caldera · ATT&CK NavigatorExplore validation & frameworksChoose how you want to practise
Practise a guided workflow in your browser or build a self-hosted lab with the tools covered in CDK.