Practical Cyber Defence

Cyber Defence Kit

Hands-on guides to learn security tools and build cyber defence labs.
Scroll to explore

About Cyber Defence Kit

Cyber Defence Kit (CDK) is a personal project I started to explore open-source cyber security tools. I documented how I built and tested my lab through guides, notes, and proof-of-concept videos. CDK brings that work together for others to learn from and use in their own labs.

Interactive Labs let you practise workflows in your browser. Full Labs guide you through building and testing your own environment with the tools covered in CDK. Check each product's licence and requirements.

Start your way

What brings you to CDK?

Choose a route for today. Switch paths any time—CDK's guides and labs work together.

A practical learning path

From concepts to improvement

Learn a concept, build a lab, investigate evidence, then improve your defences.

Understand the defensive landscape

Learn what each SOC capability does, where it fits, and which open-source tools can provide it.

Explore core concepts
Recommended starting points

Choose your first lab

Choose a beginner lab by goal and setup. Each includes a practical guide and a short demonstration.

What do you want to practise?

4 recommended labs

Quick startGuided beginner

Wireshark traffic analysis

Inspect packet captures, apply display filters, and investigate malware traffic.

First result: identify suspicious traffic in a supplied packet capture.

Single workstation Windows or Linux
Network detectionGuided beginner

Suricata IDS lab

Monitor network traffic, generate controlled activity, and analyse IDS alerts.

First result: generate and investigate a network detection alert.

Multi-host lab Linux sensor
SIEM and XDRGuided beginner

Wazuh detection lab

Collect endpoint telemetry, investigate alerts, and test active response.

First result: collect endpoint activity and trace it through an alert.

Multi-host lab Linux + Windows
Case managementGuided beginner

DFIR-IRIS investigation

Create a case, organise evidence, and document a structured incident investigation.

First result: build a structured case from evidence to findings.

Self-hosted Linux Docker
Popular on YouTube

Watch practical CDK demonstrations

Watch a workflow, then use its companion guide to reproduce it in a safe lab.

Incident response

Manage an investigation with DFIR-IRIS

Create a case, organise evidence, build a timeline, and document a supported conclusion.

Explore by outcome

Build your defensive toolkit

Already know what you need? Choose a capability to open its concepts, tools, and implementation guides.

Swipe to see more

Learn by doing

Choose how you want to practise

Practise a guided workflow in your browser or build a self-hosted lab with the tools covered in CDK.

Available nowInteractive LabsPractise a guided product workflow in the browser with no installation.
Available nowFull LabsDeploy complete self-hosted workflows and produce reviewable evidence.
Ownership & project terms

Copyright, ownership & licence

Copyright © 2024–2026 Joseph Jee. Original CDK documentation is licensed under CC BY-NC 4.0; project identity and identified third-party material are excluded.

Ownership & licensingRead the full project terms