Cyber Defense
Blue-team fundamentals: threat and vulnerability management, security operations, threat emulation, incident response, and malware analysis.
Select your module(s)
You can select the modules you want to learn. There's a recommended order in the learning curve, unless you already know something and want to go further.
Learn the basics of networking, host-based systems, and active directory. These rooms will give you the foundational knowledge needed to grasp more advanced concepts.
- Tutorial — Learn how to use a TryHackMe room to start your upskilling in cyber security.
- Introductory Networking — An introduction to networking theory and basic networking tools
- Network Services — Learn about, then enumerate and exploit a variety of network services and misconfigurations.
- Network Services 2 — Enumerating and Exploiting More Common Network Services & Misconfigurations
- Wireshark 101 — Learn the basics of Wireshark and how to analyze various protocols and PCAPs
- Windows Fundamentals 1 — In part 1 of the Windows Fundamentals module, we'll start our journey learning about the Windows desktop, the NTFS file system, UAC, the Control Panel, and more..
- Active Directory Basics — This room will introduce the basic concepts and functionality provided by Active Directory.
Identify how attackers are developing their techniques to use in your defensive strategy.
- Nessus — Learn how to set up and use Nessus, a popular vulnerability scanner.
- MITRE — This room will discuss the various resources MITRE has made available for the cybersecurity community.
- Yara — Learn the applications and language that is Yara for everything threat intelligence, forensics, and threat hunting!
- Zero Logon — Learn about and exploit the ZeroLogon vulnerability that allows an attacker to go from Zero to Domain Admin without any valid credentials.
- OpenVAS — Learn the basics of threat and vulnerability management using Open Vulnerability Assessment Scanning
- MISP — Walkthrough on the use of MISP as a Threat Sharing Platform
Learn how to configure and utilise tooling to ensure that suspicious activity is quickly identified and dealt with in your environment.
- Core Windows Processes — Explore the core processes within a Windows operating system and understand what normal behaviour is. This foundational knowledge will help you identify malicious processes running on an endpoint!
- Sysinternals — Learn to use the Sysinternals tools to analyze Windows systems or applications.
- Windows Event Logs — Introduction to Windows Event Logs and the tools to query them.
- Sysmon — Learn how to utilize Sysmon to monitor and log your endpoints and environments.
- Osquery: The Basics — Let's cover the basics of Osquery.
- Splunk: Basics — Learn the basics of Splunk.
- Splunk 2 — Part of the Blue Primer series. This room is based on version 2 of the Boss of the SOC (BOTS) competition by Splunk.
The best way to understand how attackers work is to get hands on experience with their techniques.
- Attacktive Directory — 99% of Corporate networks run off of AD. But can you exploit a vulnerable Domain Controller?
- Attacking Kerberos — Learn how to abuse the Kerberos Ticket Granting Service inside of a Windows Domain Controller
Incidents are inevitable. Learn how to identify and respond to them.
- Volatility — Learn how to perform memory forensics with Volatility!
- Investigating Windows — A windows machine has been hacked, its your job to go investigate this windows machine and find clues to what the hacker might have done.
- Windows Forensics 1 — Introduction to Windows Registry Forensics
- Windows Forensics 2 — Learn about common Windows file systems and forensic artifacts in the file systems.
- Redline — Learn how to use Redline to perform memory analysis and to scan for IOCs on an endpoint.
- Autopsy — Learn how to use Autopsy to investigate artefacts from a disk image. Use your knowledge to investigate an employee who is being accused of leaking private company data.
- Disk Analysis & Autopsy — Ready for a challenge? Use Autopsy to investigate artifacts from a disk image.
Analyse malicious files to prevent malicious actions and identify attacks.
- History of Malware — Join this room to learn about the first forms of malware and how they turned into the malicious code we see today.
- MAL: Malware Introductory — The start of a series of rooms covering Malware Analysis...
- MAL: Strings — Investigating "strings" within an application and why these values are important!
- Basic Malware RE — This room aims towards helping everyone learn about the basics of "Malware Reverse Engineering".
- MAL: REMnux - The Redux — A revitalised, hands-on showcase involving analysing malicious macro's, PDF's and Memory forensics of a victim of Jigsaw Ransomware; all done using the Linux-based REMnux toolset apart of my Malware Analysis series
Includes Lab practices. All prices are monthly (MXN), before taxes.
Plan your training path
Tell us your team, schedule and modules of interest and we will reply with the next steps.
Request informationOnline enrollment is coming soon. In the meantime, contact us to enroll.
