What brings you to CDK?
Choose the route that best matches where you are today. You can switch paths at any time—the concepts, labs, and tool guides are designed to work together.
From concepts to investigation
CDK connects deployment instructions, controlled simulations, telemetry, detections, and investigations—so you can see how defensive tools work together, not only how to install them.
Learn what each SOC capability does, where it fits, and which open-source tools can provide it.
Explore core conceptsFollow practical deployment guidance for connected and air-gapped environments.
Choose a first labGenerate controlled security activity, collect telemetry, and validate that detections fire.
Explore security validationCorrelate endpoint, network, and forensic evidence to understand attacker behaviour.
Explore investigationChoose your first lab
Not sure where to begin? Choose a lab by learning goal and setup complexity. Each route combines practical documentation with a proof-of-concept demonstration.
4 recommended labs
Wireshark traffic analysis
Inspect packet captures, apply display filters, and investigate malware traffic.
First result: identify suspicious traffic in a supplied packet capture.
Suricata IDS lab
Monitor network traffic, generate controlled activity, and analyse IDS alerts.
First result: generate and investigate a network detection alert.
Wazuh detection lab
Collect endpoint telemetry, investigate alerts, and test active response.
First result: collect endpoint activity and trace it through an alert.
DFIR-IRIS investigation
Create a case, organise evidence, and document a structured incident investigation.
First result: build a structured case from evidence to findings.
See the Cyber Defence Kit in action
The dedicated CDK YouTube channel brings the documentation to life through demonstrations conducted in safe, controlled lab environments.
Build and test a Wazuh security lab
Simulate cyber attacks, investigate the resulting alerts, and test active response.
Build your defensive toolkit
Already know what you need? Choose a capability to open its concepts, tools, and implementation guides.
Security monitoring
Centralise logs, detect suspicious activity, and investigate alerts.
Splunk · Wazuh · Security OnionExplore SIEM Observe and detectNetwork defence
Inspect traffic and identify malicious patterns across the network.
Suricata · Snort · Zeek · Wireshark · ZuiExplore network defence Hunt and containEndpoint visibility
Investigate process activity and collect endpoint evidence.
Velociraptor · Aurora LiteExplore EDR Triage and coordinateIncident response
Manage investigations and automate repeatable response workflows.
TheHive · DFIR-IRIS · ShuffleExplore response Acquire and reconstructDigital forensics
Preserve evidence, analyse artefacts, and reconstruct activity.
Velociraptor · KAPE · Plaso · VolatilityExplore DFIR Test and improveSecurity validation
Emulate adversary behaviour and measure defensive controls.
MITRE Caldera · ATT&CK NavigatorExplore validationPractical content that keeps growing
Deployment guidance, controlled demonstrations, and offline-aware workflows across the defensive toolkit.