Open-source SOC & DFIR labs

Cyber Defence Kit

Build a practical cyber defence lab.

Hands-on guides for detection, incident response, and digital forensics.

Scroll to explore

About Cyber Defence Kit

Built for students, defenders, and lab builders, the Cyber Defence Kit (CDK) is an open-source collection of practical documentation and exercises for creating a modern Security Operations Centre (SOC) and Digital Forensics and Incident Response (DFIR) lab.

It brings together practical documentation, proof-of-concept demonstrations, deployment guidance, and lessons learned to help cybersecurity practitioners explore security tools through hands-on experience. It is a learning project rather than a single installable product: choose the tools and learning path that fit your environment.

Start your way

What brings you to CDK?

Choose the route that best matches where you are today. You can switch paths at any time—the concepts, labs, and tool guides are designed to work together.

A practical learning path

From concepts to investigation

CDK connects deployment instructions, controlled simulations, telemetry, detections, and investigations—so you can see how defensive tools work together, not only how to install them.

Understand the defensive landscape

Learn what each SOC capability does, where it fits, and which open-source tools can provide it.

Explore core concepts
Recommended starting points

Choose your first lab

Not sure where to begin? Choose a lab by learning goal and setup complexity. Each route combines practical documentation with a proof-of-concept demonstration.

What do you want to practise?

4 recommended labs

Quick startBeginner

Wireshark traffic analysis

Inspect packet captures, apply display filters, and investigate malware traffic.

First result: identify suspicious traffic in a supplied packet capture.

Single workstationSample PCAPsLow setup effort
Network detectionBeginner

Suricata IDS lab

Monitor network traffic, generate controlled activity, and analyse IDS alerts.

First result: generate and investigate a network detection alert.

Linux environmentOffline guidanceLow setup effort
SIEM and XDRIntermediate

Wazuh detection lab

Collect endpoint telemetry, investigate alerts, and test active response.

First result: collect endpoint activity and trace it through an alert.

Multi-host labOffline guidanceMedium setup effort
Case managementIntermediate

DFIR-IRIS investigation

Create a case, organise evidence, and document a structured incident investigation.

First result: build a structured case from evidence to findings.

Container deploymentIntegrated workflowMedium setup effort
Proof of concept

See the Cyber Defence Kit in action

The dedicated CDK YouTube channel brings the documentation to life through demonstrations conducted in safe, controlled lab environments.

SIEM and XDR

Build and test a Wazuh security lab

Simulate cyber attacks, investigate the resulting alerts, and test active response.

Explore by outcome

Build your defensive toolkit

Already know what you need? Choose a capability to open its concepts, tools, and implementation guides.

Project coverage

Practical content that keeps growing

Deployment guidance, controlled demonstrations, and offline-aware workflows across the defensive toolkit.

95Practical guidesConcepts and deployment
12Guides with PoC videosWatch, build, and validate
25Offline-aware guidesConnected and air-gapped
5Security capability areasMonitoring, detection, response, forensics, and validation
Ownership & project terms

Copyright, ownership & licence

Copyright © 2024–2026 Joseph Jee. The original CDK documentation, diagrams, artwork, project identity, and source materials were independently created and are owned by Joseph Jee, except where third-party material is identified. Documentation is licensed under CC BY-NC 4.0; the Cyber Defence Kit™ name, CDK name, and logo are excluded from that licence.

Ownership & licensingRead the full project terms