Monitoring & Detection
Learn how defenders turn security evidence into decisions. Start with the concepts, investigate real traffic, or build a monitoring lab at your own pace.
Follow the evidence
Select each stage to see how an analyst moves from raw activity to a supported decision.
Gather logs, endpoint activity, network records, or packets that can answer a defined security question.
Ask: Is the source producing complete and reliable evidence?Find your learning path
Choose what you want to achieve. The page will highlight the best place to begin.
Build the vocabulary needed for every practical guide without installing anything.
Build your foundation
These short concept guides work without a lab. Complete them in order or open the topic you need.
Choose a tool by evidence
You do not need every platform. Select the evidence you want to examine and start with one focused tool.
Search and connect many kinds of machine data, then turn useful searches into reports, alerts, and dashboards.
Check your lab readiness
Complete these checks before running a detection, prevention, or automated response exercise.