From evidence to decision

Monitoring & Detection

Learn how defenders turn security evidence into decisions. Start with the concepts, investigate real traffic, or build a monitoring lab at your own pace.

3learning routes 8practical tools 1clear first step
01

Follow the evidence

Select each stage to see how an analyst moves from raw activity to a supported decision.

Stage 1 Collect useful evidence

Gather logs, endpoint activity, network records, or packets that can answer a defined security question.

Ask: Is the source producing complete and reliable evidence?
02

Find your learning path

Choose what you want to achieve. The page will highlight the best place to begin.

Best match Learn the foundations

Build the vocabulary needed for every practical guide without installing anything.

03

Build your foundation

These short concept guides work without a lab. Complete them in order or open the topic you need.

04

Choose a tool by evidence

You do not need every platform. Select the evidence you want to examine and start with one focused tool.

Best starting point for logs and events Splunk

Search and connect many kinds of machine data, then turn useful searches into reports, alerts, and dashboards.

Also consider Wazuh for endpoint led monitoring or Security Onion for network led investigation.
Explore Splunk
05

Check your lab readiness

Complete these checks before running a detection, prevention, or automated response exercise.

!
Preparation requiredComplete all five safety checks before starting.