Open-source SOC & DFIR labs

Cyber Defence Kit

Build a practical cyber defence lab.

Hands-on guides for monitoring, response, endpoint investigation, digital forensics, and security validation.

Scroll to explore

About Cyber Defence Kit

Built for students, defenders, and lab builders, the Cyber Defence Kit (CDK) is an open-source collection of concepts, guided exercises, and implementation guides for creating a modern Security Operations Centre (SOC) and Digital Forensics and Incident Response (DFIR) lab.

Start with browser-based Interactive Labs, then reproduce complete workflows in self-hosted Full Labs with reviewable evidence. CDK is a learning project rather than one installable product; a dedicated DFIR VM and CDK Builder are planned to make practical lab building easier.

Start your way

What brings you to CDK?

Choose the route that best matches where you are today. You can switch paths at any time—the concepts, labs, and tool guides are designed to work together.

A practical learning path

From concepts to improvement

CDK connects deployment instructions, controlled simulations, telemetry, detections, and investigations—so you can see how defensive tools work together, not only how to install them.

Understand the defensive landscape

Learn what each SOC capability does, where it fits, and which open-source tools can provide it.

Explore core concepts
Recommended starting points

Choose your first lab

Not sure where to begin? Choose a lab by learning goal and setup complexity. Each route combines practical documentation with a proof-of-concept demonstration. These selected starters focus on traffic analysis, detection, and incident investigation; explore the capability cards below for automation, endpoint, and validation routes.

What do you want to practise?

4 recommended labs

Quick startGuided beginner

Wireshark traffic analysis

Inspect packet captures, apply display filters, and investigate malware traffic.

First result: identify suspicious traffic in a supplied packet capture.

Single workstationSetup 30–60 minCore 90–120 min
Network detectionGuided beginner

Suricata IDS lab

Monitor network traffic, generate controlled activity, and analyse IDS alerts.

First result: generate and investigate a network detection alert.

Linux environmentSetup 120–240 minCore 120–180 min
SIEM and XDRGuided beginner

Wazuh detection lab

Collect endpoint telemetry, investigate alerts, and test active response.

First result: collect endpoint activity and trace it through an alert.

Multi-host labSetup 120–240 minCore 120–240 min
Case managementGuided beginner

DFIR-IRIS investigation

Create a case, organise evidence, and document a structured incident investigation.

First result: build a structured case from evidence to findings.

Linux or containersSetup 120–240 minCore 120–180 min
Popular on YouTube

Watch practical CDK demonstrations

Start with demonstrations that have resonated most with viewers, then open the companion guide to reproduce the workflow in a safe, controlled lab.

Incident response

Manage an investigation with DFIR-IRIS

Create a case, organise evidence, build a timeline, and document a supported conclusion.

Explore by outcome

Build your defensive toolkit

Already know what you need? Choose a capability to open its concepts, tools, and implementation guides.

Learn now. Build more soon.

Choose how you want to practise

Move from guided browser exercises to complete self-hosted workflows, with new ways to assemble a DFIR environment planned for future releases.

Available nowInteractive LabsPractise a guided product workflow in the browser with no installation.
Available nowFull LabsDeploy complete self-hosted workflows and produce reviewable evidence.
Coming soonDFIR VMUse a prepared environment containing a practical suite of DFIR tools.
Coming soonCDK BuilderAssemble a focused defence lab from selected CDK capabilities and tools.
Ownership & project terms

Copyright, ownership & licence

Copyright © 2024–2026 Joseph Jee. Original CDK documentation is licensed under CC BY-NC 4.0; project identity and identified third-party material are excluded.

Ownership & licensingRead the full project terms