What brings you to CDK?
Choose the route that best matches where you are today. You can switch paths at any time—the concepts, labs, and tool guides are designed to work together.
From concepts to improvement
CDK connects deployment instructions, controlled simulations, telemetry, detections, and investigations—so you can see how defensive tools work together, not only how to install them.
Learn what each SOC capability does, where it fits, and which open-source tools can provide it.
Explore core conceptsFollow practical deployment guidance for connected and air-gapped environments.
Choose a first labCorrelate endpoint, network, and forensic records to reconstruct what happened.
Explore investigationRun bounded tests, compare expected and observed evidence, then document what should improve.
Explore security validationChoose your first lab
Not sure where to begin? Choose a lab by learning goal and setup complexity. Each route combines practical documentation with a proof-of-concept demonstration. These selected starters focus on traffic analysis, detection, and incident investigation; explore the capability cards below for automation, endpoint, and validation routes.
4 recommended labs
Wireshark traffic analysis
Inspect packet captures, apply display filters, and investigate malware traffic.
First result: identify suspicious traffic in a supplied packet capture.
Suricata IDS lab
Monitor network traffic, generate controlled activity, and analyse IDS alerts.
First result: generate and investigate a network detection alert.
Wazuh detection lab
Collect endpoint telemetry, investigate alerts, and test active response.
First result: collect endpoint activity and trace it through an alert.
DFIR-IRIS investigation
Create a case, organise evidence, and document a structured incident investigation.
First result: build a structured case from evidence to findings.
Watch practical CDK demonstrations
Start with demonstrations that have resonated most with viewers, then open the companion guide to reproduce the workflow in a safe, controlled lab.
Manage an investigation with DFIR-IRIS
Create a case, organise evidence, build a timeline, and document a supported conclusion.
Build your defensive toolkit
Already know what you need? Choose a capability to open its concepts, tools, and implementation guides.
Security monitoring
Centralise logs, detect suspicious activity, and investigate alerts.
Splunk · Wazuh · Security OnionExplore SIEM Observe and detectNetwork defence
Inspect traffic and identify malicious patterns across the network.
Suricata · Snort · Zeek · Wireshark · ZuiExplore network defence Hunt and containEndpoint visibility
Investigate process activity and collect endpoint evidence.
Velociraptor · Aurora LiteExplore EDR Triage, coordinate, automateResponse & automation
Manage investigations and automate repeatable response workflows.
TheHive · DFIR-IRIS · ShuffleExplore response & automation Acquire and reconstructDigital forensics
Preserve evidence, analyse artefacts, and reconstruct activity.
Velociraptor · DFIR tool suite coming soonExplore DFIR Test, map, improveValidation & threat frameworks
Emulate adversary behaviour, measure controls, and communicate coverage.
MITRE Caldera · ATT&CK NavigatorExplore validation & frameworksChoose how you want to practise
Move from guided browser exercises to complete self-hosted workflows, with new ways to assemble a DFIR environment planned for future releases.