Open-source SOC & DFIR labs

Cyber Defence Kit

Build a practical cyber defence lab.

Hands-on guides and labs for building, investigating, and validating cyber defences.

Scroll to explore

About Cyber Defence Kit

I built Cyber Defence Kit (CDK) as an independent learning project to make defensive cyber security easier to practise. Its guides, tools, and exercises cover monitoring, incident response, digital forensics, endpoint investigation, automation, security validation, and threat frameworks.

Practise workflows in browser-based Interactive Labs or build Full Labs with open-source tools. Follow a learning path, test what works, and adapt it to your own lab.

Start your way

What brings you to CDK?

Choose the route that best matches where you are today. You can switch paths at any time—the concepts, labs, and tool guides are designed to work together.

A practical learning path

From concepts to improvement

CDK connects deployment instructions, controlled simulations, telemetry, detections, and investigations—so you can see how defensive tools work together, not only how to install them.

Understand the defensive landscape

Learn what each SOC capability does, where it fits, and which open-source tools can provide it.

Explore core concepts
Recommended starting points

Choose your first lab

Not sure where to begin? Choose a lab by learning goal and setup complexity. Each route combines practical documentation with a proof-of-concept demonstration. These selected starters focus on traffic analysis, detection, and incident investigation; explore the capability cards below for automation, endpoint, and validation routes.

What do you want to practise?

4 recommended labs

Quick startGuided beginner

Wireshark traffic analysis

Inspect packet captures, apply display filters, and investigate malware traffic.

First result: identify suspicious traffic in a supplied packet capture.

Single workstation Windows or Linux
Network detectionGuided beginner

Suricata IDS lab

Monitor network traffic, generate controlled activity, and analyse IDS alerts.

First result: generate and investigate a network detection alert.

Multi-host lab Linux sensor
SIEM and XDRGuided beginner

Wazuh detection lab

Collect endpoint telemetry, investigate alerts, and test active response.

First result: collect endpoint activity and trace it through an alert.

Multi-host lab Linux + Windows
Case managementGuided beginner

DFIR-IRIS investigation

Create a case, organise evidence, and document a structured incident investigation.

First result: build a structured case from evidence to findings.

Self-hosted Linux Docker
Popular on YouTube

Watch practical CDK demonstrations

Start with demonstrations that have resonated most with viewers, then open the companion guide to reproduce the workflow in a safe, controlled lab.

Incident response

Manage an investigation with DFIR-IRIS

Create a case, organise evidence, build a timeline, and document a supported conclusion.

Explore by outcome

Build your defensive toolkit

Already know what you need? Choose a capability to open its concepts, tools, and implementation guides.

Learn by doing

Choose how you want to practise

Practise a guided workflow in your browser or build a complete self-hosted lab using open-source tools.

Available nowInteractive LabsPractise a guided product workflow in the browser with no installation.
Available nowFull LabsDeploy complete self-hosted workflows and produce reviewable evidence.
Ownership & project terms

Copyright, ownership & licence

Copyright © 2024–2026 Joseph Jee. Original CDK documentation is licensed under CC BY-NC 4.0; project identity and identified third-party material are excluded.

Ownership & licensingRead the full project terms