Training in Guardian Foundry

Find your next skill.

Explore courses and learning paths built around practical cybersecurity work. See what you’ll practice, then continue in Guardian Foundry.

Courses focus on a topic. Learning paths combine related courses into a guided sequence and can include assessments.

36 results

Learning path

0 to HelpDesk and SysAdmin & CDT

Build an IT foundation in Windows, Linux and networking, then configure an Active Directory environment and resolve helpdesk tickets. The path concludes with the Cyber Defense Technician (CDT) assessment.

  • System administration
  • Helpdesk
  • Networking
  • Windows
89 exercises1 assessmentDuration not provided
Explore learning path
Learning path

0 to Tier 1 SOC Analyst & CDT, CDA, CDR, and CDCA

Progress from IT and networking foundations to phishing analysis, Windows host triage and SIEM investigations. Practice report writing and work a Virtual SOC alert queue, with CDT, CDA, CDR and CDCA assessments along the path.

  • SOC analysis
  • Security foundations
  • Incident response
  • Report writing
154 exercises3 assessmentsDuration not provided
Explore learning path
Courseadvanced

Adversary Tactics & Vulnerability Management

Study how attackers exploit weaknesses, establish persistence and move through systems. Practice vulnerability scanning, scoring and validation, then document a finding in a report.

  • Vulnerability management
  • Report writing
16 exercisesDuration not provided
Explore course
Courseintermediate

Applied Cyber Threat Intelligence

Turn intelligence requirements into a focused investigation. Work through collection, threat analysis and case studies, then write a report that connects the evidence to a defender's needs.

  • Threat intelligence
  • Report writing
11 exercisesDuration not provided
Explore course
Coursebeginner

Cryptography Fundamentals

Learn how hashing, encoding and encryption support secure communications and data protection. Explore digital signatures and certificates, then work with encoded and encrypted data in CyberChef.

  • Cryptography
8 exercisesDuration not provided
Explore course
Coursebeginner

Cyber Threat Intelligence Fundamentals

Explore the intelligence lifecycle through breach reports and threat actor case studies. Use the Cyber Kill Chain, Pyramid of Pain and MITRE ATT&CK to organize what you learn about an attack.

  • Threat intelligence
  • Security foundations
4 exercisesDuration not provided
Explore course
Coursebeginner

Cybersecurity Industry

Build a foundation in the concepts security teams use every day. Explore security controls, identity and access management, defense in depth, common threat actors and the ways attacks reach an organization.

  • Security foundations
7 exercisesDuration not provided
Explore course
Learning path

Detection Engineering & Threat Hunting: Windows & CDETH

Build and test YARA, Snort and Sigma detections, manage detection code in GitHub and use adversary emulation to assess coverage. Progress through practical detection challenges to the Certified Detection Engineer & Threat Hunter (CDETH) assessment.

  • Detection engineering
  • Threat hunting
  • Windows
91 exercisesDuration not provided
Explore learning path
Courseintermediate

Detection Engineering Challenges

Analyze Windows and Sysmon event logs and write Sigma rules for suspicious behavior. Work through detection challenges involving reconnaissance, encoded commands, persistence and credential attacks.

  • Detection engineering
  • Windows
  • Threat intelligence
10 exercisesDuration not provided
Explore course
Coursebeginner

Detection Engineering Fundamentals

Start with the principles behind useful detections. Explore detection engineering practices, documentation standards, indicator and behavior analysis, and the Pyramid of Pain in this free introductory course.

  • Detection engineering
  • Security foundations
6 exercisesDuration not provided
Explore course
Coursebeginner

DevSecOps & Cloud Security Fundamentals

Examine cloud security through breach case studies involving AWS, Azure and Google Cloud. Explore security boundaries, exposed secrets and DevSecOps practices in GitHub, then apply the concepts in practical exercises.

  • Cloud security
  • DevSecOps
0 exercisesDuration not provided
Explore course
Courseadvanced

Digital Forensics & Incident Response (DFIR)

Investigate endpoint and network evidence with tools including Velociraptor, Volatility, osquery and Hayabusa. Explore execution artifacts, persistence, memory analysis and timelines to reconstruct suspicious activity.

  • Digital forensics
  • Incident response
10 exercisesDuration not provided
Explore course
Coursebeginner

Governance, Risk & Compliance (GRC) Fundamentals

Connect security frameworks and risk assessments to the work of managing systems. Practice Windows Server hardening with CIS Benchmarks and review a security audit.

  • Governance and risk
  • Security foundations
  • System administration
4 exercisesDuration not provided
Explore course
Coursebeginner

Helpdesk & Windows Administration

Build and administer a Windows Active Directory environment, then work through helpdesk tickets. Practice user and policy management, remote administration, system hardening and troubleshooting.

  • Windows
  • Helpdesk
  • System administration
25 exercisesDuration not provided
Explore course
Courseintermediate

Intro to Detection Engineering

Write endpoint detections with Sigma and YARA, then test them through adversary emulation. Connect detection logic to the behavior and artifacts produced by an attack simulation.

  • Detection engineering
3 exercisesDuration not provided
Explore course
Coursebeginner

Linux Operating System Fundamentals

Get comfortable navigating a Linux system through its desktop and command line. Work with files, processes, logs, users and permissions while learning the operating system's basic structure.

  • Linux
  • System administration
15 exercisesDuration not provided
Explore course
Coursebeginner

Network Operations - Command Line

Use command-line tools on Windows and Linux to inspect hosts, test connections and explore network services. Practice DNS lookups, remote connections, file transfers and basic network discovery.

  • Networking
  • System administration
8 exercisesDuration not provided
Explore course
Courseintermediate

Network Protocol Analysis

Examine DNS, ICMP, HTTP and TLS traffic with Wireshark. Follow protocol exchanges, inspect request details and correlate activity across protocols during a packet-capture investigation.

  • Networking
18 exercisesDuration not provided
Explore course
Learning path

Network Security Analyst

Progress from networking foundations and command-line tools to packet analysis and network threat hunting. Investigate DNS, HTTP, TLS and ICMP traffic, then document suspicious activity in a network forensics report.

  • Networking
  • Threat hunting
  • Digital forensics
47 exercises3 assessmentsDuration not provided
Explore learning path
Courseintermediate

Network Threat Hunting

Investigate packet captures for malware activity and suspicious network behavior. Follow evidence across traffic-analysis challenges and bring your findings together in a network forensics report.

  • Threat hunting
  • Digital forensics
  • Report writing
5 exercisesDuration not provided
Explore course
Coursebeginner

Network Traffic Analysis

Learn to navigate and filter packet captures in Wireshark. Explore ARP, TCP and HTTP, extract endpoint metadata and identify traffic that deserves further investigation.

  • Networking
7 exercisesDuration not provided
Explore course
Coursebeginner

Networking Foundations

Learn how devices connect and exchange data. Explore network models, topologies and equipment, then work through addressing, subnetting, ports and the differences between TCP and UDP.

  • Networking
10 exercisesDuration not provided
Explore course
Courseintermediate

Pentesting Web Apps & AppSec Fundamentals

Follow an introductory web application penetration test in a training environment. Start with rules of engagement and reconnaissance, then investigate vulnerabilities, gain a foothold and explore privilege escalation.

  • Application security
5 exercisesDuration not provided
Explore course
Courseintermediate

PHANTOM

Investigate a supply-chain compromise using a case artifact pack. Extract indicators, write YARA, Snort and Sigma detections, develop a threat hunt and assemble an incident report.

  • Incident response
  • Detection engineering
  • Threat hunting
17 exercisesDuration not provided
Explore course
Coursebeginner

Phish Slayer

Investigate a business email compromise phishing campaign through a sequence of challenges. Examine the bait, extract indicators and decode hidden payloads, then write a campaign report.

  • Email security
  • Report writing
3 exercisesDuration not provided
Explore course
Coursebeginner

PowerShell Scripting

Build PowerShell skills from basic commands to reusable scripts. Work with files, objects and the pipeline, then apply scripting to Windows processes, services, the registry and Active Directory tasks.

  • Scripting
  • Windows
12 exercisesDuration not provided
Explore course
Coursebeginner

Practical Linux System Administration 1

Practice the command-line tasks used to maintain a Linux system. Manage processes, services, scheduled jobs and software, then bring scripting and file operations together in a backup tool.

  • Linux
  • System administration
  • Scripting
9 exercisesDuration not provided
Explore course
Coursebeginner

Python for Security

Learn Python fundamentals through tasks relevant to security work. Move from variables and control flow to files and network requests, then use those skills to build a security tool.

  • Scripting
13 exercisesDuration not provided
Explore course
Coursebeginner

Report Writing

Turn investigation evidence into a clear incident report for technical and executive readers. Critique an existing report, then build your own analysis, summaries and recommendations from raw evidence.

  • Report writing
  • Incident response
3 exercisesDuration not provided
Explore course
Coursebeginner

SOC Analyst Tier 1 Triage

Practice the investigations a SOC analyst encounters across email, Windows hosts and security logs. Examine phishing messages, malware behavior and persistence, then use ELK queries and detection tools to follow the evidence.

  • SOC analysis
  • Windows
  • Email security
30 exercisesDuration not provided
Explore course
Courseintermediate

SOC Analyst Tier 2 Triage

Go deeper into Windows internals, compromised-host investigations and threat hunting in ELK. Examine memory, persistence and log evidence, then document findings in DFIR and threat hunt reports.

  • SOC analysis
  • Digital forensics
  • Threat hunting
30 exercisesDuration not provided
Explore course
Learning path

Tier 1 to Tier 2 SOC Analyst & CDCP

Build investigation skills across network protocols, Windows triage, threat intelligence, vulnerability management and digital forensics. Apply them to escalated Virtual SOC alerts and the Cyber Defense Certified Professional (CDCP) assessment.

  • SOC analysis
  • Digital forensics
  • Threat hunting
  • Threat intelligence
96 exercisesDuration not provided
Explore learning path
Learning path

Tier 2+ Cyber Defense Specializations: Finding Your Path

Explore the technical disciplines that branch out from SOC analysis. Try PowerShell and Python scripting, detection engineering, cloud security, DevSecOps and web application testing to identify a direction for further study.

  • Scripting
  • Detection engineering
  • Cloud security
  • Application security
33 exercisesDuration not provided
Explore learning path
Coursebeginner

Try Guardian Foundry

Try a free phishing investigation and write a short incident report, then submit your work for instructor feedback. This introductory course welcomes newcomers and requires no virtual machine setup.

  • Email security
  • Report writing
  • Security foundations
3 exercisesDuration not provided
Explore course
Courseintermediate

Virtual SOC Tier 2

Work through escalated alerts in a simulated SOC environment. Investigate malicious DNS, unusual user activity, network anomalies and endpoint malware detections using the evidence available in each case.

  • SOC analysis
  • Incident response
6 exercisesDuration not provided
Explore course
Coursebeginner

Windows Operating System Fundamentals

Learn the structure of Windows and practice its core administration tools. Explore files, accounts, permissions, processes and services, then use the command line, registry and Event Viewer to inspect the system.

  • Windows
  • System administration
15 exercisesDuration not provided
Explore course

Exercise counts include distinct answer-based activities and labs. Assessments are shown separately. Durations are authored estimates when available; your pace may vary.

Talk to Rob or Anthony

Plan your team’s training.

Tell us how many people you’re training, their experience levels, and what they need to practice. We’ll discuss a training plan, learner support, and the reporting your team needs.

info@leveleffect.com
Email the team

We aim to respond within 1–2 business days.