Detection

Detection & Threat Hunting

Hands-on labs focused on investigations, attacker behavior, email compromise, identity abuse, and practical threat hunting workflows.

Browse category →

Featured detection labs

Practical labs that connect attacker behavior to investigation workflows, detection logic, and real-world defensive decision making.

Email Security • Identity

EWS Phishing Lab Phase 1

Simulate an AitM phishing scenario and post-compromise mailbox access path in a safe lab. Learn how EWS-style mailbox interaction fits into business email compromise investigations.

Read lab →
Email Compromise

Investigating a Possible Email Compromise

Follow a realistic mailbox compromise scenario involving inbox rules, suspicious sign-ins, message activity, and user behavior pivots.

Coming soon →
KQL

Useful KQL Queries for Microsoft Investigations

Practice practical KQL for sign-ins, suspicious process activity, email abuse, and investigation pivots across Microsoft security data.

Coming soon →
Threat Hunting

Introduction to Threat Hunting Workflows

Move from alert review into structured hunting by building hypotheses, validating activity, and documenting findings.

Coming soon →
Endpoint

Hunting for Suspicious Process Chains

Examine parent-child process relationships, command lines, and execution context to identify suspicious behavior beyond single alerts.

Coming soon →
Attack Patterns

Recognizing Common Initial Access Patterns

Explore phishing, credential abuse, suspicious remote access, and early-stage attacker behavior that can lead to deeper compromise.

Coming soon →

What this category covers

Each lab is designed to connect real attacker behavior with practical defensive analysis, repeatable workflows, and clear investigation outcomes.

Investigations Alert triage, pivoting, timelines, and practical methods for turning telemetry into findings.
Threat hunting Hypothesis-based hunting, attacker behavior patterns, and repeatable workflows for finding hidden activity.
KQL workflows Reusable query patterns for Microsoft environments, investigation pivots, and hunting-focused data analysis.