Cyfotok Labs
Master the latest vulnerabilities in our high-fidelity, isolated lab environments. From zero-days to enterprise misconfigurations.
Security Operations Center (SOC) teams handle thousands of alerts every day. Investigating every alert manually is time-consuming and difficult. The technology used to solve this problem is SOAR (Security Orchestration, Automation and Response). In this lab, we will learn what SOAR is, how it works with SIEM, how automation workflows are created, what automated response actions are, and the common use cases of SOAR. Finally, we will create a simple automation workflow.
Understanding how cyber attackers compromise systems, the techniques they use, and the activities they perform throughout the attack lifecycle is essential in cybersecurity. The MITRE ATT&CK Framework provides a structured way to study and analyze these adversary behaviors. In this learning path, you will start with the fundamentals of the MITRE ATT&CK Framework and gradually explore attacker tactics, techniques, and sub-techniques, the ATT&CK Matrix, threat hunting, detection engineering, SOC investigations, and incident response mapping through a step-by-step approach.
In this lab, you will learn the basics of log management. We will understand how logs are generated from different sources such as systems, applications, firewalls, and web servers. You will learn how security teams use logs to identify suspicious activities, failed login attempts, attacks, and system issues. In this lab, you will explore: Different types of logs, Log sources, Log parsing, Log normalization, Log retention concepts, Sample log analysis By the end of this lab, you will gain a practical understanding of the basic log analysis workflow followed by SOC Analysts and Blue Teams.
In this learning path, learners will discover how to proactively identify, investigate, and detect cyber threats. Instead of simply reacting to security alerts, you will learn how to think like a threat hunter by assuming an attacker may already be inside the network and systematically searching for signs of malicious activity.
In the cybersecurity world, not every alert has the same level of importance. Some alerts are purely informational, while others can affect an organization's entire infrastructure. In this learning path, learners will understand how SOC analysts classify incidents based on severity levels such as: Low Medium High Critical
In this learning path, you will learn the fundamentals of a Security Operations Center (SOC) in a beginner-friendly way. Through step-by-step explanations and real-world examples, you will understand how cyber attacks are detected, monitored, and analyzed.
In this learning path, you will learn the fundamentals of Security Information and Event Management (SIEM) in a simple and easy-to-understand way. Step by step, you will explore how SIEM collects logs, identifies suspicious activities, generates alerts, and helps analyze security incidents.
In this lab, we will learn the fundamentals of Threat Intelligence. We will understand the practical concepts of how cyber threats are identified, how the indicators used by attackers are analyzed, and how security teams respond to threats. This lab covers the following topics: Threat Intelligence basics, Types of Threat Intelligence, IOC feeds, Intelligence lifecycle, Threat investigation process, Security monitoring concepts By the end of this lab, learners will gain a clear understanding of the threat analysis methods used in real-world cybersecurity environments.
In this lab, we will learn how organizations manage security, create policies, maintain compliance, and handle audits. Using Governance, Risk, and Compliance (GRC) concepts, we will understand the basics of enterprise-level security management. This lab is beginner-friendly and provides a strong foundation for understanding real-world corporate cybersecurity environments.
Insecure Direct Object Reference (IDOR) is a web application security vulnerability that occurs when proper authorization validation is missing, allowing users to access resources they are not authorized to view or modify. This vulnerability commonly arises when identifiers such as user IDs, file names, invoice numbers, or API object references can be manipulated. IDOR vulnerabilities are typically caused by weak access controls and missing backend permission checks.
Page 4 of 7(63 labs)