Reference hubs, a detection engineering course, and a playbook library. Use as much of it as you want without paying anything or signing up for anything. The credential is the paid part, and it is at the bottom of this page.
The frameworks, cross-referenced and navigable. Good on their own, and the groundwork if you go further.
14 tactics, 19 techniques
Adversary techniques through the MITRE ATT&CK framework. Understand how attacks work so you can build something that catches them.
7 tactics, 31 techniques
The defensive half of the matrix, which almost nobody teaches. Model, harden, detect, isolate, deceive, evict, restore.
Bidirectional ATT&CK ↔ D3FEND
Bidirectional mapping. Pick an attack and see what stops it, or pick a defense and see what it actually covers. Coverage heat map and gap analysis included.
10 L1, 22 L2, 30+ Sigma rules
Detection use cases organized from business risk down to working rules, so a detection has a reason to exist before it has syntax.
Longer-form material, also free.
6 modules, 31 lessons
Six modules on writing detections that hold up: ATT&CK and D3FEND in practice, AI-assisted detection authoring, use case management, and purple team operations. This is the groundwork the credential builds on.
20 playbooks, 4 categories
Twenty incident response playbooks across initial response, threat-specific handling, technical procedures, and communication. Written to be used during an incident, not read before one.
The paid path
Everything above teaches you the frameworks. The credential makes you build the stack: your own lab, your own detection layer, your own attacker, and then the endpoint mesh that keeps working when the central console goes dark. The exam is a build under time pressure and a defense of your design, not a quiz.