Skip to main content
Cyber Defense TacticsCyber Defense Tactics
HomeLearnResourcesBlogCommunity
Cyber Defense TacticsCyber Defense Tactics

Learn defensive security, leverage AI for cyber defense, and join a community of security professionals.

Learning

  • Blog
  • Resources
  • Newsletter

Community

  • Community
  • YouTube
  • About

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Cyber Defense Tactics. All rights reserved.

A Carbene.AI Project

All of this is free. No account required.

Reference hubs, a detection engineering course, and a playbook library. Use as much of it as you want without paying anything or signing up for anything. The credential is the paid part, and it is at the bottom of this page.

Reference hubs

The frameworks, cross-referenced and navigable. Good on their own, and the groundwork if you go further.

ATT&CK Hub

14 tactics, 19 techniques

Adversary techniques through the MITRE ATT&CK framework. Understand how attacks work so you can build something that catches them.

Open the hub

D3FEND Hub

7 tactics, 31 techniques

The defensive half of the matrix, which almost nobody teaches. Model, harden, detect, isolate, deceive, evict, restore.

Open the hub

Purple Matrix

Bidirectional ATT&CK ↔ D3FEND

Bidirectional mapping. Pick an attack and see what stops it, or pick a defense and see what it actually covers. Coverage heat map and gap analysis included.

Open the hub

MaGMa Use Cases

10 L1, 22 L2, 30+ Sigma rules

Detection use cases organized from business risk down to working rules, so a detection has a reason to exist before it has syntax.

Open the hub

Courses and playbooks

Longer-form material, also free.

Detection Engineering Course

6 modules, 31 lessons

Six modules on writing detections that hold up: ATT&CK and D3FEND in practice, AI-assisted detection authoring, use case management, and purple team operations. This is the groundwork the credential builds on.

Start reading

IR Playbooks

20 playbooks, 4 categories

Twenty incident response playbooks across initial response, threat-specific handling, technical procedures, and communication. Written to be used during an incident, not read before one.

Start reading

The paid path

When you want to build it instead of read about it

Everything above teaches you the frameworks. The credential makes you build the stack: your own lab, your own detection layer, your own attacker, and then the endpoint mesh that keeps working when the central console goes dark. The exam is a build under time pressure and a defense of your design, not a quiz.

See the CredentialGet Waitlist Updates