Independent blue-team fieldwork New labs published periodically
CyberToolGuardian

01 Learn by operating

Defensive security,
built in public.

Practical labs for analysts who want to understand the tools—not just click through them. Build the stack, trace the data, and document what works.

01 Real infrastructure

02 Replayable steps

03 Analyst context

02 Watch and build

Latest field labs

View the full archive

03 The method

From raw telemetry to a useful decision.

Every lab follows the same practical route: deploy the tool, understand the data path, create a signal, then leave behind notes another analyst can replay.

  1. 01

    Build

    Deploy the stack in a real lab environment.

  2. 02

    Observe

    Trace the events, logs, and decisions end to end.

  3. 03

    Detect

    Turn raw data into signals an analyst can use.

  4. 04

    Document

    Publish the commands, context, and lessons learned.

04 Read and reference

Field notes

Commands, integrations, and implementation details for when the video is not enough.

WazuhSuricataElasticZeekOpenSearchHoneypots

Continue the operation

Build your next detection with me.

Subscribe for practical walkthroughs across open-source defensive security.

Join on YouTube