Advanced cybersecurity training

Defenders are made in the lab.

Hands-on courses in detection engineering, threat hunting, and incident response — built and taught by practitioners who run security operations for a living.

As taught atBlack Hat USA · Wild West Hackin' Fest · x33fcon

Digital Defense Institute phoenix mark

Our training philosophy

The best way to learn is by doing

No lengthy slideshows. No passive listening. Our courses drop you into real-world scenarios where hands-on practice comes first — so what you learn is applicable the moment you're back on shift.

Hands-on over hand-outs

Immersive labs simulating real intrusions, from initial detection through containment and post-incident analysis. You practice the work, not the theory of the work.

Methodology over tools

We teach the principles and strategy behind the tooling, so you can adapt to any stack — or any adversary — you meet in your professional role.

Built for practitioners

Advanced material for professionals serious about their craft, taught by instructors who have built and run SOCs, CSIRTs, and IR engagements.

Courses we offer

Pick your training ground

Flagship 4 days In person Black Hat USA 2026

Advanced Security Operations & Threat Hunting

Four days inside a live enterprise under attack — and every day drops a new, complex attack chain into the range for you to take apart. You'll build detections, hunt adversaries, and run forensics at fleet scale across a real investigation stack — LimaCharlie, OpenSearch, Arkime, and Velociraptor — then close out the course by running a full incident response against an active intrusion.

  • 4 attack chains to investigate
  • 20+ hands-on labs
  • 4 tool investigation stack
  • 1 IR capstone
  1. Day 01

    Detection Engineering

    The detection lifecycle from raw telemetry to tested rule. Profile credential theft, lateral movement, and persistence tradecraft, then write Sigma, YARA, Suricata, and LimaCharlie detections that catch it.

  2. Day 02

    Threat Hunting

    Hypothesis-driven hunting across endpoint and network telemetry — C2 channels, evasive PowerShell, anti-forensics — plus GenAI-assisted detection engineering and real-world case studies like Volt Typhoon.

  3. Day 03

    Forensics at Scale

    Velociraptor across the fleet: hunt artifacts enterprise-wide, stack for rarity, and pivot from a phishing email to host-level evidence — Autoruns, Prefetch, ShimCache, and memory.

  4. Day 04

    Live IR Capstone

    An intel drop lands and it's your incident. Run the full response lifecycle against an active intrusion in the range — identification through containment, eradication, and lessons learned.

Every student gets their own seat in the ASOTH range — a simulated enterprise with live adversaries — and leaves with DDI's analyst cheatsheets, lab guides, and a curated resource library.

I paid for this 100% out of pocket, investing in myself, and it was worth every penny.

ASOTH student · Black Hat USA 2025
2 days On demand WWHF 2026 · In person + virtual

Threat Hunting & Incident Response with Velociraptor

Master Velociraptor end to end — deploy a server, write VQL, and hunt across a fleet — then use it to unravel a complete intrusion: scoping, forensic analysis, malware discovery, C2 extraction, and coordinated eradication. Led by Eric Capuano and Whitney Champion.

  • 16 hands-on labs
  • 8 optional deep-dives
  • 1 full intrusion to unravel
  1. Part 01

    Deploy & Command

    Stand up a Velociraptor server, roll agents out fleet-wide, and learn the anatomy of VQL artifacts — the collection language behind every question you'll ask an endpoint.

  2. Part 02

    Hunt at Scale

    Hunts, notebooks, and stacking analysis: group and count behavior across every endpoint, surface long-tail anomalies, stream real-time telemetry, and run Sigma over event logs.

  3. Part 03

    Investigate an Intrusion

    Scope a real compromise — map IOCs to artifacts, analyze processes and network activity, prove execution with Prefetch and ShimCache, find persistence, and extract C2 beacon configs from memory.

  4. Part 04

    Eradicate

    The phase most courses skip: coordinated, fleet-wide eradication — remote scripting through hunts to remove malware, persistence, and C2 across every affected endpoint at once, with proof it worked.

Cloud-hosted lab VMs are provided, and every lab includes a video walkthrough. Optional deep-dives go further: the Velociraptor API, custom MSI packaging, Sysmon deployment, and AI-driven workflows with Velociraptor MCP.

I've been a Velociraptor user for years. Holy cow did this class knock my socks off — I feel like I have lightning in a jar.

THVR student · Wild West Hackin' Fest 2024
Self-paced Hands-on lab Pay what you can

So You Want to be a SOC Analyst?

A modern on-ramp to the SOC analyst role. Skip the painful lab setup: using LimaCharlie's free tier, you'll build an attack-and-defend environment, emulate an adversary with Sliver, and write the detection and response rules that catch it — the exact skills hiring managers look for.

What you will learn
  • Setting up an attack & defend environmentStand up cloud-hosted Windows and Linux VMs ready for adversary emulation.
  • Adversary simulation techniquesUse the Sliver red team framework to dump LSASS memory and see how attackers harvest credentials with legitimate Windows binaries.
  • Crafting detection and response rulesCatch credential theft attempts with LimaCharlie EDR detection and response rules.

From our students

Events

Where we've been and where we'll be

Find us

On the conference floor

Find us at an upcoming conference. We won't necessarily be running trainings at all of these events, but plan to be in attendance — come say hi.

Private training options

Bring the lab to your team

Can't make it to a conference? We offer private training tailored to your needs — virtual sessions or on-site at your location, customized to your team's schedule and requirements.

Ask about private training

Our team

Practitioners first, instructors second

Eric Capuano

Eric Capuano

Co-founder · SANS DFIR Instructor

Full bio

Eric Capuano is an InfoSec Founder, Practitioner, Trainer, Advisor, SANS DFIR Instructor, Member of the IANS Faculty with over a decade of experience in Security Operations, Digital Forensics, and Incident Response. He began his Information Security career as a Tactics Developer for the United States Air Force, later transitioning to Cyber Warfare Operations. After his military service, Eric led cybersecurity operations across private and government sectors, including serving as CTO of Recon Infosec, a company he founded to deliver enterprise-grade security to organizations of all sizes. In 2016, he developed OpenSOC, a blue team CTF that has trained thousands of SOC and IR professionals worldwide. Eric also managed the Security Operations Center for the Texas Department of Public Safety, where he established the agency's first CSIRT. In his spare time, Eric shares technical training labs on his blog at blog.ecapuano.com. His certifications include GIAC, GCFE, GCFA, CEH, Security+, Linux+, LPIC-1, PCNSE, and A+.

Whitney Champion

Whitney Champion

Co-founder · Security Architect

Full bio

Whitney is a Security Architect, Advisor, Trainer, and co-founder of Recon InfoSec. She is a seasoned architect and engineer with over 15 years of experience in designing and automating large-scale security infrastructure. She began her journey as a web and flash developer and sysadmin in the 90s and early 2000s, and after college became a security analyst for the Navy. Her work spans across building advanced security platforms, managing complex multi-environment deployments, and architecting comprehensive solutions that integrate cutting-edge tools and technologies. This includes building, automating, and maintaining the range environments and platforms used to drive and support our trainings. With extensive experience in both the private and public sectors, she excels at automating and orchestrating massive environments and streamlining security operations. Whitney’s passion for security and infrastructure drives her to continuously innovate and enhance the efficiency of security teams and operations. Her certifications include RHCA, RHCE, RHCVA, CISSP, CEH, Security+, Linux+, among others.

Matt Bromiley

Matt Bromiley

Instructor · DFIR

Full bio

Matt Bromiley brings a wealth of experience in digital forensics, incident response, and cybersecurity. In his current role, he helps organizations build robust security programs using the best technology available to complement their needs. Previously an incident response consultant at numerous renowned DFIR firms, Matt has a diverse background in assisting clients across various industries with complex cybersecurity challenges. He is recognized for his expertise in digital forensics, malware analysis, network security monitoring, and rapid forensic analysis across large enterprises. As a DFIR SANS instructor, Matt has taught courses on advanced digital forensics, network forensics, and incident response. Matt has held the following certifications: GCFA, GNFA, GCTI.

Hayden Covington

Hayden Covington

Instructor · Security Operations

Full bio

Hayden Covington is a security operations leader, detection engineer, trainer, and practitioner focused on agentic automation and security analytics. He serves as Associate Director of Security Operations at Black Hills Information Security, teaches with Antisyphon Training, and serves as a Black Hat trainer. Previously, Hayden worked in CSIRT and insider threat roles at Newport News Shipbuilding. His professional affiliations also include Noct Information Security and HII. Across these roles, his experience spans the operational and instructional sides of modern security work. Outside of cybersecurity, Hayden is a triathlete, a Dungeons & Dragons dungeon master, and a Formula 1 enthusiast.

Contact us

Say hello

Connect with us on socials, or shoot us an email.

hello@digitaldefenseinstitute.com