M365 Security, Detection Engineering and DFIR: taught by building what you'd deploy.
Detection rules, investigation reports, hardening baselines and policy sets, written by engineers who still do the job. Preview the first module of any course free, no account needed.
Preview any course free. No account, no card, no trial timer.
Read the content, run the queries, judge the quality.
Cybersecurity Courses
36 courses across security architecture, detection, incident response, forensics, and GRC. Every one opens with a free module.
Choose your path
Each path is an ordered course sequence built around a career outcome. Start with the free preview on the first course.
Design and operate identity, endpoint, and platform security across M365.
Write production detections, run hypothesis-driven hunts, and automate response.
Investigate incidents end-to-end across cloud, Windows, Linux, macOS, and memory.
Deploy detections across Sentinel, Splunk, and Active Directory with Sigma CI.
Run governance with risk registers, compliance mappings, and the security operations they answer for.
Move from IT into security engineering with your first production stack.
Blog Post
Written to provide something you can apply at work this week.
Work real incidents, gain genuine hands-on experience.
Graded SOC scenarios, forensic cases, Splunk and AWS query drills, a free-run KQL and SPL console, and a suite of response playbooks. Every one runs against Northgate Engineering: 810 staff, 865 endpoints, and telemetry generated from real attack chains. Several are free with an account, no card.
Access the Practice HubFree Resources
Interactive tools and working references for SOC analysts and incident responders. Built by cybersecurity professionals who still do the job. Nothing gated, use them in the browser.
Start building the capability
Every course opens with a free module. Pick the one closest to the work in front of you, read it, and decide from there.
Browse Courses


































