About
A2I delivers hands‑on cybersecurity training built around the real tools and workflows used by red teams, blue teams, AI & Machine Learning and cloud security professionals.
Our curated resources equip learners to analyze attacker behavior, strengthen defensive capabilities, and develop industry‑ready skills in safe, accessible environments.

RED‑TEAM TOOLS & Hands-On Learning Resources
| Tool | Description | Free Book / PDF | Free Course | Free Lab | Free Project | Exam Prep | |
|---|---|---|---|---|---|---|---|
| Cobalt Strike | free C2 labs (but not Cobalt Strike itself, because it’s paid) | Red Team Operator Handbook | THM Red Team Fundamentals | Sliver C2 Lab | Github | CRTO (Certified Red Team Operator) Prep Blogs | The main use of Cobalt Strike is to assess the security of networks and systems. It is a commercial penetration testing tool that is commonly used by security professionals to test the security of networks and systems, and to identify and exploit potential vulnerabilities and weaknesses. |
| https://www.cobaltstrike.com/ | https://tryhackme.com | https://github.com/BishopFox/sliver | https://github.com/h3ll0clar1c3/CRTO | https://rouvin.gitbook.io/ibreakstuff/blogs/reviews/crto-review https://github.com/dr34mhacks/CRTO-CheatSheet/blob/main/README.md | https://8bitsecurity.com/posts/threat-hunting-cobalt-strike-the-final-guide-from-the-depths-of-beaconing-to-c2-infrastructure/ https://deetee1.medium.com/crto-certified-red-team-operator-review-june-2023-806e7b6c6bc9 | ||
| Metasploit | Metasploit Unleashed | Cybrary Metasploite | Metasploitable2 | Custom MSF Module | eJPT Prep | ||
| BloodHound | AD Security 101 | HackTricks AD | BloodHound CE Lab | Map AD Lab | CRTP Prep | ||
| Empire | PowerShell for Hackers | THM PowerShell | Empire Lab | Build PS Reverse Shell | OSEP Prep | ||
| Nmap | Nmap Network Scanning | Nmap Full Guide | VulnHub Scans | Python Nmap Scanner | Security+ Prep | ||
| BeEF | Browser Security Handbook | Web Academy | BeEF + DVWA | Custom Hook Module | OSWE Prep | ||
| Responder | Windows Auth Internals | HackTricks Windows | Responder Lab | LLMNR Poison Script | CRTP Prep | ||
| SET | Art of Human Hacking | SE.org Training | SET Phishing Lab | Phishing Simulation | CEH Prep | ||
| Burp Suite | WAHH Free Chapters | Web Academy | Burp Labs | Web Scanner Project | OSWE Prep | ||
| FireCompass | ASM Guide | THM ASR | Amass/Subfinder | ASM Pipeline | OSCP Prep | ||
| Havoc | C2 Dev Handbook | Havoc Basics | Havoc Lab | Custom Payloads | CRTO Prep | ||
| Sliver | Sliver Docs | Sliver Training | Sliver Lab | Custom Operators | OSEP Prep | ||
| Deepfake Tools | Deepfake Ethics | AI For Everyone | Deepfake Lab | Voice Clone Simulation | CEH Prep | ||
| AI Recon Bots | OSINT Framework Guide | OSINT Fundamentals | OSINT Recon Lab | Build AI Recon Bot | eJPT Prep | ||
BLUE‑TEAM TOOLS & Hands-On Learning Resources
| Tool | Description | Free Book / PDF | Free Course | Free Lab | Free Project | Recommended Certification |
|---|---|---|---|---|---|---|
| Microsoft Defender XDR | Microsoft Defender XDR is a unified enterprise defense suite designed to enhance cybersecurity by coordinating detection, prevention, investigation, and response across various components such as endpoints, identities, email, and applications. It integrates information from multiple Microsoft security products, allowing security teams to detect threats more effectively and respond to them in real-time. | Microsoft Security Best Practices | SC‑200 Microsoft Learn | Defender XDR Sandbox | Build Home SOC | SC-200T00-A, AZ‑500, CISSP |
| https://www.hurix.com/blogs/improve-your-it-security-posture-with-microsoft-defenders-best-practices/ | https://www.microsoft.com/en-au/security/business/siem-and-xdr/microsoft-defender-xdr | https://www.google.com/search?q=Build+Home+SOC& | https://learn.microsoft.com/en-us/training/courses/sc-200t00 | |||
| Splunk Enterprise Security | Splunk Enterprise Security is a SIEM system that makes use of machine-generated data to get operational insights into threats, vulnerabilities, security technologies, and identity information | Splunk Fundamentals | Splunk Work+ Fundamentals | Boss of the SOC | Build SIEM Dashboard | Splunk SPLK-3001 Actual |
| https://www.splunk.com/en_us/training/certification-track/splunk-certified-cybersecurity-defense-analyst.html | https://www.splunk.com/en_us/training/course-catalog.html?size=n_20_n&filters=filterGroup3SOCAnalyst&sort=Newest | https://bots.splunk.com/workshops/3HVBZjMPIxzWR1UXlpHXAz/detail | https://www.examtopics.com/exams/splunk/splk-3001/view/# | |||
| Microsoft Sentinel | Microsoft Sentinel is a cloud-native, AI-powered SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It centralizes log data, threat detection, investigation, and response across hybrid, multi-cloud, and Microsoft 365 environments, enabling automated threat intelligence and rapid security operations. | Azure Security Guide | Sentinel Analyst Training | Sentinel Sandbox | Cloud SIEM Pipeline | SC‑200 Prep |
| https://learn.microsoft.com/en-us/credentials/certifications/security-operations-analyst/?practice-assessment-type=certification | ||||||
| ELK / Elastic Security | Elastic Security, built on the ELK Stack (Elasticsearch, Logstash, Kibana), is an open-source platform offering SIEM, XDR, and endpoint protection for threat detection, investigation, and response. It enables real-time monitoring of logs from cloud, network, and endpoint sources, utilizing behavioral analysis and machine learning to detect threats, with integration via Elastic Agent and Fleet | Elastic Stack Book | Elastic Analyst Training | Elastic Cloud Lab | Build ELK SIEM | Elastic Analyst Prep |
| https://www.elastic.co/guide/index.html | https://www.elastic.co/training | https://www.elastic.co/training/certification | ||||
| Suricata | Suricata is a free and open source, mature, fast and robust network threat detection engine. Suricata provides threat detection capabilities. In IDS mode, it is going to analyse the traffic and generate an alert when a signature matches. In IPS mode, it acts like a firewall. It provides traffic filtering and monitoring and allows network administrators to write and enforce detection rules. | Suricata User Guide | OISF Training | Security Onion Suricata Lab | Build Home IDS | GIAC Certifications |
| https://suricata.io/learn/ | https://suricata.io/learn/ | https://www.freecodecamp.org/news/build-a-real-time-intrusion-detection-system-with-python/ | https://www.classcentral.com/subject/suricata?lang=english https://securityonionsolutions.com/ https://www.sans.org/blog/lessons-learned-on-the-impact-of-training-on-hiring-success-a-mastercard-use-case | |||
| Zeek | Zeek is a passive, open-source network traffic analyzer tool used by many operators. It analyzes network traffic packets and creates “Zeek logs” which can be used to detect malicious activity within a network. Suricata excels at real-time threat detection and prevention with a focus on ease of use. Zeek provides a comprehensive view of network activity through deep analysis and historical data, but requires more technical expertise to leverage its full potential. | Zeek NSM Guide | Zeek Training Series | Security Onion Zeek Lab | Zeek Monitoring Pipeline | GCIA Prep |
| https://docs.zeek.org/en/current/ | https://docs.zeek.org/en/current/ | https://github.com/zeek/zeek/blob/master/README.md | https://securityonionsolutions.com/certification | |||
| Wireshark | Wireshark is a free open source tool that analyzes network traffic in real-time for Windows, Mac, Unix, and Linux systems. It captures data packets passing through a network interface (such as Ethernet, LAN, or SDRs) and translates that data into valuable information for IT professionals and cybersecurity teams. | Wireshark Analysis Book | Wireshark University | Packet Capture Labs | Home Network Analysis | Wireshark Certifications |
| https://www.wireshark.org/docs/ | https://malware-traffic-analysis.net/index.html | https://www.wireshark.org/certifications/ | ||||
| OSQuery | Osquery is an open-source instrumentation, monitoring, and analytics framework that exposes operating systems (Linux, macOS, Windows) as high-performance relational databases. It allows users to query system data—such as running processes, network connections, and file hashes—using SQL commands, simplifying security investigation, compliance monitoring, and incident response | OSQuery Documentation | Trail of Bits Training | FleetDM Lab | Endpoint Monitoring Dashboard | BTLO Prep |
| https://osquery.io/docs | https://github.com/osquery/osquery/tree/master | https://fleetdm.com/ | https://blueteamlabs.online/home | |||
| Velociraptor | Velociraptor DFIR Handbook | Velociraptor DFIR Series | Velociraptor Lab | DFIR Collection Pipeline | GCFA Prep | |
| TheHive | TheHive Documentation | DFIR Science IR Training | TheHive + Cortex Lab | IR Case Management System | GCIH Prep | |
| Cortex XSOAR | SOAR Playbook Guide | XSOAR Fundamentals | XSOAR Community Lab | Automated IR Playbooks | PCNSA Prep | |
| OpenCTI | MITRE ATT&CK TI Guide | MISP + OpenCTI Training | OpenCTI + MISP Lab | Threat Intel Pipeline | CTIA Prep | |
| CrowdStrike Falcon | EDR Guide | CrowdStrike University | LimaCharlie EDR Lab | EDR Telemetry Collector | GCIH Prep | |
| Sysmon + Sigma | Windows Logging Guide | Sigma Rule Writing | Sysmon + ELK Lab | Build Detection Ruleset | BTLO Prep | |
| Wazuh | Wazuh Documentation | Wazuh University | Wazuh + ELK Lab | Build Wazuh SIEM | Security+ Prep | |
🔐 MITRE Caldera
A powerful open-source adversary emulation platform used to simulate attacker behavior, automate red team operations, and test defensive detection capabilities.
Link: https://caldera.mitre.org
🛡️ Metasploit Framework
A widely used penetration testing framework that helps learners understand exploitation techniques, payloads, and vulnerability testing in controlled environments.
Link: https://www.metasploit.com
🔍 Blue Team Labs Online
A free defensive cybersecurity platform offering hands-on labs, incident response challenges, and SOC-style investigations for blue team skill development.
Link: https://blueteamlabs.online
☁️ OWASP Juice Shop
A deliberately vulnerable web application used to teach secure coding, web exploitation, and application security testing.
Link: https://owasp.org/www-project-juice-shop/
🧪 Free Cyber Ranges
A collection of free cyber ranges and virtual labs where learners can practice offensive and defensive techniques in safe, isolated environments.
Links:


