LetsDefend
Simulated SOC training platform where learners investigate realistic alerts in a blue team workflow.
Technical Architecture & Overview
LetsDefend places learners in a simulated security operations center where alerts arrive as tickets and investigations run against emulated endpoint, email, and log artifacts. Learning paths map to SOC analyst and DFIR roles with MITRE ATT&CK coverage, and a free tier provides access to starter content. Hack The Box acquired LetsDefend in September 2025, so branding and platform integration may change over time.
Targeted Technical Use Cases
Blue team learners who want alert triage practice that mirrors real SOC workflows.
Evaluation & Trade-offs
Core Strengths
- +Ticket-based workflow replicates SOC reality.
- +Artifacts are emulated inside the platform, no VMs needed.
- +Role-based learning paths.
Trade-Offs & Limitations
- -Content depth trails what a live SOC generates.
- -Ownership transition may change access or pricing.
Defensive Security Application
Training analysts in alert triage, escalation judgment, and investigation documentation.
Frequently Asked Questions
What is LetsDefend?→
LetsDefend places learners in a simulated security operations center where alerts arrive as tickets and investigations run against emulated endpoint, email, and log artifacts. Learning paths map to SOC analyst and DFIR roles with MITRE ATT&CK coverage, and a free tier provides access to starter content. Hack The Box acquired LetsDefend in September 2025, so branding and platform integration may change over time.
What is LetsDefend used for?→
Blue team learners who want alert triage practice that mirrors real SOC workflows.
What are the strengths of LetsDefend?→
- +Ticket-based workflow replicates SOC reality.
- +Artifacts are emulated inside the platform, no VMs needed.
- +Role-based learning paths.
What are the limitations of LetsDefend?→
- +Content depth trails what a live SOC generates.
- +Ownership transition may change access or pricing.
How is LetsDefend used defensively?→
Training analysts in alert triage, escalation judgment, and investigation documentation.