SOC Operations
Work a live alert queue, read the telemetry, and assign severity with the impact of your decision reflected in the score.
You set the severity
- Critical
- High
- Medium
- Low
- Info
A wrong escalation can cost as much as a missed incident.
Work through realistic SOC, phishing and attack investigation scenarios in purpose-built consoles. Make the call, submit the evidence, and get graded on the decision you actually made.
Free accounts include one run of each simulator every day. No card required.
Compact, role-focused exercises that mirror the type of decisions analysts make in live security operations.
Work a live alert queue, read the telemetry, and assign severity with the impact of your decision reflected in the score.
You set the severity
A wrong escalation can cost as much as a missed incident.
Open a sandboxed campaign, inspect headers and redirects, review attachments, and submit the indicators you can defend.
Indicators you extract
The exercise rewards evidence quality, not guesswork.
Piece together logs, alerts, OSINT and network evidence, then map the incident to the stages of the attack lifecycle and to 14 MITRE ATT&CK tactics.
The chain you reconstruct
Build the sequence, justify the evidence, and identify where the operation changed.
Start free, then remove the daily limits when you need deeper practice.