Practice the decisions analysts make every day.

Work through realistic SOC, phishing and attack investigation scenarios in purpose-built consoles. Make the call, submit the evidence, and get graded on the decision you actually made.

Free accounts include one run of each simulator every day. No card required.

Three workflows. One analyst mindset.

Compact, role-focused exercises that mirror the type of decisions analysts make in live security operations.

Detection and triage

SOC Operations

Work a live alert queue, read the telemetry, and assign severity with the impact of your decision reflected in the score.

You set the severity

  • Critical
  • High
  • Medium
  • Low
  • Info

A wrong escalation can cost as much as a missed incident.

Email investigation

Phishing Analysis

Open a sandboxed campaign, inspect headers and redirects, review attachments, and submit the indicators you can defend.

Indicators you extract

  • Domain
  • URL
  • IP Address
  • Email
  • Hash
  • Filename
  • .exe
  • .bat
  • .cmd
  • .scr
  • .ps1
  • .vbs
  • .js
  • .jar
  • .xlsm
  • .docm
  • +6 more

The exercise rewards evidence quality, not guesswork.

Incident reconstruction

Attack Investigation

Piece together logs, alerts, OSINT and network evidence, then map the incident to the stages of the attack lifecycle and to 14 MITRE ATT&CK tactics.

The chain you reconstruct

  1. 1Reconnaissance
  2. 2Weaponization
  3. 3Delivery
  4. 4Exploitation
  5. 5Installation
  6. 6Command & Control
  7. 7Actions on Objectives

Build the sequence, justify the evidence, and identify where the operation changed.

Grading happens on the server. Correct answers are only returned after a decision is committed.

Designed for repeatable, defensible practice

Open the first console.

Start free, then remove the daily limits when you need deeper practice.