Eight free investigations, each a realistic corpus of hundreds of log events with one attack chain hidden inside. Read the briefing, work the console, pin your evidence, answer the form and get graded per item. No account needed; share your result card when you are done.
Incident Investigation Lab
An endpoint detection fires on a finance workstation at a fictional healthcare company in the middle of a normal working morning. Nobody has reported anything. You get the whole day of logs from seven sources and one question: is the detection real, and if so, how did it start, where did it spread and what left the building? Reconstruct the chain from the first email to the last byte out.
SIEM Lab
A correlation rule wakes the night shift at a fictional freight company: a flood of failed logons against a domain controller, then a success. The alert is the easy part. You have the whole night's telemetry across nine sources and must prove the compromise, work out how the intruder got from the perimeter to the file server, and reconstruct what they did once they had a foothold.
SOC Simulator
The SOAR queue has filled with thirty alerts since the start of the shift at a fictional hybrid-Exchange shop, and only a handful of them tell one story. Work the queue like an analyst: decide what to escalate, what to close and what is a duplicate, then follow the real thread through the raw logs to find patient zero, the blast radius and the one change the attacker made to stay.
EDR Investigation Lab
An endpoint sensor at a fictional ledger company sees something unsigned read the memory of the process that holds every logged-on credential. The detection card gives you a four-process tree. The case gives you the full afternoon of endpoint telemetry: process, file, registry, image-load, network and sensor events. Reconstruct the chain from a document to credential theft and decide what to contain.
Threat Hunting Lab
No alert has fired. A sector intelligence advisory says peers of a fictional financial firm were quietly breached by an actor who favours signed tooling, disguised persistence and deliberately slow beaconing. You get four weeks of telemetry from a handful of treasury workstations and five hypotheses. Pick the ones worth testing, query the corpus, prove or disprove each, and write the detection that would actually hold.
Email Triage Lab
An accounts-payable clerk at a fictional logistics company reports a past-due-invoice email, and her workstation has been running hot ever since. The gateway let the message through despite failing authentication. Work the mailbox corpus: who else received it, who interacted with it, what infrastructure sent it, how any payload would have run, and why the controls that should have stopped it did not.
PCAP Analysis Lab
A network sensor on the OT segment of a fictional municipal utility flags periodic outbound traffic from an engineering workstation that should never talk to the internet, followed hours later by a burst of unusual name lookups. Work a decoded capture of over a thousand packets: confirm or refute the beaconing, find the real exfiltration channel, and quantify what left the plant.
Malware Triage Lab
An endpoint sensor at a fictional robotics company quarantines a binary pretending to be a Windows system process. It carries a valid-looking code signature from a certificate that was revoked months ago. The triage queue mixes its static and sandbox artifacts with a day of ordinary submissions. Separate the sample from the noise, identify the masquerade, confirm the packing, and extract indicators you can block, without running anything.
Every case is the free scenario of its lab. Each lab also has premium scenarios; browse all labs.