Learn the SOC by working the SOC.
Module 0 plus nine self-paced days built from realistic, production-shaped tickets - search real logs, triage real alerts across four EDR vendors, and write the escalation a senior analyst would actually accept.
Every scenario traces back to realistic, production-shaped alerts - not textbook examples.
Once you've done a day slow and careful, run it again against the clock, the way the floor actually feels.
Progress, activity, and scores update in real time - no status-update meetings needed.
Every organization gets its own recruits, invite link, and manager dashboard - fully isolated from every other tenant.
Module 0, then nine graded days.
Every day ends in an artifact your manager can grade - a verdict, a query, a written escalation.
EDR/XDR, SIEM, Mail Relay, Identity & Cloud - four field guides, five questions each.
Read five real-shaped tickets. Call the verdict.
Search a raw log console, then write real queries against a live console and translate them across SIEMs.
Look up every IOC yourself before you call a verdict.
CrowdStrike, SentinelOne, Trend Micro, Defender - pick the right console.
Search the sign-in console before you trust any single login.
Reconstruct a full intrusion path from beacon to domain controller.
Write the escalation a senior would accept with no follow-up questions.
Decide what to tune, hunt down a file with no alert pointing at it, and map alerts to MITRE ATT&CK.
Two connected incidents, back-to-back, each with its own full report. The final evaluation.
Before you start.
Nine program days at roughly 6.5 hours each, self-paced - most recruits finish across about two weeks.
Every exercise has a model answer you can reveal once you've made a real attempt. No penalty for checking.
No - drills and the customer-scenario practice are bonus reps, kept separate from your graded score.
Yes, live. That's by design - progress updates on their dashboard as you work, no status meetings needed.