Your first week on the team. Ed promised you'd have time to settle in - that lasted about an hour. A routine phishing report just escalated into something bigger. Work alongside a real SOC team, investigate real evidence, and think like an analyst — not a test-taker.

Over 3-4 hours, go from watching the team work to working alongside them — learning SOC fundamentals through a single incident from first alert to containment.
Monday, 8:47 AM. Your first shift, and Ed says it's a quiet week. Tess sits with you on your first reported email. The next one is yours alone.
Tuesday, 9:55 AM. Yesterday's Finance alert is your first ticket: three copies of one supplier invoice. Read it, look it up, and find out how far it went.
Tuesday, 2:45 PM. The watch on j.doe's account just reported a VPN session. Find out who it was, what they did, and where they came from.
Wednesday, 9:00 AM. A Finance colleague forwards a note that looks like it came from j.doe and asks if it is real. Every check passes. Follow it from an inbox to a machine.
Thursday, 7:30 AM. IT worked the ticket overnight. Before anything comes back online, check their work: the scope, the machine, and the campaign.

@epiclead
15-year security veteran who started at help desk and worked his way up. Leads by example, not ego. When Ed says 'we've got this,' everyone believes it.

@techstack
10-year SOC veteran and technical mastermind. She architects the detection logic and knows every tool in the stack inside out.

@spfhardfail
Former email admin turned security analyst. She can spot a spoofed header from a mile away.

@campaigntrail
Always has the latest threat feeds at his fingertips. His contextual intel often breaks cases wide open.
Get looped in on what happened, from the people who caught it.
Analyze real evidence — emails, logs, endpoints, threat intel — and make the calls a real analyst would.
See how your read on the incident compares, and what happens next.
No setup, no VMs, nothing to install. 5 episodes, 25–50 minutes each.
Season 0 is free, no credit card required. See what it's like to think like a SOC analyst.