Season 0 is completely free

Your first week was supposed to be easy.

Your first week on the team. Ed promised you'd have time to settle in - that lasted about an hour. A routine phishing report just escalated into something bigger. Work alongside a real SOC team, investigate real evidence, and think like an analyst — not a test-taker.

5 Episodes
15 Challenges
3-4 hours
Season Zero: Fundamentals

Five episodes. One incident that keeps getting worse.

Over 3-4 hours, go from watching the team work to working alongside them — learning SOC fundamentals through a single incident from first alert to containment.

First Day
Episode 1
30-40 min

First Day

Monday, 8:47 AM. Your first shift, and Ed says it's a quiet week. Tess sits with you on your first reported email. The next one is yours alone.

Email Analysis
Inbox Zero
Episode 2
40-50 min

Inbox Zero

Tuesday, 9:55 AM. Yesterday's Finance alert is your first ticket: three copies of one supplier invoice. Read it, look it up, and find out how far it went.

Email Analysis
Threat Intelligence
Log/SIEM Analysis
Follow the Thread
Episode 3
40-50 min

Follow the Thread

Tuesday, 2:45 PM. The watch on j.doe's account just reported a VPN session. Find out who it was, what they did, and where they came from.

Log/SIEM Analysis
Threat Intelligence
Lateral
Episode 4
40-50 min

Lateral

Wednesday, 9:00 AM. A Finance colleague forwards a note that looks like it came from j.doe and asks if it is real. Every check passes. Follow it from an inbox to a machine.

Email Analysis
Log/SIEM Analysis
Endpoint Investigation
Containment
Episode 5
40-50 min

Containment

Thursday, 7:30 AM. IT worked the ticket overnight. Before anything comes back online, check their work: the scope, the machine, and the campaign.

Log/SIEM Analysis
Endpoint Investigation
Threat Intelligence

Meet the team you're joining

Ed Mercer

Ed Mercer

@epiclead

SOC Lead

15-year security veteran who started at help desk and worked his way up. Leads by example, not ego. When Ed says 'we've got this,' everyone believes it.

Mara Vance

Mara Vance

@techstack

Tech Lead

10-year SOC veteran and technical mastermind. She architects the detection logic and knows every tool in the stack inside out.

Tess Harrow

Tess Harrow

@spfhardfail

Email Specialist

Former email admin turned security analyst. She can spot a spoofed header from a mile away.

Eli Navarro

Eli Navarro

@campaigntrail

Threat Intel

Always has the latest threat feeds at his fingertips. His contextual intel often breaks cases wide open.

What you'll actually learn

Navigate a SOC environment and understand team roles
Analyze phishing emails and extract IOCs
Correlate SIEM logs to build attack timelines
Identify lateral movement through authentication logs
Investigate endpoints for persistence mechanisms
Participate in incident containment and documentation

How it works

1. Briefing

Get looped in on what happened, from the people who caught it.

2. Investigate

Analyze real evidence — emails, logs, endpoints, threat intel — and make the calls a real analyst would.

3. Debrief

See how your read on the incident compares, and what happens next.

No setup, no VMs, nothing to install. 5 episodes, 25–50 minutes each.

Ready to start your first investigation?

Season 0 is free, no credit card required. See what it's like to think like a SOC analyst.

SOC Analyst Training Adventures | Learn by Investigating Real Incidents | EpicDetect