
We turn cybersecurity knowledge into analyst experience
RealCyberWork is a case-driven cybersecurity training platform that helps aspiring and early-career security professionals move beyond theory and develop the practical judgment required inside a real Security Operations Center.
soc@realcyberwork:~$ open case CH-2291severity ....... HIGHvector ......... credential phishingrecipients ..... 14soc@realcyberwork:~$ assess --evidenceSPF fail · DKIM none · DMARC p=nonereply-to mismatch detectedsoc@realcyberwork:~$ decide> your call, analyst.
Case-driven
Not task-driven
9 pillars
Per investigation
Playbook
Runs behind the scenes
Portfolio
Proof you can show
The gap
Knowledge is not the bottleneck. Experience is.
Many people complete certifications, bootcamps, courses and labs. They know phishing, SPF, DKIM, DMARC, indicators of compromise, threat intelligence, containment and incident reporting. Yet when a recruiter asks the question below, many candidates struggle to explain what they would do, why, and how they would decide during the investigation.
“Walk me through how you would investigate a suspicious email.”
The problem is not always a lack of knowledge. It is a lack of realistic, repeatable experience. RealCyberWork was created to close that gap.
Our mission
Help people build the confidence, practical skills and investigative mindset required to perform effectively in cybersecurity roles — by placing them inside realistic SOC cases where they review evidence, form hypotheses, extract indicators, determine scope, decide, contain, document and communicate.
Not what phishing is — what it feels like to investigate it.
Why RealCyberWork exists
Traditional training stops where the real work starts
Typical platforms focus on
- Definitions and theory
- Multiple-choice questions
- Guided walkthroughs
- Tool demonstrations
- Isolated exercises
- Capture-the-flag
Valuable, but they do not prepare learners for the uncertainty and responsibility of real security operations.
In a real SOC the analyst must
- Receive a ticket
- Work incomplete information
- Choose what evidence matters
- Pick the right tools
- Judge legit / suspicious / malicious
- Assess who is affected
- Contain or escalate
- Write a report others understand
RealCyberWork is built around that reality.
Case-driven, not task-driven
Every investigation starts with a ticket, not a checklist
Suspicious payroll email
Fake invoice request
Business email compromise
Credential-harvesting link
Malicious attachment
QR-code phishing
OAuth consent attack
Thread hijacking
Callback phishing
False positive
The learner must investigate the evidence and decide what the case means. The playbook operates behind the scenes, guiding the experience without turning the investigation into a sequence of obvious answers — so users develop the most important ability in cybersecurity: reducing uncertainty and making defensible decisions.
What users do
From first report to final incident report
Triage the message
- Review the original email
- Examine sender and recipient information
- Analyze message headers
- Interpret SPF, DKIM and DMARC results
- Trace the email delivery path
- Identify display-name spoofing
- Compare From, Reply-To, Return-Path
Extract and enrich
- Extract domains, URLs, IPs, addresses, hashes
- Analyze suspicious links and attachments
- Review threat intelligence results
Scope the impact
- Determine whether a link was clicked or a file opened
- Investigate identity and endpoint activity
- Assess how many users received the message
- Classify the attack
Decide and report
- Close, escalate, contain or keep investigating
- Preserve evidence
- Build an incident timeline
- Recommend remediation
- Write executive and technical reports
- Explain it in recruiter-style interview mode
The goal is not to memorize the process. The goal is to perform it.
More than a phishing lab
One SOC experience, expanding across domains
Email security
Identity compromise
Endpoint threats
Malware
Business email compromise
Cloud security
SIEM alerts
Network incidents
Insider threats
Threat hunting
Incident response
Digital forensics
Who it is built for
Aspiring and developing analysts
- Students exploring cybersecurity careers
- Career changers moving into technology
- Certification holders who need hands-on confidence
- Bootcamp graduates preparing for employment
- Junior SOC analysts seeking practice
- IT professionals transitioning into security
- Universities and training organizations
- Cybersecurity instructors
- Teams developing entry-level analysts
No two learners begin from the same place. RealCyberWork supports guided beginner cases, advanced practitioner scenarios, independent investigations, interview preparation and structured career progression.
Learning through decisions
Strong analysts are developed through decision-making. A learner should not only know that an email contains a suspicious domain — they should be able to explain:
- Why the domain is suspicious
- Whether authentication results change the assessment
- What additional evidence should be gathered
- Whether one user or many are affected
- Whether immediate containment is justified
- What risks exist if the case is closed too early
- How findings should be communicated
AI that mentors, not replaces
The AI SOC Mentor supports learning without removing the investigation from the learner. It will:
- Ask useful investigative questions
- Highlight possible gaps
- Provide progressive hints
- Explain findings in context
- Review documentation
- Challenge weak conclusions
- Improve your reasoning
- Run interview-style follow-ups
Like a senior analyst guiding a junior — never the answer key.
From investigation to communication
Documentation is part of the investigation
Every case requires you to document
- What happened
- What evidence was reviewed
- What indicators were identified
- What systems or users were affected
- What actions were taken
- Why those actions were appropriate
- What should happen next
Completed investigations feed an analyst portfolio that demonstrates structured practice, report writing, investigative reasoning and familiarity with SOC workflows.
Interview mode rehearses the real questions
- “Walk me through a phishing investigation.”
- “What would you check first?”
- “Why can a malicious email still pass SPF or DKIM?”
- “How would you determine whether other users were affected?”
- “What would you do if credentials were entered?”
- “How would you document the incident?”
- “When would you escalate?”
The bridge we are building
Between education and employment
Aspiring analysts should not have to wait for their first cybersecurity job before they can experience meaningful security operations work. They should be able to practise investigating incidents, making decisions, handling mistakes, documenting evidence and improving their judgment before they enter the workplace.
What we believe
Our promise
Realistic, structured and responsible learning: scenarios that challenge without overwhelming, investigation without exposing real systems to harm, and preparation to speak honestly about your capabilities. RealCyberWork does not promise instant expertise — it gives you a place to practise the work, develop the mindset and become more prepared every time you investigate.
Go beyond the lab
Investigate. Decide. Master.
