Security operations centre at night with analyst dashboards
About RealCyberWork

We turn cybersecurity knowledge into analyst experience

RealCyberWork is a case-driven cybersecurity training platform that helps aspiring and early-career security professionals move beyond theory and develop the practical judgment required inside a real Security Operations Center.

realcyberwork — investigation shell
soc@realcyberwork:~$ open case CH-2291
severity ....... HIGH
vector ......... credential phishing
recipients ..... 14
soc@realcyberwork:~$ assess --evidence
SPF fail · DKIM none · DMARC p=none
reply-to mismatch detected
soc@realcyberwork:~$ decide
> your call, analyst.

Case-driven

Not task-driven

9 pillars

Per investigation

Playbook

Runs behind the scenes

Portfolio

Proof you can show

The gap

Knowledge is not the bottleneck. Experience is.

Many people complete certifications, bootcamps, courses and labs. They know phishing, SPF, DKIM, DMARC, indicators of compromise, threat intelligence, containment and incident reporting. Yet when a recruiter asks the question below, many candidates struggle to explain what they would do, why, and how they would decide during the investigation.

“Walk me through how you would investigate a suspicious email.”

The problem is not always a lack of knowledge. It is a lack of realistic, repeatable experience. RealCyberWork was created to close that gap.

Our mission

Help people build the confidence, practical skills and investigative mindset required to perform effectively in cybersecurity roles — by placing them inside realistic SOC cases where they review evidence, form hypotheses, extract indicators, determine scope, decide, contain, document and communicate.

Not what phishing is — what it feels like to investigate it.

Why RealCyberWork exists

Traditional training stops where the real work starts

Typical platforms focus on

  • Definitions and theory
  • Multiple-choice questions
  • Guided walkthroughs
  • Tool demonstrations
  • Isolated exercises
  • Capture-the-flag

Valuable, but they do not prepare learners for the uncertainty and responsibility of real security operations.

In a real SOC the analyst must

  • Receive a ticket
  • Work incomplete information
  • Choose what evidence matters
  • Pick the right tools
  • Judge legit / suspicious / malicious
  • Assess who is affected
  • Contain or escalate
  • Write a report others understand

RealCyberWork is built around that reality.

Case-driven, not task-driven

Every investigation starts with a ticket, not a checklist

CASE-01

Suspicious payroll email

CASE-02

Fake invoice request

CASE-03

Business email compromise

CASE-04

Credential-harvesting link

CASE-05

Malicious attachment

CASE-06

QR-code phishing

CASE-07

OAuth consent attack

CASE-08

Thread hijacking

CASE-09

Callback phishing

CASE-10

False positive

The learner must investigate the evidence and decide what the case means. The playbook operates behind the scenes, guiding the experience without turning the investigation into a sequence of obvious answers — so users develop the most important ability in cybersecurity: reducing uncertainty and making defensible decisions.

What users do

From first report to final incident report

01

Triage the message

  • Review the original email
  • Examine sender and recipient information
  • Analyze message headers
  • Interpret SPF, DKIM and DMARC results
  • Trace the email delivery path
  • Identify display-name spoofing
  • Compare From, Reply-To, Return-Path
02

Extract and enrich

  • Extract domains, URLs, IPs, addresses, hashes
  • Analyze suspicious links and attachments
  • Review threat intelligence results
03

Scope the impact

  • Determine whether a link was clicked or a file opened
  • Investigate identity and endpoint activity
  • Assess how many users received the message
  • Classify the attack
04

Decide and report

  • Close, escalate, contain or keep investigating
  • Preserve evidence
  • Build an incident timeline
  • Recommend remediation
  • Write executive and technical reports
  • Explain it in recruiter-style interview mode

The goal is not to memorize the process. The goal is to perform it.

More than a phishing lab

One SOC experience, expanding across domains

Email security

Identity compromise

Endpoint threats

Malware

Business email compromise

Cloud security

SIEM alerts

Network incidents

Insider threats

Threat hunting

Incident response

Digital forensics

receive the incident → investigate the evidence → make the decision → contain the threat → tell the story

Who it is built for

Aspiring and developing analysts

  • Students exploring cybersecurity careers
  • Career changers moving into technology
  • Certification holders who need hands-on confidence
  • Bootcamp graduates preparing for employment
  • Junior SOC analysts seeking practice
  • IT professionals transitioning into security
  • Universities and training organizations
  • Cybersecurity instructors
  • Teams developing entry-level analysts

No two learners begin from the same place. RealCyberWork supports guided beginner cases, advanced practitioner scenarios, independent investigations, interview preparation and structured career progression.

Learning through decisions

Strong analysts are developed through decision-making. A learner should not only know that an email contains a suspicious domain — they should be able to explain:

  • Why the domain is suspicious
  • Whether authentication results change the assessment
  • What additional evidence should be gathered
  • Whether one user or many are affected
  • Whether immediate containment is justified
  • What risks exist if the case is closed too early
  • How findings should be communicated

AI that mentors, not replaces

The AI SOC Mentor supports learning without removing the investigation from the learner. It will:

  • Ask useful investigative questions
  • Highlight possible gaps
  • Provide progressive hints
  • Explain findings in context
  • Review documentation
  • Challenge weak conclusions
  • Improve your reasoning
  • Run interview-style follow-ups

Like a senior analyst guiding a junior — never the answer key.

From investigation to communication

Documentation is part of the investigation

Every case requires you to document

  • What happened
  • What evidence was reviewed
  • What indicators were identified
  • What systems or users were affected
  • What actions were taken
  • Why those actions were appropriate
  • What should happen next

Completed investigations feed an analyst portfolio that demonstrates structured practice, report writing, investigative reasoning and familiarity with SOC workflows.

Interview mode rehearses the real questions

  • Walk me through a phishing investigation.
  • What would you check first?
  • Why can a malicious email still pass SPF or DKIM?
  • How would you determine whether other users were affected?
  • What would you do if credentials were entered?
  • How would you document the incident?
  • When would you escalate?

The bridge we are building

Between education and employment

Education → Employment
Certification → Performance
Theory → Judgment
Tools → Investigation
Learning → Confidence

Aspiring analysts should not have to wait for their first cybersecurity job before they can experience meaningful security operations work. They should be able to practise investigating incidents, making decisions, handling mistakes, documenting evidence and improving their judgment before they enter the workplace.

What we believe

01Practical experience should be accessible
02Cybersecurity training should reflect real work
03Learners should be allowed to make and understand mistakes
04Investigation skills require repetition
05Strong analysts ask good questions
06Tools are useful, but judgment matters more
07Documentation is part of the investigation
08Communication is a technical skill
09AI should strengthen human thinking, not replace it
10Confidence should come from practice, not memorization

Our promise

Realistic, structured and responsible learning: scenarios that challenge without overwhelming, investigation without exposing real systems to harm, and preparation to speak honestly about your capabilities. RealCyberWork does not promise instant expertise — it gives you a place to practise the work, develop the mindset and become more prepared every time you investigate.

Go beyond the lab

Investigate. Decide. Master.