

RealCyberWork SOC Console
Triage tickets, investigate suspected emails, document tool evidence and build a résumé-ready analyst record.
New here? Follow the four steps below — you'll be working a real ticket in minutes.
Your path
Paste a suspicious email and read the verdict. Two minutes, no account.
Paste a suspicious email and read the verdict. Two minutes, no account.
See what a header, link, attachment and message body actually tell you.
Pick a reported email from the queue and investigate it yourself.
Say what happened, what you found and what should be done about it.
A is the team that deals with attacks as they happen. This console is a safe copy of one. Staff report emails they think are dodgy, those reports land in a queue, and you pick one up and find out what it really is.
Nothing here can hurt anyone: every link, file and address is defanged, and dangerous artefacts only open inside a .
Someone in the company forwarded something suspicious. You read what they said happened.
Open the header, check the link, look up the sender's domain. You record what each tool told you.
Safe, phishing or something worse — then say what should be blocked, reset or removed.
Your first ticket
You'll read the report, look at the email, use a few free public tools, then write down what you found. There is no wrong first move — the clock is only there for realism and nothing is graded against you.
Nothing assigned right now.
AiTM phishing kits remain the dominant credential-theft path
Your identity workspace coverage is 55%. This case is built around OAuth consent abuse.
Open caseClose two cases with evidence coverage above 80% before end of shift.
1 / 2 complete · +250 XP
3,180 XP to Incident Responder — unlocks containment authority.
View career mapTwo of your last five cases were closed before checking recipient scope. Ask "who else got this?" before you classify.