Training mode — all data simulated, all indicators defanged

Your order of work — learn it, pick one, work it

RealCyberWork SOC Console

Train like a phishing investigator

Triage tickets, investigate suspected emails, document tool evidence and build a résumé-ready analyst record.

Open SOC queue

Good morning, analyst

New here? Follow the four steps below — you'll be working a real ticket in minutes.

Your path

Step 1 of 4Check an email

Paste a suspicious email and read the verdict. Two minutes, no account.

Check an email
  1. 1Check an email

    Paste a suspicious email and read the verdict. Two minutes, no account.

  2. 2Learn the components

    See what a header, link, attachment and message body actually tell you.

  3. 3Work your first ticket

    Pick a reported email from the queue and investigate it yourself.

  4. 4Write the report

    Say what happened, what you found and what should be done about it.

A is the team that deals with attacks as they happen. This console is a safe copy of one. Staff report emails they think are dodgy, those reports land in a queue, and you pick one up and find out what it really is.

Nothing here can hurt anyone: every link, file and address is defanged, and dangerous artefacts only open inside a .

01

You get a reported email

Someone in the company forwarded something suspicious. You read what they said happened.

02

You gather proof

Open the header, check the link, look up the sender's domain. You record what each tool told you.

03

You make the call

Safe, phishing or something worse — then say what should be blocked, reset or removed.

Your first ticket

Start with a low-risk case and take your time

You'll read the report, look at the email, use a few free public tools, then write down what you found. There is no wrong first move — the clock is only there for realism and nothing is graded against you.

Analyst level
Tier 2
4,820 XP · 62% to next
Cases you're working on
0
Assigned to you
Running out of time
4
Less than 60 minutes left
How sure you were
74%
Average confidence, last 30 days
How complete your evidence was
68%
Across cases you closed

Today's SOC queue

View all

Weekly performance

Common analyst mistakes (cohort)

Recent IOCs

defanged
email
admin[at]serbiagotcold[.]wikiMalicious
email
payroll[.]verify[at]mailbox-secure[.]clickMalicious
domain
payroll-corp-notices[.]comMalicious
url
https://payroll-corp-notices[.]com/verify?u=ah8821Malicious
ip
91[.]240[.]118[.]203Suspicious

Active investigations

Nothing assigned right now.

Threat Intel

More

Recommended next case

OAuth Consent Phishing

Your identity workspace coverage is 55%. This case is built around OAuth consent abuse.

Open case

Daily challenge

Close two cases with evidence coverage above 80% before end of shift.

1 / 2 complete · +250 XP

Career progression

Tier 2 Analyst4,820 XP

3,180 XP to Incident Responder — unlocks containment authority.

View career map

Recent achievements

First BloodClosed your first case
Header Hound10 header analyses completed
Chain of CustodyPreserved evidence in 5 cases

Recent incident reports

RPT-0119Thread Hijack — Invoice 447192
RPT-0118MFA Fatigue Follow-On88
RPT-0117Fake SharePoint Share76
RPT-0116Malicious Macro Document81

Saved email checks

Payroll Adjustment — Q3 Bonus
Your subscription renews today
Contract_Amendment_Final.pdf

Mentor tip

Two of your last five cases were closed before checking recipient scope. Ask "who else got this?" before you classify.

SLA watch

INC-19700101-0300:26
INC-19700101-0700:52
INC-19700101-0800:45
INC-19700101-1600:21