Training mode — all data simulated, all indicators defanged
RealCyberWork SOC dashboard with investigation modules

RealCyberWork SOC Console

Train like a phishing investigator

Triage tickets, investigate suspected emails, document tool evidence and build a résumé-ready analyst record.

Console / Dashboard

Good morning, analyst

Tier 2 Analyst · 4 items in your queue · 2 approaching SLA

Analyst level
Tier 2
4,820 XP · 62% to next
Open assignments
3
Assigned to you
SLA risk
6
< 60 minutes remaining
Investigation confidence
74%
30-day average
Evidence coverage
68%
Across closed cases

Today's SOC queue

View all

Weekly performance

Common analyst mistakes (cohort)

Recent IOCs

defanged
email
admin[at]serbiagotcold[.]wikiMalicious
email
payroll[.]verify[at]mailbox-secure[.]clickMalicious
domain
payroll-corp-notices[.]comMalicious
url
https://payroll-corp-notices[.]com/verify?u=ah8821Malicious
ip
91[.]240[.]118[.]203Suspicious

Active investigations

Threat Intel

More

Recommended next case

OAuth Consent Phishing

Your identity workspace coverage is 55%. This case is built around OAuth consent abuse.

Open case

Daily challenge

Close two cases with evidence coverage above 80% before end of shift.

1 / 2 complete · +250 XP

Career progression

Tier 2 Analyst4,820 XP

3,180 XP to Incident Responder — unlocks containment authority.

View career map

Recent achievements

First BloodClosed your first case
Header Hound10 header analyses completed
Chain of CustodyPreserved evidence in 5 cases

Recent incident reports

RPT-0119Thread Hijack — Invoice 447192
RPT-0118MFA Fatigue Follow-On88
RPT-0117Fake SharePoint Share76
RPT-0116Malicious Macro Document81

Saved email checks

Payroll Adjustment — Q3 Bonus
Your subscription renews today
Contract_Amendment_Final.pdf

Mentor tip

Two of your last five cases were closed before checking recipient scope. Ask "who else got this?" before you classify.

SLA watch

INC-2026-048100:42
INC-2026-048300:12
INC-2026-048600:33
INC-2026-049100:55
INC-2026-049400:40
INC-2026-049500:25