
Platform
Everything an analyst touches on a phishing case
One console. Real workflow. No numbered checklist in sight.
Part 1 · Ways in
Three places to start
These are the products you choose between. Pick the one that matches where you are today — each opens the same console at a different depth.
Anyone · 5 minutes · free
AI Email Check
Paste a suspicious email and get a plain-English verdict with the signals behind it.
Beginners · 1–2 hours · free
Guided Training
Learn the four phishing components coached step by step, with every tool explained.
Practitioners · ongoing
Investigations
Work live SOC tickets end to end: evidence, containment decision and incident report.
Part 2 · Inside the console
The workspaces you use once you are in a case
You do not pick these — they are the tabs and tools of the investigation itself, grouped the way the workflow runs.
Evidence workspaces
Where you actually open the artefacts and pull indicators out of them.
Outlook-style viewer with HTML/text toggle, links list, raw source and one-click IOC capture.
Syntax-highlighted raw headers, parsed fields, SPF/DKIM/DMARC cards and a visual delivery route.
Defanged extraction, domain decomposition, simulated redirect chains and reputation cards.
Metadata, hashes, macro and embedded-object status, sandbox summary and process tree.
Central indicator table with defanging, dedupe, confidence, tags and CSV/JSON export.
Simulated VirusTotal, URLScan, AbuseIPDB, Talos, GreyNoise, OTX, Any.Run and Defender TI panels.
Pivots and scope
Follow the evidence past the mailbox into identity, endpoint and the wider campaign.
Sign-in logs, impossible travel, OAuth grants, inbox rules and session revocation.
EDR alerts, process trees, persistence, PowerShell activity and host isolation.
Similar-message search, click and submission counts, campaign clustering and escalation calls.
Decide and contain
The part quizzes skip: operational calls with consequences attached.
Operational choices with confidence, rationale and evidence references — then consequences.
Email, identity, endpoint, network and communication actions, each requiring a rationale.
Auto-captured and uploaded evidence with hashes and chain-of-custody notes.
Record and report
Everything you did, written up the way a SOC expects to receive it.
Chronological incident timeline built automatically from your actions.
Editable report generated from your work, exportable with an IOC list.
Structured observation → tool → finding → evidence → decision notes plus a scratchpad.
Coaching and career
Support while you learn, and proof of the work afterwards.
Three hint levels that ask questions before they give answers.
Recruiter-style questions with rubric feedback after each closed case.
SOC Intern to Principal Analyst, each level unlocking harder work and less guidance.
