Dark SOC dashboards glowing emerald

Platform

Everything an analyst touches on a phishing case

One console. Real workflow. No numbered checklist in sight.

Part 2 · Inside the console

The workspaces you use once you are in a case

You do not pick these — they are the tabs and tools of the investigation itself, grouped the way the workflow runs.

01

Evidence workspaces

Where you actually open the artefacts and pull indicators out of them.

Email workspace

Outlook-style viewer with HTML/text toggle, links list, raw source and one-click IOC capture.

Header analysis

Syntax-highlighted raw headers, parsed fields, SPF/DKIM/DMARC cards and a visual delivery route.

URL analysis

Defanged extraction, domain decomposition, simulated redirect chains and reputation cards.

Attachment analysis

Metadata, hashes, macro and embedded-object status, sandbox summary and process tree.

IOC board

Central indicator table with defanging, dedupe, confidence, tags and CSV/JSON export.

Threat intel hub

Simulated VirusTotal, URLScan, AbuseIPDB, Talos, GreyNoise, OTX, Any.Run and Defender TI panels.

02

Pivots and scope

Follow the evidence past the mailbox into identity, endpoint and the wider campaign.

Identity investigation

Sign-in logs, impossible travel, OAuth grants, inbox rules and session revocation.

Endpoint investigation

EDR alerts, process trees, persistence, PowerShell activity and host isolation.

Scope workspace

Similar-message search, click and submission counts, campaign clustering and escalation calls.

03

Decide and contain

The part quizzes skip: operational calls with consequences attached.

Decision center

Operational choices with confidence, rationale and evidence references — then consequences.

Containment center

Email, identity, endpoint, network and communication actions, each requiring a rationale.

Evidence locker

Auto-captured and uploaded evidence with hashes and chain-of-custody notes.

04

Record and report

Everything you did, written up the way a SOC expects to receive it.

Timeline

Chronological incident timeline built automatically from your actions.

Incident report

Editable report generated from your work, exportable with an IOC list.

Analyst notebook

Structured observation → tool → finding → evidence → decision notes plus a scratchpad.

05

Coaching and career

Support while you learn, and proof of the work afterwards.

AI SOC mentor

Three hint levels that ask questions before they give answers.

Interview mode

Recruiter-style questions with rubric feedback after each closed case.

Career mode

SOC Intern to Principal Analyst, each level unlocking harder work and less guidance.