
Platform
Everything an analyst touches on a phishing case
One console. Real workflow. No numbered checklist in sight.
Outlook-style viewer with HTML/text toggle, links list, raw source and one-click IOC capture.
Syntax-highlighted raw headers, parsed fields, SPF/DKIM/DMARC cards and a visual delivery route.
Defanged extraction, domain decomposition, simulated redirect chains and reputation cards.
Metadata, hashes, macro and embedded-object status, sandbox summary and process tree.
Central indicator table with defanging, dedupe, confidence, tags and CSV/JSON export.
Simulated VirusTotal, URLScan, AbuseIPDB, Talos, GreyNoise, OTX, Any.Run and Defender TI panels.
Sign-in logs, impossible travel, OAuth grants, inbox rules and session revocation.
EDR alerts, process trees, persistence, PowerShell activity and host isolation.
Similar-message search, click and submission counts, campaign clustering and escalation calls.
Operational choices with confidence, rationale and evidence references — then consequences.
Email, identity, endpoint, network and communication actions, each requiring a rationale.
Auto-captured and uploaded evidence with hashes and chain-of-custody notes.
Chronological incident timeline built automatically from your actions.
Editable report generated from your work, exportable with an IOC list.
Structured observation → tool → finding → evidence → decision notes plus a scratchpad.
Three hint levels that ask questions before they give answers.
Recruiter-style questions with rubric feedback after each closed case.
SOC Intern to Principal Analyst, each level unlocking harder work and less guidance.
