01Alert Triage→
Ten alerts hit your queue one at a time. Read the entities and the raw event, then make the tier-1 call: escalate, dismiss as benign, or tune the noisy rule.
~10 MINRun drill →
02Spot the Phish→
Messages rendered exactly as the user saw them. Click the red flags hiding in senders, links, and attachments, then call it: quarantine or release. One is legitimate.
~10 MINRun drill →
03Log Hunt→
A live grep bar over hundreds of raw log lines. Find the spray, the webshell, and the beacon, then click the exact line that proves each one.
~15 MINRun drill →
04Kill Chain Builder→
Real incident evidence, shuffled. Drag each event onto the kill-chain stage where it belongs and rebuild what happened, from delivery to exfiltration.
~15 MINRun drill →
05Imposter Hunt→
Five artifacts, one imposter. Spot the typosquat, the homoglyph, the double extension, or the subdomain trick before it fools someone in Finance.
~8 MINRun drill →
06Containment Call→
A live incident advances one update at a time. At each decision point, pick the containment move that stops the attacker without destroying evidence or the business.
~12 MINRun drill →
07Work the Queue→
Five tickets, one shift. Drag them into the order you would actually work them - severity, SLA clocks, and asset criticality all pull in different directions.
~10 MINRun drill →
08Access Review→
Six accounts, their roles, and every grant they hold. Click the permissions that violate least privilege - and know when to leave a clean account alone.
~10 MINRun drill →
09KQL Hunt→
Build the query, land the hunt. Assemble Kusto (KQL) pipelines clause by clause over SecIntel telemetry - the exact operators analysts write in Sentinel and Defender - then run them.
~15 MINRun drill →
10Pattern Match→
Write the regex that catches every bad string and none of the good ones. Live-tested pattern building over real artifacts - IPs, log lines, encoded commands, DGA domains.
~10 MINRun drill →
11Decode the Payload→
Peel back the obfuscation. Base64, hex, and URL layers hide real attacker payloads - decode each one, then say what it actually does. Four artifacts from the casebook.
~10 MINRun drill →
12Score the Vuln→
Read the vulnerability, build the CVSS v3.1 vector, land the right severity. Five findings from the exposure queue - the reasoning that decides what gets patched first.
~12 MINRun drill →
13Process Tree Hunt→
Follow five endpoint lineages and find the exact edge where signed Windows tools become script execution, beaconing, and persistence.
~10 MINRun drill →
14Sign-in Risk→
Separate token replay from travel, VPN use, password noise, and ordinary authentication behavior across five identity evidence sets.
~10 MINRun drill →
15Header Trace→
Trace authentication results, reply paths, Received hops, and registered domains to prove which sender identity can be trusted.
~8 MINRun drill →
16IOC Pivot→
Move from one phishing domain through passive DNS, certificates, internal telemetry, confidence, and confirmed impact.
~12 MINRun drill →
17Sigma Builder→
Assemble portable rule logic for Office child processes, rundll32 script protocols, logon tasks, tuning, and correlation.
~12 MINRun drill →
18Packet Triage→
Call beaconing, DNS staging, approved backups, ambiguous browser flows, and cloud collection from compact network evidence.
~10 MINRun drill →
19Evidence Locker→
Collect defensible exhibits, preserve volatile data, maintain chain of custody, check integrity, and separate facts from claims.
~10 MINRun drill →
20Scope the Incident→
Classify confirmed, exposed, and unrelated entities while the SILENT DELEGATE blast radius grows across four control planes.
~12 MINRun drill →