foyl Learn · foyl Drills

Short reps.
Sharp instincts.

Drills are scored, replayable exercises built around one analyst reflex at a time: triage a live queue, spot the red flags inside a phish, grep evidence out of raw logs, rebuild an attack timeline. No reading, no lectures - you make the calls and the drill tells you why you were right or wrong.

20 drills live Scored · replayable · best score saved foyl SecIntel
01
Make the call Every round puts one decision in front of you: escalate or dismiss, phish or legit, which log line, which order. No multiple-choice trivia - the evidence is on the screen.
02
Get the why immediately Right or wrong, the drill explains the tell you should have keyed on before the next round is dealt. Streaks reward consistency, misses cost accuracy.
03
Beat your best Your score is saved to your profile and your personal best never regresses. Drills count toward learning paths and class syllabi, and rounds are shuffled so replays stay honest.
01Alert Triage
Ten alerts hit your queue one at a time. Read the entities and the raw event, then make the tier-1 call: escalate, dismiss as benign, or tune the noisy rule.
SOC Tier 1 10 rounds
~10 MINRun drill →
02Spot the Phish
Messages rendered exactly as the user saw them. Click the red flags hiding in senders, links, and attachments, then call it: quarantine or release. One is legitimate.
SOC Tier 1 4 messages
~10 MINRun drill →
03Log Hunt
A live grep bar over hundreds of raw log lines. Find the spray, the webshell, and the beacon, then click the exact line that proves each one.
SOC Tier 1-2 3 hunts
~15 MINRun drill →
04Kill Chain Builder
Real incident evidence, shuffled. Drag each event onto the kill-chain stage where it belongs and rebuild what happened, from delivery to exfiltration.
SOC Tier 2 2 incidents
~15 MINRun drill →
05Imposter Hunt
Five artifacts, one imposter. Spot the typosquat, the homoglyph, the double extension, or the subdomain trick before it fools someone in Finance.
SOC Tier 1 8 rounds
~8 MINRun drill →
06Containment Call
A live incident advances one update at a time. At each decision point, pick the containment move that stops the attacker without destroying evidence or the business.
SOC Tier 2 2 incidents
~12 MINRun drill →
07Work the Queue
Five tickets, one shift. Drag them into the order you would actually work them - severity, SLA clocks, and asset criticality all pull in different directions.
SOC Tier 1 3 rounds
~10 MINRun drill →
08Access Review
Six accounts, their roles, and every grant they hold. Click the permissions that violate least privilege - and know when to leave a clean account alone.
IAM / GRC 6 accounts
~10 MINRun drill →
09KQL Hunt
Build the query, land the hunt. Assemble Kusto (KQL) pipelines clause by clause over SecIntel telemetry - the exact operators analysts write in Sentinel and Defender - then run them.
Detection Eng 4 hunts
~15 MINRun drill →
10Pattern Match
Write the regex that catches every bad string and none of the good ones. Live-tested pattern building over real artifacts - IPs, log lines, encoded commands, DGA domains.
Detection Eng 5 patterns
~10 MINRun drill →
11Decode the Payload
Peel back the obfuscation. Base64, hex, and URL layers hide real attacker payloads - decode each one, then say what it actually does. Four artifacts from the casebook.
SOC Tier 1-2 4 artifacts
~10 MINRun drill →
12Score the Vuln
Read the vulnerability, build the CVSS v3.1 vector, land the right severity. Five findings from the exposure queue - the reasoning that decides what gets patched first.
VM / GRC 5 findings
~12 MINRun drill →
13Process Tree Hunt
Follow five endpoint lineages and find the exact edge where signed Windows tools become script execution, beaconing, and persistence.
SOC Tier 25 trees
~10 MINRun drill →
14Sign-in Risk
Separate token replay from travel, VPN use, password noise, and ordinary authentication behavior across five identity evidence sets.
Identity / IR5 sign-ins
~10 MINRun drill →
15Header Trace
Trace authentication results, reply paths, Received hops, and registered domains to prove which sender identity can be trusted.
Email Security5 messages
~8 MINRun drill →
16IOC Pivot
Move from one phishing domain through passive DNS, certificates, internal telemetry, confidence, and confirmed impact.
Threat Intel5 pivots
~12 MINRun drill →
17Sigma Builder
Assemble portable rule logic for Office child processes, rundll32 script protocols, logon tasks, tuning, and correlation.
Detection Eng5 rules
~12 MINRun drill →
18Packet Triage
Call beaconing, DNS staging, approved backups, ambiguous browser flows, and cloud collection from compact network evidence.
Network Defense5 flows
~10 MINRun drill →
19Evidence Locker
Collect defensible exhibits, preserve volatile data, maintain chain of custody, check integrity, and separate facts from claims.
Incident Response5 exhibits
~10 MINRun drill →
20Scope the Incident
Classify confirmed, exposed, and unrelated entities while the SILENT DELEGATE blast radius grows across four control planes.
Incident Response5 scope calls
~12 MINRun drill →