Skip to content
HACKTHESOC
Live SOC simulation

HACK THE SOC

Most training hands you a labelled alert and asks what it is. This hands you the whole feed and asks what's wrong with it.

Real vendor telemetry. A live intrusion buried in ordinary traffic. No hints, no highlighting — you investigate, you decide, you write the report, and it gets marked against what actually happened.

Licensed access · Individual seats and cohort licences for colleges

soc.cryotech.io / live
streaming

Live alert feed

  • 09:47:12CRITICALEncoded PowerShell spawned by WINWORD.EXE
  • 09:47:18HIGHOutbound TLS to telemetry-api-3a8f1.xyz
  • 09:47:30HIGHHKCU\Run key 'WindowsUpdater' created
  • 09:48:02CRITICALLSASS MiniDump via comsvcs.dll
  • 09:51:44HIGHSSO from new ASN, impossible travel
  • 09:54:18HIGHS3 GetObject 184MB customer-exports

Six of these belong to the same intrusion. The rest of the shift doesn't.

Your verdict

True positive
False positive
Escalate to Tier 2

IOC notebook

  • HOSTWS-FIN-3041
  • DOMAINtelemetry-api-3a8f1.xyz
  • USERa.park@cryotech.io
  • TTPT1003.001

Tagged by you, as you read the evidence.

// How a shift runs

Nobody tells you which alert matters

The loop is the same one a Tier-1 analyst runs every day — and it ends the way a real one does, with something you wrote being judged on whether it holds up.

  1. 01

    The feed opens

    Alerts arrive in real time across your tenants. No triage queue, no severity sorting done for you.

  2. 02

    You investigate

    Open events, read raw fields, pivot between hosts and identities, tag what looks like evidence.

  3. 03

    You call it

    True positive, false positive, escalate — and then write the report that justifies the call.

  4. 04

    You're marked

    Graded against ground truth: what the attack really was, which indicators were real, what you missed.

// What's inside

An entire SOC, and the judgement to work in one

The tooling is only half of it. The other half is being made to reason without a safety net, over and over, until it's a habit.

A feed that doesn't tell you where to look

Telemetry streams across several companies at once — overwhelmingly ordinary activity, with a real intrusion moving through it. Nothing is highlighted, nothing is pre-sorted. Finding it is the exercise.

Raw logs, not screenshots of logs

Expand any event and you get the actual field names a vendor emits — winlog.event_data, event_simpleName, aws.cloudtrail. You learn to read the source, not a tidied-up summary of it.

You write the incident report

State the attack, the evidence, and the response in your own words. It's graded against what actually happened — cite an indicator that never appeared in the logs and you'll be told exactly which one you invented.

Investigate like an analyst

Tag indicators as you find them, pivot host to user to session, and build the timeline yourself. The IOC notebook fills up from your own reading of the evidence.

Every technique, in context

MITRE ATT&CK mapping throughout, with plain-language explainers on the tactic, the technique, and why an analyst should care — attached to the alert where it matters, not buried in a reference table.

Structured from zero

Guided rooms that start below networking fundamentals and end at nation-state kill chains. Prerequisites unlock in order, so nothing ever assumes knowledge you weren't taught.

// The telemetry

The field names are the real field names

Every event is modelled on what the product actually emits, down to the schema. When you later open a genuine console, nothing about it is unfamiliar — you have been reading its output all along.

CrowdStrike FalconMicrosoft Defender XDRMicrosoft SentinelSplunkElastic SecurityWazuhCheck PointPalo Alto NetworksFortiGateOktaEntra IDAWS CloudTrailMicrosoft PurviewCisco ISE
EDRProcessRollup2raw fields
event_simpleNameProcessRollup2
ParentBaseFileNameWINWORD.EXE
FileNamepowershell.exe
CommandLine-nop -w hidden -enc SQBFAF...
SHA256HashData9f3a7c12e8b4...d21a
SeverityNameCritical
ComputerNameWS-FIN-3041

// Coverage

From first principles to nation-state

Built as one ordered path, not a library to browse. Each domain assumes only what the path has already taught you.

Endpoint & EDR

Process trees, parent-child anomalies, credential dumping, isolation decisions.

SIEM & Detection

Query languages, rule tuning, correlation, and the false-positive economics of a real SOC.

Identity & Access

Password spray, MFA fatigue, token theft, privileged access, conditional-access failures.

Cloud & Container

AWS, Azure and GCP control-plane abuse, IAM escalation, storage exfiltration, Kubernetes.

Network & Perimeter

Firewall logs, DNS investigation, tunnelling, C2 channels, encrypted-traffic analysis.

Response & Reporting

Playbook execution, escalation judgement, and writing the report a manager can act on.

// Access

One door in

Building an intrusion that survives an analyst's scrutiny takes real work, and it gets rebuilt as the tradecraft moves. Access is licensed, and every seat is a real seat.

Access by code

For colleges, teams & individuals

Every seat lives inside a licensed environment — your college's or your team's. Registration takes one thing: the access code your instructor or admin shares with you.

  • The live SOC console and every attack scenario
  • The full guided curriculum, start to finish
  • AI-graded incident reports with ground-truth feedback
  • A private organisation, isolated from every other tenant
  • Instructor console: assignments, per-student drill-down, exportable grades

Already registered? Sign in · Licensing an environment is arranged directly — talk to us first.