foyl Learn · foyl Labs

Guided scenarios.
Real attack chains.

Each lab walks you through a realistic security scenario using the foyl Mock tools. No hand-holding — you get a brief, the tools, and a problem to solve.

5 scenarios staged 1 coming soon Ficsit Inc. · Pioneer Division
01
Read the brief Each lab starts with a scenario summary — what's happened, what you have access to, and what you need to deliver.
02
Use the tools Navigate to the linked foyl Mock tools. The data is already loaded. Investigate, hunt, and respond as you would in a real SOC.
03
Build your findings Document your timeline, conclusions, and containment steps. A reference answer is provided at the end of each scenario.
01
Incident Response
A finance executive receives a convincing phishing email. Their credentials are captured via an AiTM proxy. The attacker authenticates with a valid session token, bypasses MFA, and begins lateral movement toward the domain controller. Your job: detect, contain, document.
SOC Tier 1 45 min IRON CHIMNEY T1566 · T1078 · T1021
SIEM EDR Identity SOAR
Begin lab →
02
Log Analysis
You receive a batch of raw logs: authentication events, web requests, and endpoint telemetry from a 72-hour window. Something happened. Your job is to find it — build a timeline from noise, identify the initial vector, and trace the attacker's path through the environment.
SOC Tier 1 30 min T1059 · T1105
SIEM
Begin lab →
03
Threat Lab
A suspicious process drops an unknown binary on a finance workstation. You have the EDR telemetry, a handful of IOCs, and access to the threat intelligence platform. Identify the malware family, map it to a known actor, pivot on infrastructure, and brief the incident team.
SOC Tier 2 60 min T1055 · T1071 · T1041
TIP EDR SIEM
Begin lab →
04
Vulnerability Management
Your quarterly scan just completed and dropped 340 findings across 47 assets. Leadership wants to know: what's on fire, what can wait, and what's your 30-day remediation plan? Prioritize using CVSS, EPSS, and asset criticality — then build the remediation ticket queue.
SOC Tier 2 40 min CVSS 9.8 · Log4Shell
Vuln Mgmt Queue SOAR
Begin lab →
05
Networking
Unusual outbound traffic is flagged on the perimeter firewall — high-volume connections to an external IP, off-hours, from an internal host that shouldn't be reaching out. Trace the flow, identify the exfiltration vector, and determine what data left the network.
Infrastructure 35 min T1048 · T1071.001
NGFW SIEM TIP
Begin lab →
06
Threat Hunting
Proactive hunt across three weeks of endpoint telemetry to uncover persistent threats that bypassed initial detection. No alerts to start from — just data and instinct.
Coming soon SOC Tier 3