foyl Learn · foyl Labs

Guided labs.
Real attack chains.

Each lab is a step-by-step walkthrough built for classroom use. Instructors can run the attack chain live while students follow along in the mock tools. Correctly completed hands-on activities are checkpointed so you and your instructor can see demonstrated progress, not just pages visited.

8 labs staged foyl SecIntel
01
Incident Response
A finance executive receives a convincing phishing email. Their credentials are captured via an AiTM proxy. The attacker authenticates with a valid session token, bypasses MFA, and begins lateral movement toward the domain controller. Your job: detect, contain, document.
SOC Tier 1 ~2.5 hr IRON CHIMNEY T1566 · T1078 · T1021
SIEM EDR Identity SOAR
Begin lab →
02
Log Analysis
You receive a batch of raw logs: authentication events, web requests, and endpoint telemetry from a 72-hour window. Something happened. Your job is to find it - build a timeline from noise, identify the initial vector, and trace the attacker's path through the environment.
SOC Tier 1 30 min T1059 · T1105
SIEM
Begin lab →
03
Threat Lab
A suspicious process drops an unknown binary on a finance workstation. You have the EDR telemetry, a handful of IOCs, and access to the threat intelligence platform. Identify the malware family, map it to a known actor, pivot on infrastructure, and brief the incident team.
SOC Tier 2 60 min T1055 · T1071 · T1041
TIP EDR SIEM
Begin lab →
04
Vulnerability Management
Your quarterly scan just completed and dropped 340 findings across 47 assets. Leadership wants to know: what's on fire, what can wait, and what's your 30-day remediation plan? Prioritize using CVSS, EPSS, and asset criticality - then build the remediation ticket queue.
SOC Tier 2 40 min CVSS 9.8 · Log4Shell
Vuln Mgmt Queue SOAR
Begin lab →
05
Networking
Unusual outbound traffic is flagged on the perimeter firewall - high-volume connections to an external IP, off-hours, from an internal host that shouldn't be reaching out. Trace the flow, identify the exfiltration vector, and determine what data left the network.
Infrastructure 35 min T1048 · T1071.001
NGFW SIEM TIP
Begin lab →
06
SOAR Automation
Walk through the full IRON CHIMNEY automated response - from raw SIEM alert to isolated endpoint in 142 seconds. Build and step through PB-001, trace the enrichment pipeline, and understand how SOAR orchestrates four tools simultaneously.
SOC T2 90 min T1566 · T1078 · T1059
SOAR SIEM EDR Identity
Begin lab →
07
Detection Engineering
Reverse-engineer a SecIntel ransomware incident, inspect the SIEM and EDR records that caught it, then engineer a production rule from telemetry contract through test bench, tuning, validation, correlation, detection-as-code, and operational health.
Detection Eng ~2 hours 10 scored checkpoints · linked alerts
SIEM EDR
Begin lab →
08
Account Takeover Response
SILENT DELEGATE replayed a Finance user's cloud session, planted mailbox and OAuth persistence, collected sensitive files, and reached the user's endpoint through signed Windows tools. Prove the takeover, evict every session, scope the data impact, and close both return paths.
Identity + IR ~100 min 10 scored checkpoints · 3D evidence graph
MailGuard Identity SIEM EDR CASB SOAR
Begin lab →