SECINTEL-PROD-01 · foyl SecIntel · analyst on shift
The SOC and blue team
teaching platform.
A complete blue team SOC in your browser, built to teach and to learn: 10 mock consoles, 8 guided labs, 20 scored drills, 14 visual concepts, a 3D network range and six cross-referenced incidents that thread through everything. No prod to break, no license to expense.
3 curated shifts
10 tools
8 labs
20 drills
3D range
6 incidents
6 report builders
380+ certs
8 interview roles
14 concepts
Assigned to you
Jump back in
Work a living queue, contact end users, investigate across consoles, and own the handoff.
quiet desk to capstone
SIEM to ticket queue, every console loaded with the same incidents. The daily drivers.
0/10
Eight guided investigations across networking, logs, threat analysis, vulnerability management, SOAR, detection engineering, full IR and account takeover.
0/8
Twenty scored reps across email, identity, endpoint, network, detection, evidence and incident response. Replays keep your personal best.
0/20
Fly the SecIntel topology, replay real intrusions hop by hop, contain the hosts.
0/1
Fourteen visual explainers turn attack techniques into animated 3D scenes, steppers, maps and hands-on demonstrations.
0/14
The six incidents as guided walkthroughs across every console they touched.
0/6
Instructor-led: your instructor drives these in class.
Explore the same incidents yourself on the Range.
The report IS the deliverable. Build the formal IR document section by section, checked against the incident record, then print it.
0/6
Every security cert mapped by vendor, level and cost. Each one has a 5-question practice quiz, plus 25 career paths.
quiz every cert
Realistic questions with strong answers, from SOC analyst to cloud security.
0/8
The full MITRE ATT&CK matrix - searchable, filterable, with campaign routes mapped.
0/1
Critical
INV-2024-0087
IRON CHIMNEY
AiTM phishing steals marcus.chen's session, lateral movement toward the DC, staged exfiltration over C2.
AiTMlateral movementexfil
Replay in 3D →
High
ATO-002
MFA Fatigue Takeover
m.blake is push-bombed at 2am, approves the 14th prompt, and the account starts moving data to cloud apps.
MFA bypassaccount takeover
Replay in 3D →
High
BEC-001
CEO Wire Fraud
A spoofed CEO thread pressures finance into a $47,500 wire to Trident Capital. No malware, pure process failure.
BEC$47,500
Replay in 3D →
Medium
VF-001
Vendor Fraud
A one-character homoglyph domain (acme-industr1al.com) invoices l.park for $23,847 against a real vendor thread.
homoglyphinvoice fraud
Replay in 3D →
Each incident opens as a 3D replay on the Range. The same four thread through the
SIEM, EDR, Identity, MailGuard and every other console - follow the evidence.