foyl Learn · foyl Mock

Ten tools.
One simulated SOC.

Production-grade mock security tools with real incident data. No cloud account needed — open a tool and start working.

10 tools online Ficsit Inc. · Pioneer Division MITRE ATT&CK v14.1 IRON CHIMNEY incident loaded
Detection & Response
SIEM Live
Security Information & Event Management
Correlate security events across your entire environment. Hunt threats with KQL-style queries, build timelines, and drive investigations from alert to resolution.
Alerting Investigations Log Search Reports
Open tool →
EDR Live
Endpoint Detection & Response
Monitor endpoints for malicious activity, isolate compromised hosts, and dig into process trees and memory artifacts across your endpoint fleet.
Detections Process Tree Isolation Hunt
Open tool →
SOAR Live
Security Orchestration, Automation & Response
Run automated playbooks, manage response cases, and coordinate cross-tool actions without leaving a single pane of glass.
Playbooks Cases Automation
Open tool →
Network & Perimeter
NGFW Live
Next-Generation Firewall
Inspect network traffic at the application layer, manage policy rules, detect lateral movement, and respond to perimeter threats in real time.
Traffic Logs Policy Rules Geo Block
Open tool →
CASB Live
Cloud Access Security Broker
Discover shadow IT, enforce cloud app policies, investigate DLP incidents, and govern data movement across sanctioned and unsanctioned cloud services.
Shadow IT DLP App Control Policies
Open tool →
Identity & Email
IAM Live
Identity & Access Management
Manage users, roles, and permissions. Investigate risky sign-ins, review MFA gaps, audit PIM elevations, and respond to account compromise.
Users Risky Sign-ins MFA PIM
Open tool →
Mail Live
MailGuard
Triage phishing reports, analyze email headers and message traces, quarantine malicious messages, and track BEC campaigns to their source.
Quarantine Headers BEC Phishing
Open tool →
Intelligence & Risk
TIP Live
Threat Intelligence Platform
Search and pivot across IOCs, track threat actors and campaigns, manage intel feeds, and produce finished intelligence reports for your stakeholders.
IOCs Actors Campaigns Feeds
Open tool →
VM Live
Vulnerability Management
Review scan findings, prioritize by CVSS and real-world exploitability, track remediation SLAs, and generate executive risk reports.
CVSS Findings Remediation SLA
Open tool →
Tickets Live
Incident Queue
Jira-style ticket management built for security teams. Track incidents, manage sprints, monitor SLA compliance, and visualize workload with a kanban board.
Kanban Sprints SLA Burndown
Open tool →