Work a real alert from first signal to final verdict. At every step you get the actual evidence — the decoded payload, the log lines, the process tree — and you make the call an analyst would make. Every decision is graded immediately with an explanation, and you finish with a score, a verdict, and the optimal path to compare against yours.

How it works

  1. Read the alert. Each scenario opens with the signal that landed in your queue and the data sources available to you.
  2. Examine the evidence. Every step shows a real artifact — Sysmon events, auditd records, ESF telemetry, proxy logs, file metadata.
  3. Make the call. Pick the interpretation you'd defend in a handoff. You're graded right away, with an explanation of what the evidence actually shows.
  4. Reach a verdict. Not every scenario is an intrusion — some resolve as authorized activity, and calling those correctly matters just as much.