Alert Triage Investigations
Work a real alert from first signal to final verdict. At every step you get the actual evidence — the decoded payload, the log lines, the process tree — and you make the call an analyst would make. Every decision is graded immediately with an explanation, and you finish with a score, a verdict, and the optimal path to compare against yours.
How it works
- Read the alert. Each scenario opens with the signal that landed in your queue and the data sources available to you.
- Examine the evidence. Every step shows a real artifact — Sysmon events, auditd records, ESF telemetry, proxy logs, file metadata.
- Make the call. Pick the interpretation you'd defend in a handoff. You're graded right away, with an explanation of what the evidence actually shows.
- Reach a verdict. Not every scenario is an intrusion — some resolve as authorized activity, and calling those correctly matters just as much.
Choose Your Platform
Windows Investigations
20 graded scenarios: encoded PowerShell, LSASS dumping, lateral movement, ransomware precursors, WMI persistence, and Kerberos attacks. Read Sysmon events, EDR process trees, and Windows Security logs.
Start Windows investigations →Linux Investigations
20 graded scenarios: reverse shells, cron and systemd persistence, rootkits, container escapes, supply chain compromise, and credential harvesting. Read auditd records, /proc, and package verification output.
Start Linux investigations →macOS Investigations
20 graded scenarios: LaunchAgent persistence, keychain theft, TCC manipulation, dylib hijacking, rogue profiles, and authorization plugins. Read ESF telemetry, codesign output, and the Unified Log.
Start macOS investigations →