Hands-On SOC Labs — Not a Game
No points. No streaks. No badges. You get a real company network, real logs in Splunk, and a real incident to work — scored like a shift, not a quiz.
No card. Your environment is live in about three minutes.
Training a team? CymBytes for security teams

Most platforms hand you a challenge and a submit box. We hand you a company.
A live Windows domain — domain controller, workstations, a Splunk server — boots on real cloud infrastructure and opens in your browser. You are inside it, not looking at a picture of it.
Weeks of ordinary logins, patches and file shares sit alongside the attack. Filtering the boring out to find the one thing that matters is the job.
Checkpoints grade the SPL you actually ran — not a flag you pasted into a box. Your score reflects how you investigated.
Stuck? Ask the in-lab assistant the way you'd ask the senior analyst next to you. It walks you through the thinking; it doesn't hand you the answer.
Lab 1 — Free
MNCs train their freshers. Everyone else expects you SOC-ready on day 1. Sign up with an email. Splunk First Steps spins up your own enterprise network in about three minutes. Work the incident, and you finish with a scored Readiness Report you can put in front of an employer.
No card. No sales call.
“Building practical learning environments that help people move from saying ‘I know the concept’ to ‘I have actually worked with it’.”
How You're Scored
Not on flags captured. Four things get measured — the same four a SOC manager measures on the floor. Every session ends in a Readiness Report you can share.
MTTD
Mean Time to Detect
MTTI
Mean Time to Investigate
MTTC
Mean Time to Contain
MTTR
Mean Time to Recover
Attack simulation began.
You identified rjohnson as the suspicious user by querying their specific process activity — cmd.exe and powershell.exe usage is anomalous for a Sales Director
SPL query:
index=main sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/OperationalYou correlated rjohnson's activity across multiple Sysmon event types (process creation, network connections, file creation) to map the full attack chain
SPL query:
index=main sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/OperationalYou disabled the account in Active Directory, isolated the host in the firewall, and submitted a ticket to rotate the credentials
You documented your investigation findings including the affected user, suspicious activities, timeline, and insider threat assessment
T0-T4 markers track your incident response: T0 = attack start, T1 = detection, T2 = investigation, T3 = containment, T4 = report submitted.
SOC Report Card
Shareable, screenshot-ready report cards with IR metrics, skill breakdowns, MITRE ATT&CK coverage, and peer percentile rankings.
Splunk Log Analysis 101 — Insider Threat Investigation · March 24, 2026
Overall Score
87%
Excellent
Correctness 91%
Speed 72%
Process 85%
Top 35%
Overall score vs 8 analysts
MTTD: Top 40% detection speed
Process Score Breakdown
Incident Response Metrics
MTTD
8m 32s
Good
MTTI
4m 18s
Good
MTTC
16m 56s
Good
MTTR
22m 41s
Good
Industry avg MTTD: 204 days (IBM/Ponemon 2024) — Lab environments use compressed timelines
Skills Earned
MITRE ATT&CK Techniques Practiced (13)
Strengths
Fast threat detection
Thorough investigation documentation
See the full report card
Start the free labGenerated by CymBytes Cyber Range Platform — cymbytes.com
Stuck? Ask.
The in-lab assistant answers the way a senior analyst would. Ask it a question in plain English and it will help you build the Splunk query — then point at the field you should be reasoning about, instead of handing you the answer. It knows your lab's topology, and it's there at 2am.
Lab Assistant
Socratic mode · online
Can you generate a Splunk query to find image=powershell.exe?
Sure — this surfaces every PowerShell process launch so you can spot the unusual ones:
Before you run it — which column tells you whether PowerShell was launched by a person or by another process? Start with ParentImage.
The Path
Four labs take a complete beginner to the work an L1 analyst does on day one: Splunk basics, Windows logs, writing your own detections, and a full investigation. Four more advanced investigations take you toward L2.
Score 70+ on the four course labs to claim the SOC L1 Certificate
Premium
₹399per month
MAX
₹1,399per month
Annual billing brings Premium to ₹299/month and MAX to ₹999/month. Full comparison →
For Security Teams
The same environments and the same scoring, run across a SOC — with per-analyst evidence, MITRE ATT&CK coverage maps, and audit-ready reports for onboarding and promotion reviews.