Hands-On SOC Labs — Not a Game

Do the job
before you get
the job.

No points. No streaks. No badges. You get a real company network, real logs in Splunk, and a real incident to work — scored like a shift, not a quiz.

Start your first lab — free

No card. Your environment is live in about three minutes.

Training a team? CymBytes for security teams

This is not a puzzle with a flag at the end.

Most platforms hand you a challenge and a submit box. We hand you a company.

A real network, not a screenshot

A live Windows domain — domain controller, workstations, a Splunk server — boots on real cloud infrastructure and opens in your browser. You are inside it, not looking at a picture of it.

Real noise, not a clean dataset

Weeks of ordinary logins, patches and file shares sit alongside the attack. Filtering the boring out to find the one thing that matters is the job.

We read your query, not your answer

Checkpoints grade the SPL you actually ran — not a flag you pasted into a box. Your score reflects how you investigated.

A tutor, not a hint button

Stuck? Ask the in-lab assistant the way you'd ask the senior analyst next to you. It walks you through the thinking; it doesn't hand you the answer.

Lab 1 — Free

Your first shift is free.

MNCs train their freshers. Everyone else expects you SOC-ready on day 1. Sign up with an email. Splunk First Steps spins up your own enterprise network in about three minutes. Work the incident, and you finish with a scored Readiness Report you can put in front of an employer.

No card. No sales call.

“Building practical learning environments that help people move from saying ‘I know the concept’ to ‘I have actually worked with it’.”
Karthik Donepudi — SOC analyst candidateRead the full post on LinkedIn

How You're Scored

You're scored on the calls you'd make on a shift.

Not on flags captured. Four things get measured — the same four a SOC manager measures on the floor. Every session ends in a Readiness Report you can share.

T0
Did you spot it?
How long before you noticed something was wrong.

MTTD

Mean Time to Detect

T1
Did you find all of it?
Whether you followed the attack chain end to end, or stopped at the first alert.

MTTI

Mean Time to Investigate

T2
Did you shut it down?
Whether you contained the right thing — and how fast.

MTTC

Mean Time to Contain

T3
Did you get it back to normal?
Total time from the first alert to a clean environment.

MTTR

Mean Time to Recover

Incident Timeline

T0
Incident Start
10:32 AM

Attack simulation began.

T1
Detection
10:41 AM(+9m)

You identified rjohnson as the suspicious user by querying their specific process activity — cmd.exe and powershell.exe usage is anomalous for a Sales Director

SPL query:

index=main sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
T2
Investigation
10:47 AM(+15m)

You correlated rjohnson's activity across multiple Sysmon event types (process creation, network connections, file creation) to map the full attack chain

SPL query:

index=main sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
T3
Containment
10:54 AM(+22m)

You disabled the account in Active Directory, isolated the host in the firewall, and submitted a ticket to rotate the credentials

T4
Resolution
10:58 AM(+26m)

You documented your investigation findings including the affected user, suspicious activities, timeline, and insider threat assessment

T0-T4 markers track your incident response: T0 = attack start, T1 = detection, T2 = investigation, T3 = containment, T4 = report submitted.

SOC Report Card

Every Lab Generates a Performance Report

Shareable, screenshot-ready report cards with IR metrics, skill breakdowns, MITRE ATT&CK coverage, and peer percentile rankings.

SOC Performance Report Card

Splunk Log Analysis 101 — Insider Threat Investigation · March 24, 2026

Overall Score

87%

Excellent

Correctness 91%

Speed 72%

Process 85%

Top 35%

Overall score vs 8 analysts

MTTD: Top 40% detection speed

Process Score Breakdown

Report Quality90%
Evidence Depth85%
Workflow Discipline78%

Incident Response Metrics

MTTD

8m 32s

Good

MTTI

4m 18s

Good

MTTC

16m 56s

Good

MTTR

22m 41s

Good

Industry avg MTTD: 204 days (IBM/Ponemon 2024) — Lab environments use compressed timelines

See the full report card

Start the free lab

Generated by CymBytes Cyber Range Platform — cymbytes.com

Stuck? Ask.

A tutor, not a hint button

The in-lab assistant answers the way a senior analyst would. Ask it a question in plain English and it will help you build the Splunk query — then point at the field you should be reasoning about, instead of handing you the answer. It knows your lab's topology, and it's there at 2am.

Plain English → SPLKnows your lab topologyExplains the whyAvailable 24/7

Lab Assistant

Socratic mode · online

Splunk SPL

Can you generate a Splunk query to find image=powershell.exe?

Sure — this surfaces every PowerShell process launch so you can spot the unusual ones:

search.spl
index=sysmon EventCode=1 Image="*\powershell.exe"
| stats count by host, User, ParentImage, CommandLine
| sort -count

Before you run it — which column tells you whether PowerShell was launched by a person or by another process? Start with ParentImage.

The Path

Zero to SOC L1 — then past it.

Four labs take a complete beginner to the work an L1 analyst does on day one: Splunk basics, Windows logs, writing your own detections, and a full investigation. Four more advanced investigations take you toward L2.

Score 70+ on the four course labs to claim the SOC L1 Certificate

Free

₹0forever

  • Lab 1, fully scored
  • 2 free lab sessions
  • Scored Readiness Report
Start free
Most popular

Premium

₹399per month

  • All 4 Zero to SOC L1 labs
  • The L1 → L2 path: 4 advanced investigations
  • 8 lab sessions per month
See Premium

MAX

₹1,399per month

  • Every lab in the catalog
  • 12 lab sessions per month
  • SOC L1 Certificate with a public verification ID
See MAX

Annual billing brings Premium to ₹299/month and MAX to ₹999/month. Full comparison →

For Security Teams

Training a team?

The same environments and the same scoring, run across a SOC — with per-analyst evidence, MITRE ATT&CK coverage maps, and audit-ready reports for onboarding and promotion reviews.