Hands-On, Evidence-Based Cybersecurity Training
The evidence-based cyber range where SOC analysts detect, investigate, and contain real intrusions — on infrastructure that mirrors production.
Learning on your own? Start with a free lab

Evidence-Based Assessment
Every lab session produces measurable, auditable evidence of skill — not self-reported checkboxes. Track MTTD, MTTI, MTTC, and MTTR across every analyst, every incident.
Defensible enough to put in a promotion review.
“How fast did they notice?”
“How deep did they go?”
“How fast did they act?”
“How fast did they fix?”
Attack simulation began.
You identified rjohnson as the suspicious user by querying their specific process activity — cmd.exe and powershell.exe usage is anomalous for a Sales Director
SPL query:
index=main sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/OperationalYou correlated rjohnson's activity across multiple Sysmon event types (process creation, network connections, file creation) to map the full attack chain
SPL query:
index=main sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/OperationalYou disabled the account in Active Directory, isolated the host in the firewall, and submitted a ticket to rotate the credentials
You documented your investigation findings including the affected user, suspicious activities, timeline, and insider threat assessment
T0-T4 markers track your incident response: T0 = attack start, T1 = detection, T2 = investigation, T3 = containment, T4 = report submitted.
SOC Report Card
Shareable, screenshot-ready report cards with IR metrics, skill breakdowns, MITRE ATT&CK coverage, and peer percentile rankings.
Splunk Log Analysis 101 — Insider Threat Investigation · March 24, 2026
Overall Score
87%
Excellent
Correctness 91%
Speed 72%
Process 85%
Top 35%
Overall score vs 8 analysts
MTTD: Top 40% detection speed
Process Score Breakdown
Incident Response Metrics
MTTD
8m 32s
Good
MTTI
4m 18s
Good
MTTC
16m 56s
Good
MTTR
22m 41s
Good
Industry avg MTTD: 204 days (IBM/Ponemon 2024) — Lab environments use compressed timelines
Skills Earned
MITRE ATT&CK Techniques Practiced (13)
Strengths
Fast threat detection
Thorough investigation documentation
See the full report card
Request a DemoGenerated by CymBytes Cyber Range Platform — cymbytes.com
Real-Time Analytics
Your dashboard tracks detection speed, investigation quality, and MITRE ATT&CK coverage — all in real time, across every lab session.
Incident Response Metrics
MTTD
8m 32s
Good
Detection Speed
How fast did you notice the threat?
MTTI
4m 18s
Good
Investigation Time
How long did your investigation take?
MTTC
16m 56s
Good
Containment Speed
How fast did you contain the threat?
MTTR
22m 41s
Good
Full Response
Total time from detection to report
Industry avg MTTD: 204 days (IBM/Ponemon 2024) — Lab environments use compressed timelines
MITRE ATT&CK Coverage
6/6 (100%)
T1087
Account Discovery
100%
T1059
Command & Scripting Interpreter
100%
T1078
Valid Accounts
100%
T1033
System Owner/User Discovery
100%
T1560
Archive Collected Data
100%
T1531
Account Access Removal
100%
CymBytes gets security teams to operational readiness by training them in environments that mirror production — and measuring what they actually did.
Hands-on training for analysts to find threats in realistic noise — with the enriched data relationships, authentic user activity, real process trees, and live network traffic that production SOCs are still building.
Live-fire incident response exercises on enterprise-grade infrastructure with Active Directory, network segmentation, and real security tooling.
Measure every metric that matters — MTTD, MTTI, MTTC, MTTR — per analyst, per incident. Audit-ready reports aligned to NIST and NICE frameworks for compliance and board reporting.
AI-Powered Learning
Your analysts get a lab assistant that uses the Socratic method — translating plain-English questions into SPL, giving context-aware nudges based on the lab topology, and adapting to each analyst's level. It shortens onboarding without handing anyone the answer.
Lab Assistant
Socratic mode · online
Can you generate a Splunk query to find image=powershell.exe?
Sure — this surfaces every PowerShell process launch so you can spot the unusual ones:
Before you run it — which column tells you whether PowerShell was launched by a person or by another process? Start with ParentImage.
Build high-performing, cyber-resilient teams with hands-on, evidence-based training. Run live-fire exercises on production-realistic environments, measure MTTD and MTTR, and track improvement with audit-ready reports.
“Prove your team is ready before the next incident.”
Talk to usScalable hands-on labs for universities, bootcamps, and academies — with anti-cheat scoring, AI tutoring, and full enterprise environments for every student.
“Deploy a full AD lab for your entire cohort in 10 minutes.”
Build mission-ready cyber defense teams with live-fire team exercises and evidence-based assessment — on secure cloud infrastructure.
“Operational readiness, measured and proven.”
Learning on your own? The same environments and the same scoring, starting with a free lab — no card, no sales call.
“Do the job before you get the job.”
See the learner plansOnboard new hires to trusted shift status in 60 days.
Learning on your own? Start with a free lab