Hands-On, Evidence-Based Cybersecurity Training

Prove Your Team
Is Ready Before
The Breach

The evidence-based cyber range where SOC analysts detect, investigate, and contain real intrusions — on infrastructure that mirrors production.

Request a Demo

Learning on your own? Start with a free lab

Evidence-Based Assessment

Scoring Spotlight

Every lab session produces measurable, auditable evidence of skill — not self-reported checkboxes. Track MTTD, MTTI, MTTC, and MTTR across every analyst, every incident.

Defensible enough to put in a promotion review.

T0
MTTD
Mean Time to Detect

How fast did they notice?

T1
MTTI
Mean Time to Investigate

How deep did they go?

T2
MTTC
Mean Time to Contain

How fast did they act?

T3
MTTR
Mean Time to Recover

How fast did they fix?

Incident Timeline

T0
Incident Start
10:32 AM

Attack simulation began.

T1
Detection
10:41 AM(+9m)

You identified rjohnson as the suspicious user by querying their specific process activity — cmd.exe and powershell.exe usage is anomalous for a Sales Director

SPL query:

index=main sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
T2
Investigation
10:47 AM(+15m)

You correlated rjohnson's activity across multiple Sysmon event types (process creation, network connections, file creation) to map the full attack chain

SPL query:

index=main sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
T3
Containment
10:54 AM(+22m)

You disabled the account in Active Directory, isolated the host in the firewall, and submitted a ticket to rotate the credentials

T4
Resolution
10:58 AM(+26m)

You documented your investigation findings including the affected user, suspicious activities, timeline, and insider threat assessment

T0-T4 markers track your incident response: T0 = attack start, T1 = detection, T2 = investigation, T3 = containment, T4 = report submitted.

SOC Report Card

Every Lab Generates a Performance Report

Shareable, screenshot-ready report cards with IR metrics, skill breakdowns, MITRE ATT&CK coverage, and peer percentile rankings.

SOC Performance Report Card

Splunk Log Analysis 101 — Insider Threat Investigation · March 24, 2026

Overall Score

87%

Excellent

Correctness 91%

Speed 72%

Process 85%

Top 35%

Overall score vs 8 analysts

MTTD: Top 40% detection speed

Process Score Breakdown

Report Quality90%
Evidence Depth85%
Workflow Discipline78%

Incident Response Metrics

MTTD

8m 32s

Good

MTTI

4m 18s

Good

MTTC

16m 56s

Good

MTTR

22m 41s

Good

Industry avg MTTD: 204 days (IBM/Ponemon 2024) — Lab environments use compressed timelines

See the full report card

Request a Demo

Generated by CymBytes Cyber Range Platform — cymbytes.com

Real-Time Analytics

Track Every Metric That Matters

Your dashboard tracks detection speed, investigation quality, and MITRE ATT&CK coverage — all in real time, across every lab session.

Incident Response Metrics

MTTD

8m 32s

Good

Detection Speed

How fast did you notice the threat?

MTTI

4m 18s

Good

Investigation Time

How long did your investigation take?

MTTC

16m 56s

Good

Containment Speed

How fast did you contain the threat?

MTTR

22m 41s

Good

Full Response

Total time from detection to report

Industry avg MTTD: 204 days (IBM/Ponemon 2024) — Lab environments use compressed timelines

MITRE ATT&CK Coverage

6/6 (100%)

T1087

Account Discovery

100%

T1059

Command & Scripting Interpreter

100%

T1078

Valid Accounts

100%

T1033

System Owner/User Discovery

100%

T1560

Archive Collected Data

100%

T1531

Account Access Removal

100%

Not practiced <30% 30-79% 80%+

Detect. Respond. Prove.

CymBytes gets security teams to operational readiness by training them in environments that mirror production — and measuring what they actually did.

DETECT

Hands-on training for analysts to find threats in realistic noise — with the enriched data relationships, authentic user activity, real process trees, and live network traffic that production SOCs are still building.

RESPOND

Live-fire incident response exercises on enterprise-grade infrastructure with Active Directory, network segmentation, and real security tooling.

PROVE

Measure every metric that matters — MTTD, MTTI, MTTC, MTTR — per analyst, per incident. Audit-ready reports aligned to NIST and NICE frameworks for compliance and board reporting.

AI-Powered Learning

AI Guidance That Teaches, Not Tells

Your analysts get a lab assistant that uses the Socratic method — translating plain-English questions into SPL, giving context-aware nudges based on the lab topology, and adapting to each analyst's level. It shortens onboarding without handing anyone the answer.

Natural language → SPLContext-aware hintsPractice on real toolingAvailable 24/7

Lab Assistant

Socratic mode · online

Splunk SPL

Can you generate a Splunk query to find image=powershell.exe?

Sure — this surfaces every PowerShell process launch so you can spot the unusual ones:

search.spl
index=sysmon EventCode=1 Image="*\powershell.exe"
| stats count by host, User, ParentImage, CommandLine
| sort -count

Before you run it — which column tells you whether PowerShell was launched by a person or by another process? Start with ParentImage.

Built For

Security Teams

Build high-performing, cyber-resilient teams with hands-on, evidence-based training. Run live-fire exercises on production-realistic environments, measure MTTD and MTTR, and track improvement with audit-ready reports.

Prove your team is ready before the next incident.

Talk to us

Learning Institutions

Scalable hands-on labs for universities, bootcamps, and academies — with anti-cheat scoring, AI tutoring, and full enterprise environments for every student.

Deploy a full AD lab for your entire cohort in 10 minutes.

Government

Build mission-ready cyber defense teams with live-fire team exercises and evidence-based assessment — on secure cloud infrastructure.

Operational readiness, measured and proven.

Individual Learners

Learning on your own? The same environments and the same scoring, starting with a free lab — no card, no sales call.

Do the job before you get the job.

See the learner plans

SOC analyst readiness platform with auditable scoring evidence.

Onboard new hires to trusted shift status in 60 days.

Learning on your own? Start with a free lab