SOC Training Tool

SOC Analyst Lab Generator

Create a complete defensive SOC training package from a scenario: timeline, telemetry, detections, MITRE mapping, tasks, hints, rubrics, and exports.

Lab Builder

Generate a SOC lab

Generated Package

Suspicious PowerShell Execution Investigation

Intermediate incident investigation lab for Cortex XSIAM. Students investigate a workstation shows encoded powershell, suspicious dns lookups, and a new persistence artifact after a phishing email. The lab uses synthetic telemetry only and is scoped to 45 minutes.

Telemetry

5

Detections

2

MITRE

3

Score

100

Incident timeline

09:14

Email delivered to target user

s.patel received invoice_update.html from an external sender.

09:18

Suspicious command execution

ENG-WKS-207 launched powershell.exe -NoP -W Hidden -EncodedCommand JABjAGwAaQBlAG4AdAA=.

09:20

Outbound lookup observed

ENG-WKS-207 resolved cdn-update.example using workstation DNS cache.

09:24

Persistence attempt

Run key created for s.patel profile with a staged updater command.

09:31

Endpoint alert generated

Cortex XSIAM raised a suspicious script execution alert.

Start a conversation

Whether you are planning an implementation, migration, security architecture review, or operational optimization, let us discuss your requirements.