SOC Training Tool
SOC Analyst Lab Generator
Create a complete defensive SOC training package from a scenario: timeline, telemetry, detections, MITRE mapping, tasks, hints, rubrics, and exports.
Lab Builder
Generate a SOC lab
Generated Package
Suspicious PowerShell Execution Investigation
Intermediate incident investigation lab for Cortex XSIAM. Students investigate a workstation shows encoded powershell, suspicious dns lookups, and a new persistence artifact after a phishing email. The lab uses synthetic telemetry only and is scoped to 45 minutes.
Telemetry
5
Detections
2
MITRE
3
Score
100
Incident timeline
Email delivered to target user
s.patel received invoice_update.html from an external sender.
Suspicious command execution
ENG-WKS-207 launched powershell.exe -NoP -W Hidden -EncodedCommand JABjAGwAaQBlAG4AdAA=.
Outbound lookup observed
ENG-WKS-207 resolved cdn-update.example using workstation DNS cache.
Persistence attempt
Run key created for s.patel profile with a staged updater command.
Endpoint alert generated
Cortex XSIAM raised a suspicious script execution alert.