The platform
Cyber Career Lab puts you in a simulated security role. You receive alerts, examine the evidence, make decisions and document your work — the same loop security teams run every day.
Your analyst dashboard
See your open incidents, priorities, completed investigations and SOC readiness in one place — then pick up the next alert in your queue.
64%
SIEM Investigation
Investigate Suspicious PowerShell Activity
How a simulation works
You are never handed the answer. You work from evidence to a decision, then explain it.
Step 01
An alert lands in your queue with limited context, just like on a real shift. Some are genuine threats. Some are noise.
Step 02
Review authentication logs, email headers, endpoint activity, network connections and user reports to build the picture.
Step 03
Classify the alert, set severity, and decide whether to close, contain or escalate — with your reasoning recorded.
Step 04
Write your investigation notes, receive a score and feedback, and see which skills to practise next.
The investigation workspace
The workspace mirrors the tools analysts use: an incident header, evidence tabs, raw log data and a notes panel. Nothing is highlighted for you.
Suspicious Microsoft 365 Login
| Time | User | Location | Result | Source IP |
|---|---|---|---|---|
| 09:42 | Sarah Mitchell | Manila | SUCCESS | 49.145.x.x |
| 09:51 | Sarah Mitchell | Manila | SUCCESS | 49.145.x.x |
| 10:03 | Sarah Mitchell | Moscow | FAILED | 185.220.x.x |
| 10:04 | Sarah Mitchell | Moscow | FAILED | 185.220.x.x |
| 10:05 | Sarah Mitchell | Moscow | SUCCESS | 185.220.x.x |
“Unusual authentication activity detected...”
What you get
Each scenario is built from the kinds of artefacts analysts actually review: sign-in logs, email headers, process activity and network events.
Not every alert is an attack. Learning to close benign alerts confidently is as important as catching real threats.
Your work is scored on evidence coverage, classification, severity, response decisions and documentation — not on guessing.
After each investigation you see which evidence mattered and where your reasoning could be stronger.
Results roll up into a profile across eight SOC skill areas, so you know where you stand.
Start with the SOC Analyst path. More cybersecurity roles are in development.
Most cybersecurity courses teach concepts: what phishing is, how a SIEM works, which ports matter. That knowledge is necessary, but it is not what an interviewer or a hiring manager tests. They want to know whether you can take an alert you have never seen before, work out what happened and explain it clearly.
A cybersecurity job simulator closes that gap. Instead of watching someone else investigate, you do the investigation yourself:
The result is practical experience you can talk about in interviews — specific investigations, the evidence you used and the decisions you made. If you are still building foundations, start with the SOC analyst roadmap and practise alongside it.
The SOC Analyst simulator is the first career path on Cyber Career Lab. Penetration testing, cloud security, network security, digital forensics and GRC paths are in development and are clearly marked as coming soon across the site.
FAQ
No. Scenarios start at an entry level and explain the context you need. If you are completely new, the SOC analyst roadmap and glossary will help you get up to speed.
No. Every scenario uses simulated data modelled on real-world incidents. Names, IP addresses and organisations are fictional, and you never interact with live systems.
No. Simulations run in your browser. There are no virtual machines or tools to install.
You can start for free. See the pricing page for what is included now and what is planned.
Your first shift is waiting
Start with the SOC Analyst path and see how you handle a real-world alert queue.
Start free. No experience required.