Labs
Practice detection and investigation on your own machine with free tools — plus five projects to get you started.
Updated October 2026 · Beginner to intermediate
A home lab lets you generate real logs, simulate attacks safely and investigate them with the same kinds of tools used in a SOC. It is also one of the best things to talk about in interviews. You can build a useful lab entirely with free software.
Stay legal and isolated. Only run attack simulations against machines you own, inside an isolated lab network. Never test techniques on systems you do not have explicit permission to use.
Generate repeated failed logons against a test account, then find the 4625 events in your SIEM and build an alert. Check whether you can spot a successful logon afterwards.
Run a harmless PowerShell command with an encoded argument, then use Sysmon event 1 to find the process, its parent and its full command line. Decode it with CyberChef.
Capture traffic with Wireshark while browsing, then identify DNS lookups, TLS handshakes and the hosts contacted.
Use an open-source adversary emulation library such as Atomic Red Team — only inside your lab — to run individual MITRE ATT&CK techniques and check which ones your logging catches.
For each project, write a short investigation report: what happened, the evidence, and how you detected it. These write-ups become portfolio pieces for job applications.
Short, focused Cyber Career Lab labs for drilling individual skills — log analysis, email headers and query writing — are in development. In the meantime, the SOC Analyst simulator lets you investigate complete incidents without building any infrastructure.
FAQ
No, but it helps. A lab gives you hands-on experience and concrete projects to discuss. Browser-based simulations are a faster alternative if you do not have the hardware.
Yes. Cloud providers offer free tiers and credits, but watch costs carefully and shut resources down when you finish.
Running tools against machines you own in an isolated lab is generally fine. Using them against systems you do not own or have permission to test is illegal in most countries.
No lab? No problem
Skip the setup and investigate realistic incidents in the SOC Analyst simulator.
Start free. No experience required.