Live SOC console · runs in your browser

Learn the SOC job by doing the SOC job.

A browser-based security operations simulator. Triage real alerts end to end — investigate, classify against MITRE ATT&CK, build a response plan, hand off to Tier 2 — then get scored and coached on what you missed.

Play the free demo See pricing

Runs in your browser. No install, no card, no signup for the demo.

101Scenarios
67ATT&CK techniques
15Real breach recreations
7Domains

The queue is filling. Let's get to work.

Twenty scenarios, the guided first-day tutorial and a threat hunt — free, forever, no account. If you have never worked a queue before, start with 🎓 First day on the job.

Open the demo full screen →

What you actually practise

Not multiple-choice quizzing. Every alert is a full investigation with evidence you have to read, decoys you have to dismiss, and a response plan you have to justify.

🔍

Investigate for real

Pivot on entities, read raw logs and evidence exhibits, and work findings in the right order — some only unlock once you have extracted the indicator from an earlier step.

⚖️

Make the call

True or false positive, severity, ATT&CK technique — with a confidence wager and a requirement to cite the evidence that justifies your verdict.

📖

Landmark breaches

Fifteen scenarios recreate real incidents — SolarWinds, Log4Shell, Colonial Pipeline, NotPetya, Stuxnet, MOVEit — each with the detection opportunity that actually existed.

🔭

Threat hunting

No alert. A hypothesis, a dataset, and a call to make. Half the environments are genuinely clean, because knowing when to close a hunt is the skill.

🎯

It remembers your misses

Miss a technique and it returns until you get it right twice running. A competency radar and ATT&CK coverage map show exactly where you are thin.

🛠

Author your own

Build scenarios in a guided editor and export them as JSON packs — so an instructor can hand a whole class the same cases.

Pricing

One payment, permanent access — no subscription. You play in the browser and your progress follows your account across devices. Students and teachers pay less, because the people who most need this are the ones least able to expense it.

Demo

Anyone curious. No account needed.
Free
forever
  • 20 scenarios across 7 domains
  • Guided first-day tutorial
  • One threat hunt
  • Full scoring & coaching
  • No account required
  • Campaigns & attribution
  • Scenario builder
Play now
Most popular

Individual

Analysts, career changers, home labbers.
$8 /month
or $59/year — five months free
  • All 101 scenarios
  • 15 landmark breach recreations
  • All 8 threat hunts
  • Campaigns + adversary attribution
  • Scenario builder + JSON packs
  • Progress synced to your account
Start — $8/month

Student

Verified school email required.
$4 /month
or $29/year
  • Everything in Individual
  • Progress synced to your account
  • Verified with a school email
Get student pricing

Classroom

Instructors, bootcamps, training teams.
$3 /seat/month
5 seats minimum · your seat is free
  • Everything in Individual, per student
  • Seats reassign between cohorts
  • Add or drop seats any month
  • Class join codes & roster console
  • Author & share scenario packs
$90/month
Start a class

Prices in USD, cancel any time. Every paid tier is the same software — the discount is on who you are, not what you get. Classroom billing is prorated: add seats mid-term and you pay the difference, drop them and it comes off the next invoice. If cost is the only thing stopping you, email me — I would rather you had it.

Already teaching with it? Open your classroom console · Student with a class code? Join your class.

Questions

Do I need any security experience?

No. The guided tutorial walks you through a complete alert with coaching at every stage, and it does not touch your stats. People with no background have used it as a first introduction to what the job is.

Is this affiliated with MITRE?

No. It references the publicly available MITRE ATT&CK framework for classification and teaching, as most security tooling does. MITRE does not endorse it.

Are the "real incident" scenarios accurate?

They are recreations, not reconstructions. Hosts, users and infrastructure are fictional; the attack pattern and the detection opportunity mirror the public reporting on each case, and the real incident is named in the debrief so you can go read the primary sources.

Do I need to install anything?

No. It runs in the browser — the demo needs no account at all. Buying gives you a sign-in link; after that your progress syncs to your account so you can pick up on another machine.

What do I get when I buy?

Immediate access to the full app in your browser, permanently, including every update. Sign-in is a link emailed to you — no password to manage. Sentinel Shift runs online only; there is no download.

Can I get a refund?

Yes — email within 30 days and I will refund it, no argument. The demo exists so you can judge before paying.