← Back

The lab

The labs I have worked through so far, across forensic investigations, detection and monitoring, and network defense. Labs are updated regularly, with the newest at the top and severity on the left. Click a line to open it, and try your own below.

01

Hands-on labs

Lab work from coursework and my own study. Open an entry for any findings, difficulties, or setup. This lab experience updates as I have time to complete them on online platforms or a personal VM.

Lab feed · self-directed work Active · updated regularly
SevStatus WorkStack
02

Try it yourself

Three short exercises set at Flexin Watches, a company I made up. Work an alert queue, read a packet capture, find the red flags in a phishing email. Nothing to sign up for, nothing to install.

1 · SIEM triage

You are the Tier-1 analyst on shift. Every alert needs a call: escalate, investigate, or close. A couple look worse than they are, and one of the quiet ones is anything but.

Flexin Watches SOC · alert queue TRIAGED 0 / 5scroll queue ↓

2 · Packet capture

A slice of traffic from a Flexin workstation during a suspected data theft. Read it the way you would in Wireshark. Click a packet to open it and see what made it evidence.

flexin-workstation-capture.pcapng 6 packets shown
filter tcp.stream eq 4 || ftp-data || tcp.flags.reset == 1
No.Time SourceDestination ProtoInfo

3 · Spot the phish

This email landed in a Flexin employee’s inbox. Click anything you think is a red flag. The panel keeps score and each flag explains itself once you find it.

Red flags found
0 / 7
click the suspicious parts
Look at the sender, the links, the tone, and anything it’s rushing you to do.
All flags found

That is all of them. Real phishing rarely trips this many at once, but any single one is reason enough to stop and verify before you click.