The lab
The labs I have worked through so far, across forensic investigations, detection and monitoring, and network defense. Labs are updated regularly, with the newest at the top and severity on the left. Click a line to open it, and try your own below.
Hands-on labs
Lab work from coursework and my own study. Open an entry for any findings, difficulties, or setup. This lab experience updates as I have time to complete them on online platforms or a personal VM.
Try it yourself
Three short exercises set at Flexin Watches, a company I made up. Work an alert queue, read a packet capture, find the red flags in a phishing email. Nothing to sign up for, nothing to install.
1 · SIEM triage
You are the Tier-1 analyst on shift. Every alert needs a call: escalate, investigate, or close. A couple look worse than they are, and one of the quiet ones is anything but.
2 · Packet capture
A slice of traffic from a Flexin workstation during a suspected data theft. Read it the way you would in Wireshark. Click a packet to open it and see what made it evidence.
tcp.stream eq 4 || ftp-data || tcp.flags.reset == 1
3 · Spot the phish
This email landed in a Flexin employee’s inbox. Click anything you think is a red flag. The panel keeps score and each flag explains itself once you find it.
That is all of them. Real phishing rarely trips this many at once, but any single one is reason enough to stop and verify before you click.