Go beyond the lab.
Investigate. Decide. Master.
RealCyberWork drops you into real SOC tickets. Pull headers, extract IOCs, contain the threat, and write the report — exactly the way analysts do it on the job.
No credit card · 4 free cases · Training mode, all indicators defanged
Threat Intel
Live simulated intelligence feed. New indicators drop every 24 hours with defanged IOCs, source attribution and MITRE mapping.
Callback and QR lures pushing victims onto unmanaged devices
Sat, Aug 8, 2026 · 6 items · current drop
Malicious
2
Suspicious
3
Sources
5
AlienVault OTX
TA577 activity against HR mailboxes
Thread hijacking on compromised supplier accounts, followed by an inbox rule that files replies under RSS Feeds to hide the conversation.
sender · 9h ago
billing@vault-invoice[.]wiki
T1114.003 — Email Forwarding Rule
URLhaus
Gift-card BEC pretext circulating
Free-mail sender using a spoofed display name of a real executive, asking for 18 gift cards "for a client thank-you". No links, no attachment — content-only signal.
sender · 16h ago
ceo.payroll@signin-vault[.]shop
T1656 — Impersonation
Spamhaus
QR-code (quishing) wave targeting ADP
PDF attachment with an embedded QR pointing at a shortener chain, aimed at moving the victim onto an unmanaged phone outside endpoint controls.
url · 16h ago
hxxps://payroll-payroll[.]icu/q/3ie0
T1566.002 — Spearphishing Link
Learn every phishing component
before you touch a live case
Nine components, one at a time. What each one means, what to look at, what is normal, what you can safely ignore — and what turns a report into a full investigation.
Component 1 · Origin & delivery path
Header
Headers are the envelope of the message: every server that touched it, in the order it was touched. The visible From: line is display text an attacker controls; the headers are the closest thing to a delivery receipt.
- Read Received: hops bottom-up — the bottom-most hop is the true origin.
- Compare Return-Path / envelope sender with the visible From: address.
- Reply-To pointing at a different domain than the sender.
- Message-ID whose domain does not match the sending infrastructure.
- Suspiciously few hops, or a hop from a consumer/residential IP.
- Legitimate bulk mail routes through known providers (Google, Microsoft, SendGrid, Mimecast).
- Timestamps that increase smoothly from origin to your gateway.
- Internal-only headers added by your own gateway at the top.
- X-* vendor headers that only describe scanning or routing metadata.
- Small clock skew of a few seconds between hops.
- Base64 encoded subject lines — normal for non-ASCII text.
- Origin IP belongs to bulletproof or newly leased hosting → open the Domain & infrastructure component.
- Envelope sender differs from From: → verify Authentication next.
- The same origin IP appears in earlier tickets → likely a campaign, not a one-off.
Learning only · no live artefacts on this page
Everything you need to stop phishing emails
AI email check, guided training, advanced scenarios and real SOC investigations — one platform from first suspicion to final report.

AI Email Check
One wrong click can drain your account or hijack your identity. Paste any suspicious email here first — our AI tells you in plain English if it's safe, phishing, or a scam.
Check it before you click
Beginner — Guided phishing training
Your first win in cybersecurity starts here. Coached, real-world phishing cases walk you through exactly what to do, which tool to use, and why — no experience needed. Jump in and investigate your first email today.
Start free training
Practitioner Track
This is where analysts are made. Bring your own email or take one from the live queue and work the full SOC framework end-to-end — headers, links, attachments, identity — then export a professional incident report.
Open a case
Terminology in Email Phishing
SPF, DKIM, DMARC alignment, Received headers, IOCs, BEC, quishing, AiTM, containment sequencing — every term defined the way a real SOC uses it, so nothing in a case sounds foreign.
Read the glossaryHow it works
No numbered checklist. A playbook runs quietly behind the case.
Get assigned
A ticket lands in your queue with a reporter, a subject and an SLA clock.
Investigate
Headers, URLs, attachments, identity, endpoint — pivot wherever the evidence leads.
Decide
Classify, escalate or contain. Every decision needs confidence, rationale and evidence.
Report & debrief
Produce an incident report, then get scored like a senior analyst would score you.
Why it sticks
Operational decisions, not quizzes
You choose containment actions and live with the consequences the engine generates.
Evidence discipline
Chain of custody, hashes and preservation are built into the workflow, not bolted on.
Branching outcomes
Miss an indicator and the case comes back. Get it right and you see the clean outcome.
Portfolio you can show
Reports, IOC counts and MITRE coverage exportable as a labelled simulated-experience portfolio.
Stop watching tutorials. Start closing tickets.
Free gets you inside the console. Practitioner gives you the live queue, containment calls and a résumé built from cases you actually closed.
Free
For anyone curious about SOC work.
- 4 beginner cases
- AI Email Check (5 / month)
- Header, URL and IOC workspaces
- Beginner Guided Training
- Terminology library and Academy previews
- Basic debrief score
Practitioner
For career changers and junior analysts.
- Full case library
- Daily SOC queue with SLA pressure
- Identity, endpoint and containment workspaces
- Attachment detonation and MITRE mapping
- Career mode + Interview mode
- Exportable analyst résumé and reports
- Unlimited AI Email Check
All plans run in training mode. No live malicious content is ever served.
Your first ticket is waiting.
INC-2026-0481 is unassigned and the SLA clock is at 42 minutes.
