CASE-DRIVEN SOC SIMULATION

Go beyond the lab.
Investigate. Decide. Master.

RealCyberWork drops you into real SOC tickets. Pull headers, extract IOCs, contain the threat, and write the report — exactly the way analysts do it on the job.

No credit card · 4 free cases · Training mode, all indicators defanged

CH
Cybersecurity and Compliance
RealCyberWork Studio

Threat Intel

Live simulated intelligence feed. New indicators drop every 24 hours with defanged IOCs, source attribution and MITRE mapping.

Open full feed

Callback and QR lures pushing victims onto unmanaged devices

Sat, Aug 8, 2026 · 6 items · current drop

Next drop in --:--:--
Open feed

Malicious

2

Suspicious

3

Sources

5

Malicious
Campaign
85%

AlienVault OTX

TA577 activity against HR mailboxes

Thread hijacking on compromised supplier accounts, followed by an inbox rule that files replies under RSS Feeds to hide the conversation.

sender · 9h ago

billing@vault-invoice[.]wiki

T1114.003 — Email Forwarding Rule

Suspicious
Campaign
58%

URLhaus

Gift-card BEC pretext circulating

Free-mail sender using a spoofed display name of a real executive, asking for 18 gift cards "for a client thank-you". No links, no attachment — content-only signal.

sender · 16h ago

ceo.payroll@signin-vault[.]shop

T1656 — Impersonation

Suspicious
Credential theft
71%

Spamhaus

QR-code (quishing) wave targeting ADP

PDF attachment with an embedded QR pointing at a shortener chain, aimed at moving the victim onto an unmanaged phone outside endpoint controls.

url · 16h ago

hxxps://payroll-payroll[.]icu/q/3ie0

T1566.002 — Spearphishing Link

Learning session

Learn every phishing component before you touch a live case

Nine components, one at a time. What each one means, what to look at, what is normal, what you can safely ignore — and what turns a report into a full investigation.

Component 1 · Origin & delivery path

Header

Headers are the envelope of the message: every server that touched it, in the order it was touched. The visible From: line is display text an attacker controls; the headers are the closest thing to a delivery receipt.

What to look at
  • Read Received: hops bottom-up — the bottom-most hop is the true origin.
  • Compare Return-Path / envelope sender with the visible From: address.
  • Reply-To pointing at a different domain than the sender.
  • Message-ID whose domain does not match the sending infrastructure.
  • Suspiciously few hops, or a hop from a consumer/residential IP.
What to expect
  • Legitimate bulk mail routes through known providers (Google, Microsoft, SendGrid, Mimecast).
  • Timestamps that increase smoothly from origin to your gateway.
  • Internal-only headers added by your own gateway at the top.
What can be ignored
  • X-* vendor headers that only describe scanning or routing metadata.
  • Small clock skew of a few seconds between hops.
  • Base64 encoded subject lines — normal for non-ASCII text.
What leads to a wider investigation
  • Origin IP belongs to bulletproof or newly leased hosting → open the Domain & infrastructure component.
  • Envelope sender differs from From: → verify Authentication next.
  • The same origin IP appears in earlier tickets → likely a campaign, not a one-off.

Learning only · no live artefacts on this page

What you can do here

Everything you need to stop phishing emails

AI email check, guided training, advanced scenarios and real SOC investigations — one platform from first suspicion to final report.

DON'T CLICK!!! Be sure before you tap that link.

AI Email Check

DON'T CLICK!!! Be sure before you tap that link.

One wrong click can drain your account or hijack your identity. Paste any suspicious email here first — our AI tells you in plain English if it's safe, phishing, or a scam.

Check it before you click
Learn phishing investigation, step by step

Beginner — Guided phishing training

Learn phishing investigation, step by step

Your first win in cybersecurity starts here. Coached, real-world phishing cases walk you through exactly what to do, which tool to use, and why — no experience needed. Jump in and investigate your first email today.

Start free training
Investigate a real suspected email

Practitioner Track

Investigate a real suspected email

This is where analysts are made. Bring your own email or take one from the live queue and work the full SOC framework end-to-end — headers, links, attachments, identity — then export a professional incident report.

Open a case
Speak the language of the SOC

Terminology in Email Phishing

Speak the language of the SOC

SPF, DKIM, DMARC alignment, Received headers, IOCs, BEC, quishing, AiTM, containment sequencing — every term defined the way a real SOC uses it, so nothing in a case sounds foreign.

Read the glossary

How it works

No numbered checklist. A playbook runs quietly behind the case.

01

Get assigned

A ticket lands in your queue with a reporter, a subject and an SLA clock.

02

Investigate

Headers, URLs, attachments, identity, endpoint — pivot wherever the evidence leads.

03

Decide

Classify, escalate or contain. Every decision needs confidence, rationale and evidence.

04

Report & debrief

Produce an incident report, then get scored like a senior analyst would score you.

Why it sticks

Operational decisions, not quizzes

You choose containment actions and live with the consequences the engine generates.

Evidence discipline

Chain of custody, hashes and preservation are built into the workflow, not bolted on.

Branching outcomes

Miss an indicator and the case comes back. Get it right and you see the clean outcome.

Portfolio you can show

Reports, IOC counts and MITRE coverage exportable as a labelled simulated-experience portfolio.

Stop watching tutorials. Start closing tickets.

Free gets you inside the console. Practitioner gives you the live queue, containment calls and a résumé built from cases you actually closed.

Free

$0
forever

For anyone curious about SOC work.

  • 4 beginner cases
  • AI Email Check (5 / month)
  • Header, URL and IOC workspaces
  • Beginner Guided Training
  • Terminology library and Academy previews
  • Basic debrief score
Start free
Most popular

Practitioner

$29
per month

For career changers and junior analysts.

  • Full case library
  • Daily SOC queue with SLA pressure
  • Identity, endpoint and containment workspaces
  • Attachment detonation and MITRE mapping
  • Career mode + Interview mode
  • Exportable analyst résumé and reports
  • Unlimited AI Email Check
Choose Practitioner

All plans run in training mode. No live malicious content is ever served.

Your first ticket is waiting.

INC-2026-0481 is unassigned and the SLA clock is at 42 minutes.