Threat Detection & Triage
Spot phishing and credential attacks, read the tells, and rate severity the way a real Security Operations Center does on a live intrusion.
Opening your project
Real company data. Verifiable proof. On its way…
Step into a German SOC on the night shift. As a Tier-1 Security Operations analyst at Falkenstein Automotive, you follow a live intrusion from the first phishing click through log analysis, the kill chain, containment and the GDPR 72-hour breach clock — then meet the real case it is based on: Continental's 2022 LockBit breach, using public data only. You leave with a real incident report and a CompTIA Security+ / BSI readiness map.
Clock in as a Tier-1 SOC analyst at a German automotive supplier. Meet your shift coach, learn how you pass and how AI is used on a real security team, and make your first gut call: how do you think the attacker got in?
A suspicious email lands. Learn how phishing, credential theft, and MFA work, then triage a real lure: spot the tells, rate the severity, and decide whether this is the first domino of a breach.
Follow the attacker through the logs. Read SIEM events, map the activity to the cyber kill chain, and extract the indicators of compromise (IoCs) that prove an intruder is inside.
Stop the bleeding. Draft a containment plan that cuts the attacker off quietly, then write the GDPR/DSGVO 72-hour breach notification to the regulator — the legal clock most beginners never hear about.
Translate a long night into clear decisions. Write the incident report and the forward-looking security recommendations that leadership will actually act on.
The reveal: everything tonight was modeled on the documented 2022 Continental LockBit breach (public data only). Analyze the real case like the analyst you have become and submit your final incident report.
Spot phishing and credential attacks, read the tells, and rate severity the way a real Security Operations Center does on a live intrusion.
Follow an attacker through SIEM logs, map the cyber kill chain, extract indicators of compromise, and contain the breach without tipping them off.
Run the GDPR/DSGVO 72-hour breach clock and brief leadership with a clear incident report — the skills that get a beginner hired into a German SOC.
i got to learn the work of a soc analyst.. or at least i got to know what a soc analyst's day job looks like... was a fun real world scenario put together to showcase this.