A dynamic, ever-changing SOC simulator built to develop and sharpen real analyst skills.
SOCForge is not a course. There are no walkthroughs. Every session is a live organisation under attack, a growing queue of alerts and a threat that keeps moving. Launch your environment, triage what is coming in and defend what matters.
Spin up a live SOC environment. Each session gets a unique organisation, a distinct threat profile and an alert queue already in motion.
Work through incoming alerts spanning lateral movement, privilege escalation and exfiltration. Cut through the noise and make your call.
Stop the attacker before they reach their objective. Your MTTR, accuracy and MITRE coverage are tracked every session as the difficulty keeps climbing.
A unique organisation, a distinct threat profile and an alert queue already in motion.
Alerts spanning lateral movement, privilege escalation and exfiltration. Cut the noise and make your call.
Stop the attacker. MTTR, accuracy and MITRE coverage tracked every session as the difficulty keeps climbing.
Lateral Movement Detected
SMB traffic from WORKSTATION-04 → DC01
Privilege Escalation Attempt
Token impersonation on SRV-FINANCE
Suspicious PowerShell Execution
Encoded command from user jsmith
Alerts fire as incidents develop. Attackers move laterally, escalate privileges and exfiltrate data whether you are watching or not. The SIEM will not tell you what matters. That is your job.
Courses teach you how detection works. SOCForge keeps you sharp enough to actually do it. Every session pushes your limits so your skills never go stale.
SOCForge raises the bar as you improve. More stages, more noise and harder attack chains until you start missing things.
Track Mean Time to Respond, detection accuracy, false positive rate and MITRE ATT&CK coverage across every session.
Run several SOC environments simultaneously, each with a different organisation, threat actor and active incident set.
Publish your analyst profile or a session report and show employers your actual performance numbers.
Every alert you touch feeds your scorecard. SOCForge holds you accountable to the same standards a real SOC lead would use to evaluate your performance.
How fast you close alerts averaged across the session. Speed matters but not at the cost of accuracy.
How many alerts you called correctly as true positives. Your core triage skill measured under real pressure.
How often you escalated noise that was not a real threat. High rates burn analyst time and erode trust.
The tactics and techniques you have encountered and triaged across all sessions. Your breadth as a detection analyst.
SOCForge is live and actively expanding. We are deepening the scenario engine, broadening MITRE ATT&CK coverage and building team-based SOC exercises. What ships next is shaped by the analysts using it now.
Your environment spins up mid-incident. Alerts are already firing. The attacker is already moving. How long before you catch them?
Available with a Rebel subscription