Live cyber event sandbox

Analyze a foreign-linked intrusion as it unfolds.

This browser-based simulator turns the assessment into the workspace itself: users review incoming evidence, run lightweight in-simulation tests, map tactics, update confidence, and brief leadership while a synthetic attack continues in real time.

Mode: 60-minute exercise

Current case

SEV-2

Mission overview

Live attack feed

Evidence locker

Interactive workbench

In-simulation testing

Incident timeline

Built from live and stored events

IOC board

Analyst tasks

Evidence vs assumptions

MITRE ATT&CK tagging

Spot report

Target 300 words

Assessment

Condensed 2-page structure

Oral brief

Cue cards will appear here.

Context and policy

Geopolitical layer

Instructor review

Locked

Unlock instructor mode to reveal benchmark hypotheses, red-team explanation, and grading notes.

Analyst readiness test