What it is
The range gives analysts a monitoring environment that matches yours: the same SIEM views, EDR console, log sources and case workflow. We generate attack activity and background traffic in it, and analysts work the alerts from triage to escalation.
It suits SOC managers onboarding new analysts, teams adopting new detection content, and leads who want to compare investigation quality across shifts. The analyst course itself is covered under SOC analyst training.
Scenarios
Alert triage under volume
A mix of true and false positives arrives over a shift. Analysts prioritize, close benign alerts with notes, and escalate the rest.
Phishing investigation
A user reports an AI-written phishing email. Analysts find other recipients, check for clicks and credential use, and contain.
Sign-ins after a help desk reset
An MFA reset follows a deepfake voice call to the help desk. Analysts link the ticket, the reset, and the sign-ins that follow.
Endpoint compromise
EDR flags a malicious process. Analysts build the process tree, check for persistence and lateral movement, and recommend isolation.
Threat hunt
Analysts start from a hypothesis or threat report and search logs for activity that did not raise an alert.
AI agent misuse
An internal AI agent makes unusual tool calls and data requests. Analysts determine whether it was manipulated and what it accessed.
How an exercise runs
We agree the skills to practice and the experience level of the group, and choose cases to fit. We review your SIEM, EDR, log sources and escalation runbooks.
We set up the monitoring stack with your rules and dashboards, in your cloud, on-premises or on our hosting. Hosts and identities produce the logs you collect, and background activity runs so alerts appear among normal traffic.
Analysts work cases alone or as a shift. They triage, query logs, write case notes and escalate through your usual workflow. A facilitator can release hints or extra injects.
We go through each case: the evidence available, what the analyst found, and the decision made. Gaps in rules, dashboards or runbooks are recorded alongside individual feedback.
What the range includes
The monitoring stack in the range is set up to look and behave like the one your analysts use each day.
Monitoring stack
- Your SIEM and EDR where licensing allows
- Or Wazuh, Security Onion and OpenSearch
- Your detection rules, dashboards and saved searches
Log sources
- Endpoint, identity, email, network and cloud logs
- Hosts and users that generate background activity
- Log formats matching production
Case workflow
- Ticketing or case management as your SOC uses it
- Escalation paths and runbooks
- Case note templates
Scoring
- Expected findings defined for each case
- Analyst actions and timing recorded
- Results by analyst and by shift
Exercise formats
| Format | How it works | When it fits |
|---|---|---|
| Guided case | One case worked step by step with a facilitator. | New analysts and onboarding. |
| Shift simulation | A queue of alerts over a set period, worked as a team with handovers. | Testing triage, prioritization and handover between analysts. |
| Threat hunt | An open search from a hypothesis, with no alert to start from. | Experienced analysts and detection engineers. |
| Purple team session | Our operators run techniques one at a time while analysts check what was logged and tune rules. | Building and testing new detection content. |
What you receive
Each exercise ends with a debrief for the analysts and their lead. We go through every case and record what was found, what was missed, and why.
Afterward you receive written findings on detection content, investigation quality and escalation, with recommended changes to rules, dashboards and runbooks. Individual feedback for each analyst goes only to the people you name.
Cases are kept in a library for your range, so you can rerun them with new analysts or after changing detection rules.
Questions
Does the range connect to our production SIEM?
No. The range has its own monitoring stack and log sources. Your rules and dashboards are exported into it, and nothing is sent back to production.
How close is it to our SOC setup?
We match your tools, log sources, rules and case workflow, as far as the cases need. Where licensing prevents using your SIEM or EDR in the range, we use open-source equivalents and note the differences.
Can we use the cases for onboarding?
Yes. Cases can be grouped by level and run again with each new group of analysts.
Who facilitates?
A facilitator from our team runs the cases and leads the debrief. Your senior analysts can take over facilitation for later runs.
How is analyst performance data handled?
Individual results are shared only with the people you name. We agree retention and deletion rules before the first session and sign an NDA on request.
How to prepare
Tell us your SIEM and EDR platforms, and share an export of the detection rules and dashboards you want in the range, along with your escalation runbooks. Let us know the experience level of the analysts taking part.
Agree how results will be used, for example onboarding sign-off or team development, and tell analysts before the first session.

