Real incidents. Real investigation. Real skills.

clickbox.io / command-center
entity:sarah.chen severity>=high last:24h
Open incidents
7
Alerts triaged (24h)
1,942
Cases closed (24h)
34
Median time to verdict
11m
Linked evidenceconf 96%
Impossible travel + MFA fatigue on sarah.chen@contoso.com. 4 related signals across entra id and identity, within a 6-hour window — worth pulling the thread on.
T1078T1110.003T1213
Suggested response
Revoke active sessionsidentity
Quarantine hostendpoint
Open incident + page on-callworkflow
4 signal domains, one console
A fresh scenario every session
Graded against a hidden ground truth
MITRE ATT&CK mapped by default
0+
Investigation scenarios
0
Security domains covered
0
MITRE ATT&CK techniques mapped
0
Structured learning tracks
Cohorts
Organization support
Platform

One ecosystem. Every capability.

SOC Console

The unified investigation workspace.

Investigation Workspace

Evidence, timeline, and notes — one place.

Scenario Engine

A fresh, realistic incident every session.

Threat Intelligence

Indicators, actors, campaigns — with decoys.

Scoring Engine

Graded against a hidden ground truth.

Instructor Tools

Rosters, grading, scenario assignment.

Progress Tracking

Score trend and technique mastery over time.

Certificates

Verifiable proof of completion.

Organization Management

Cohorts, seats, and reporting for teams.

01Investigation Workspace

Investigate with the tools analysts actually use.

Evidence, timeline, and case notes in one workspace.

clickbox.io / investigations / INC-42188
INC-42188
Consent phish → privileged data access
active
opened 4h ago
21:58
OAuth consent phish delivered
Email
Sender ASN first-seen 6h ago · no DMARC alignment
22:04
Consent granted to 'Contoso Reports'
Email
Scopes: Mail.Read, offline_access
22:11
Refresh token minted
Identity
Client 4a1e… · IP 45.86.x.x (unfamiliar ASN)
01:47
MFA fatigue — 14 pushes, 1 approval
Identity
sarah.chen@contoso.com
02:14
SSH to SRV-DB-07 accepted
Endpoint
Key auth · session 44m
02:19
LSASS memory read
Endpoint
procdump-like behaviour, unsigned binary
02:41
3 privileged queries on customers.pii
Cloud
1.2M rows scanned · no export
02:58
S3 policy widened on prod-artifacts
Cloud
Principal: * (blocked by ThreatLens playbook)
Evidence you've pinned
OAuth consent phish deliveredT1566.002
Refresh token minted from unfamiliar ASNT1078
MFA fatigue — 14 pushes, 1 approvalT1621
SSH to SRV-DB-07 acceptedT1021.004
LSASS memory readT1003.001
Your case notes (example)

A consent-phish granted persistent mail access, which was used to socially engineer an MFA approval and pivot to SRV-DB-07. Credential material was read from memory before privileged queries hit customers.pii. No exfiltration observed — my verdict below.

Revoke tokenQuarantine SRV-DB-07Export brief
02Progress & Instructor Dashboard

Numbers that actually track whether you're learning.

Score trend and mastery — for you, or a whole cohort.

clickbox.io / progress
Your progress — 12 cases completed
updated after every submitted case
87SCORE
Up 23 points since your first case
vs. cohort median 61
Avg. case score
87
+23 pts
Technique accuracy
91%
+34 pts
Evidence precision
88%
+19 pts
Cases completed
12
this month
Verdict accuracy
92%
+11 pts
Median time / case
34m
−41%
Score trend — last 12 cases
score / 100
Case 1Case 12
Who it's for

Built for individuals and organizations.

A practical environment to build skills. Infrastructure to train talent at scale.

For individuals

Students & career switchers

Portfolio-ready case work for people breaking into their first SOC role.

SOC analysts

Building the investigation reps a certification alone can't teach.

Cybersecurity learners

Structured practice, not another course you'll forget by next month.

Independent professionals

Staying sharp between jobs, or preparing for an interview loop.

For organizations

Universities & bootcamps

Cybersecurity programs that need hands-on labs, not another slide deck.

Enterprises

Onboarding new hires or leveling up junior analysts, at their own pace.

Government agencies

Workforce-ready SOC training without standing up a live range.

Workforce development programs

Measurable outcomes for public and nonprofit training initiatives.

Training providers & MSSPs

A lab component you don't have to build or maintain yourselves.

Accelerators & incubators

Practical security training as part of a founder or cohort curriculum.

How it works

From first signal to final verdict.

Six stages. Every one of them yours to work through.

01
Evidence Review
Examine activity across identity, endpoint, email, cloud, and network telemetry. Determine which signals matter and preserve the evidence that supports your investigation.
02
Hypothesis
Develop a working explanation of what happened, then challenge it against the available evidence. Deliberate decoys help test whether your reasoning holds up.
03
Investigation Notes
Record your observations, assumptions, questions, and conclusions as the investigation develops. Your reasoning becomes part of the assessment.
04
Timeline
Organize relevant events into a coherent timeline and identify the sequence that connects the individual signals into an incident.
05
Findings & Verdict
Classify the incident and explain your conclusion. Select the response actions you would take based on the evidence and observed impact.
06
Scoring
Your investigation is evaluated against the scenario's hidden ground truth, including evidence selection, reasoning, findings, and response decisions.
Pricing

Start free. Scale when your team is ready.

Free for individuals. Custom-priced for cohorts and institutions.

Individual
Free

For anyone building the investigation reps a certification alone can't teach.

  • Unlimited scenarios
  • All investigation portals
  • MITRE ATT&CK mapping & scoring
  • Progress dashboard
  • Community support
Start investigating
Institutions & Teams
Most cohorts
Contact sales

For bootcamps, universities, and companies onboarding a cohort at once.

  • Unlimited students/analysts
  • Cohort rostering & instructor tools
  • Custom scenario packs
  • LMS & gradebook integration
  • Dedicated support
Let's Talk