Investigate across identity, endpoint, email, cloud, and network telemetry in one structured environment — from the first alert to the final verdict.
ThreatLens places you inside realistic security scenarios containing identity activity, endpoint telemetry, email signals, cloud audit trails, and network events. Each case uses synthetic data designed to reproduce the ambiguity and complexity of a real security investigation — without exposing real customer data.
The unified investigation workspace — Sentinel/Chronicle-familiar.
01A realistic incident, generated fresh, every session.
02Entra-, Defender-, and Outlook-style investigation surfaces.
03Indicators, actors, and campaigns — with deliberate decoys.
04Evidence, timeline, notes, and verdict — one workspace.
05Every technique tagged, every session scored against it.
06Graded on your evidence and reasoning, not just your answer.
07Structured tracks from first alert to job-ready.
08Cohorts, rosters, grading overrides, progress at a glance.
09Practice across the surfaces attackers actually move through — not a quiz, an investigation.