Platform

A complete environment for security investigation practice.

Investigate across identity, endpoint, email, cloud, and network telemetry in one structured environment — from the first alert to the final verdict.

01Signal

Every investigation begins with incomplete information.

ThreatLens places you inside realistic security scenarios containing identity activity, endpoint telemetry, email signals, cloud audit trails, and network events. Each case uses synthetic data designed to reproduce the ambiguity and complexity of a real security investigation — without exposing real customer data.

events / case
80–300
domains covered
4
Modules

One console, every domain.

SOC Console

The unified investigation workspace — Sentinel/Chronicle-familiar.

01

Scenario Engine

A realistic incident, generated fresh, every session.

02

Identity, Endpoint & Email Portals

Entra-, Defender-, and Outlook-style investigation surfaces.

03

Threat Intelligence

Indicators, actors, and campaigns — with deliberate decoys.

04

Case Management

Evidence, timeline, notes, and verdict — one workspace.

05

MITRE ATT&CK Mapping

Every technique tagged, every session scored against it.

06

Scoring & Feedback

Graded on your evidence and reasoning, not just your answer.

07

Learning Paths & Certificates

Structured tracks from first alert to job-ready.

08

Instructor Tools

Cohorts, rosters, grading overrides, progress at a glance.

09
Coverage

Every domain a real SOC touches, one platform.

Practice across the surfaces attackers actually move through — not a quiz, an investigation.

EVIDENCE
VERDICT
IDENTITY
ENDPOINT
EMAIL