SOC analyst range

A private cyber range where SOC analysts investigate alerts in a copy of your monitoring stack, from triage to escalation. Each exercise ends with a debrief on what was found, what was missed and what to improve.

On this page

What it is

The range gives analysts a monitoring environment that matches yours: the same SIEM views, EDR console, log sources and case workflow. We generate attack activity and background traffic in it, and analysts work the alerts from triage to escalation.

It suits SOC managers onboarding new analysts, teams adopting new detection content, and leads who want to compare investigation quality across shifts. The analyst course itself is covered under SOC analyst training.

Scenarios

Alert triage under volume

A mix of true and false positives arrives over a shift. Analysts prioritize, close benign alerts with notes, and escalate the rest.

Phishing investigation

A user reports an AI-written phishing email. Analysts find other recipients, check for clicks and credential use, and contain.

Sign-ins after a help desk reset

An MFA reset follows a deepfake voice call to the help desk. Analysts link the ticket, the reset, and the sign-ins that follow.

Endpoint compromise

EDR flags a malicious process. Analysts build the process tree, check for persistence and lateral movement, and recommend isolation.

Threat hunt

Analysts start from a hypothesis or threat report and search logs for activity that did not raise an alert.

AI agent misuse

An internal AI agent makes unusual tool calls and data requests. Analysts determine whether it was manipulated and what it accessed.

How an exercise runs

We agree the skills to practice and the experience level of the group, and choose cases to fit. We review your SIEM, EDR, log sources and escalation runbooks.

What the range includes

The monitoring stack in the range is set up to look and behave like the one your analysts use each day.

Monitoring stack

  • Your SIEM and EDR where licensing allows
  • Or Wazuh, Security Onion and OpenSearch
  • Your detection rules, dashboards and saved searches

Log sources

  • Endpoint, identity, email, network and cloud logs
  • Hosts and users that generate background activity
  • Log formats matching production

Case workflow

  • Ticketing or case management as your SOC uses it
  • Escalation paths and runbooks
  • Case note templates

Scoring

  • Expected findings defined for each case
  • Analyst actions and timing recorded
  • Results by analyst and by shift

Exercise formats

FormatHow it worksWhen it fits
Guided caseOne case worked step by step with a facilitator.New analysts and onboarding.
Shift simulationA queue of alerts over a set period, worked as a team with handovers.Testing triage, prioritization and handover between analysts.
Threat huntAn open search from a hypothesis, with no alert to start from.Experienced analysts and detection engineers.
Purple team sessionOur operators run techniques one at a time while analysts check what was logged and tune rules.Building and testing new detection content.

What you receive

Each exercise ends with a debrief for the analysts and their lead. We go through every case and record what was found, what was missed, and why.

Afterward you receive written findings on detection content, investigation quality and escalation, with recommended changes to rules, dashboards and runbooks. Individual feedback for each analyst goes only to the people you name.

Cases are kept in a library for your range, so you can rerun them with new analysts or after changing detection rules.

Questions

Does the range connect to our production SIEM?

No. The range has its own monitoring stack and log sources. Your rules and dashboards are exported into it, and nothing is sent back to production.

How close is it to our SOC setup?

We match your tools, log sources, rules and case workflow, as far as the cases need. Where licensing prevents using your SIEM or EDR in the range, we use open-source equivalents and note the differences.

Can we use the cases for onboarding?

Yes. Cases can be grouped by level and run again with each new group of analysts.

Who facilitates?

A facilitator from our team runs the cases and leads the debrief. Your senior analysts can take over facilitation for later runs.

How is analyst performance data handled?

Individual results are shared only with the people you name. We agree retention and deletion rules before the first session and sign an NDA on request.

How to prepare

Tell us your SIEM and EDR platforms, and share an export of the detection rules and dashboards you want in the range, along with your escalation runbooks. Let us know the experience level of the analysts taking part.

Agree how results will be used, for example onboarding sign-off or team development, and tell analysts before the first session.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.