🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
Free tool · no signup · SOC practice

SOC Log Triage Trainer

A thousand logs from across the stack — identity, EDR, firewall, email, DNS, cloud. Open a log, click the fields that look suspicious, then Check. The tool shows how a real analyst would triage it and explains every red flag — no SOC experience needed.

How to play — a 20-second start

  1. Pick a log on the left. Most are normal noise; a few are attacks.
  2. In the detail pane, click any field value that looks wrong (odd country, weird command, failed SPF…).
  3. Hit Check — green = you caught a real flag, amber = you missed one, red = false alarm, each with a “why”.
  4. Stuck? Press Reveal to just learn the answer. Use End shift for your report.

Keyboard: ↑↓ move · 1–9 flag a field · Enter check/next · R reveal · N next.

0Reviewedof 1000
0Signals caught
0Missed
0False alarms
0%Recallof red flags
0Streak
Inbox1000 logs
Showing 400 of 1000 — refine with search, a source filter, or a mode above.
IdentityinfoL100269 · 05:27:41

Successful sign-in — a.patel

Click any field value you think is a red flag (or press 1–9), then Check.

New to the SOC? Most logs are normal noise — the skill is spotting the few that aren't. Watch for logins from anonymizing networks or impossible-travel geographies, encoded PowerShell spawned by Office apps, living-off-the-land downloads (certutil, mshta), look-alike sender domains, high-entropy DNS to new domains, and cloud privilege grants without MFA.Ambient music: “Ghostpocalypse” by Kevin MacLeod (incompetech.com), licensed CC BY 4.0. Off by default — toggle it bottom-right.

FAQ

What is the SOC Log Triage Trainer?

It is a free, browser-based exercise that mimics a security analyst's console. A thousand synthetic logs stream in from identity, EDR, firewall, email, DNS, proxy, cloud, VPN and Windows sources. You open a log, click the individual fields you think are suspicious, and press Check — the tool then shows which fields were the real red flags, which you missed, and which were false alarms, with a plain-English explanation for each.

Do I need SOC experience to use it?

No — that is the point. Most logs are ordinary noise, and the skill being practised is spotting the few that are not. Every genuine indicator comes with a "why it matters" note, so you learn the patterns as you go: logins from anonymizing networks, impossible travel, encoded PowerShell launched by Office apps, living-off-the-land downloads, look-alike phishing domains, high-entropy DNS, and cloud privilege grants without MFA.

Are these real logs?

No. Every log is synthetically generated in your browser — no real users, hosts, IPs or PII. The data is deterministic, so the same set of logs and indicators appears each time, which makes it usable for training and comparison.

Is any of my activity uploaded?

No. The logs are generated locally and all scoring happens in your browser. Nothing you click is sent to a server.

How is my triage scored?

For every log you check, a flag on a truly-suspicious field counts as a detection, a missed suspicious field counts against you, and flagging a normal field is a false alarm. The running score bar tracks detections, misses, false alarms and an overall accuracy percentage across every log you have reviewed — the same true-positive / false-positive trade-off a real analyst is judged on.

SOC Log Triage Trainer — Practice Spotting Bad Logs (Free) · PlayCISO