Tracework

Learn the work behind the alert.

Investigate realistic alerts, run simulated PowerShell commands and fixture-backed KQL, connect evidence, choose a disposition, and write analyst reports inside a calm investigation workspace.

Existing accounts can sign in to save investigation progress

Investigation workspace preview
AlertHigh · Active

Suspicious PowerShell

Encoded command detected on wrkstn-14

Process chain
WINWORD.EXE
 └─ 
TerminalSimulated

PS C:\> Get-Process powershell

Evidence result1 matchEvidence linked

Parent confirmed: WINWORD.EXE

Method

How an investigation runs

Guided → Assisted → AnalystSimulated PowerShell terminalFixture-backed KQLEvidence-linked notesServer-side gradingKeyboard-ready controls

Receive the alert

Open a case with objectives, severity, and the primary evidence set.

New case

Suspicious PowerShell

Severity: High · Source: EDR

Investigate the evidence

Read process trees, network rows, files, and the timeline in order.

Timeline

ProcessCreate → CommandLine → NetworkConnect

Run commands and queries

Use the simulated terminal and KQL lab against fixture data.

Query lab

DeviceProcessEvents | where FileName == "powershell.exe"

Document and defend the decision

Classify the activity and submit a report for grading.

Disposition

Document findings and submit for server-side grading.

Workspace

Investigation surfaces you will use

Case navigator, evidence workspace, analyst notebook, terminal and query tools, and report outcome stay in one calm layout.

Investigation workspace preview
  • Case navigator
  • Evidence workspace
  • Analyst notebook
  • Terminal and query tools
  • Report outcome

FirstShift

Beginner path with honest availability

FirstShift is the beginner SOC path. The investigation available now is Suspicious PowerShell. Later modules stay labeled until they ship.

View FirstShift

Suspicious PowerShell

Available now

Full investigation shell with modes and grading

SOC Foundations modules

In development

Structured lessons around the live case

Additional FirstShift cases

Planned

Network, SIEM, and reporting practice cases

Learning modes

Support decreases as competence grows

Guided

Guided mode

Stronger scaffolding, clearer next steps, and more hints while you learn the flow.

Assisted

Assisted mode

Fewer prompts. You drive the investigation with targeted support when stuck.

Analyst

Analyst mode

Minimal guidance. You own triage, tools, notes, and the final report.

Skills you practice in the workspace

  • Alert triage
  • Process analysis
  • PowerShell investigation
  • Network correlation
  • KQL
  • ATT&CK mapping
  • Analyst reporting

Explore the investigation experience.

Review FirstShift, its investigation workflow, and the currently available Suspicious PowerShell case.