Receive the alert
Open a case with objectives, severity, and the primary evidence set.
Suspicious PowerShell
Severity: High · Source: EDR
Investigate realistic alerts, run simulated PowerShell commands and fixture-backed KQL, connect evidence, choose a disposition, and write analyst reports inside a calm investigation workspace.
Existing accounts can sign in to save investigation progress
Suspicious PowerShell
Encoded command detected on wrkstn-14
WINWORD.EXE
└─ PS C:\> Get-Process powershell
Parent confirmed: WINWORD.EXE
Method
Open a case with objectives, severity, and the primary evidence set.
Suspicious PowerShell
Severity: High · Source: EDR
Read process trees, network rows, files, and the timeline in order.
ProcessCreate → CommandLine → NetworkConnect
Use the simulated terminal and KQL lab against fixture data.
DeviceProcessEvents | where FileName == "powershell.exe"
Classify the activity and submit a report for grading.
Document findings and submit for server-side grading.
Workspace
Case navigator, evidence workspace, analyst notebook, terminal and query tools, and report outcome stay in one calm layout.
FirstShift
FirstShift is the beginner SOC path. The investigation available now is Suspicious PowerShell. Later modules stay labeled until they ship.
View FirstShiftFull investigation shell with modes and grading
Structured lessons around the live case
Network, SIEM, and reporting practice cases
Learning modes
Stronger scaffolding, clearer next steps, and more hints while you learn the flow.
Fewer prompts. You drive the investigation with targeted support when stuck.
Minimal guidance. You own triage, tools, notes, and the final report.
Review FirstShift, its investigation workflow, and the currently available Suspicious PowerShell case.