Tracework

Beginner path

FirstShift

FirstShift teaches investigation by working alerts, reading evidence, practicing with guided tools, and writing notes the way an analyst would on shift.

What FirstShift teaches

  • Alert triage and severity context
  • Process and parent-child analysis
  • Simulated PowerShell investigation steps
  • Fixture-backed KQL against case data
  • Evidence-linked notebook entries
  • Defensible dispositions and reports

How investigations work

You open a case, inspect evidence, run commands and queries in a safe fixture environment, capture notes, and submit a report. Grading runs server-side against the scenario configuration.

Current content and planned path

Suspicious PowerShell investigation

Available now

Live case: alert triage, process analysis, terminal, KQL, notes, report.

Stage 0: SOC Foundations

In development

Concepts that frame the first investigation.

Stage 1: Systems and Command Line

Planned

Planned modules; not available in the workspace yet.

Stage 2: Networking for Analysts

Planned

Planned modules; not available in the workspace yet.

Stage 3: SIEM and Log Analysis

Planned

Planned modules; not available in the workspace yet.

Guided, Assisted, and Analyst

Guided

More scaffolding and hints while you learn the investigation loop.

Assisted

You lead; support appears when you request it.

Analyst

Minimal guidance. Full ownership of tools and documentation.

Time and outputs

Plan roughly 45–90 minutes for Suspicious PowerShell depending on mode. You produce notebook entries, a disposition, and a graded report tied to the attempt.

Current limitations

  • One live investigation case is available now.
  • Curriculum stages beyond the live case are not open yet.
  • Terminal and KQL use fixtures, not live production systems.