Practice in your browser
Work through security decisions without touching a live system.
Assess an operational domain, build a cyber-health baseline, triage a synthetic alert, plan an authorised validation or inspect an agent release gate. Each exercise produces something useful and explains where its evidence stays.
Security domain readiness
Assess one of 13 operational security domains and export a risk-ranked, owner-ready improvement plan.
Boundary: Answers and evidence references stay in page memory and are included only in files you choose to export.
Open labSmall-business cyber health
Answer 22 plain-language questions across 11 areas and receive an explainable 30/90-day improvement plan.
Boundary: Answers stay in this browser tab and are not stored or transmitted.
Open labGoverned SOC triage
Run four harmless alerts through deterministic triage, inspect the evidence and record a human decision.
Boundary: Every identity, domain, event and action is synthetic. No security system is connected.
Open labPurple-team evidence planner
Define scope, ATT&CK techniques, owners and evidence before a benign validation exercise begins.
Boundary: The planner creates documentation only. It contains no exploit steps and performs no live activity.
Open labAgent assurance
Compare a fixed candidate and control across defensive scenarios, deterministic checks, safety vetoes and runner policy.
Boundary: The record is synthetic and static. No model, customer evidence, production system or external evaluator is connected.
Open labKeep going when a lab exposes a gap.
Use the result as a discussion aid, not as permission to act. Review the evidence with an accountable owner, then choose the next practical resource.