Cloud security · Incident response
Investigate cloud incidents the way a SOC would.
Walk a case from ticket briefing to evidence locker, log console, and findings report. Evidence is synthetic AWS data — no production accounts or customer information.
How a case works
One investigation path for every lab
10 open cases across WAF, EC2, IAM, RDS, S3. The workspace stays the same as the catalog grows — only the evidence changes.
01
Case briefing
Read the ticket, environment, and log window before you open evidence.
02
Evidence locker
Review the synthetic exports attached to the case — CloudTrail, WAF, VPC Flow, and more.
03
Investigate
Search and pivot across logs the way a SOC would: source IP, request ID, session, object key.
04
File findings
Answer from evidence, then close the case with score, ATT&CK mapping, and remediation.
Case catalog
Filter, search, and open a lab
The lab list lives on its own page so it can scale. Search by code or topic, or filter by AWS service.