Skip to main content
S
SOCSimulatorDocumentation
Security Tools

Security Tools Overview

Master three essential security tools - SIEM, XDR, and Firewall.

Security Tools

SOC Simulator provides three realistic security tool interfaces modeled on production systems. Each tool has its own dashboard with unique capabilities.

Available Tools

Tool Colors

Each tool has a distinct color to help you quickly identify alert sources:

ToolColorUse Case
SIEMCyanLog analysis, correlation, threat hunting
XDRPurpleEndpoint detection, process analysis, response
FirewallGreenNetwork traffic, blocking, rule management

Common Workflows

Cross-Tool Investigation

Real incidents often span multiple tools. A typical workflow:

  1. SIEM detects suspicious log patterns (e.g., brute force attempts)
  2. XDR reveals endpoint activity (e.g., malicious process execution)
  3. Firewall shows network connections (e.g., C2 communication)

Alert Triage

When an alert appears in any tool:

  1. Review alert details and severity
  2. Check related logs or events
  3. Look for correlated alerts across tools
  4. Make a triage decision (Escalate, Investigate, Resolve, False Positive)

Skill Tracking

Your progress with each tool is tracked separately:

  • Alerts Handled - Total alerts you've triaged
  • Accuracy Rate - Correct decisions vs total decisions
  • Response Time - Average time to triage
  • Techniques Covered - MITRE ATT&CK techniques encountered

View your tool mastery on the Dashboard or Profile page.

On this page

We use cookies to improve your experience and measure usage. Learn more