# PracticeSIEM PracticeSIEM is a free, browser-based SOC analyst training platform. It provides 28 realistic security incident cases with real log files and a working Splunk-like search console. No account required for the first 3 cases. ## What it is - 28 hands-on security investigation cases with real log artifacts - A working search console that parses 8 log formats (syslog, nginx, BIND DNS, CloudTrail, Windows Security Events, UFW/iptables, vsftpd, CSV) - A Splunk-like query language for filtering logs by field, value, wildcard, and numeric comparison - Progress tracking with grades (S/A/B/C/D) based on speed and independence - MITRE ATT&CK technique tags on each case - Runs entirely in the browser, no backend, no install ## Categories Getting Started, Initial Access, Network Forensics, Active Directory, Web Security, Threat Hunting, Persistence, Data Exfiltration, Incident Response, Forensics, Cloud Security, Advanced Threats ## Difficulty levels Very Easy (10 pts) to Hard (450 pts) ## Log formats supported auth.log/syslog, nginx access logs, BIND DNS queries, Windows Security Event Logs, AWS CloudTrail JSON, UFW/iptables firewall logs, vsftpd FTP logs, CSV integrity reports ## Key pages - [Home](https://practicesiem.com/) - Landing page with hero and featured cases - [Cases](https://practicesiem.com/challenges) - Browse and filter all 28 cases - [Query Reference](https://practicesiem.com/reference) - Search syntax and field documentation - [License](https://practicesiem.com/login) - Activate Gumroad license key ## License Free for 3 cases. Full access (28 cases) via Gumroad license: https://franklinux.gumroad.com/l/aqognu ## Contact Created by Frank. The site is a training simulator; all logs, hosts, and IP addresses are synthetic.