We create cybersecurity scenarios. You get better by practicing them.

Every KC7 case is a fictional organization that has been attacked, with realistic logs of what happened. You investigate, answer questions, and move on to a harder one. There is no textbook and no lecture, and you do not need any prior experience.

How a case works

  • 1. Get a real scenario

    You're dropped into an actual breach. A company's been hacked and needs your help. Read emails, check login records, and investigate suspicious files to figure out what happened.

  • 2. Follow the evidence

    We guide you through analyzing the data using KQL, the same query language used at top companies. You'll spot phishing emails, trace suspicious logins, and track down attackers.

  • 3. Solve the mystery

    Answer questions to prove what happened. Each solved case builds your investigative instincts. After a few cases, you'll start to think like a professional SOC analyst.

Why practice, not lectures

Traditional cybersecurity training starts with networking, operating systems and cryptography, and most people forget it or quit before they reach the interesting part. KC7 flips the order. You step straight into the role of an analyst and meet IP addresses, file hashes and processes inside a case where they matter. When you later learn how those things work, you have already used them, so the theory has somewhere to land.

Every case trains the same three habits:

  • Pay attention to details.
  • Ask good questions.
  • Be good with data.

Why we built it this way

Talks from the people who build KC7 and teach with it, and an independent walkthrough of your first case.

  • SANS CTI Summit

    Making CTI cool: teaching threat intelligence through gaming

    A Louisville high school teacher and a former watch repairer on what happens when students investigate a case instead of studying for a certification.

  • SANS New2Cyber Summit

    Role-play your way into cyber: hands-on with KC7

    Why working many attack chains in a weekend beats waiting years to see one on the job, followed by the room playing a case live.

  • ATT&CKcon 4.0

    Using ATT&CK to create wicked actors in real data

    How a threat actor becomes a config file of ATT&CK techniques, and how that config becomes the logs of a fictional company.

  • CyberLabs007

    Hands-on guide to KC7 training

    An independent walkthrough of the first module, KQL 101, one question at a time.

  • They take on the role of a threat analyst. They find an intrusion, they hop in and search for data. That doesn't sound cool until you're in it and you're solving it. You're part of a story. Students saw themselves on a leaderboard and were willing to struggle through something, and it taught them to ask the right questions.
    Bryan QuillenHigh school cybersecurity teacher, Louisville, KY
  • When I first started my KC7 journey, there was a banner on the website that said "anyone can do this." I saw it every day, and eventually one day I believed it. This game pushes you to do a lot more than you think you can.
    Jibby SaetangSecurity researcher at Microsoft, former watch repairer
  • If you need the data to get the skills, how can you get the data without a job? It's a vicious cycle: you need a job to get the data to get the skills to get the job. The way to break it is to simulate the data.
    Greg SchloemerKC7 Foundation vice president, at ATT&CKcon 4.0
  • It's not about doing it once and never seeing it again. It's about practice. The next time someone gives you a tip, you won't need anyone to hand you the questions.
    Simeon KakpoviKC7 founder, at the SANS New2Cyber Summit

It works at every level

In 2023 we ran a week-long camp for 4th to 7th graders in Lexington, Kentucky, most of whom had never touched computer science. In five days they investigated an end-to-end intrusion using KQL, attributed it to the people responsible, and presented their findings. The same cases run for university students, career changers and senior analysts at security companies. The content changes a little for each audience; the approach does not.

Read the summer camp case study

Start with a beginner case

Your first investigation takes about ten minutes and runs in the browser. No account needed.