We create cybersecurity scenarios. You get better by practicing them.
Every KC7 case is a fictional organization that has been attacked, with realistic logs of what happened. You investigate, answer questions, and move on to a harder one. There is no textbook and no lecture, and you do not need any prior experience.
How a case works

1. Get a real scenario
You're dropped into an actual breach. A company's been hacked and needs your help. Read emails, check login records, and investigate suspicious files to figure out what happened.

2. Follow the evidence
We guide you through analyzing the data using KQL, the same query language used at top companies. You'll spot phishing emails, trace suspicious logins, and track down attackers.

3. Solve the mystery
Answer questions to prove what happened. Each solved case builds your investigative instincts. After a few cases, you'll start to think like a professional SOC analyst.
Why practice, not lectures
Traditional cybersecurity training starts with networking, operating systems and cryptography, and most people forget it or quit before they reach the interesting part. KC7 flips the order. You step straight into the role of an analyst and meet IP addresses, file hashes and processes inside a case where they matter. When you later learn how those things work, you have already used them, so the theory has somewhere to land.
Every case trains the same three habits:
- Pay attention to details.
- Ask good questions.
- Be good with data.
Why we built it this way
Talks from the people who build KC7 and teach with it, and an independent walkthrough of your first case.
- SANS CTI Summit
Making CTI cool: teaching threat intelligence through gaming
A Louisville high school teacher and a former watch repairer on what happens when students investigate a case instead of studying for a certification.
- SANS New2Cyber Summit
Role-play your way into cyber: hands-on with KC7
Why working many attack chains in a weekend beats waiting years to see one on the job, followed by the room playing a case live.
- ATT&CKcon 4.0
Using ATT&CK to create wicked actors in real data
How a threat actor becomes a config file of ATT&CK techniques, and how that config becomes the logs of a fictional company.
- CyberLabs007
Hands-on guide to KC7 training
An independent walkthrough of the first module, KQL 101, one question at a time.
They take on the role of a threat analyst. They find an intrusion, they hop in and search for data. That doesn't sound cool until you're in it and you're solving it. You're part of a story. Students saw themselves on a leaderboard and were willing to struggle through something, and it taught them to ask the right questions.
When I first started my KC7 journey, there was a banner on the website that said "anyone can do this." I saw it every day, and eventually one day I believed it. This game pushes you to do a lot more than you think you can.
If you need the data to get the skills, how can you get the data without a job? It's a vicious cycle: you need a job to get the data to get the skills to get the job. The way to break it is to simulate the data.
It's not about doing it once and never seeing it again. It's about practice. The next time someone gives you a tip, you won't need anyone to hand you the questions.
It works at every level
In 2023 we ran a week-long camp for 4th to 7th graders in Lexington, Kentucky, most of whom had never touched computer science. In five days they investigated an end-to-end intrusion using KQL, attributed it to the people responsible, and presented their findings. The same cases run for university students, career changers and senior analysts at security companies. The content changes a little for each audience; the approach does not.
At first I didn't want to be here and now I'm enjoying the camp. I feel smart in something that I didn't know before.
Start with a beginner case
Your first investigation takes about ten minutes and runs in the browser. No account needed.
