What you get
- A live Splunk lab, free for seven days. Your credentials are emailed the moment you enroll. A real SIEM with real data, not a screenshot of one.
- A seven-day intrusion, in order. Day 1 reconnaissance through Day 7 ransomware — you follow the attacker the way the week actually unfolded.
- Real packets. Downloadable PCAPs of the attack, opened in Wireshark. Following the bytes is a career-long skill and most free courses never hand you a single capture.
- A second incident and a third to hunt. After the ransomware week: a domain-compromise follow-on worked through the PICERL framework, and Operation Alpha — a separate intrusion with its own logs.
- You run the attack yourself. The Red Team Drill puts you on the other side of the wire: scan the authorized target, then go find your own traffic in the SIEM. Defense stops being abstract the moment you catch yourself.
- A verifiable certificate. Finish the investigation and earn Cover6: First Watch — yours to share.
- A clear next step. The exact path from your first week on watch to SOC Analyst Prep Labs.
Seven days is the point.
Most training gives you an alert and asks what you’d do. Real intrusions don’t arrive as an alert. They arrive as a week — a scan on Monday nobody looked at, a foothold on Wednesday, encrypted files on Friday — and the job is reconstructing that week from what the logs kept.
That’s what this is. Not a course about being an analyst. Seven days of being one, in a live SIEM, on an intrusion that actually developed over time.
What makes this different
- A real SIEM with a real incident in it. You log into Splunk and query it yourself. The data is the actual attack — web logs, auth logs, audit logs — not a tidy sample built so one query works.
- The whole kill chain, in sequence. Reconnaissance, web enumeration, initial access, command and control, internal recon, exfiltration, ransomware. One coherent intrusion across seven days, so you learn how an attack develops rather than how to spot seven unrelated alerts.
- What your detection can’t see is part of the lesson. The attacker’s port scan never reaches the web server’s application layer — so it cannot appear in web access logs, no matter how good your query is. The course teaches you why, and where to pivot instead. Knowing the limits of a detection is what separates an analyst from someone running searches.
- You attack it, then you catch it. Scan the authorized target yourself and hunt your own traffic. Standing on both sides of the wire is the moment the job clicks.
The scenario: seven days at Odapeeka State
You’re the analyst on duty at Odapeeka State University. The call comes Friday afternoon: the registrar can’t reach student records, and reports are climbing across campus.
What you find, working backwards, is a week. Someone scanned the perimeter on Monday and nobody noticed. By Wednesday they were inside. By Friday the files were encrypted.
Each day is one investigation. You query the logs, read the packets, and write down what happened — and by Day 7 you can tell the whole story in order, which is exactly what an incident report is.
Prove it — earn your certificate
Work the investigation through and you earn the Cover6: First Watch certificate — verifiable, and yours to put in front of a hiring manager. It says something more useful than “completed a course”: it says you worked an intrusion end to end in a live SIEM.
Who this is for
- Career-changers who need one real thing to point to in an interview.
- Students and self-taught learners who’ve read about SOC work and never touched a SIEM.
- Help-desk and IT people making the move into security.
- Pentesters and red-teamers who want to see what their own noise looks like from the defender’s chair.
No experience required. If you can read a log line, you can start.
How the free week works
- Enroll and your lab credentials arrive by email. Splunk is live from that moment.
- You have seven days. The investigation is built to fit inside them.
- Want to keep going? Monthly Access is $19.99 a month and cancels any time. It keeps your lab open — and new scenarios land in the library as we build them, so the same subscription keeps giving you new incidents to work.
Where this leads
First Watch is one week and one intrusion. SOC Analyst Prep Labs is the whole job: a live target that real attackers are scanning right now, threat-intel enrichment with the tools working analysts use, endpoint forensics, and a full incident report. $599, with practice exams for four certifications included.
If you want the offensive side instead, Cover6: First Shell is the same idea pointed the other way — your first shell, six different ways.
FAQ
Is it really free? Yes. Enroll, get Splunk credentials, work the investigation, earn the certificate — no card required.
Do I need to install anything? No. Splunk runs in your browser. Wireshark is optional and free if you want to open the packet captures.
How long do I have? Seven days of lab access from enrollment.
What if I need more time? Monthly Access is $19.99 a month and cancels any time — it reopens your lab and includes new scenarios as they land.
Do I need experience? None. Day 1 starts with a single question and one query.
What do I walk away with? A week of real SIEM work, packet captures you analyzed yourself, a verifiable certificate, and a clear next step.
Take the watch.
A real SIEM. A real intrusion. Seven days to work it — and an answer, finally, when someone asks what you’ve actually investigated.







Reviews
There are no reviews yet.