Northgate Engineering / Practice Hub M365 E5 · Entra ID · Sentinel · Defender XDR · Splunk · AWS

Practice Hub

Every surface here runs against one fictional estate: 810 staff, 865 endpoints, twelve servers, and telemetry generated from real attack chains rather than sampled at random. You write the queries, reach the findings, and make the containment calls, and the engine scores the decision rather than the keystrokes.

Graded exercises
Playbooks
Corpus tables
6Environments
Free, no card
Triage Investigate Decide Report
Everything here is included with any paid plan. The list is public so you can see what you would be working with. Preview any course free first, no account needed. See pricing

Graded environments

You work the problem and the engine scores the decision, not just the answer.

SOC Simulator
Take one alert end to end

Take an alert from intake through investigation against live telemetry to a containment decision and a written record. Scored throughout, with the reasoning behind every call.

KQLSentinel▶ Run
SigninLogs | where ResultType != 0 | summarize count() by IPAddress
Open SOC Simulator →
Incident Queue
Choose what to work first

The queue as it actually arrives: several open incidents, competing priorities, and the judgment of which one to take first.

P1Global Admin Account Takeover2m
P2Impossible travel, k.foster14m
P2Mailbox rule created31m
Open Incident Queue →
Forensic Lab
Examine evidence, reach a finding

Generated evidence across Windows, Linux and cross-platform intrusions. Examine the artifacts, reach a finding, and defend it.

INC-NE-2026-0729 · Business Email Compromise
MailboxAuditLog.csv
InboxRules.json
SigninLogs_export.csv
Open Forensic Lab →
Splunk Lab
Write SPL that is graded on its result

Write SPL against the same estate the courses investigate, projected into Splunk CIM sourcetypes. Graded on the result your query actually returns.

sourcetype=aws:cloudtrail errorCode=AccessDeniedSearch
2,062 events · last 30 days
Open Splunk Lab →
AWS Query Lab
Query a generated AWS estate

CloudTrail, VPC flow and GuardDuty against a generated AWS estate. Practitioner drills first, then multi-phase investigations.

SQLCloudTrail▶ Run
SELECT eventName, count(*) FROM cloudtrail_logs GROUP BY 1
Open AWS Query Lab →

Open practice

No exercise, no grading. The estate and a console.

Reference you keep

Written for the moment you need them rather than for reading end to end.

Read a full module before you decide.

Every course opens with lessons you can read in full and queries you can run, without an account. The practice surfaces come with any paid plan.