Cyber defence simulation

Build the experience the job asks for.

CAER gives aspiring analysts somewhere safe to investigate realistic security incidents inside one persistent simulated organisation—before they have the job title.

  • 01 Persistent company
  • 02 Realistic telemetry
  • 03 Guided progression
CAER / Operations
Simulation live
Investigation INV-2026-0042
High

Suspicious process activity

PowerShell opened an external connection

FIN-PC-01 · theo.walker · Finance

Outbound connection activity Activity remains low before rising sharply near the alert time.
The CAER environment Employees Endpoints Identity Network Investigations
One environment. Real context.

Not another collection of disconnected labs.

You learn one simulated company over time—its people, devices, departments and normal behaviour—so unusual activity means something when it appears.

Environment map 24 systems healthy
Departments
Finance6 users
Operations9 users
People4 users
CAER environment core Persistent company
Telemetry
Endpoint2,481 events
Identity318 events
Network864 events
  1. 01

    Learn the baseline

    Build familiarity with normal users, assets and activity instead of starting from zero every time.

  2. 02

    Investigate the signal

    Move between alert, endpoint, identity and network evidence using a consistent analyst workflow.

  3. 03

    Make the judgement

    Record what happened, explain why it matters and close or escalate the case with confidence.

Interactive investigation

Follow the evidence. Make the call.

Review the three evidence sources below. CAER keeps the context close without deciding for you.

Open case INV-2026-0042
0 of 3 evidence sources reviewed
Endpoint / ProcessSuspicious child process
Needs review
Parent process
WINWORD.EXE
Child process
powershell.exe
Command
-w hidden -enc JABX...
Host
FIN-PC-01
Analyst context

A document spawning hidden, encoded PowerShell is uncommon for this Finance endpoint and deserves correlation with other evidence.

Progress without changing worlds

The same environment grows with you.

Start with explanations and visible next steps. Remove support gradually until you are working through noise, ambiguity and incomplete evidence independently.

01
Guided mode

Learn what every field means.

Clear explanations, terminology and sensible next steps stay beside the investigation while you build your first repeatable workflow.

  • Field-level explanations
  • Suggested investigation order
  • Recoverable decisions
Designed for real learners

Clarity is part of the training.

01 / Navigate

Predictable by design

Consistent layouts, strong labels and progressive disclosure keep attention on the investigation—not on deciphering the interface.

02 / Access

Built beyond one type of learner

Keyboard navigation, scalable text, visible focus, reduced motion and non-colour status cues are considered from the start.

03 / Recover

Practice without punishment

Revisit guidance, correct a judgement and understand why it changed. A mistake should become evidence—not lost progress.

04 / Progress

Support that steps back

Guidance reduces as confidence grows, while the underlying company and analyst workflow remain familiar.

“Give people somewhere safe to gain the experience employers keep asking for before they’ve had a chance to get the job.”

The CAER mission Currently in active development in Abergavenny, Wales.
Follow the build

CAER is becoming a real platform.

Follow development updates, see new investigations take shape and get in touch if the mission speaks to you.