Playground
An unlimited, ungraded analyst shell over 20 specimens — 20 of them with a recorded sandbox run. Every tool is emulated: answers come from each specimen's authored artifacts, or are derived from them. Nothing here executes, on your machine or ours.
Recorded Browser Cases use recorded output; no specimen is downloaded or executed in the Browser Case. Optional Live Labs use externally referenced specimens in a learner-managed isolated VM.
Triage objectives
0/5Questions in the form the job asks them. Nothing here is scored — the tick is for you.
What is this file, and what hash would you put in the report?
Extensions lie. The type comes from the bytes, and the hash is what makes every later claim checkable.
What can this binary do, without running it?
The import table and the capability report are the fastest honest answer to 'how bad is it?'.
What does it talk to, and how often?
The endpoint is the indicator a defender can block today; the interval is what separates a beacon from ordinary traffic.
Does this persist at all — and if not, what does that tell you?
Absence is a finding. A sample that never persists is doing its work in one pass, which changes the whole response.
Read the shipped rule. Would it fire on anything else here?
A rule that matches its own ruleset, or every PE on the disk, is worse than no rule. Scoping is the skill.
MAA analyst shell — emulated. Nothing executes.
Type 'help', or click a step on the left.
3 files in this directory — run to see them, or for every tool.
