Private beta is live. Access is by invitation; the waitlist is open.

Know where to start when a security incident lands.

CaseNest turns realistic cybersecurity investigations into a guided practice loop without doing the investigation for you.

Current catalog
28 authored cases
Active tracks
3 beginner routes
Learning loop
6 clear stages

Case CN-PH-001

Phishing Email Investigation

Investigate

Investigation question

Does this message show credential theft, malware delivery, or a false positive?
Sender domain
payrolI-secure.example
Lookalike
Authentication
SPF: fail · DKIM: none
Review
Attachment
benefits_update.html
Artifact
Evidence saved3 artifacts

Step inside a CaseNest investigation.

Follow a real phishing case from learning the concept to inspecting evidence, submitting findings, and connecting the result to cybersecurity work.

Recorded in CaseNest. The incident and evidence are authored training material.
Read the walkthrough transcript

CaseNest guides you through hands-on cybersecurity investigations. Choose a case, learn the core concept, and read the scenario. The Virtual stage provides an authored case map. In Investigate, inspect the reported email, its authentication headers, the email gateway log, and the account authentication log. Optional hints support your analysis. Submit your evidence-based findings for server-verified feedback, then review the Summary and the case’s career context.

Orient first. Investigate with confidence.

Every case uses the same learner-facing path, so the work becomes familiar while the cybersecurity stays real.

  1. 01

    Learn

    Build the minimum knowledge needed for this case.

  2. 02

    Scenario

    Understand the incident, role, and investigative question.

  3. 03

    Virtual

    Orient yourself in the authored visual case map.

  4. 04

    Investigate

    Inspect evidence, compare artifacts, and make your call.

  5. 05

    Hints

    Ask for optional guidance only when you need it.

  6. 06

    Submit

    Commit your findings for server-verified review.

After Submit: Summary explains the result, then Career connects the work to real roles. They are outcomes, not stages seven and eight.

You perform the investigation.

CaseNest teaches enough to begin, then places the evidence and decisions in your hands. Hints support the work without replacing it.

  • Read authentic-feeling evidence in its proper technical format.
  • Form a conclusion from artifacts, not from decorative “AI analysis.”
  • Submit once you can explain what happened and why.

Analyst note · saved

“The sender uses a lookalike payroll domain, fails SPF, and delivers an HTML attachment. Together, those artifacts support a credential-phishing classification.”

Clarity comes from connecting evidence, not from guessing the interface.

From first case to first job.

Start with a beginner route, build evidence of practice, and see how each investigation maps to cybersecurity work.

01

SOC / SecOps

Alert triage, phishing, endpoint and network investigations

Beginner entry
02

DFIR

Evidence handling, breach analysis and incident response

Beginner entry
03

Cloud Security

Identity, configuration and cloud incident investigations

Beginner entry

Join the CaseNest Community

Meet other learners, follow the product as it develops, and stay close to the investigations shaping CaseNest.

Community pulse

Public signals from official CaseNest destinations.

Discord
81members
Cached public count
GitHub
276followers
Cached public count
Counts are cached for up to six hours. This page remains available if a provider does not respond.

Join the community

Choose the space that best fits how you want to connect.

Follow and build in public

Follow product progress, new investigations, and the work behind CaseNest.

Your first investigation should not feel like a blank screen.

Join the private-beta waitlist and be ready when the next cohort opens.

Join Waitlist
Essential session notice

CaseNest uses the essential session storage required for authentication. Optional browser analytics and preference tracking are not enabled in this private-beta source build. See the legal and trust draft.