
Br3ach
Be the SOC. Stop the breach.
0 ratings
$9.99
About
Br3ach Network is hiring. You're an independent SOC analyst — and your inbox is real cybersecurity incidents.
Each case is a self-contained story. Open the file, work through the task — pick the red flags out of a phishing email, trace the kill-chain through a server log, contain live ransomware on a SOAR console — submit your findings, and earn XP toward your next rank. Real techniques, taught by doing them.
TWO CLIENTS. 46 CASES. FIVE THREAT ACTORS.
Helix Cloud is a B2B SaaS company under attack from three crews: a financially-motivated business-email-compromise group, a credential-theft insider operator, and a nation-state actor running a supply-chain campaign. Eighteen cases ranging from quick standalone investigations to multi-phase incident-response chains.
Silver's Retail — your bigger, family-grown international client — is an entirely different scale. Twenty-eight cases across five full incident-response lifecycle chains: vendor-invoice fraud, point-of-sale malware, a web-skimming supply-chain attack, a ransomware affiliate, and a DDoS used as cover for something quieter. Every incident is worked through Identification → Containment → Eradication → Recovery → Lessons Learned, the way a real SOC actually runs. Three of those chains add a Detection Engineering phase between Recovery and Lessons Learned, where Theo — the team's detection engineer — asks you to author the Sigma rule that would have caught the attack on day one.
ELEVEN CASE TYPES.
Cipher (Caesar, substitution, Vigenère, with a crib-drag assistant) · Phishing Triage · Log Analysis · Auth Review · Network Triage · Containment Action · OSINT Attribution · Live Containment (real-time SOAR) · Postmortem · Web Vulnerability Triage · Detection Engineering (Sigma rule authoring).
Each teaches the discipline behind it — not just the pattern to recognize, but the reasoning that makes the pattern obvious in retrospect.
REAL TECHNIQUES, REAL FRAMEWORKS.
Every case is mapped to the MITRE ATT&CK techniques it actually exemplifies, and the in-app glossary explains the SOC concepts behind the gameplay. You're not learning trivia; you're practicing the analyst's instincts: separate the loud thing from the quiet one, distinguish the attack from a real traffic spike, name what's missing instead of just what happened.
CAREER PROGRESSION.
Earn XP from every solved case. Climb from Tier 1 SOC Analyst → Tier 2 → Senior Threat Hunter → IR Lead → SOC Manager. Unlock 20 Game Center achievements as you master each task type and complete campaigns. Compare your Career XP with friends on the Game Center leaderboard.
THE AMATEUR CODERS PROMISE.
No ads. No tracking. No analytics SDKs. No personal data collected. One price — no subscriptions, no in-app purchases. The app stores your progress on your device only, never on our servers — because we don't have any servers. We just made a game we'd want to play.
Built for cybersecurity-curious players age 15 and up. No prior experience required; mentor hints walk you through each technique the first time you encounter it. Game Center sign-in is optional.
BR3ACH. READ THE LOGS. STOP THE BREACH.
More cases, campaigns, and case types planned as the community grows.
Show more
What's New in Br3ach
1.0
May 18, 2026







