SHIFT ZERODEFENSIVE TRAINING RANGE
CHECKING EVALUATORRELEASE: v1.4.0POSTURE: DEFENSIVEEXECUTION: LEARNER CONTROLLED

RANGE CONTROL / PUBLIC ACCESS

SHIFT ZERO // RANGE GATEWAY

Learn how networks work in plain language, then apply that foundation in a MacBook-first defensive practice range. Follow the packet, inspect authored evidence, make a safe decision, and explain it clearly.

NEXT AUTHORED CASEQUEUE POSITION 01
SZ-001
Pressure at the SSH DoorTriage a burst of Linux authentication failures without mistaking normal administrator access for the incident.
Lane
SOC Analysis
Evidence
1 file
Shift
25 minutes
Output
authentication triage note
Evaluator
checking evaluator
Release
v1.4.0 · 2026-08-11
Persistence
device-local record

RANGE MAP / TRUST BOUNDARIES

The learner owns the tools. The range owns the scenario.

Shift Zero never opens a shell. It stages the evidence, verifies submitted findings, and keeps the learner record on the MacBook.

LEARNER ZONE / MACBOOK
RANGE CONSOLEMission workspacebriefing · notes · findings
YOUR TERMINALInvestigation toolsgrep · awk · Python · PowerShell
LOCAL STORETraining recordprogress · notes · review queue
RANGE SERVICE / PUBLIC DEPLOYMENT
SCENARIO PACKAuthored evidencelogs · headers · scripts · exports
PRIVATE EVALUATORSolution modelmission answer key stays server-side
Mission trust boundary: only submitted findings cross into the evaluator. No terminal command, private note, or learning history is sent with the check.

OPERATION BOARD / ACTIVE CURRICULUM

12 cases. One investigation at a time.

The inventory moves from familiar support signals into incident timelines, endpoint telemetry, automation, and intelligence enrichment.

Shift Zero training operations
CaseOperationLaneLevelEvidenceShiftOutput
SZ-001Pressure at the SSH DoorTriage a burst of Linux authentication failures without mistaking normal administrator access for the incident.SOC Analysisfoundation1 file25 minauthentication triage note
SZ-002The Service Nobody DocumentedIdentify an undocumented web service and explain why its current configuration deserves attention.Network Defensefoundation3 files25 minservice exposure assessment
SZ-003Make the Log SpeakFinish a small Python parser that turns an application log into a reliable incident summary.Security Automationfield2 files35 minPython automation writeup
SZ-004The Invoice That Changed DirectionTriage a suspicious invoice message using routing and authentication headers instead of appearance.SOC Analysisfoundation1 file20 minphishing triage report
SZ-005The Portal That MovedResolve a disagreement between healthy DNS and one workstation's effective name resolution.Network Defensefield4 files30 minDNS incident note
SZ-006Someone Found the Backups FolderSeparate routine health checks from forced browsing that reached an exposed backup file.SOC Analysisfield1 file30 minweb incident timeline
SZ-007The Cron Job Anyone Could RewriteTriage a Linux permission finding and separate a real escalation path from normal SUID inventory.Network Defensefield2 files25 minLinux hardening ticket
SZ-008Eight Failures, One Loud SourceUse Python's CSV tools to summarize failed logins without losing successful events or double-counting rows.Security Automationfield2 files35 minidentity triage script report
SZ-009The Three-Layer Case FileFollow a safe chain of local clues through Base64, configuration text, and a ZIP archive.Network Defensefield3 files30 minlocal CTF walkthrough
SZ-010From VPN Login to Case ExportCorrelate authentication and web activity into one defensible incident timeline.SOC Analysisanalyst2 files45 minSOC incident timeline
SZ-011PowerShell After the Ticket ClosedTriage a PowerShell script-block event and connect it to the account and remote training host involved.SOC Analysisanalyst2 files40 minendpoint triage report
SZ-012One Observable, Three SourcesCorroborate fictional observables across local telemetry and an offline enrichment export.Threat Intelligenceanalyst3 files45 minIOC enrichment memo

INVESTIGATION LOOP / STANDARD SHIFT

Brief to evidence to decision to record.

A shift has a clear exit. Finish the case, preserve the reasoning, schedule the recall, and close the console.

  1. 01Receive

    Read the incident brief

    Start with a ticket, alert, or intelligence question written like work you would receive on shift.

  2. 02Inspect

    Work the evidence

    Download authored logs, headers, scripts, and exports. Investigate them in your own terminal.

  3. 03Decide

    Submit a finding

    Commit to an answer. The private evaluator returns field-level pass or retry results without exposing the key.

  4. 04Record

    Preserve the reasoning

    Export a Markdown case record with the evidence, findings, containment decision, and any commands you recorded.

  5. 05Recall

    Review what mattered

    Bring cleared concepts back on a spaced schedule so the technique survives beyond one lab.

CASE OUTPUT / PORTABLE PROOF

A cleared mission leaves behind the investigation record.

The artifact captures the brief, evidence reviewed, learner findings, containment, assistance used, and any commands the learner recorded. It is readable Markdown, not a platform badge.

  • Specific enough to discuss in an interview
  • Exportable to a portfolio or private notebook
  • Clear about simulated evidence and learner decisions
Download demonstration case
CASE RECORDSZ-004.mdSTATUS: CLEARED

# The Invoice That Changed Direction

CLASSIFICATION
Defensive investigation / authored simulation
EVIDENCE
Raw message headers and authentication results
FINDING
Sender identity failed alignment checks
DECISION
Contain, search for related mail, notify, preserve
OUTPUT
phishing triage report
$ grep -i "authentication-results" message-headers.txt
spf=fail  dmarc=fail

# analyst note
The visible sender and authenticated identity do not align.
REVIEWABLE · PORTABLE · LEARNER FINDINGS

ENGINEERING RECORD / PORTFOLIO NOTES

Designed as a tool I can use every day and explain under scrutiny.

This MacBook edition is a ground-up rebuild by Eddie Perry. The design decisions are visible on purpose: local learning state, private answer checks, authored safe evidence, and no hidden command runner.

Application
Shift Zero v1.4.0
Release record
2026-08-11 · health endpoint verified at runtime
Delivery target
Cloudflare Worker with static assets
Persistence
Versioned browser storage with JSON backup
Evaluation
Mission checks server-side; Foundations explicitly guided
Release gate
Lint · types · deterministic tests · clean production build
Curriculum
12 authored cases across 4 operational lanes
Safety model
Simulated evidence, no target access, no command execution
HONEST BUILD BOUNDARY

Shift Zero demonstrates investigation workflow, security-minded product decisions, and deliberate practice. It does not claim production incident experience, issue certificates, or hide simulated work behind inflated metrics.

CONSOLE READY / NEXT SHIFT

Choose a case. Work the evidence. Keep the record.