foyl Research is an open, telemetry-rich simulation testbed for studying attention, cognitive workload, and decision-making in security operations. It reframes realistic SOC tasks as controlled experiments: it manipulates signal noise, time pressure, and interface framing while logging millisecond-level interaction data, so socio-technical questions about analyst performance can be studied empirically.
Security analysts work in high-noise, high-tempo environments where alert fatigue, ambiguous evidence, and time pressure degrade judgement. Most security training and tooling is evaluated on whether it functions, not on how it shapes human performance. foyl Research treats a working simulation platform as a research instrument: an ecologically grounded environment in which realistic analyst tasks become controlled experimental probes.
Participants complete instrumented triage and phishing-detection tasks under randomly assigned conditions that vary signal-to-noise ratio, temporal pressure, and motivational framing. The platform records a fine-grained interaction stream and derives sensitivity (d′), decision criterion, time-to-first-diagnostic, and friction measures, alongside validated workload and self-efficacy instruments. The result is a reusable workbench for studying how interface and environmental factors move analyst attention, workload, and accuracy.
Each participant action flows through a logging pipeline; an experimental condition engine parameterises the task the participant sees.
| Factor | Levels | Motivation |
|---|---|---|
| Signal noise | low · high | alert fatigue, discriminability |
| Time pressure | off · on | speed-accuracy tradeoff |
| Framing | control · mastery | self-efficacy, motivation |
| Measure | What it captures |
|---|---|
| d′ / criterion | sensitivity and decision bias (signal-detection theory) |
| Accuracy | correct triage and quarantine/release decisions |
| Time-to-first-diagnostic | onset-to-first-decision latency |
| Friction | hesitation, backtracking, context-switching |
A NASA-TLX rating after each task captures perceived mental demand, temporal load, effort, and frustration.
A short security self-efficacy scale, measured before and after, pairs with the framing manipulation.
A post-task confidence rating supports criterion and calibration analysis against actual accuracy.
No account, no email, no personal data. Every company, person, and incident is fictional.
Begin the studyA technical report describing the instrument and pilot results is in preparation. Researchers can review the aggregate dashboard and study information.