SOC L1 alerts

Your alert queue starts empty. Launch an attack, wait for Splunk to raise the alert (usually 1–2 minutes), investigate it in Splunk, then submit your verdict: True Positive, False Positive or Benign True Positive.

Checking lab…

Splunk login trainee / Soc-8bb9a670

Open Splunk

Session  · 

Score 0 / 0

My alert queue

Only alerts raised by Splunk for your own launches. Refreshes every 15 seconds and is saved even when the lab is offline.

No alerts yet. Launch something.

My verdicts

In Splunk: index=soc_live lab_run=<RUN-ID>. Investigate first, then decide. The answer is shown after you submit.

No launches yet.

Scenarios

Red edge = real attack. Grey edge = noise that looks suspicious. In a real SOC you do not get the colour, so prefer the mystery button.

Scenario

Web Brute Force

Automated password guessing against the Joomla admin login.

Scenario

Login Load Test

High-volume POSTs to the login page from an internal host.

Scenario

External Vulnerability Scan

Web scanner signatures from an Internet address.

Scenario

Internal Nessus Scan

Port 445/135 sweeps from an internal host.

Scenario

Web Shell on IIS

Commands executed by the IIS anonymous account.

Scenario

Macro Ransomware Chain

USB, Word macro, dropper, and C2 lookup on a workstation.

Scenario

Forwarder Script Noise

cmd.exe launched repeatedly on a workstation.

Scenario

Software in AppData

Executables starting from a user AppData folder.

Scenario

IDS Malformed DNS

Repeated IDS DNS signature between internal servers.

Scenario

Built-in Card Reader

USB mass-storage registry activity on a workstation.