Scenario
Web Brute Force
Automated password guessing against the Joomla admin login.
Your alert queue starts empty. Launch an attack, wait for Splunk to raise the alert (usually 1–2 minutes), investigate it in Splunk, then submit your verdict: True Positive, False Positive or Benign True Positive.
Checking lab…
Splunk login trainee / Soc-8bb9a670
Session ·
Score 0 / 0
Only alerts raised by Splunk for your own launches. Refreshes every 15 seconds and is saved even when the lab is offline.
No alerts yet. Launch something.
In Splunk: index=soc_live lab_run=<RUN-ID>. Investigate first, then decide. The answer is shown after you submit.
No launches yet.
Red edge = real attack. Grey edge = noise that looks suspicious. In a real SOC you do not get the colour, so prefer the mystery button.
Scenario
Automated password guessing against the Joomla admin login.
Scenario
High-volume POSTs to the login page from an internal host.
Scenario
Web scanner signatures from an Internet address.
Scenario
Port 445/135 sweeps from an internal host.
Scenario
Commands executed by the IIS anonymous account.
Scenario
USB, Word macro, dropper, and C2 lookup on a workstation.
Scenario
cmd.exe launched repeatedly on a workstation.
Scenario
Executables starting from a user AppData folder.
Scenario
Repeated IDS DNS signature between internal servers.
Scenario
USB mass-storage registry activity on a workstation.