Track 07
Sentinel
56 Levels · Blue-Team Detection & Response
The defender's track: triage, hunt, and investigate real intrusions inside a live, shared SIEM.
Briefing
Sentinel drops you into one live SIEM shared by every operator on the crew, no personal sandbox to spin up and reset. The data is real telemetry from real intrusions, and your queries land against the same corpus everyone else is working.
Eight acts carry you from SOC foundations and alert triage through endpoint and network detection, memory and disk forensics, detection engineering, threat hunting and CTI, cloud and identity DR, and a live-SOC graduation capstone where you run incident command on a full campaign.
Eight acts, one SOC
- Act I. SOC Foundations & Alert Triage (L0–L5)
Orient in the SIEM, learn the SOC frameworks, and work your first alerts end-to-end, up to a full graded incident ticket. - Act II. Endpoint & Windows Detection (L6–L12)
Windows telemetry hunting: logon forensics, process ancestry, PowerShell deobfuscation, persistence, credential access, and defense evasion, into a full endpoint kill-chain report. - Act III. Network Detection & Phishing (L13–L19)
Packet and Zeek analysis, C2 beaconing, DNS tunneling, phishing header forensics and attachment teardown, culminating in a full network-intrusion report. - Act IV. DFIR: Memory & Disk (L20–L27)
Host forensics on the endpoint the wire led to: memory triage with Volatility 3, disk-triage with KAPE, deleted-file and execution-artifact recovery, timestomp and log-clear detection, an interrupted-ransomware live response, and a full host post-mortem with an ordered kill chain. - Act V. Detection Engineering (L28–L35)
Detection-as-code, author Sigma, YARA and Suricata rules graded fire-on-evil and silent-on-benign against held-out corpora: first Sigma rules, false-positive tuning, multi-backend portability, malware-family and C2 detection, a real CI gate, coverage-gap analysis, and a full multi-modal detection pack. - Act VI. Threat Hunting & CTI (L36–L42)
Go hunting without an alert: hypothesis-driven hunts across a shared enterprise estate (unsigned-service persistence, stack-counting a beacon, host-to-cloud living-off-the-land, an insider exfil), then consume and produce intelligence (IOC/TTP extraction, responsible attribution), and graduate on an intel-led hunt that closes the loop from lead to findings report to a shipped detection. - Act VII. Cloud & Identity DR (L43–L49)
A full Entra ID + M365 identity-first cloud intrusion: illicit consent, AiTM token replay, app/role persistence, CA tamper, M365 mail exfil, and a cloud-IR capstone that closes the loop with a KQL detection. - Act VIII. Capstone: Incident Command (L50–L55)
The live-SOC finale: work a real alert queue, scope and contain a breach start to finish, hand off a shift mid-incident, run a purple-team correlation pass against your own detections, and graduate as incident commander on the full campaign.
SIEM · OpenSearch Dashboards
Every Sentinel level shares one live SIEM, with no per-level target to spawn. Each act uses its own read-only viewer login; the OpenSearch role lock scopes what each can see. Your Act I entry login:viewerView50d3ca7417ab4518bddc9Aa@