Briefing

Sentinel drops you into one live SIEM shared by every operator on the crew, no personal sandbox to spin up and reset. The data is real telemetry from real intrusions, and your queries land against the same corpus everyone else is working.

Eight acts carry you from SOC foundations and alert triage through endpoint and network detection, memory and disk forensics, detection engineering, threat hunting and CTI, cloud and identity DR, and a live-SOC graduation capstone where you run incident command on a full campaign.

Eight acts, one SOC
  • Act I. SOC Foundations & Alert Triage (L0–L5)
    Orient in the SIEM, learn the SOC frameworks, and work your first alerts end-to-end, up to a full graded incident ticket.
  • Act II. Endpoint & Windows Detection (L6–L12)
    Windows telemetry hunting: logon forensics, process ancestry, PowerShell deobfuscation, persistence, credential access, and defense evasion, into a full endpoint kill-chain report.
  • Act III. Network Detection & Phishing (L13–L19)
    Packet and Zeek analysis, C2 beaconing, DNS tunneling, phishing header forensics and attachment teardown, culminating in a full network-intrusion report.
  • Act IV. DFIR: Memory & Disk (L20–L27)
    Host forensics on the endpoint the wire led to: memory triage with Volatility 3, disk-triage with KAPE, deleted-file and execution-artifact recovery, timestomp and log-clear detection, an interrupted-ransomware live response, and a full host post-mortem with an ordered kill chain.
  • Act V. Detection Engineering (L28–L35)
    Detection-as-code, author Sigma, YARA and Suricata rules graded fire-on-evil and silent-on-benign against held-out corpora: first Sigma rules, false-positive tuning, multi-backend portability, malware-family and C2 detection, a real CI gate, coverage-gap analysis, and a full multi-modal detection pack.
  • Act VI. Threat Hunting & CTI (L36–L42)
    Go hunting without an alert: hypothesis-driven hunts across a shared enterprise estate (unsigned-service persistence, stack-counting a beacon, host-to-cloud living-off-the-land, an insider exfil), then consume and produce intelligence (IOC/TTP extraction, responsible attribution), and graduate on an intel-led hunt that closes the loop from lead to findings report to a shipped detection.
  • Act VII. Cloud & Identity DR (L43–L49)
    A full Entra ID + M365 identity-first cloud intrusion: illicit consent, AiTM token replay, app/role persistence, CA tamper, M365 mail exfil, and a cloud-IR capstone that closes the loop with a KQL detection.
  • Act VIII. Capstone: Incident Command (L50–L55)
    The live-SOC finale: work a real alert queue, scope and contain a breach start to finish, hand off a shift mid-incident, run a purple-team correlation pass against your own detections, and graduate as incident commander on the full campaign.

SIEM · OpenSearch Dashboards

Every Sentinel level shares one live SIEM, with no per-level target to spawn. Each act uses its own read-only viewer login; the OpenSearch role lock scopes what each can see. Your Act I entry login:
viewer
View50d3ca7417ab4518bddc9Aa@
Each later act uses its own separate login, shown on those levels once you clear the previous act.Open SIEM ↗

Levels

#LevelPointsOperativesFirst BloodStatus
Act ISOC Foundations & Alert Triage
0Day One in the SOC10013@ravi
1Anatomy of an Alert1509@ravi
2Signal in the Noise2006@ravi
3Reading the Logs2006@ravi
4Follow the Indicator2506@ravi
5First Ticket3005@ravi
Act IIEndpoint & Windows Detection
6Borrowed Logons3505@zxd1
7Family Tree4005@zxd1
8Unwrapping the Payload4505@zxd1
9Squatter's Rights5005@zxd1
10Memory Thief5505@zxd1
11Blindfold6005@zxd1
12Full Kill Chain8002@ravi
Act IIINetwork Detection & Phishing
13First Packets4502@iinovacore
14Needle in the Flows5502@iinovacore
15Steady Drumbeat6502@iinovacore
16Whispers in DNS6502@iinovacore
17Return to Sender7502@iinovacore
18Open Carefully8002@iinovacore
19Full Callback1000FIRST BLOOD AVAILABLE
Act IVDFIR: Memory & Disk
20First Dump500FIRST BLOOD AVAILABLE
21Hollow Man600FIRST BLOOD AVAILABLE
22Secrets in the Dump700FIRST BLOOD AVAILABLE
23Deleted, Not Gone700FIRST BLOOD AVAILABLE
24What Ran Here700FIRST BLOOD AVAILABLE
25Covering Tracks850FIRST BLOOD AVAILABLE
26Zero Hour900FIRST BLOOD AVAILABLE
27Full Post-Mortem1200FIRST BLOOD AVAILABLE
Act VDetection Engineering
28First Sigma Rule550FIRST BLOOD AVAILABLE
29Fire on Evil, Silent on Benign650FIRST BLOOD AVAILABLE
30Sigma at Scale750FIRST BLOOD AVAILABLE
31Family Resemblance750FIRST BLOOD AVAILABLE
32On the Wire800FIRST BLOOD AVAILABLE
33Merge the Rule800FIRST BLOOD AVAILABLE
34Mind the Gap900FIRST BLOOD AVAILABLE
35Ship the Pack1300FIRST BLOOD AVAILABLE
Act VIThreat Hunting & CTI
36The Hunt Begins700FIRST BLOOD AVAILABLE
37Find the Outlier800FIRST BLOOD AVAILABLE
38Off the Land, Into the Cloud900FIRST BLOOD AVAILABLE
39The Insider1000FIRST BLOOD AVAILABLE
40Read the Intel1000FIRST BLOOD AVAILABLE
41Trace the Campaign1150FIRST BLOOD AVAILABLE
42Intel-Led Hunt1600FIRST BLOOD AVAILABLE
Act VIICloud & Identity DR
43Illicit Consent750FIRST BLOOD AVAILABLE
44Impossible Traveler850FIRST BLOOD AVAILABLE
45Keys to the Kingdom950FIRST BLOOD AVAILABLE
46Privilege Creep1050FIRST BLOOD AVAILABLE
47Blind the Sensors1150FIRST BLOOD AVAILABLE
48Mailbox Heist1300FIRST BLOOD AVAILABLE
49Cloud Incident Response1800FIRST BLOOD AVAILABLE
Act VIIICapstone: Incident Command
50The Live Queue2000FIRST BLOOD AVAILABLE
51Scope the Breach2200FIRST BLOOD AVAILABLE
52Contain, Eradicate & Harden2400FIRST BLOOD AVAILABLE
53Shift Handover2600FIRST BLOOD AVAILABLE
54Purple Grand Finale2800FIRST BLOOD AVAILABLE
55Graduation: Incident Command3000FIRST BLOOD AVAILABLE