Level 0
Objective
Orient inside the SIEM before you hunt anything. Learn where the data lives, how to pivot between the frameworks the SOC actually runs on — the NIST incident-response lifecycle, MITRE ATT&CK, the Cyber Kill Chain and the Pyramid of Pain — and prove you can navigate the console by recovering your analyst onboarding token from the platform's own logs.
How to play
Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.
Why this matters in 2026
Every SOC hire spends week one learning the console and the vocabulary before they touch a live alert. Analysts who move fluently between ATT&CK, the kill chain and the incident lifecycle triage faster and escalate cleaner than the ones who only know how to scroll.
SIEM — OpenSearch Dashboards
Every Sentinel level shares this SIEM — there is no per-level target to spawn.https://sentinel-siem.breachlab.orgOpen the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.
viewerView50d3ca7417ab4518bddc9Aa@