Level 1
Objective
A workstation tripped a PowerShell alert. Read it end to end — the command line, the parent process, the outbound connection it tried to make — and make the analyst's first real decision: is this a true positive? Identify the external host the payload reached for.
How to play
Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.
Why this matters in 2026
Alert triage is the single most repeated task in a SOC, and what separates a real analyst from a queue-clearer is reading an alert as a story rather than a row — deciding true-positive from false on the evidence in front of them.
SIEM — OpenSearch Dashboards
Every Sentinel level shares this SIEM — there is no per-level target to spawn.https://sentinel-siem.breachlab.orgOpen the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.
viewerView50d3ca7417ab4518bddc9Aa@