Sentinel Track

Level 1

Anatomy of an Alert
150 pts+50 first-blood bonus

Objective

A workstation tripped a PowerShell alert. Read it end to end — the command line, the parent process, the outbound connection it tried to make — and make the analyst's first real decision: is this a true positive? Identify the external host the payload reached for.

How to play

Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.

Why this matters in 2026

Alert triage is the single most repeated task in a SOC, and what separates a real analyst from a queue-clearer is reading an alert as a story rather than a row — deciding true-positive from false on the evidence in front of them.

SIEM — OpenSearch Dashboards

Every Sentinel level shares this SIEM — there is no per-level target to spawn.
https://sentinel-siem.breachlab.org
Open SIEM ↗

Open the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.

Read-only viewer login for Act I:
viewer
View50d3ca7417ab4518bddc9Aa@
🩸
First Blood captured by
ACTIVE RECORD