Level 2
Objective
Triage an org's overnight activity. Most of it looks alarming — failed logons, odd processes, off-hours access — until one extra field reframes each event as benign. Find the single host where the story never resolves to normal: the one that is genuinely compromised.
How to play
Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.
Why this matters in 2026
Real SOC queues are almost entirely benign-but-scary. Learning to disprove alerts quickly — to find the one field that exonerates each false positive — is what frees an analyst to spend attention on the one host that actually matters.
SIEM — OpenSearch Dashboards
Every Sentinel level shares this SIEM — there is no per-level target to spawn.https://sentinel-siem.breachlab.orgOpen the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.
viewerView50d3ca7417ab4518bddc9Aa@