Sentinel Track

Level 2

Signal in the Noise
200 pts+50 first-blood bonus

Objective

Triage an org's overnight activity. Most of it looks alarming — failed logons, odd processes, off-hours access — until one extra field reframes each event as benign. Find the single host where the story never resolves to normal: the one that is genuinely compromised.

How to play

Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.

Why this matters in 2026

Real SOC queues are almost entirely benign-but-scary. Learning to disprove alerts quickly — to find the one field that exonerates each false positive — is what frees an analyst to spend attention on the one host that actually matters.

SIEM — OpenSearch Dashboards

Every Sentinel level shares this SIEM — there is no per-level target to spawn.
https://sentinel-siem.breachlab.org
Open SIEM ↗

Open the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.

Read-only viewer login for Act I:
viewer
View50d3ca7417ab4518bddc9Aa@
🩸
First Blood captured by
ACTIVE RECORD