Sentinel Track

Level 3

Reading the Logs
200 pts+50 first-blood bonus

Objective

Something on the network is quietly beaconing outbound. No single log names the culprit — you have to correlate across DNS, proxy and endpoint telemetry to tie the periodic callout back to the process that owns it. Identify the responsible process.

How to play

Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.

Why this matters in 2026

Modern intrusions rarely announce themselves in one log; the analyst who can join DNS to proxy to process-execution reconstructs the whole beacon where a single-source analyst sees only noise. Cross-source correlation is the core hunting skill.

SIEM — OpenSearch Dashboards

Every Sentinel level shares this SIEM — there is no per-level target to spawn.
https://sentinel-siem.breachlab.org
Open SIEM ↗

Open the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.

Read-only viewer login for Act I:
viewer
View50d3ca7417ab4518bddc9Aa@
🩸
First Blood captured by
ACTIVE RECORD