Level 3
Objective
Something on the network is quietly beaconing outbound. No single log names the culprit — you have to correlate across DNS, proxy and endpoint telemetry to tie the periodic callout back to the process that owns it. Identify the responsible process.
How to play
Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.
Why this matters in 2026
Modern intrusions rarely announce themselves in one log; the analyst who can join DNS to proxy to process-execution reconstructs the whole beacon where a single-source analyst sees only noise. Cross-source correlation is the core hunting skill.
SIEM — OpenSearch Dashboards
Every Sentinel level shares this SIEM — there is no per-level target to spawn.https://sentinel-siem.breachlab.orgOpen the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.
viewerView50d3ca7417ab4518bddc9Aa@