Level 4
Objective
Threat intel handed you one confirmed-malicious domain. Use it as a seed to scope the whole intrusion across the SIEM, then walk the timeline backward to patient zero — the first machine to touch the indicator. Identify that host.
How to play
Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.
Why this matters in 2026
An IOC is a starting point, not a conclusion. Scoping outward from one indicator to the full blast radius, then back to the first-infected host, is exactly how incident responders bound an intrusion and find where it began.
SIEM — OpenSearch Dashboards
Every Sentinel level shares this SIEM — there is no per-level target to spawn.https://sentinel-siem.breachlab.orgOpen the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.
viewerView50d3ca7417ab4518bddc9Aa@