Sentinel Track

Level 4

Follow the Indicator
250 pts+75 first-blood bonus

Objective

Threat intel handed you one confirmed-malicious domain. Use it as a seed to scope the whole intrusion across the SIEM, then walk the timeline backward to patient zero — the first machine to touch the indicator. Identify that host.

How to play

Open the SIEM, investigate the incident, and work out the analytical answer the logs reveal — a token, a hostname, a process name, whatever the brief is asking for. Submit it on this page to bank the points.

Why this matters in 2026

An IOC is a starting point, not a conclusion. Scoping outward from one indicator to the full blast radius, then back to the first-infected host, is exactly how incident responders bound an intrusion and find where it began.

SIEM — OpenSearch Dashboards

Every Sentinel level shares this SIEM — there is no per-level target to spawn.
https://sentinel-siem.breachlab.org
Open SIEM ↗

Open the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.

Read-only viewer login for Act I:
viewer
View50d3ca7417ab4518bddc9Aa@
🩸
First Blood captured by
ACTIVE RECORD