Sentinel Track
Level 5
First Ticket
300 pts+100 first-blood bonus
Objective
Investigate a complete intrusion end to end and deliver the analyst's real product: a full, structured incident ticket. Scope, root cause, impact, indicators, ATT&CK mapping and a chronological timeline — every field graded on its own. This is the Act I capstone.
How to play
Fill the ticket in the panel to the right; passing review reveals the flag to submit.
Why this matters in 2026
The ticket is the deliverable. An investigation nobody can read, reproduce or act on is worthless — writing a defensible, well-scoped incident ticket is the skill that turns a hunch into containment and gets an analyst off the tier-1 queue.
SIEM — OpenSearch Dashboards
Every Sentinel level shares this SIEM — there is no per-level target to spawn.https://sentinel-siem.breachlab.orgOpen the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.
Read-only viewer login for Act I:
viewerView50d3ca7417ab4518bddc9Aa@🩸
ACTIVE RECORDFirst Blood captured by
@ravi