Sentinel Track

Level 5

First Ticket
300 pts+100 first-blood bonus

Objective

Investigate a complete intrusion end to end and deliver the analyst's real product: a full, structured incident ticket. Scope, root cause, impact, indicators, ATT&CK mapping and a chronological timeline — every field graded on its own. This is the Act I capstone.

How to play

Fill the ticket in the panel to the right; passing review reveals the flag to submit.

Why this matters in 2026

The ticket is the deliverable. An investigation nobody can read, reproduce or act on is worthless — writing a defensible, well-scoped incident ticket is the skill that turns a hunch into containment and gets an analyst off the tier-1 queue.

SIEM — OpenSearch Dashboards

Every Sentinel level shares this SIEM — there is no per-level target to spawn.
https://sentinel-siem.breachlab.org
Open SIEM ↗

Open the Act I — SOC Triage saved search (sentinel-act1-*) in Discover — it pre-loads the network, DNS, proxy and endpoint columns you need.

Read-only viewer login for Act I:
viewer
View50d3ca7417ab4518bddc9Aa@
🩸
First Blood captured by
ACTIVE RECORD