Browser LabLD-ELA-LAB-001Easy
Browser LabLD-ELA-LAB-001Easy18 min
Write the Query
Jisr Bank's Elastic Security flags overnight authentication anomalies. You are in Discover on the auth data view. Use KQL — field:value and boolean logic, not free text — to isolate which account was actually taken over, and prove it from the fields.
What you will be able to do
- Filter on ECS fields with KQL rather than free text.
- Read a failed-then-succeeded pattern as account takeover.
- Distinguish a locked-out victim from a compromised one.
Log AnalysisSIEM OperationIncident TriageT1110 — Brute ForceT1078 — Valid Accounts
Sign in to start this lab.
Sign in