Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-ELA-LAB-001Easy
Browser LabLD-ELA-LAB-001Easy18 min

Write the Query

Jisr Bank's Elastic Security flags overnight authentication anomalies. You are in Discover on the auth data view. Use KQL — field:value and boolean logic, not free text — to isolate which account was actually taken over, and prove it from the fields.

What you will be able to do

  • Filter on ECS fields with KQL rather than free text.
  • Read a failed-then-succeeded pattern as account takeover.
  • Distinguish a locked-out victim from a compromised one.
Log AnalysisSIEM OperationIncident TriageT1110Brute ForceT1078Valid Accounts

Sign in to start this lab.

Sign in