Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC1-LAB-008Medium
Browser LabLD-SOC1-LAB-008Medium18 min

Three Sources, One Aggregation

It is a normal shift and your SIEM dashboard shows three summaries: failed logins by source, outbound connections by destination, and a data-transfer view. Nothing here is a raw event — your job is to read the aggregations correctly and decide which rows are noise, which is a spray, and which is a beacon. Reading count without its second dimension is the trap the whole lab is built around.

What you will be able to do

  • Separate a scanner from a spray using distinct-user count
  • Identify beaconing from a regular interval and constant byte size
  • Decide true positive vs false positive from evidence, not volume
SIEM OperationLog AnalysisNetwork AnalysisIOC AnalysisT1110.003Password SprayingT1071.001Application Layer Protocol: Web Protocols

Sign in to start this lab.

Sign in