Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC2-LAB-001Medium
Browser LabLD-SOC2-LAB-001Medium20 min

Correlating a Multi-Source Intrusion

Tier-1 escalated an alert they could not close: a successful logon that looked routine. You have four sources for the same window — an authentication summary, a SIEM detection, an endpoint chain and outbound network flows. Read them together, not one at a time.

What you will be able to do

  • Identify the pivot entity shared across all four sources.
  • Quantify the access step from the authentication evidence.
  • Attribute the command-and-control callout to its source and technique, and decide the action.
Log AnalysisSIEM OperationT1110.003Brute Force: Password SprayingT1059.001Command and Scripting Interpreter: PowerShellT1071.001Application Layer Protocol: Web Protocols

Sign in to start this lab.

Sign in