SOC Analyst Exam: VPN + Fileserver Incident
A blue-team SOC examination box. An OpenSearch + Dashboards SIEM runs in Docker, fed by a log generator that writes VPN and fileserver logs; Logstash and Filebeat are installed but STOPPED. The exam: configure the shipper + the Logstash grok pipeline, build index patterns, and hunt the planted incident in Dashboards. Examiner-graded — there are no auto-validated flags.
hard
Machines
| Name | Role | Image | Access | Flags |
|---|---|---|---|---|
| soc-1 | victim | ubuntu-22.04 | httpssh | 0 |
Network
Isolated labyes
Machines see each otheryes
Scoring
Flags0
Total points100
Pass threshold60
Scoring is informational in this preview.
Launch this lab
11launches1operators5solved
Categoryblue-team
Est. duration~180 min
SIEMopensearch
#soc #siem #blue-team #opensearch #logstash #filebeat #exam
Sign in to launch