SOC Analyst Exam: VPN + Fileserver Incident

A blue-team SOC examination box. An OpenSearch + Dashboards SIEM runs in Docker, fed by a log generator that writes VPN and fileserver logs; Logstash and Filebeat are installed but STOPPED. The exam: configure the shipper + the Logstash grok pipeline, build index patterns, and hunt the planted incident in Dashboards. Examiner-graded — there are no auto-validated flags.

hard
Machines
NameRoleImageAccessFlags
soc-1victimubuntu-22.04httpssh0
Network
Isolated labyes
Machines see each otheryes
Scoring
Flags0
Total points100
Pass threshold60

Scoring is informational in this preview.

Launch this lab
11launches1operators5solved
Categoryblue-team
Est. duration~180 min
SIEMopensearch

#soc #siem #blue-team #opensearch #logstash #filebeat #exam

Sign in to launch