Credential AttacksBeginnerFree, no sign-up
Brute Force Detection
A case from the SIEM Lab
Briefing
A correlation rule wakes the night shift at a fictional freight company: a flood of failed logons against a domain controller, then a success. The alert is the easy part. You have the whole night's telemetry across nine sources and must prove the compromise, work out how the intruder got from the perimeter to the file server, and reconstruct what they did once they had a foothold.
693 events9 log sourcesabout 45 min
Solve this case
Opens the lab with this case selected. Graded in the browser; nothing to install.
What you will practise
- Writing SIEM queries that cut hundreds of rows down to the ones that matter
- Following an authentication story from failures to a foothold
- Correlating VPN, directory and host telemetry into one timeline
- Scoping lateral movement and writing it up
Maps to these certifications
Security+CySA+CEH
Log sources in the corpus
Windows Security · VPN · Sysmon · EDR · Proxy · DNS · Firewall · Email Gateway · Cloud Audit
How a case works
- Read the briefing: the alert as the analyst received it, the environment and the time window.
- Work the console: search, filter and pivot across every source; open raw lines; pin evidence.
- Fill the investigation form and write a short executive summary. Hints are available and cost points.
- Get graded per item with the evidence behind each answer, then share your result card.