Phishing CampaignBeginnerFree, no sign-up
Phishing Campaign Triage
A case from the SOC Simulator
Briefing
The SOAR queue has filled with thirty alerts since the start of the shift at a fictional hybrid-Exchange shop, and only a handful of them tell one story. Work the queue like an analyst: decide what to escalate, what to close and what is a duplicate, then follow the real thread through the raw logs to find patient zero, the blast radius and the one change the attacker made to stay.
483 events8 log sourcesabout 40 min
Solve this case
Opens the lab with this case selected. Graded in the browser; nothing to install.
What you will practise
- Triaging an alert queue: escalate, close or merge
- Spotting the signal among duplicate and low-value alerts
- Tracing a credential-phishing wave through identity and mail audit logs
- Finding persistence that does not look like malware
Maps to these certifications
Security+CySA+CEH
Log sources in the corpus
Email Gateway · Azure AD · M365 Audit · Proxy · Sysmon · Windows Security · DNS · Firewall
How a case works
- Read the briefing: the alert as the analyst received it, the environment and the time window.
- Work the console: search, filter and pivot across every source; open raw lines; pin evidence.
- Fill the investigation form and write a short executive summary. Hints are available and cost points.
- Get graded per item with the evidence behind each answer, then share your result card.