HACK THE SOC
Most training hands you a labelled alert and asks what it is. This hands you the whole feed and asks what's wrong with it.
Real vendor telemetry. A live intrusion buried in ordinary traffic. No hints, no highlighting — you investigate, you decide, you write the report, and it gets marked against what actually happened.
Licensed access · Individual seats and cohort licences for colleges
Live alert feed
- 09:47:12CRITICALCRWD-9F3A7C12Encoded PowerShell spawned by WINWORD.EXEWS-FIN-3041
- 09:47:18HIGHPAN-A8B12345Outbound TLS to telemetry-api-3a8f1.xyzWS-FIN-3041
- 09:47:30HIGHSYSMON-0001HKCU\Run key 'WindowsUpdater' createdWS-FIN-3041
- 09:48:02CRITICALCRWD-9F3A7C5ELSASS MiniDump via comsvcs.dllWS-FIN-3041
- 09:51:44HIGHOKTA-77BB12SSO from new ASN, impossible travela.park@cryotech.io
- 09:54:18HIGHAWS-CT2278S3 GetObject 184MB customer-exportsa.park@cryotech.io
Six of these belong to the same intrusion. The rest of the shift doesn't.
Your verdict
IOC notebook
- HOSTWS-FIN-3041
- DOMAINtelemetry-api-3a8f1.xyz
- USERa.park@cryotech.io
- TTPT1003.001
Tagged by you, as you read the evidence.