BT-LOGLOG ANALYSIS
Log Triage
Read a block of Apache access logs and pick the row that betrays an attacker walking the directory tree.
BEGINNER
A defensive sandbox. Sharpen the eyes that read logs, tune alerts, and pull signal from telemetry noise.
Read a block of Apache access logs and pick the row that betrays an attacker walking the directory tree.
Five Suricata alerts, five packet captures. Mark each one true-positive or false-positive without burning out the SOC.
A YARA rule meets a file dump. Pick the strings that fire the rule.
An email's headers landed on your desk. Find the row that proves SPF failed and the domain was spoofed.
Six events from a real breach scattered out of order. Drop them back into the kill chain.
A Sysmon Process Create event needs a Sigma rule. Pick the rule that actually fires on this telemetry.