Lab 15 • Defensive Cyber Operations
Defensive SOC Case Lab & Incident Containment
Triage telemetry alerts into Benign, Suspicious, or Critical. Contain compromised identity accounts while avoiding false-positive business disruptions on approved executive travel.
SIEM Real-Time Ingestion Queue
08:14 UTC • cfo@company.comsuspicious
Login from Tokyo IP. Note: CFO has approved travel itinerary on file with IT desk.
08:19 UTC • admin_svcsuspicious
42 consecutive failed SSH attempts followed by successful sudo privilege escalation from unknown subnet.
08:24 UTC • sales_rep1@company.comsuspicious
Clicked link in email claiming "Urgent Wire Receipt Update" pointing to inert domain [hxxp://pay-internal-portal[.]top]