Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Alert Triage With Elastic

Premium room

Investigate alerts with Elastic by analyzing logs and spotting threats.

medium

60 min

8,320

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

As a Security Operations Center () analyst, you aim to investigate alerts and escalate incidents with clear evidence to support your findings. In this guided-challenge room, you'll use (part of the Elastic Stack) to perform alert triage and initial investigations, analyzing suspicious activity on an and Windows server. You’ll explore potential indicators of compromise (IoCs) and collect evidence by correlating events across multiple log sources to gain a deeper understanding of the attack.

Objectives

  • Use to analyze common security logs
  • Learn how to identify key indicators of compromise
  • Correlate events across multiple log sources
  • Uncover the breach through a series of alerts

Prerequisites

Machine Access

Click the Start Machine button below. Please give Elastic five minutes to start and access the dashboard with this link:

  • https://LAB_WEB_URL.p.thmlabs.com/

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Target Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Target machine
Status:Off
Answer the questions below

I understand the learning objectives and am ready to investigate with Elastic!

Ready to learn Cyber Security?

The Alert Triage With Elastic room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.

Already have an account? Log in

We use cookies to ensure you get the best user experience. For more information see our cookie policy.