Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Alert Triage With Splunk

Premium room

Use Splunk to triage alerts and investigate malicious activity efficiently.

medium

60 min

10,009

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

As a analyst, it’s important to be able to investigate different types of suspicious activity across a variety of assets in the environment. Knowing what to look for and which details matter most during an investigation is a key part of the role.

Learning Objectives

  • Learn how to properly investigate alerts in a environment.
  • Understand how to investigate brute-force attacks on systems.
  • Discover the mechanism on Windows systems.
  • Analyse a web shell on a vulnerable web server.
  • Learn how to investigate alerts for three given scenarios using .

Room Prerequisites

It is suggested to complete the following rooms first before proceeding:

Lab Access

Before proceeding, start the lab by clicking the Start Machine button below. You will then have access to the Web Interface. 
To access , please follow this link: https://LAB_WEB_URL.p.thmlabs.com (opens in new tab). Please wait 4-5 minutes for the instance to launch. Use 's All Time range to search. The indexes where logs are stored for each practical exercise are present in each task.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Target Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Target machine
Status:Off
Answer the questions below

Let's go!