Section 1 · 1 tasks
Log Fundamentals
Theory
Useful fields include timestamp, source and destination IP, username, hostname, event type, and status. Normalize time zones before comparing systems. A single event rarely tells the whole story.
soc · beginner
Connect fictional authentication, web, and system events into an evidence-based timeline.
Login required to start this lab and save your progress.
Section 1 · 1 tasks
Useful fields include timestamp, source and destination IP, username, hostname, event type, and status. Normalize time zones before comparing systems. A single event rarely tells the whole story.
Section 2 · 1 tasks
Authentication logs show sign-in attempts, web logs show requests, and system/audit logs show process or privilege activity. Correlation looks for shared fields such as 10.20.30.80, user alex, and host workstation-07.
Section 3 · 1 tasks
Start with one validated event, search a narrow time window, match stable fields, order results, and note uncertainty. Correlation demonstrates a relationship in the evidence; it does not automatically prove who operated a device.
Section 4 · 3 tasks
alex from 10.20.30.80alex from 10.20.30.80alex launched whoami on workstation-07/admin/export from workstation-07These records are fictional and contain no personal data.