All roadmaps

SOC analysts and on-call engineers

Detection and incident response

Work incidents end to end from web, auth, audit, CI and git evidence using a shell. Each lab starts from a ticket and ends with scope and impact.

0/6 labs solved0%
Start roadmap
  1. 1

    Reading web and auth logs

    Separate attack traffic from normal traffic and attribute it.

    0/2
    • Investigate a credential-stuffing breach

      A customer list leaked. Use web, auth and audit logs to find the account, the attacker and what was exported.

      Not solved
    • Find the SQL injection the WAF missed

      The WAF blocked a noisy sqlmap scan. Use web, WAF and database logs to prove whether anything got through.

      Not solved
  2. 2

    Secrets and supply chain

    Find how a credential leaked and everything it was used for.

    0/2
    • Trace a secret leaked by CI

      A deploy token was used at 2 a.m. from an unknown address. Find how it leaked, who used it and what was read.

      Not solved
    • Trace a key leaked through git history

      A live payments key was “removed” from the repo weeks ago. The repo went public today. Find out what happened.

      Not solved
  3. 3

    Compromise and account takeover

    Reconstruct a server compromise and an account takeover from the evidence.

    0/2