Shift 09:00 — 17:00 · Morning
SOC Operations Home
Environment ACME-CORP is ingesting live telemetry. You are working this shift as SOC Analyst L1.
Events Today
1,248,209
+4.2% vs baseline
Active Alerts
25
36 total ingested
Critical Alerts
5
Requires L2 review
Open Incidents
3
1 SLA breach
SOC Status
Operational
17 sources · 3 degraded
Event ingestion — last 24 hours
Events per hour vs alerts raised
Latest threats
Newest detections in the queue
- criticalALT-2405
Ransomware canary file modified on file server
SRV-SQL-01 · 1970-01-01 08:37:00Z
- criticalALT-2412
Encoded PowerShell spawned by Microsoft Word
SRV-SQL-01 · 1970-01-01 08:27:00Z
- criticalALT-2426
LSASS memory access by unsigned binary
LNX-BUILD-07 · 1970-01-01 08:16:00Z
- mediumALT-2411
Scheduled task created for persistence
WS-FIN-014 · 1970-01-01 07:44:00Z
- highALT-2425
Password spray against Entra ID tenant
WS-ENG-231 · 1970-01-01 07:16:00Z
My tasks
Assigned across alerts and incidents
Learning progress
1/32 lessons complete
Recommended lab
Matched to your role and gaps
Phishing Attack
BeginnerMacro document leads to a PowerShell loader and C2 beacon.
Launch scenario · 45mPassword Spray
BeginnerDistributed authentication failures against the identity provider.
Launch scenario · 35mAccount Compromise
IntermediateValid account abuse, inbox rules and data staging.
Launch scenario · 50mOpen incidents
Cases requiring coordination
| ID | Title | Severity | Status | Owner | SLA |
|---|---|---|---|---|---|
| INC-1041 | Phishing-led intrusion with credential dumping on WS-FIN-014 | critical | Investigating | S. Hartono | 4h response · 2h 10m elapsed |
| INC-1042 | Password spray followed by mailbox rule abuse | high | Contained | D. Kusuma | 8h response · met |
| INC-1043 | Ransomware staging detected on SRV-FILE-03 | critical | Eradication | A. Pratama | 1h response · breached by 12m |