RCW IT TrainingHands-on cybersecurity labs

Defender XDR series · five advanced labs · 500 points

Microsoft Defender practice labs that mark the reasoning, not the clicking

Five console-replica labs built for people who already know where the alert queue is. Each one drops you into a simulated tenant at a fixed clock, gives you synthetic telemetry you can actually query, and refuses the shortcut — the hard delete before the export, the tenant-wide allow list, the unbounded hunt, the report that calls an indicator confirmed when it is still pending.

100 pts per lab · 7 objectives Offline · no tenant, no login Real KQL engine in the browser WCAG 2.2 AA · keyboard-first NIST · ISO 27001 · NIS2 mapped
Pradeep Raju, founder of RCW IT Training Built by Pradeep Raju, founder, RCW IT Training · labs written from real shift practice, run entirely in your browser.

The five labs

Work them in order if you want the narrative to build; skip straight to the one that matches your gap. Every lab states its own objective list, marking table and answer expectations inside the Lab guide view.

Defender incident triage, response and closure

A correlated incident reaches the queue nine days from its SLA: PowerShell under a delivered link, a startup rule, a mailbox forwarding rule. You claim it, prove the story, bound the blast radius and close it honestly.

  • Queue discipline before selection — and the one incident that does not belong
  • Assert only the techniques the alerts evidence
  • Approvable containment, classification that survives an audit
100 pts7 objectivesKQL blast radius70–90 min

Defender for Endpoint containment and live response

One workstation, a signed binary doing information gathering, a beacon, and the same file hash on three hosts. Scope it, read the process tree, then run live response so the evidence survives the session.

  • Collect before you mutate — the sequence is graded
  • Isolation versus containment, with the business impact named
  • Vulnerability remediation and an exception with an owner and an expiry
100 pts7 objectivesLive response console75–95 min

Advanced hunting to working detection

A service account logs on at the wrong hour, ten children appear on one device, and the beacon has one jittered interval you must not average away. You write the queries — a real KQL engine runs them in your browser — then turn the finding into a detection and a suppression that expires.

  • Four graded queries: row counts come from what your query actually returned
  • Severity, category, tactic, frequency and limit that agree with each other
  • Alert tuning with scope, expiry and an owning role
100 pts7 objectivesKQL subset engine80–100 min

Identity attack paths and hybrid containment

Night shift, on-premises Active Directory: Kerberoasting, a DSync enquiry, a four-minute clock skew on a domain controller and a honeytoken that finally spoke. The graph shows possibility; you have to prove which edge was walked and cut it in the right order.

  • Containment sequence — sessions, refresh tokens, then the account, then the password
  • Graph limits: SID history, non-joined identities, what a path cannot answer
  • Hardening with a governed exception, and a report that keeps “indicated” visible
100 pts7 objectivesAttack-path grid75–95 min

Defender for Office 365: campaign containment and tracking

Friday 09:00. One reported mail, eleven delivered, four clicked, two credential posts, a forward-and-delete inbox rule, and a detection that was overridden by a tenant rule. Scope it, remediate it in an order that keeps the evidence, then write the record a regulator could read.

  • Submission verdicts without inventing a tenant allow list
  • Soft delete, ZAP, indicators and approval — in that order
  • NIS2 and GDPR clocks on the facts, not the loudest field label
100 pts7 objectivesEmail + identity + policy80–100 min

The series standard, in one page

Why these labs look like the console but never pretend to be it, what data they may contain, how the scoring works, and how accessibility is verified rather than claimed.

  • Console fidelity with an explicit anti-impersonation boundary
  • Synthetic-data rules and the privacy limits on evidence
  • Control mapping: NIST, ISO/IEC 27001, CIS, NIS2, GDPR, DORA, PCI DSS
Read before you teach with these

How these labs are built

The same eight rules apply to all five. They are what makes the practice transferable to a real shift without the lab pretending to be vendor software.

Console replica
Layout, terminology, list → pane → page flow, filters, action centre and approval states follow the 2026 portal so the transfer to a real console is muscle memory. No Microsoft logo, no 4-square mark, no claim of affiliation.
Fully offline
Static HTML, CSS and vanilla JavaScript. No analytics, no web fonts, no CDN, no API, no login, no telemetry. Opening the network tab shows requests for the page’s own files and nothing else.
Synthetic tenant
One fabricated tenant, contoso-rcw.example. Reserved example domains for addresses, documentation ranges for IPs, invented message IDs and hashes. Nothing here came out of anyone’s environment.
No learner data collected
Progress lives in localStorage in your browser and nowhere else. The audit log is local, redacts identities by default, and is only shared if you export and send it yourself.
Graded on reasoning
Every objective combines a state check (what you selected, in what order, with what approval) and a written field with a floor length and required vocabulary. “Looks right” does not pass.
Queries actually run
A KQL subset engine in shared/kql-lite.js executes your query against the same tables the answer key was derived from, so bounds, joins, projections and aggregates are verified — not pattern-matched.
Shortcuts recorded
Destructive-first actions, unapproved verbs and over-claims are flagged and stay flagged until you redo the sequence, mirroring an action centre that remembers what you did.
Accessibility is a spec item
WCAG 2.2 AA target: single tab stop, roving focus in grids, live-region announcements for selection and sequence state, 3:1 focus outline, forced-colours and reduced-motion support, print view that expands the tabs.

Not certification preparation. These labs practise judgement on synthetic data. They do not follow an exam outline, do not award credit, and are not affiliated with or endorsed by Microsoft. Product names are used to teach the workflow.