Work them in order if you want the narrative to build; skip straight to the one that matches your gap. Every lab states its own objective list, marking table and answer expectations inside the Lab guide view.
1
A correlated incident reaches the queue nine days from its SLA: PowerShell under a delivered link, a startup rule, a mailbox forwarding rule. You claim it, prove the story, bound the blast radius and close it honestly.
- Queue discipline before selection — and the one incident that does not belong
- Assert only the techniques the alerts evidence
- Approvable containment, classification that survives an audit
100 pts7 objectivesKQL blast radius70–90 min
2
One workstation, a signed binary doing information gathering, a beacon, and the same file hash on three hosts. Scope it, read the process tree, then run live response so the evidence survives the session.
- Collect before you mutate — the sequence is graded
- Isolation versus containment, with the business impact named
- Vulnerability remediation and an exception with an owner and an expiry
100 pts7 objectivesLive response console75–95 min
3
A service account logs on at the wrong hour, ten children appear on one device, and the beacon has one jittered interval you must not average away. You write the queries — a real KQL engine runs them in your browser — then turn the finding into a detection and a suppression that expires.
- Four graded queries: row counts come from what your query actually returned
- Severity, category, tactic, frequency and limit that agree with each other
- Alert tuning with scope, expiry and an owning role
100 pts7 objectivesKQL subset engine80–100 min
4
Night shift, on-premises Active Directory: Kerberoasting, a DSync enquiry, a four-minute clock skew on a domain controller and a honeytoken that finally spoke. The graph shows possibility; you have to prove which edge was walked and cut it in the right order.
- Containment sequence — sessions, refresh tokens, then the account, then the password
- Graph limits: SID history, non-joined identities, what a path cannot answer
- Hardening with a governed exception, and a report that keeps “indicated” visible
100 pts7 objectivesAttack-path grid75–95 min
5
Friday 09:00. One reported mail, eleven delivered, four clicked, two credential posts, a forward-and-delete inbox rule, and a detection that was overridden by a tenant rule. Scope it, remediate it in an order that keeps the evidence, then write the record a regulator could read.
- Submission verdicts without inventing a tenant allow list
- Soft delete, ZAP, indicators and approval — in that order
- NIS2 and GDPR clocks on the facts, not the loudest field label
100 pts7 objectivesEmail + identity + policy80–100 min
§
The series standard, in one page
Why these labs look like the console but never pretend to be it, what data they may contain, how the scoring works, and how accessibility is verified rather than claimed.
- Console fidelity with an explicit anti-impersonation boundary
- Synthetic-data rules and the privacy limits on evidence
- Control mapping: NIST, ISO/IEC 27001, CIS, NIS2, GDPR, DORA, PCI DSS
Read before you teach with these