soc30 / lms
connected
splunk>enterprise
Administrator ▾Settings ▾
ES
Enterprise Security
Splunk App for Enterprise Security · v7.3.0
DAY 30 LAB · LAB 30 — CAPSTONE· week 4
CAPSTONE — full breach: phish → cred theft → VPN → PsExec → DNS exfil → ransomware.
  • 10 notables in your queue (12:04 → 12:55) — they tell ONE story.
  • Triage every notable. Order on a timeline.
  • Map every step to ATT&CK.
  • Deliver: IR report, IOC list, containment plan, 3 new detections.
Hint: Order by time. Map every event. Story: phish → exec → C2 → priv esc → lateral → exfil → ransom.

Incident Review

Status
Urgency
Owner
Time
10 events · Notable Events Timeline
10 of 10 matching
TimeDomainTitleUrgencyStatusOwnerRisk
2026-05-07 12:55:30Networklow18
2026-05-07 12:50:11Networkhigh72
2026-05-07 12:44:55Identityhigh70
2026-05-07 12:41:00Identitymedium42
2026-05-07 12:33:09Networkmedium35
2026-05-07 12:30:44Endpointcritical98
2026-05-07 12:22:14Endpointcritical88
2026-05-07 12:18:51Threathigh78
2026-05-07 12:11:08Endpointcritical92
2026-05-07 12:04:22Accesshigh65