Back to Cybersecurity Track

Global SOC Infrastructure Buildout

Architect and deploy a geographically distributed Security Operations Center using ELK/Splunk and custom SOAR playbooks.

SIEM ArchitectureSOAR Automation
Investigation Progress0/12 steps

Capstone Investigation

You are in a sandbox environment simulating real infrastructure. Complete ALL steps below in order. You must type commands from memory — no answer keys. Read output carefully — you'll be asked analysis questions based on what you see.

1

Step 1: Verify SIEM Health

Confirm Splunk is running and all Splunk daemons are healthy before beginning investigation.

💡 Check the status of the Splunk service using its CLI.

Step 2: Review Log Ingestion Sources

🔒 Complete previous steps to unlock

Step 3: Analysis: Identify Missing Log Source

🔒 Complete previous steps to unlock

Step 4: Enable Forwarder Reception

🔒 Complete previous steps to unlock

Step 5: Restart Splunk to Apply Changes

🔒 Complete previous steps to unlock

Step 6: Query Elasticsearch Cluster Health

🔒 Complete previous steps to unlock

Step 7: Analysis: Diagnose Cluster Status

🔒 Complete previous steps to unlock

Step 8: Analysis: Identify the Problem

🔒 Complete previous steps to unlock

Step 9: Check Elasticsearch Service Status

🔒 Complete previous steps to unlock

Step 10: Investigate Recent Security Alerts

🔒 Complete previous steps to unlock

Step 11: Analysis: Identify the Attacker

🔒 Complete previous steps to unlock

Step 12: Block the Attacker IP

🔒 Complete previous steps to unlock

Investigation Tips

  • • Type 'help' for guidance and current step hints
  • • Type 'objectives' to see your full mission
  • • Read command output carefully — you'll be tested on it
  • • Analysis questions require correct answers to proceed
  • • No answer keys — you must know the commands
  • • 3 wrong analysis answers reveals the hint

Task Status

Complete all 12 steps in order. Progress: 0/12.

Terminal — Capstone Investigation0/12 steps complete
╔══════════════════════════════════════════════════════════════╗
║ iSET+ Capstone Sandbox — Interactive Investigation Environment ║
║ Type 'help' for guidance. Type 'objectives' for your mission. ║
╚══════════════════════════════════════════════════════════════╝
user@iset:~$
user@iset:~$