Sign In
Elastic & Kibana · Practical Attack Detection

Run the attack, read the logs,
detect the attack.

A fully isolated environment for hands-on blue and red team practice. Execute realistic attack scenarios against the target, then hunt for their traces in Kibana logs and document the incident like a SOC analyst.

What will you do in this lab?

Start with web attacks, move into Active Directory and Windows, and test your detection skills in a live exercise.

Web Scenarios

Web Injection & Vulnerabilities

Run SQL Injection, XSS, IDOR, SSRF, and malicious file uploads against a vulnerable target and hunt them in logs.

9 learning paths
Active Directory

Active Directory Lab

Kerberoasting, AS-REP, ACL abuse, and domain attack paths with secure access via VPN.

Real domain
Live Exercise

Red vs Blue Exercise

The red team runs authorized attacks while the blue team detects them in real time using KQL and evidence.

Live scoring
Documentation

Reporting & Leaderboard

Document incidents like a SOC analyst, submit reports, and see your rank on the class leaderboard.

Rankings

How does it work?

Four simple steps from getting access to submitting your final report.

1

Account created by admin

There is no self-registration; fill out the form below and an admin will create an account for you.

2

Sign in to the dashboard

Sign in with your Elastic account and get access to all scenarios and training tools.

3

Run a scenario

Execute the attack step by step and identify its traces in Kibana and logs.

4

Submit a report

Record your findings and evidence in a SOC report format and earn points and rank.

Request Access

Have a question or want access to the lab? Fill out the form and we will get in touch.

Self-registration is not available. Fill out this form and, after review, an account will be created and login details sent to you.