Run the attack, read the logs,
detect the attack.
A fully isolated environment for hands-on blue and red team practice. Execute realistic attack scenarios against the target, then hunt for their traces in Kibana logs and document the incident like a SOC analyst.
What will you do in this lab?
Start with web attacks, move into Active Directory and Windows, and test your detection skills in a live exercise.
Web Injection & Vulnerabilities
Run SQL Injection, XSS, IDOR, SSRF, and malicious file uploads against a vulnerable target and hunt them in logs.
9 learning pathsActive Directory Lab
Kerberoasting, AS-REP, ACL abuse, and domain attack paths with secure access via VPN.
Real domainRed vs Blue Exercise
The red team runs authorized attacks while the blue team detects them in real time using KQL and evidence.
Live scoringReporting & Leaderboard
Document incidents like a SOC analyst, submit reports, and see your rank on the class leaderboard.
RankingsHow does it work?
Four simple steps from getting access to submitting your final report.
Account created by admin
There is no self-registration; fill out the form below and an admin will create an account for you.
Sign in to the dashboard
Sign in with your Elastic account and get access to all scenarios and training tools.
Run a scenario
Execute the attack step by step and identify its traces in Kibana and logs.
Submit a report
Record your findings and evidence in a SOC report format and earn points and rank.
Request Access
Have a question or want access to the lab? Fill out the form and we will get in touch.