Red / Blue / Purple
Red team has a two-hour window against the range. Blue must detect, respond and map every action to ATT&CK.
- Detect & respond
- Map activity to MITRE ATT&CK
- Collaborate as a purple team
- Red objectives & limits
- Blue detection & response
- Purple collaboration
- Threat hunting
- Detection engineering
- Deconfliction
Four-mode learning matrix
Stand up log forwarding from a device to a collector.
Labs 10–11 — Investigate auth / access logs; forward logs to a SIEM.
Enter a virtual SOC; run a red-vs-blue simulation. Role: SOC analyst.
No headset? Desktop SIEM screenshots + rules. Printed and mobile versions are also available.
Build one detection rule and test it.
Purple-team round: red acts, blue detects, map to ATT&CK.
- SIEM training VM (e.g., Security Onion)
- Log sources
- Security Onion / SIEM
- Sigma rules
SOC analysts spend their shift doing exactly this: triage, map, respond, document.
From idp and jump logs, reconstruct who accessed what and when.
Forward proxy, idp and sensor logs to siem; confirm ingestion and build one dashboard.
Run the provided attack script; write one detection rule and map it to ATT&CK.