SOC Hub

Practice like an analyst · Deploy like one

Engine loading… Learning Mode

🔬 Room 01 — Mumucorp Day 1

Your mission: Mumucorp's SIEM ingested 24 hours of events. Five suspicious patterns are hidden. Find them with SQL.

Show the 5 hidden incidents (spoiler)
  1. Brute-force login attempts against admin from a single external IP
  2. Data exfiltration — a user downloads > 500 MB in a few hours
  3. Lateral movement — service account hits many hosts in minutes
  4. After-hours admin login (between 02:00 and 05:00)
  5. Impossible travel — same user logs in from two countries minutes apart
SQL Editor
Results will appear here