Detection Lab
Anyone can write a rule that catches the attack. The job is catching it without drowning in false positives. Write detection rules over a labelled log stream, add count-based correlation to kill the noise, and watch your precision and recall move in real time until you catch the whole chain β the spray, the encoded PowerShell, the beacon and the exfil β with zero false alarms. An AI adversary is running the chain live.
Goal
Write detection rules that catch every malicious event in this attack chain (the password spray, the encoded PowerShell, and the beacon + exfil to the bad IP) with ZERO false-positive alerts on the benign noise. The starter rule is too naive β tune it with a count threshold and add rules for the other stages.
Detection rules
Detection quality
Write and tune rules, then run them.
Live now
4 huntingadversary stagingβ¦
What this lab is
- A free SIEM detection-engineering lab: write field-based detection rules and run them against a labelled log stream to see what fires.
- Rules combine conditions (equals / contains / greater-than) with AND, plus an optional count-based correlation (e.g. β₯5 failed logins per user).
- Every alert is graded against ground truth as a true or false positive, giving you live precision and recall.
- The lesson is alert fatigue: a naive rule catches the attack but buries it in false positives β you tune thresholds and specificity until recall is 100% and false positives are zero.
- A live arena shows other detection engineers tuning rules and an AI adversary advancing a real attack chain as you work.
Frequently asked questions
What is the Detection Lab?
A free, in-browser detection-engineering exercise. You write SIEM-style rules β conditions over log fields, optionally correlated by a count threshold β and run them against a stream of labelled events that contains both a real attack chain and benign noise. Each alert is scored as a true or false positive so you can see your precision and recall immediately.
How does count-based correlation work?
Many detections only make sense in aggregate. A single failed login is noise; five from one user in a window is a password spray. Set a rule to count by a field (such as user) with a minimum, and it fires one alert per group that crosses the threshold instead of one per event. This is how you turn a noisy signal into a precise detection.
What are precision and recall here?
Recall is the share of malicious events your rules caught β miss the beacon and your recall drops. Precision is the share of your alerts that were real β fire on benign logins and your precision drops, which is exactly the alert fatigue that makes real SOCs miss true positives. The goal is to catch the whole chain with zero false positives.
Is the attack real?
No. The events and the attack chain are invented training data, labelled so the lab can grade you. The live participants are a self-contained simulation inside the page. Nothing here connects to a real SIEM or log source.