SIEM console

Defense center

A simulated analyst workspace for defensive commands, threat hunting labs, triage queues, and evidence review. Data is generated from the database and no external systems are queried.

Open labs

critical

4

Simulated alert queue

high

19

Simulated alert queue

medium

85

Simulated alert queue

low

13

Simulated alert queue

Live event stream

Time Host Severity Source Event
22:14:47 vpn-edge high Kubernetes Extract pod security contexts.
22:07:47 win-hr-014 low Kubernetes List service account token secrets.
22:00:47 web-01 medium Kubernetes Inspect pod security and runtime details.
21:53:47 vpn-edge medium Kubernetes Review cluster events by time.
21:46:47 web-01 high Kubernetes List validating admission webhooks.
21:39:47 web-01 high Kubernetes Review pod resource usage for anomalies.
21:32:47 web-01 low Trivy Scan a container image for vulnerabilities.
21:25:47 linux-jump low Trivy Scan filesystem for vulnerabilities and misconfiguration.

Defensive labs

All labs

Defensive command playbook

Filter library