Back to labs
defensive Intermediate Free

Basic Splunk Search Query

Run a safe simulated search for failed Windows logons.

Scenario

You are hunting for failed logon attempts in Windows security logs.

Objective

Find Event ID 4625 in the simulated index.

Target infrastructure

Provided in the lab scenario

Example command format

index=windows EventCode=4625

Beginners can use this as the first clue before entering the exercise.

Safety disclaimer

This is a simulated educational terminal. CyberCLI Web never executes your input, never runs Nmap, Hydra, SQLMap, Metasploit, or shell commands, and never connects to external targets.

Log in to start