QRadar101 Lab Challenge
Hands-on Analysis & Investigation Guide
Last updated
Hands-on Analysis & Investigation Guide
Last updated
✅ Get familiar with IBM QRadar as a SIEM tool.
🔍 Practice filtering and analyzing logs to track attacker activity.
🕵️♂️ Investigate a real attack scenario using QRadar's event logs and offenses.
🧠 Improve skills in log correlation, event investigation, and IOC identification.
💡 Learn how to extract useful insights and link logs to specific hosts, users, and malicious actions.
📁 Build a clear timeline of the attack using available artifacts (e.g., process creation logs, Suricata alerts, HTTP payloads).
Based on CyberDefenders Blue Team CTF