← Tiers

Analyst Tier 1

Free to learnPro ranges

Monitoring & Triage

The entry stage. Before anyone can respond to an incident they have to be able to see one: what the environment normally looks like, what an attack does to it, and how to work the tooling a SOC actually sits in front of all day. Every page of the material is free to read and needs no account; the ranges that put it into practice need a plan, like every other range.

What this stage covers

  • Core security concepts and the vocabulary of detection and response
  • MITRE ATT&CK as the map of how adversaries actually operate
  • What a live range is and how a session becomes a graded result
  • Reading raw logs and events, and knowing which fields to trust
  • Working Elastic Security: searching, querying, and using the dashboards
  • Taking a single alert end to end, from first signal to written conclusion

What you should be able to do

  • Recognise normal versus suspicious in real telemetry
  • Navigate a SIEM without a runbook holding your hand
  • Map observed activity to an ATT&CK technique
  • Write up a finding someone else can act on

The path through it

Work these in order. Every page is free to read and needs no account.

  1. 01FoundationsThe groundwork a blue-team analyst builds on: core security concepts, the vocabulary of detection and response, and how the pieces of a modern SOC fit together.
  2. 02MITRE ATT&CKThe framework that maps how real adversaries operate. How tactics, techniques, and sub-techniques are organised, and how we use ATT&CK as the backbone of every scenario and detection.
  3. 03How Our Ranges WorkA look under the hood of one of our ranges: the live, breached network you drop into, the telemetry it generates, and how a session goes from launch to auto-graded result.
  4. 04Reading the TelemetryHow to read the logs and events a range actually produces: what normal looks like, what an attack does to it, and the fields worth learning to trust.
  5. 05Using Elastic SecurityA practical tour of the SIEM every range runs on: searching events, building queries, and using the dashboards that turn raw telemetry into a workable lead.
  6. 06Your First InvestigationA start-to-finish walkthrough of your first session: launching a scenario, reading the briefing, how detections, objectives, tries, and hints actually work, and what to do when you get stuck.

Ranges in this stage

Live networks, breached for real, graded automatically.

First Light

Beginner

A burst of failed logons culminates in a successful sign-in from an unusual source -- trace the account, confirm the compromise, and escalate.

~30 min · Available now

Ghostwriter

Beginner

An obfuscated PowerShell command runs on a workstation and quietly pulls something down. Find out what it grabbed and where it came from.

~30 min · Available now

Every technique these stages touch is written up in the TTP Catalog, which spans all three tiers rather than belonging to any one of them.