Repeated failed logons
Five failed authentication events against one account inside a ten-minute window.
BS-AUTH-001 · T1110DEFENSIVE SECURITY · SYNTHETIC LAB
A reproducible Blue Team / SOC learning lab that models Windows security telemetry, detection engineering, investigation and response recommendations using safe simulated events.
01 / END-TO-END WORKFLOW
02 / DETECTION USE CASES
Five failed authentication events against one account inside a ten-minute window.
BS-AUTH-001 · T1110PowerShell process creation with a synthetic encoded-command marker.
BS-PS-001 · T1059.001A synthetic local account event requiring change validation and access review.
BS-ACC-001 · T1136.001A service-change event that demonstrates persistence-oriented triage.
BS-SVC-001 · T1543.00303 / INVESTIGATION METHOD
Every alert carries its source events, host, account, timestamp, confidence, MITRE ATT&CK mapping, containment recommendation and remediation guidance.
✓ Validate the alert
✓ Reconstruct the timeline
✓ Record evidence and uncertainty
✓ Recommend safe containment
✓ Document hardening opportunities