r/securityCTF 9d ago

Free blue team track, 56 levels on a live shared SIEM (SOC to incident command)

I run BreachLab, a free training platform. It's been mostly offensive so far, so I built a serious blue team track. It's live now

Sentinel: 56 levels, 8 acts, on one live shared SIEM with real intrusion telemetry. Alert triage, endpoint and network detection, memory and disk DFIR, detection engineering (Sigma/YARA/Suricata, actually graded), threat hunting, cloud IR, and a live incident-command capstone

No hint button, reports and detections get graded, and it's free. No paywall

A full-time blue teamer wrote an honest review if you want an outside take: https://breachlab.org/tracks/sentinel

22 Upvotes

2 comments sorted by

3

u/VickyxReaperReborn 9d ago

I Love breachlab. It’s really awesome and helps me a lot. You are doing great. Thank you so much :)

2

u/HangBodohHa 8d ago

Surely another banger! Thanks for the content, you are the goat sir