✅ You are authorized to scan this machine. This is a live cybersecurity training environment. Scanning, enumeration, and exploitation are permitted and expected. All activity is logged and forwarded to student SIEM environments.

Odapeeka State University

Office of Information Technology

IT Portal · Systems Status · SOC Operations Dashboard

LAB SYSTEMS ONLINE  |  GCP us-east4-a  |  All activity logged to student SIEM
8,200
Enrolled Students
14
IT Staff
47
Active Subnets
3
Open Incidents
⚠ Active Incident — INC-2026-0312 Anomalous authentication activity detected across multiple endpoints in the registrar subnet (10.6.14.0/24). Investigation ongoing. Users experiencing login failures should contact the helpdesk at ext. 4400.
Service Status
ServiceHostStatusLast Check
Student Records (SIS)sis.osu.internalDegraded2 min ago
Active Directory (LDAP)dc01.osu.internalInvestigating4 min ago
Email (Exchange)mail.osu.internalOperational1 min ago
Financial Aid Portalfinaid.osu.internalOffline11 min ago
Research File Sharesfiles.osu.internalRestricted6 min ago
IT Helpdesk Portalhelpdesk.osu.internalOperational1 min ago
Student Lab Systems

🔍 Splunk SIEM

Primary analysis environment. All scenario logs — web, SSH, audit, and endpoint — are indexed here. Use the provided detection queries and build your own searches.

Launch Splunk →

🛡 Security Onion

Network visibility layer — Zeek connection logs, Suricata alerts, and PCAP replay. Cross-reference Splunk findings with raw network data.

Launch Security Onion →
Scenario — The Odapeeka Breach

You are a SOC analyst responding to an alert on odapeeka.cover6solutions.com, a university web server. An attacker performed a full kill chain — from initial reconnaissance through ransomware deployment. Reconstruct the timeline using Splunk, Security Onion, and the provided PCAPs.

PHASE 01
Reconnaissance
T1595.001 · Active Scanning
PHASE 02
Web Enumeration
T1046 · Service Discovery
PHASE 03
Initial Access
T1190 · T1078 · T1110.001
PHASE 04
C2 Beacon
T1071.001 · Web Protocols
PHASE 05
Internal Recon
T1059.004 · T1087 · T1082
PHASE 06
Exfiltration
T1560.001 · T1048.003
PHASE 07
Ransomware
T1486 · T1490 · T1491.001
Access Credentials

Your credentials are provided by your instructor before the session begins. Use your assigned fwl-studentXX@cover6.solutions account on both Splunk and Security Onion — same password on both systems.

✓ Same username and password on both Splunk and Security Onion
✓ Do not share credentials with other students
✓ Contact your instructor if you experience login issues
Lab Resources