| Service | Host | Status | Last Check |
|---|---|---|---|
| Student Records (SIS) | sis.osu.internal | Degraded | 2 min ago |
| Active Directory (LDAP) | dc01.osu.internal | Investigating | 4 min ago |
| Email (Exchange) | mail.osu.internal | Operational | 1 min ago |
| Financial Aid Portal | finaid.osu.internal | Offline | 11 min ago |
| Research File Shares | files.osu.internal | Restricted | 6 min ago |
| IT Helpdesk Portal | helpdesk.osu.internal | Operational | 1 min ago |
🔍 Splunk SIEM
Primary analysis environment. All scenario logs — web, SSH, audit, and endpoint — are indexed here. Use the provided detection queries and build your own searches.
Launch Splunk →🛡 Security Onion
Network visibility layer — Zeek connection logs, Suricata alerts, and PCAP replay. Cross-reference Splunk findings with raw network data.
Launch Security Onion →You are a SOC analyst responding to an alert on odapeeka.cover6solutions.com, a university web server. An attacker performed a full kill chain — from initial reconnaissance through ransomware deployment. Reconstruct the timeline using Splunk, Security Onion, and the provided PCAPs.
Your credentials are provided by your instructor before the session begins.
Use your assigned fwl-studentXX@cover6.solutions account on
both Splunk and Security Onion — same password on both systems.
✓ Do not share credentials with other students
✓ Contact your instructor if you experience login issues