Welcome back, Hunter!

Ready to continue your threat hunting journey?

Course Progress
0%
0%
Complete
Labs Completed
0 / 9
Labs available now
Achievement Points
0
Complete labs to earn points

Splunk Labs

S00
Beginner
Lab S00 — Splunk, Universal Forwarder, and Stream Setup
Set up Splunk Enterprise, configure the Universal Forwarder for log ingestion, and deploy the Splunk App for Stream to begin monitoring network traffic.
~45 min Splunk · SIEM
Start Lab
S01
Beginner
Lab S01 — Splunk and Sysmon
Install Sysmon on a Windows endpoint, deploy the Splunk Add-on for Microsoft Sysmon, and forward Sysmon event logs into Splunk for threat detection.
~30 min Splunk · Sysmon
Start Lab
S02
Beginner
Lab S02 — Splunk and Zeek
Install and configure Zeek network security monitor, automate log generation, and ingest Zeek logs into Splunk for network traffic analysis.
~45 min Splunk · Zeek
Start Lab
S03
Beginner
Lab S03 — Splunk and OSquery
Install OSquery on Windows and Linux, apply the Palantir configuration, deploy the Splunk Add-on for OSquery, and run SQL-based endpoint queries via Splunk.
~60 min Splunk · OSquery
Start Lab
S04
Intermediate
Lab S04 — Attack Data and Email Detection
Generate MITRE ATT&CK attack data with Atomic Red Team, configure Postfix and Dovecot for email, and build Splunk alerts for threat detection.
~75 min Splunk · MITRE · Postfix
Start Lab
S05
Intermediate
Lab S05 — AirSim Drone Simulation and Splunk ML
Set up Unreal Engine with AirSim, collect drone flight data with Python, and analyze telemetry using the Splunk Machine Learning Toolkit.
~90 min AirSim · Splunk ML
Start Lab
S06
Advanced
Lab S06 — PX4, MAVLink, and MAVSDK
Build and run PX4 firmware in SITL, control a simulated drone using MAVSDK and Python, and stream MAVLink telemetry into Splunk for analysis.
~90 min PX4 · MAVLink · Splunk
Start Lab
S07
Intermediate
Lab S07 — Tello Drone Telemetry to Splunk
Connect a physical DJI Tello drone via WiFi, collect real-time flight telemetry using the djitellopy Python library, and ingest data into Splunk for analysis.
~60 min Tello · Python · Splunk
Start Lab
S08
Advanced
Lab S08 — Detection and Incident Response
Deploy Atomic Red Team from Kali Linux to emulate MITRE ATT&CK T1518.001, then detect, analyze, and respond to the attack using Splunk and Sysmon.
~90 min Red Team · MITRE · Splunk
Start Lab

Recent Activity

Account created
Welcome to Wadjet Security