top of page

DEFENDER SOC

Mission Control for The Defenders.

Review the weekly scenario, study the clues, and prepare to enter the Challenge Room.

YOUR MISSION STARTS HERE

How to Use the Defender SOC

Follow the investigation from top to bottom.

Work through each numbered SOC station in order. Review the information, study the evidence, and build your understanding before entering the Challenge Room.

1 — READ THE MISSION

Start with the weekly scenario.

​

Understand what happened, what service may be affected, and what you are being asked to investigate.

2 — FOLLOW THE EVIDENCE

Move through each numbered SOC station.

​

Review the alerts, tickets, logs, technical evidence, and threat information provided. Look for clues that help explain the incident.

3 — MAKE YOUR RESPONSE DECISION

Use what you discovered.

​

Decide what you believe happened and what the defender should recommend doing next. You are analyzing and recommending actions—not changing real systems.

4 — ENTER THE CHALLENGE ROOM

Put your understanding to the test.

 

Answer the mission questions, make your final decisions, and prove what you learned from the investigation.

Mission Start
Hospital Staff Interaction

THIS WEEK’S CHALLENGE

Hospital Malware Investigation

A suspicious file triggered malware activity on a hospital workstation.
Your mission is to review the evidence, investigate the affected systems, determine whether the activity may have spread, and recommend the safest next response.


Mission Objective:
Protect hospital operations by identifying the suspicious activity, understanding its possible impact, and recommending the safest next step.

01

DETECT

Detection & Alert Review

A security alert has been triggered.

Our monitoring systems have detected unusual activity in the environment. Review the alert, study the available details, and look for the first signs of possible compromise.

Examine alert information

look for suspicious activity

identify clues

D-SOC_pic1_v2.png

02

TRIAGE

Triage & Prioritization

Review the malware alert.

A security ticket has been created for the suspicious activity detected in Step 01. Review the available details to determine how serious the alert may be, which system is affected, and how quickly the SOC should respond.

Review the incident details

Check the severity and affected system

Decide how urgently it should be investigated

D-SOC_pic2_v2.png

03

INVESTIGATE

Investigation & Scoping

Find out what happened on the hospital device.

The security alert has been confirmed for review. Now examine the affected device, review the suspicious activity, and decide whether the issue stayed on one device or spread to others.

Check the affected device

Look for suspicious activity

See if other systems may be affected

Estimate how far the issue may have spread

D-SOC_pic3.png

04

THREAT INTEL

Threat Intelligence & Context

Compare the clues with a known threat profile.

You have already reviewed the suspicious activity on the hospital devices. Now compare those clues with information about known attackers to see whether the behavior looks similar to a known threat.

Review the threat profile

Compare the known behavior with your clues

Look for matching indicators

Decide whether the activity may be related

D-SOC_pic4.png

05

RESPOND

Response Decision

Decide what should happen next.

You have reviewed the alert, investigated the hospital devices, and compared the activity with known threat information. Now use the evidence to recommend the safest next steps before the incident moves into remediation.

Decide which device should be isolated

Identify what should be blocked or disabled

Protect important evidence

Determine whether the incident should be escalated

D-SOC_pic5.png

05

MISSION LAUNCH

Enter the Challenge Room

Use what you learned to make the final call.

You have reviewed the alert, prioritized the incident, investigated the hospital devices, compared the evidence with threat intelligence, and considered the response options. Now enter the Challenge Room and use that information to answer the mission questions.

Review the key clues

Choose the best response

Explain what the evidence shows

Complete the mission

CWC-command_v2.png
bottom of page