PPS CLASS · PROJECT 6 OF 10 · Easy-Medium

Log & SIEM Correlation

Build detection rules that actually catch brute-force attempts and PowerShell abuse in real log data.

Tools For This Project

Splunk SPLELK / KQL

Prerequisites

Coming soon. What you need in place before starting this project (lab state, accounts, prior projects completed) goes here.

Step-by-Step Walkthrough

Coming soon. The full walkthrough, with written steps and screenshots, is being built and filmed as part of the PPS Class. Follow along on AliTere's socials to catch it as it drops.

Notes & Tips

Coming soon. Things to pay attention to while working through this project.

Troubleshooting

Coming soon. Real problems hit while building this project, and how they got fixed.
← Account Takeover Investigation Threat Intel & IOC Enrichment →