Windows Event-Log Analysis
intermediate Hands-on lab 50 min 3 tasksSubscription
Read Windows like an analyst: reconstruct a complete logon-plus-process-execution sequence from the Security and Sysmon event logs, distinguishing normal activity from an attacker's footprints.
This lab is available with a Purple Edge subscription. Sign in to view the full overview and start the lab.
Part of these paths
Unlock this lab
Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.
Updated 2026-06-06