The SOC Blue Team Capstone — Pentest Range Module M5

The SOC Blue Team Capstone — Pentest Range Module M5

Switching Chairs: The SOC Blue Team Capstone (Module M5)

Pentest Range series · Part 5 of 5 · by Vinh NTT

Anyone can learn to run an exploit. The people who get hired — and promoted — are the ones who can look at the aftermath and reconstruct what happened. Module M5 of the CertInstructor Pentest Range is where you build that skill. There's no new target. Instead, you sit in the SOC War Room and investigate the mess you made across M2, M3 and M4 — pulling every indicator of compromise into one coherent story and writing it up.

Simulation only. M5 is an analysis exercise over simulated logs and telemetry. Nothing is scanned or attacked.

Why this is the most important module

The three attack modules each ended with a mini blue-team lab. M5 is the real thing: it takes the IOCs from all three hosts and asks the question a real analyst faces at 2 a.m. — is this one incident, or three unrelated ones? Learning to answer that, with evidence, is the difference between a log-reader and an incident responder.

The M5 investigation — five stages

The labs follow an analyst's actual workflow, in order:

Stage Lab What you do
01 Triage Pull the correlated alert feed across every host — one incident or three?
02 Linux (10.10.10.11) Drill into the endpoint foothold — triage and hunt what happened on M2
03 Windows/AD (10.10.10.12) Hunt the credential theft and lateral movement from M3
04 Web (10.10.10.31) Hunt the web exploitation, exfiltration and impact from M4
05 Correlate & Report Link the hosts into one campaign and write the incident report (capstone)

Step by step

  1. From the portal, enter the SOC capstone (M5) — you'll land in the War Room launcher.
  2. Start with Triage. Open the unified alert feed. Resist the urge to dive into a single host; first form a hypothesis about scope. Are these alerts related in time? Do they share an actor, an IP, a technique?
  3. Work each host in turn — Linux, then Windows, then Web. In each, you hunt for the specific traces the corresponding attack module left behind: the Nmap sweep and NFS abuse on Linux; the EternalBlue hit, LSASS access and Pass-the-Hash on Windows; the SSTI, web shell and exfiltration on the web app. If you did those attack labs, this is a genuine "oh — that's what that looked like from the other side" moment.
  4. Correlate. In the final stage, connect the dots: the same attacker who scanned the subnet from 10.10.10.10 is the one who exploited each target. Stitch the per-host findings into a single timeline — one campaign, one intruder, three victims.
  5. Write the report. The capstone has you produce the incident write-up: what happened, how, what was taken, and what would have stopped it. This is the deliverable that real IR work actually produces — and the skill hiring managers actually test for.

The payoff

Finish M5 and you've done something most self-taught learners never do: you've walked a complete intrusion from both sides — every technique executed as the attacker and detected as the defender. That two-sided fluency is exactly what makes the ATT&CK framework click, because you've now lived both columns of the matrix.

Open the ATT&CK Navigator one last time. Seeing the techniques you attacked and the ones you detected light up together is the clearest picture you'll get of how much ground you've actually covered.

Where M5 fits in your certification path

M5 is detection, log analysis, threat hunting and incident response — the exact job role CompTIA CySA+ certifies. And the correlation-and-reporting capstone, where you reason about an entire campaign and communicate it to decision-makers, reaches into the enterprise defense and risk thinking that SecurityX (CASP+) is built around.

Next step when you're ready:

You've finished the range

Recon, exploitation across three worlds, post-exploitation, and a full defensive investigation — that's the entire lifecycle, walked end to end, for free. If you started at Module M1 not sure what "the kill chain" even meant, look back now: you've lived it.

Thank you for learning on something I built. If it helped, the best thing you can do is send it to the next person who's stuck at that day-one wall.

← Back to the Pentest Range overview


About the author — Vinh NTT (Nguyễn Trần Tường Vinh), founder of CertInstructor, 20+ years in IT-security training. Full CompTIA security stack (Security+, CySA+, PenTest+, SecurityX); two-time EC-Council Instructor Circle of Excellence Award winner (2022 & 2023). The Pentest Range is his original work, shared free for the community to learn on.

0件のコメント

コメントを残す

コメントは公開前に承認される必要があることにご注意ください。