SIEM Station
Premium Machine (Locked)
🧩 PurpleTeam
🖧 AD Network — PurpleTeam
Internal host — not internet-facing. Reach it from your cirt-gateway shell or the in-browser Pwnbox at siem-lab-pt.default.svc.cluster.local with the analyst account. All logs from the SolarGate incident are aggregated here. Parse auth.log, the Apache access log, and enriched SIEM events to identify the attacker's source IP and reconstruct the full kill chain. Write an incident report.