Skip to main content
ThreatLab gives security operations teams a dedicated console for building and running realistic investigation training. Instructors author exercise scenarios with ordered investigation steps and real log archives; analysts work through them against actual SIEM infrastructure — Splunk, QRadar, or Elasticsearch — and submit findings as they go.

Quick Start

Get ThreatLab running and complete your first exercise in minutes.

Authoring Exercises

Build investigation scenarios with steps, archives, and MITRE tags.

API Reference

Explore the full REST API for sessions, noise jobs, and health checks.

SIEM Integrations

Connect Splunk, QRadar, and Elasticsearch to ship log archives.

What you can do with ThreatLab

ThreatLab covers the full training lifecycle — from authoring content to measuring analyst performance.

Exercise Authoring

Upload LEEF or ECS log archives, define investigation steps, and set expected artifacts.

Learning Paths

Sequence exercises into structured curricula with automatic unlock logic.

Analyst Workspace

Run exercises, submit step artifacts, and keep private investigation notebooks.

Noise Log Jobs

Schedule background log dispatches to keep your SIEM populated with realistic traffic.

Leaderboard & Streaks

Track completion streaks, points, and team standings in real time.

Platform Health

Monitor your infrastructure via the Icinga-backed platform status dashboard.

Get up and running

1

Sign in

Navigate to your ThreatLab instance and sign in with your email and password, or via your organization’s Microsoft Entra ID (SSO) connection.
2

Explore the exercise catalog

Head to Exercises in the sidebar to browse available training scenarios. Each exercise shows its difficulty, estimated duration, and point value.
3

Start an exercise

Open an exercise and click Start. ThreatLab ships the log archive to your assigned SIEM and opens the investigation workspace.
4

Submit your findings

Work through each investigation step and submit the expected artifacts. When all steps are complete, ThreatLab records your completion and awards points.
If your organization uses custom roles or SIEM destinations, ask your ThreatLab administrator to configure them before you start your first exercise. See Administration for details.