Quick Start
Get ThreatLab running and complete your first exercise in minutes.
Authoring Exercises
Build investigation scenarios with steps, archives, and MITRE tags.
API Reference
Explore the full REST API for sessions, noise jobs, and health checks.
SIEM Integrations
Connect Splunk, QRadar, and Elasticsearch to ship log archives.
What you can do with ThreatLab
ThreatLab covers the full training lifecycle — from authoring content to measuring analyst performance.Exercise Authoring
Upload LEEF or ECS log archives, define investigation steps, and set expected artifacts.
Learning Paths
Sequence exercises into structured curricula with automatic unlock logic.
Analyst Workspace
Run exercises, submit step artifacts, and keep private investigation notebooks.
Noise Log Jobs
Schedule background log dispatches to keep your SIEM populated with realistic traffic.
Leaderboard & Streaks
Track completion streaks, points, and team standings in real time.
Platform Health
Monitor your infrastructure via the Icinga-backed platform status dashboard.
Get up and running
1
Sign in
Navigate to your ThreatLab instance and sign in with your email and password, or via your organization’s Microsoft Entra ID (SSO) connection.
2
Explore the exercise catalog
Head to Exercises in the sidebar to browse available training scenarios. Each exercise shows its difficulty, estimated duration, and point value.
3
Start an exercise
Open an exercise and click Start. ThreatLab ships the log archive to your assigned SIEM and opens the investigation workspace.
4
Submit your findings
Work through each investigation step and submit the expected artifacts. When all steps are complete, ThreatLab records your completion and awards points.
If your organization uses custom roles or SIEM destinations, ask your ThreatLab administrator to configure them before you start your first exercise. See Administration for details.