Scoring

Graded on the investigation, not just the answer.

Every case is scored against a hidden ground truth the moment you submit — a rubric, not a single pass/fail check. Guess the right verdict without the evidence to back it up, and it shows. Miss a required response action, and it shows.

Scoring rubric
Technique accuracy
30%
Evidence recall
25%
Evidence precision
15%
Required response actions
15%
Correct verdict
15%

Minus a hint penalty (up to 15%) for hints used along the way.

04Understanding

Turn fragmented signals into a defensible incident narrative.

Security incidents rarely arrive as a single clean alert. ThreatLens gives you the individual signals and asks you to determine how they connect. Correlate activity across users, hosts, identities, applications, and time — then build the incident narrative yourself. Map relevant activity to MITRE ATT&CK and explain why the evidence supports your conclusion.

  1. 02:14SSH success · SRV-DB-07 · unrecognized ASNT1078
  2. 02:193 privileged queries · customers.piiT1213
  3. 22:41OAuth consent granted · sarah.chen@contoso.comT1528
  4. 23:02Inbox rule created · forward-externalT1114
verdictConsent-phish → token abuse → database exfiltration attempt. One actor, 21 hours, confirmed.
identity
Revoke OAuth token
endpoint
Quarantine SRV-DB-07
email
Purge forwarding rule
cloud
Rotate DB credentials
05Response

Reach a conclusion. Decide what happens next.

Every investigation ends with an evidence-backed verdict and a response decision. Determine what happened, assess the impact, and select the actions you would take next. Your decisions are evaluated against the scenario's hidden ground truth and reflected in your investigation breakdown.

verdict options
TP · FP · benign
scored on
evidence + actions

Ready to see your own breakdown?