Authentication Detection Mini-SOC

Guided, local-only walkthrough for synthetic Windows authentication detections.

Synthetic lab only. No production logs, credentials, malware, offensive simulations or host-changing actions.

For reviewers: 3-minute guided path Start with AUTH-003-POS, inspect the matched fields, open the GitBook playbook, then compare with the validation report.
Detections
Synthetic cases
Expected alerts
Tuning cases
Pass rate

Threshold Severity reason Matched fields Playbook

Analyst narrative

Event timeline

TimestampEventIDUserSource ComputerLogonFields