Advanced Configuration Lab  · On-demand

Correlation Skills & The Debugging Challenge

Solution overview

Individual data sources tell fragments. Windows events show a logon. Wazuh flags an alert. Zeek logs a connection. But no single source answers: what happened?

In this lab, you build the skills that connect the fragments — correlation skills that pull from all 6 data sources and construct unified investigation timelines. Then something breaks. A skill you create doesn't appear. No error message. No warning. Just silence.

Finding and fixing that failure is the most transferable lesson in this entire learning path. Because in production, AI tools don't crash loudly — they fail quietly. And the analyst who can diagnose "why doesn't the AI see my skill?" is the one who keeps the SOC running.

By the end, all 9 skills are built. Your AI security analyst is complete.

Lab diagram

Loading