Is this real production telemetry?
No. Cases use generated AWS-style evidence built for investigation practice. Nothing here is pulled from a live customer environment.
Platform
Notes about how IT Security Labs is built. Investigation cases themselves stay focused on the ticket, evidence, and report.
No. Cases use generated AWS-style evidence built for investigation practice. Nothing here is pulled from a live customer environment.
No. Generators write local JSON only. They do not call AWS APIs, send HTTP requests, run scanners, or touch real infrastructure.
Addresses use documentation ranges (such as 203.0.113.0/24 and 198.51.100.0/24). Hostnames and account identifiers belong to the case narrative, not to production systems you should contact.
The goal is realistic SOC practice: same field names, correlation IDs, and investigation workflow. Treat each case as an incident you are investigating, not as a tutorial about mock data.
Here. Lab briefings, evidence lockers, and log viewers stay focused on the investigation. Platform notes about how evidence is produced belong on this FAQ page.