ISIT Security LabsIncident response training

Platform

Frequently asked questions

Notes about how IT Security Labs is built. Investigation cases themselves stay focused on the ticket, evidence, and report.

Is this real production telemetry?

No. Cases use generated AWS-style evidence built for investigation practice. Nothing here is pulled from a live customer environment.

Do labs contact AWS or the internet?

No. Generators write local JSON only. They do not call AWS APIs, send HTTP requests, run scanners, or touch real infrastructure.

Are the IP addresses and hostnames real?

Addresses use documentation ranges (such as 203.0.113.0/24 and 198.51.100.0/24). Hostnames and account identifiers belong to the case narrative, not to production systems you should contact.

Why does the evidence look like real WAF, CloudTrail, or GuardDuty exports?

The goal is realistic SOC practice: same field names, correlation IDs, and investigation workflow. Treat each case as an incident you are investigating, not as a tutorial about mock data.

Where should questions about simulation vs reality live?

Here. Lab briefings, evidence lockers, and log viewers stay focused on the investigation. Platform notes about how evidence is produced belong on this FAQ page.