I am proud to have recently participated in Splunk Boss of the SOC (BOTS) APJC 2026 which is a blue-team capture the flag-esque competition where we explored and investigated realistic event data in Splunk Enterprise and Splunk Enterprise Security.
The event brought together security analysts, threat hunters, and cybersecurity enthusiasts from across Australia and New Zealand to tackle realistic cyber attack scenarios in a simulated enterprise environment.
Caption: Participation Certificate for the Splunk Boss of the SOC APJC 2026 event.
The Competition
The challenge required deep log analysis, rapid problem-solving, and Splunk Search Processing Language (SPL) queries to reconstruct adversary attack paths, uncover persistent threats, and correlate telemetry across multiple data sources.
Competing alongside a fantastic team representing the NSW Police Force under the name SOCculentChineseMeal, we worked through incident response scenarios under strict time constraints.
The Result
After a fast-paced and highly competitive event, our team secured 11th place out of 162 competing teams.
Caption: Final standings on the scoreboard at Splunk Boss of the SOC APJC 2026.