Announcing the 2026 National Higher Education Boss of the SOC (BOTS) Winner

Industries Tom Smit

Key takeaways

  1. Splunk hosted its annual Boss of the SOC competition on April 15, 2026, challenging cybersecurity teams from across the country to investigate and solve realistic security threats using Splunk tools.
  2. Georgia Tech Research Institute took first place, followed by the University of Georgia and the University of Arizona, with all participants demonstrating impressive speed and skill under pressure.
  3. Anyone interested in testing their cybersecurity skills can play the original BOTS challenge at bots.splunk.com or sign up for BOTS11 at .conf26 in September 2026.

On April 15, 2026, teams of cyber defenders from across the country gathered for the annual Boss of the SOC (BOTS) competition, held just ahead for the National Higher Education systems.

BOTS is a high-stakes, blue-team capture-the-flag competition that puts participants in the role of a SOC analyst. Using the integrated power of Splunk Security software contestants raced to investigate and resolve a series of realistic security challenges. Led by industry specialists, this immersive workshop allows security hunters to test their skills against massive, real-world datasets in a risk-free environment.

Every year, we are blown away by the investigative speed, tactical creativity, and brilliance our participants display under pressure. We are proud to see our customers and partners take on the front-line challenges of today’s threat landscape. Whether they were uncovering hidden adversaries in seconds or pivoting through complex cloud data to thwart the "Angry Alpaca" threat group, these defenders proved that resilience is built through expertise and the right tools.

We are thrilled to congratulate this year’s top performers:

Congratulations to our winners and to all the participants who are sharpening the skills necessary to protect our most critical public sector missions. We are honored to be a part of your journey toward a more resilient future.

Interested in playing Boss of the SOC on your own? Feel free to play the original BOTS version at bots.splunk.com, or register for .conf26 and BOTS11, debuting in September 2026.

Related Articles

Enhancing SIEM Events with Automated Threat Analysis of URLs
Security
2 Minute Read

Enhancing SIEM Events with Automated Threat Analysis of URLs

Splunk debuts Add-on & App for Splunk Attack Analyzer v1.1, elevating security ops via automated URL threat analysis in Splunk ES.
LNK or Swim: Analysis & Simulation of Recent LNK Phishing
Security
15 Minute Read

LNK or Swim: Analysis & Simulation of Recent LNK Phishing

LNK files are a common starting point for many phishing campaigns. Read on to strengthen your defenses against these LNK file phishing attacks.
Staff Picks for Splunk Security Reading August 2023
Security
4 Minute Read

Staff Picks for Splunk Security Reading August 2023

Splunk security experts share a list of presentations, whitepapers, and customer case studies from August 2023 that they feel are worth a read.