Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

BreakOut-Daedalus
Threat Hunting, Endpoint Forensics, Network Forensics
hardThe hosting panel is the new front door; chase an attacker from a forged session all the way to root, breaking out of a container and burrowing into the host along the way. By correlating SIEM telemetry, host disk forensics, and network captures across the full intrusion.

Gh0stNet Intrusion
Threat Hunting, Endpoint Forensics
hardSynthesize forensic evidence from disk images, PCAP, and Splunk logs to reconstruct a Gh0stNet intrusion, identifying C2, persistence, and data exfiltration via DNS tunneling.

BYOVD - Hive0163
Endpoint Forensics, Malware Analysis
hardCorrelate diverse forensic artifacts to reconstruct a multi-stage ransomware attack, synthesizing insights from BYOVD, custom packer, and anti-analysis techniques.

Formbook
Endpoint Forensics, Malware Analysis
hardTrace the attack chain from phishing delivery through obfuscated JavaScript, PowerShell loaders, and final payload execution.

Maromafix Falldown - RansomHub
Threat Hunting, Endpoint Forensics
hardReconstruct a multi-stage ransomware attack by correlating Windows event logs, disk artifacts, and malware analysis using Elastic, MFTECmd, RegRipper, and DNSpy.

Recruiter - Hanoi Op
Endpoint Forensics
hardWhen a "candidate" submits a resume that’s more than it seems, it’s up to you to hunt through the artifacts, reconstruct the infection chain, and stop a data breach in its tracks.

LFI Escalation
Endpoint Forensics

Spooler - APT28
Endpoint Forensics
hardHunt browser downloads, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

YARA Trap
Endpoint Forensics
hardInvestigate attacker behavior by analyzing Windows artifacts to identify persistence, privilege escalation, and lateral movement using MFTECmd, PECmd, BitsParser, and registry analysis tools.

RepoReaper - Water Curse
Endpoint Forensics
hardInvestigate a disk image to uncover a UAC bypass and process hollowing and trace the attack back to a compromised software repository.