Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

BreakOut-Daedalus

PREMIUMNew

Threat Hunting, Endpoint Forensics, Network Forensics

hard

The hosting panel is the new front door; chase an attacker from a forged session all the way to root, breaking out of a container and burrowing into the host along the way. By correlating SIEM telemetry, host disk forensics, and network captures across the full intrusion.

ClawHavoc

PREMIUM

Malware Analysis

hard

Gh0stNet Intrusion

PREMIUM

Threat Hunting, Endpoint Forensics

hard

Synthesize forensic evidence from disk images, PCAP, and Splunk logs to reconstruct a Gh0stNet intrusion, identifying C2, persistence, and data exfiltration via DNS tunneling.

BYOVD - Hive0163

PREMIUM

Endpoint Forensics, Malware Analysis

hard

Correlate diverse forensic artifacts to reconstruct a multi-stage ransomware attack, synthesizing insights from BYOVD, custom packer, and anti-analysis techniques.

RansomedTrust - Lynx

PREMIUM

Threat Hunting

hard

Investigate a multi-stage LYNX ransomware intrusion across two trusted Active Directory forests in Splunk, then statically analyze the recovered binary to surface developer artifacts and the embedded victim-contact infrastructure.

Formbook

PREMIUM

Endpoint Forensics, Malware Analysis

hard

Trace the attack chain from phishing delivery through obfuscated JavaScript, PowerShell loaders, and final payload execution.

Satisfaction

PREMIUM

Malware Analysis, Network Forensics

hard

A disgruntled customer, a compromised survey, and a trail of evidence hiding in plain sight — can you trace the attack from the first click to the final payload?

Maromafix Falldown - RansomHub

PREMIUM

Threat Hunting, Endpoint Forensics

hard

Reconstruct a multi-stage ransomware attack by correlating Windows event logs, disk artifacts, and malware analysis using Elastic, MFTECmd, RegRipper, and DNSpy.

MarkShell - TA577

PREMIUM

Threat Hunting

hard

Investigate a multi-stage phishing intrusion from initial access through domain compromise, persistence, and C2 deployment.

Code Blue - APT29

PREMIUM

Cloud Forensics

hard

Reconstruct a multi-stage APT29 intrusion by analyzing Azure and M365 logs to trace device code phishing, OAuth token abuse, service account chaining, Silver SAML forgery, and PHI exfiltration.

Recruiter - Hanoi Op

PREMIUM

Endpoint Forensics

hard

When a "candidate" submits a resume that’s more than it seems, it’s up to you to hunt through the artifacts, reconstruct the infection chain, and stop a data breach in its tracks.

RoastToRoot

PREMIUM

Network Forensics

hard

Analyze network traffic to reconstruct a complete domain compromise attack chain, from AS-REP Roasting and Kerberoasting through privilege escalation, lateral movement, and data exfiltration using rclone.

LFI Escalation

PREMIUM

Endpoint Forensics

hard

Raining Dinosaurs - Storm-2603

PREMIUM

Threat Hunting

hard

Hunt through Splunk logs to uncover how attackers exploited a DMZ server, pivoted to the internal network, and deployed ransomware after exfiltrating sensitive data.

Latrodectus – LunarSpider

PREMIUM

Threat Hunting

hard

Correlate Splunk Sysmon logs and disk forensic artifacts across multiple hosts to reconstruct a multi-stage Latrodectus malware intrusion from initial access to data exfiltration.

RansomHub

PREMIUM

Threat Hunting

hard

Reconstruct RansomHub ransomware attack chain by correlating Splunk logs and disk artifacts to identify password spray, lateral movement, data exfiltration, and ransomware deployment tactics.

Spooler - APT28

PREMIUM

Endpoint Forensics

hard

Hunt browser downloads, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

BlackSuit APT Breach

PREMIUM

Threat Hunting

hard

Zoom Incident - Ignoble Scorpius APT

PREMIUM

Threat Hunting

hard

Correlate Sysmon events and forensic artifacts across multiple hosts using Splunk to reconstruct a full ransomware kill chain, from initial compromise to domain-wide impact.

YARA Trap

PREMIUM

Endpoint Forensics

hard

Investigate attacker behavior by analyzing Windows artifacts to identify persistence, privilege escalation, and lateral movement using MFTECmd, PECmd, BitsParser, and registry analysis tools.