Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

EcomBreach

PREMIUM

Endpoint Forensics

medium

Develop skills in forensic analysis, attack chain reconstruction, and threat detection following a web server compromise using Linux forensic techniques.

MSI

PREMIUM

Malware Analysis

medium

Analyze a malicious MSI installer by deconstructing its components, extracting embedded scripts, identifying C2 communication, and attributing the malware family.

Kerberoasted

PREMIUM

Threat Hunting

medium

Detect, analyze, and respond to Kerberoasting attacks by investigating Kerberos logs, identifying compromised accounts, and uncovering attacker persistence methods.

Sigma 101

PREMIUM

Detection Engineering

medium

Analyze suspicious logs to author custom Sigma rules that detect lateral movement techniques within a SIEM environment.

Yara101

PREMIUM

Detection Engineering

medium

Analyze malware samples, extract IOCs, and create effective YARA rules to detect and classify threats using static analysis techniques.

RARCVE

PREMIUM

Malware Analysis

medium

Analyze, decrypt, and trace a multi-stage malware infection, uncovering obfuscation techniques, payload delivery methods, and network communication indicators.

TeleStealer

PREMIUM

Malware Analysis

medium

Analyze packed malware behavior, detect persistence mechanisms, and investigate data exfiltration through dynamic analysis, traffic interception, and reverse engineering techniques.

T1197

PREMIUM

Threat Hunting

medium

Analyze Windows event logs in Splunk to identify T1197 BITS abuse, LOLBAS usage, attacker IP, and persistence mechanisms.

APT35

PREMIUM

Malware Analysis

medium

Perform forensic analysis on Android devices to identify, analyze, and mitigate threats from malicious applications and cyber espionage groups like Magic Hound.

KrakenKeylogger

Endpoint Forensics

medium

Analyze Windows 10 notification artifacts, installed applications, LNK files, and Applications logs to uncover malicious activity and enhance forensic investigation capabilities.