Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

GrabThePhisher

Threat Intel

easy

Analyze a cryptocurrency phishing kit to identify exfiltration methods, extract critical IOCs, and gather threat actor intelligence using local logs and Telegram APIs.

ActiveMQ - LockBit Ransomware

PREMIUMNew

Threat Hunting

mediumCommunity rating: easy

Reconstruct a full-chain ransomware attack that began with a single CVE in the DMZ and ended with domain-wide compromise, data exfiltration, and encrypted file servers.

CodeFreeze 2

PREMIUMNew

Endpoint Forensics

medium

Reconstruct a multi-stage attack timeline by analyzing forensic artifacts from browser, VSCode, WSL, registry, and application logs.

MiniFast - UNC1549

PREMIUM

Network Forensics

medium

An aviation contractor's developer installed a database tool from the top search result. Reconstruct the full intrusion from a single capture, from the lure domain through the implant's tasking to the second stage pulled down in cleartext.

Crossed Signals

PREMIUM

Endpoint Forensics

medium

A routine security audit. A trusted messaging app. By the time the victim realized something was wrong, the damage was already done. Can you trace what happened?

Maromalix Nightmare

PREMIUM

Threat Hunting, Endpoint Forensics

medium

A deal was stolen before it was ever signed. Someone got in, found exactly what they needed, and vanished. Your job is to prove it.

Penumbra

PREMIUM

Endpoint Forensics

mediumCommunity rating: hard

Synthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.

CodeFreeze

PREMIUM

Endpoint Forensics

medium

Reconstruct the complete attack timeline by analyzing browser history, event logs, registry, and Git artifacts to identify initial access, persistence, and data exfiltration mechanisms.

Rhadamanthys

PREMIUM

Endpoint Forensics

medium

Hunt mail caches, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

Shadow Token Symphony - APT29

PREMIUM

Cloud Forensics

medium

Synthesize KQL findings across Windows events and Azure logs to reconstruct an APT29 multi-stage cloud attack, identifying persistence mechanisms and data exfiltration.