Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

GrabThePhisher
Threat Intel
easyAnalyze a cryptocurrency phishing kit to identify exfiltration methods, extract critical IOCs, and gather threat actor intelligence using local logs and Telegram APIs.

ActiveMQ - LockBit Ransomware
Threat Hunting
mediumCommunity rating: easyReconstruct a full-chain ransomware attack that began with a single CVE in the DMZ and ended with domain-wide compromise, data exfiltration, and encrypted file servers.

CodeFreeze 2
Endpoint Forensics
mediumReconstruct a multi-stage attack timeline by analyzing forensic artifacts from browser, VSCode, WSL, registry, and application logs.

MiniFast - UNC1549
Network Forensics
mediumAn aviation contractor's developer installed a database tool from the top search result. Reconstruct the full intrusion from a single capture, from the lure domain through the implant's tasking to the second stage pulled down in cleartext.

Crossed Signals
Endpoint Forensics
mediumA routine security audit. A trusted messaging app. By the time the victim realized something was wrong, the damage was already done. Can you trace what happened?

Maromalix Nightmare
Threat Hunting, Endpoint Forensics
mediumA deal was stolen before it was ever signed. Someone got in, found exactly what they needed, and vanished. Your job is to prove it.

Penumbra
Endpoint Forensics
mediumCommunity rating: hardSynthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.

CodeFreeze
Endpoint Forensics
mediumReconstruct the complete attack timeline by analyzing browser history, event logs, registry, and Git artifacts to identify initial access, persistence, and data exfiltration mechanisms.

Rhadamanthys
Endpoint Forensics
mediumHunt mail caches, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

Shadow Token Symphony - APT29
Cloud Forensics
mediumSynthesize KQL findings across Windows events and Azure logs to reconstruct an APT29 multi-stage cloud attack, identifying persistence mechanisms and data exfiltration.