Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

Malicious PyPi

PREMIUM

Endpoint Forensics

medium

Perform forensic analysis on a compromised Windows system to identify malware, trace attacker activity, and understand persistence mechanisms.

LockBit

PREMIUM

Endpoint Forensics

medium

Reconstruct a multi-system LockBit ransomware attack chain by correlating Windows event logs, registry artifacts, and PowerShell activity to identify TTPs.

Sysinternals

Endpoint Forensics

medium

Conduct endpoint forensic analysis to detect, analyze, and understand malware infections using disk images, registry artifacts, and threat intelligence.

DetectLog4j

PREMIUM

Endpoint Forensics

medium

Synthesize forensic artifacts across registry, logs, and binaries to reconstruct a Log4Shell exploitation attack chain, identifying C2, persistence, and ransomware behavior.

CorporateSecrets

Endpoint Forensics

medium

Evaluate a Windows disk image by correlating registry, event log, browser, and MFT artifacts to reconstruct evidence of corporate secret exfiltration.

Szechuan Sauce

Endpoint Forensics

medium

Reconstruct a data exfiltration incident by correlating memory, disk, network, and log artifacts using a suite of forensic tools.

Poisoned Pipeline

PREMIUMNew

Threat Hunting, Endpoint Forensics

hard

Investigate a multi-stage supply-chain intrusion that landed via a poisoned npm dependency and pivoted through CI/CD into production and AWS by pivoting across Splunk, disk images, and git history.

Formbook

PREMIUM

Endpoint Forensics, Malware Analysis

hard

Trace the attack chain from phishing delivery through obfuscated JavaScript, PowerShell loaders, and final payload execution.

YARA Trap

PREMIUM

Endpoint Forensics

hard

Investigate attacker behavior by analyzing Windows artifacts to identify persistence, privilege escalation, and lateral movement using MFTECmd, PECmd, BitsParser, and registry analysis tools.

RepoReaper - Water Curse

PREMIUM

Endpoint Forensics

hard

Investigate a disk image to uncover a UAC bypass and process hollowing and trace the attack back to a compromised software repository.