Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

DetectLog4j
Endpoint Forensics
mediumSynthesize forensic artifacts across registry, logs, and binaries to reconstruct a Log4Shell exploitation attack chain, identifying C2, persistence, and ransomware behavior.

Exfiltrated
Endpoint Forensics
mediumReconstruct a Linux intrusion by analyzing forensic images, system logs, and custom scripts to identify brute-force, privilege escalation, persistence, and exfiltrated data.

Obfuscated
Malware Analysis
mediumDeobfuscate multi-stage VBA and JavaScript malware from a Word document, extracting IOCs and reconstructing execution flow with Oledump, CyberChef, and WSH.

Ancientland Breach - LockBit
Endpoint Forensics, Network Forensics
hardTrace a real-world attack chain end to end — from a leaked VPN config to domain-wide ransomware. Along the way you will decode obfuscated malware, reverse-engineer a kernel exploit, crack beacon encryption, and reconstruct the attacker's every move from disk, memory, and network artifacts.

ClawHavoc
Malware Analysis

Gh0stNet Intrusion
Threat Hunting, Endpoint Forensics
hardSynthesize forensic evidence from disk images, PCAP, and Splunk logs to reconstruct a Gh0stNet intrusion, identifying C2, persistence, and data exfiltration via DNS tunneling.

BYOVD - Hive0163
Endpoint Forensics, Malware Analysis
hardCorrelate diverse forensic artifacts to reconstruct a multi-stage ransomware attack, synthesizing insights from BYOVD, custom packer, and anti-analysis techniques.

Formbook
Endpoint Forensics, Malware Analysis
hardTrace the attack chain from phishing delivery through obfuscated JavaScript, PowerShell loaders, and final payload execution.

Satisfaction
Malware Analysis, Network Forensics
hardA disgruntled customer, a compromised survey, and a trail of evidence hiding in plain sight — can you trace the attack from the first click to the final payload?

Maromafix Falldown - RansomHub
Threat Hunting, Endpoint Forensics
hardReconstruct a multi-stage ransomware attack by correlating Windows event logs, disk artifacts, and malware analysis using Elastic, MFTECmd, RegRipper, and DNSpy.