Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

Tomcat Takeover
Network Forensics
easyAnalyze network traffic using Wireshark's custom columns, filters, and statistics to identify suspicious web server administration access and potential compromise.

AWSRaid
Cloud Forensics
easyInvestigate AWS CloudTrail logs using Splunk to identify unauthorized access, analyze configuration changes, and detect persistence mechanisms.

T1110-003
Threat Hunting

T1598.002 - Dragonfly
Endpoint Forensics
easyAnalyze a spearphishing email to identify social engineering techniques and extract indicators of compromise from its headers and malicious attachment.

T1595
Network Forensics
easyAnalyze the PCAP file to identify malicious activity, using tools like Wireshark to detect threats, IP origins, and attacker techniques.

T1584.004
Threat Intel
easyApply MISP to manage security events, create attributes, and integrate threat intelligence from data feeds.

T1583.002
Threat Intel
easyAnalyze a malware campaign using MISP to identify communication patterns and extract key indicators of compromise (IOCs), including malware family and file hashes.

RedLine
Endpoint Forensics
easyEmploy Volatility to analyze a memory dump, identifying suspicious processes, network IOCs, memory protections, and attacker's command-and-control infrastructure.

PacketDetective
Network Forensics
easyAnalyze network traffic in PCAP files using Wireshark to extract IOCs and reconstruct attacker tactics like authentication and remote execution.

GrabThePhisher
Threat Intel
easyAnalyze a cryptocurrency phishing kit to identify exfiltration methods, extract critical IOCs, and gather threat actor intelligence using local logs and Telegram APIs.