Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

Shadow Token Symphony - APT29
Cloud Forensics
mediumSynthesize KQL findings across Windows events and Azure logs to reconstruct an APT29 multi-stage cloud attack, identifying persistence mechanisms and data exfiltration.

CallMeOnTheChain - EtherRAT
Network Forensics
mediumDecrypt traffic, decompile smart contracts, and uncover how attackers turned the blockchain into a C2 channel.

Poisoned PyTorch
Threat Hunting
mediumInvestigate a software supply-chain compromise that escalates into a ransomware attack, with emphasis on identifying pre-encryption operations.

RaaS Unfold - RansomHub
Threat Intel
mediumA ransomware empire built on the ashes of its predecessors — trace its origins, expose its operators, and unfold its playbook.

ConsentStorm
Cloud Forensics
mediumInvestigate a cloud OAuth intrusion by identifying malicious consent grants (Q1-Q4), tracing service-account pivots and Azure enumeration (Q5-Q11), validating persistence through app secrets, TAP abuse, and group changes (Q12-Q17), analyzing file access and exfiltration (Q18-Q19), and mapping tradecraft to ATT&CK and Entra mitigations (Q20-Q25).

KioskExpo7
Endpoint Forensics

Stolen Time - HiddenTear
Threat Hunting
mediumSynthesize and correlate diverse forensic artifacts from multiple systems to reconstruct the complete HiddenTear attack chain and attribute threat actor TTPs.

Perfect Survey
Threat Hunting

Nitrogen - Blackcat Ransomware
Threat Hunting
mediumReconstruct multi-stage ransomware attack by correlating Splunk telemetry, disk forensics, and registry artifacts to identify persistence mechanisms, credential dumping, and lateral movement.

StarkTech Incident - APT41
Threat Hunting
mediumReconstruct a multi-stage attack timeline by analyzing Sysmon and Windows event logs in Splunk to identify attacker tactics from initial access to data exfiltration.