Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

GhostConnect - TA583

PREMIUM

Threat Hunting

easy

Hunt Sysmon process trees, Chrome browsing artifacts, and Mark-of-the-Web streams to rebuild a the full kill chain from phishing delivery through AD enumeration to HTTPS exfiltration.

CursorJack

PREMIUM

Endpoint Forensics, Cloud Forensics

easy

A developer's workstation is the new perimeter — trace an MCP-based intrusion from the first malicious deeplink through to a multi-region cloud compromise and follow the money on-chain.

Fork Bomb - TeamPCP

PREMIUM

Endpoint Forensics, Threat Intel

easy

Investigate a real-world supply chain attack from first alert to threat actor attribution — and find out how a single Python package nearly handed over the keys to an entire cloud environment.

AbuSESer - Trufflenet

PREMIUM

Cloud Forensics

easy

Investigate a complex Business Email Compromise attack by correlating AWS CloudTrail and Lambda logs in CloudWatch Logs Insights to reconstruct the attack timeline and attribute TTPs.

Maranhao

PREMIUM

Endpoint Forensics

easy

Investigate a trojanized game installer by analyzing browser history, logs, registry hives, and filesystem artifacts to map the full attack chain and extract IOCs.

Rogue Azure

PREMIUM

Cloud Forensics

easy

Reconstruct a multi-stage Azure attack timeline by analyzing Entra ID, Audit, and Storage Blob logs using Kusto Query Language to identify initial access, persistence, privilege escalation, and data exfiltration.

RevengeHotels APT

PREMIUM

Endpoint Forensics

easy

Reconstruct multi-stage APT attack chain by correlating email, browser, Sysmon logs, and registry artifacts to identify persistence mechanisms and data exfiltration techniques.

FakeGPT

Malware Analysis

easy

Analyze a malicious Chrome extension's code and behavior to identify data theft mechanisms, covert exfiltration via `<img>` tags, and anti-analysis techniques.

Red Stealer

Threat Intel

easy

Analyze a suspicious executable using VirusTotal and MalwareBazaar to extract IOCs, identify C2 infrastructure, MITRE ATT&CK techniques, and privilege escalation mechanisms.

XXE Infiltration

PREMIUM

Network Forensics

easy

Analyze PCAP data using Wireshark to identify XXE vulnerabilities, extract compromised credentials, and detect web shell uploads for persistence.

PoisonedCredentials

PREMIUM

Network Forensics

easy

Analyze network traffic for LLMNR/NBT-NS poisoning attacks using Wireshark to identify the rogue machine, compromised accounts, and affected systems.

AzureHunt

PREMIUM

Cloud Forensics

easy

Correlate Azure AD, Activity, and Blob Storage logs in Elastic Stack to reconstruct an attack timeline, identifying initial access, lateral movement, persistence, and data exfiltration.

MiniFast - UNC1549

PREMIUMNew

Network Forensics

medium

An aviation contractor's developer installed a database tool from the top search result. Reconstruct the full intrusion from a single capture, from the lure domain through the implant's tasking to the second stage pulled down in cleartext.

Crossed Signals

PREMIUMNew

Endpoint Forensics

medium

A routine security audit. A trusted messaging app. By the time the victim realized something was wrong, the damage was already done. Can you trace what happened?

Penumbra

PREMIUM

Endpoint Forensics

mediumCommunity rating: hard

Synthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.

ClickFix - VodkaStealer

PREMIUM

Threat Hunting

medium

Analyze Splunk event logs to reconstruct a multi-stage attack chain, detailing initial access, privilege escalation, lateral movement, and data exfiltration.

ConsentStorm

PREMIUM

Cloud Forensics

medium

Investigate a cloud OAuth intrusion by identifying malicious consent grants (Q1-Q4), tracing service-account pivots and Azure enumeration (Q5-Q11), validating persistence through app secrets, TAP abuse, and group changes (Q12-Q17), analyzing file access and exfiltration (Q18-Q19), and mapping tradecraft to ATT&CK and Entra mitigations (Q20-Q25).

Stolen Time - HiddenTear

PREMIUM

Threat Hunting

medium

Synthesize and correlate diverse forensic artifacts from multiple systems to reconstruct the complete HiddenTear attack chain and attribute threat actor TTPs.

Nitrogen - Blackcat Ransomware

PREMIUM

Threat Hunting

medium

Reconstruct multi-stage ransomware attack by correlating Splunk telemetry, disk forensics, and registry artifacts to identify persistence mechanisms, credential dumping, and lateral movement.

StarkTech Incident - APT41

PREMIUM

Threat Hunting

medium

Reconstruct a multi-stage attack timeline by analyzing Sysmon and Windows event logs in Splunk to identify attacker tactics from initial access to data exfiltration.