Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

Phantom Installer
Malware Analysis, Endpoint Forensics
easyOne installer looked just like the rest. By the time the damage was done, there was almost nothing left to investigate. Almost.

T1584.004
Threat Intel
easyApply MISP to manage security events, create attributes, and integrate threat intelligence from data feeds.

T1583.002
Threat Intel
easyAnalyze a malware campaign using MISP to identify communication patterns and extract key indicators of compromise (IOCs), including malware family and file hashes.

MiniFast - UNC1549
Network Forensics
mediumAn aviation contractor's developer installed a database tool from the top search result. Reconstruct the full intrusion from a single capture, from the lure domain through the implant's tasking to the second stage pulled down in cleartext.

Tax Day - BYOVD
Endpoint Forensics
mediumCorrelate forensic artifacts from event logs, browser history, and prefetch with static analysis using IDA Pro to reconstruct a BYOVD attack chain and defense evasion tactics.

BYOD Breach
Endpoint Forensics
mediumCorrelate Android and Windows forensic artifacts, including logs and malware analysis, to reconstruct a multi-stage BYOD breach from initial access to persistence.

MBuchus
Threat Intel
mediumUtilize OSINT, VirusTotal, and crt.sh to analyze a multi-stage malvertising campaign, identifying initial access, malware payloads, and attacker infrastructure.

Beta Gamer
Endpoint Forensics
mediumReconstruct an intrusion timeline by analyzing event logs, registry, file system, and network artifacts to identify attacker TTPs and data exfiltration.

Poisoned Pipeline
Threat Hunting, Endpoint Forensics
hardInvestigate a multi-stage supply-chain intrusion that landed via a poisoned npm dependency and pivoted through CI/CD into production and AWS by pivoting across Splunk, disk images, and git history.

TeamCity Exploit - APT29
Threat Hunting
insaneCorrelate Splunk logs and host forensic artifacts from triage images to reconstruct a multi-stage TeamCity compromise and identify attacker TTPs.