Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

Fork Bomb - TeamPCP
Endpoint Forensics, Threat Intel
easyInvestigate a real-world supply chain attack from first alert to threat actor attribution — and find out how a single Python package nearly handed over the keys to an entire cloud environment.

RevengeHotels APT
Endpoint Forensics
easyReconstruct multi-stage APT attack chain by correlating email, browser, Sysmon logs, and registry artifacts to identify persistence mechanisms and data exfiltration techniques.

XLMRat
Network Forensics
easyAnalyze network traffic to identify malware delivery, deobfuscate scripts, and map attacker techniques using MITRE ATT&CK, focusing on stealthy execution and reflective code loading.

T1598.002 - Dragonfly
Endpoint Forensics
easyAnalyze a spearphishing email to identify social engineering techniques and extract indicators of compromise from its headers and malicious attachment.

MiniFast - UNC1549
Network Forensics
mediumAn aviation contractor's developer installed a database tool from the top search result. Reconstruct the full intrusion from a single capture, from the lure domain through the implant's tasking to the second stage pulled down in cleartext.

CodeFreeze
Endpoint Forensics
mediumReconstruct the complete attack timeline by analyzing browser history, event logs, registry, and Git artifacts to identify initial access, persistence, and data exfiltration mechanisms.

Rhadamanthys
Endpoint Forensics
mediumHunt mail caches, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

Poisoned PyTorch
Threat Hunting
mediumInvestigate a software supply-chain compromise that escalates into a ransomware attack, with emphasis on identifying pre-encryption operations.

KioskExpo7
Endpoint Forensics

BYOD Breach
Endpoint Forensics
mediumCorrelate Android and Windows forensic artifacts, including logs and malware analysis, to reconstruct a multi-stage BYOD breach from initial access to persistence.

Job Trap - OilRig
Endpoint Forensics
mediumAnalyze PowerShell and Sysmon logs to investigate macro-based malware, identify persistence via scheduled tasks, and extract C2 indicators and keylogger behavior using FTK Imager and olevba.

VaultBreak
Endpoint Forensics
mediumReconstruct a multi-stage attack by analyzing Sysmon, WMI, and Prefetch logs to identify initial infection, advanced persistence, and C2 communications.

Silent Breach
Endpoint Forensics
mediumAnalyze a forensic image to extract communication artifacts, identify malware behavior, and decrypt encrypted files using FTK Imager, string analysis, and PowerShell scripting.

Rhysida - Vice Society
Threat Hunting
mediumReconstruct the Rhysida ransomware attack chain, identifying initial access, persistence, C2, and impact using Splunk and CyberChef.

Black Basta
Threat Hunting
mediumCorrelate Sysmon, Windows event logs, and PowerShell history to reconstruct a multi-stage Black Basta ransomware attack, identifying initial access, persistence, C2, exfiltration, and impact.

LNKTrap
Threat Hunting
mediumReconstruct a targeted cyber attack's timeline by analyzing Splunk event logs, process, and network data to identify initial access, persistence, privilege escalation, and C2.

AndroidBreach
Endpoint Forensics
mediumAnalyze an Android device dump and reverse engineer a malicious APK using ALEAPP and JADX-GUI to identify malware functionality, data exfiltration, and extract compromised credentials.

LummaStealer - Angry Likho
Endpoint Forensics
mediumAnalyze multi-stage malware behavior, decode obfuscated scripts, trace execution flow, and identify evasion, persistence, and exfiltration tactics using forensic tools.

ShadowRoast
Threat Hunting
mediumInvestigate and analyze malicious activity in an Active Directory environment using log analysis and Splunk queries to identify initial access, persistence, lateral movement, and data exfiltration techniques.

Trigona Ransomware - Water Ungaw
Endpoint Forensics
mediumLearn to investigate ransomware attacks by analyzing logs, registry entries, and artifacts to trace attacker actions, tools used, and identify indicators of compromise.