Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

MinerHunt
PREMIUM
Endpoint Forensics
mediumCorrelate Windows Event Logs and Sysmon artifacts to reconstruct a SQL Server attack, identifying initial access, multiple persistence techniques, and the attacker's cryptomining objective.

Andromeda Bot - UNC4210
PREMIUM
Endpoint Forensics
mediumAnalyze memory images and event logs using MemProcFS, EvtxECmd, and Timeline Explorer to identify Andromeda bot IOCs, reconstruct its infection timeline, and attribute it to an APT group.