Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

Maranhao

PREMIUM

Endpoint Forensics

easy

Investigate a trojanized game installer by analyzing browser history, logs, registry hives, and filesystem artifacts to map the full attack chain and extract IOCs.

Insider

Endpoint Forensics

easy

Analyze Linux disk image artifacts, including logs and Bash history, using FTK Imager to investigate insider threat activities and reconstruct user actions.

Penumbra

PREMIUMNew

Endpoint Forensics

medium

Synthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.

Famous Chollima

PREMIUM

Endpoint Forensics

medium

Synthesize forensic artifacts and Python source code from a disk image to reconstruct a credential theft attack, identifying persistence methods and C2 communications.

NetX-Support - TA569

PREMIUM

Endpoint Forensics

medium

Analyze browser, filesystem, and event artifacts to reconstruct the attack chain, identify the malicious download source, extract second-stage and C2 indicators, and determine persistence, account creation, and lateral movement.

Silent Breach

Endpoint Forensics

medium

Analyze a forensic image to extract communication artifacts, identify malware behavior, and decrypt encrypted files using FTK Imager, string analysis, and PowerShell scripting.

Beta Gamer

PREMIUM

Endpoint Forensics

medium

Reconstruct an intrusion timeline by analyzing event logs, registry, file system, and network artifacts to identify attacker TTPs and data exfiltration.

AzurePot

Endpoint Forensics

medium

Understand real-world Linux compromise via CVE-2021-41773 by analyzing disk, memory, and system artifacts to identify attacker techniques, persistence methods, and IOCs.

Sysinternals

Endpoint Forensics

medium

Conduct endpoint forensic analysis to detect, analyze, and understand malware infections using disk images, registry artifacts, and threat intelligence.

AfricanFalls

Endpoint Forensics

medium

Reconstruct a suspect's digital activities and intent by analyzing browser history, system artifacts, deleted files, and credentials from a disk image using various forensic tools.

HireMe

Endpoint Forensics

medium

Analyze a disk image to investigate multiple forensic cases by examining registry, event logs, and email artifacts using specified forensic tools.

Phishy

Endpoint Forensics

medium

Reconstruct an end-to-end phishing attack chain by analyzing disk image, registry, application, and browser artifacts using various forensic tools.

Injector

Endpoint Forensics

medium

Determine the web server compromise method and attacker actions by analyzing disk images, memory dumps, and registry artifacts using Autopsy, Volatility, and Registry Explorer.

Ulysses

Endpoint Forensics

medium

Analyze Linux system artifacts, including memory dumps and logs, with Volatility and FTK Imager to reconstruct an attack and identify IOCs.

CorporateSecrets

Endpoint Forensics

medium

Evaluate a Windows disk image by correlating registry, event log, browser, and MFT artifacts to reconstruct evidence of corporate secret exfiltration.

Szechuan Sauce

Endpoint Forensics

medium

Reconstruct a data exfiltration incident by correlating memory, disk, network, and log artifacts using a suite of forensic tools.

BreakOut-Daedalus

PREMIUM

Threat Hunting, Endpoint Forensics, Network Forensics

hard

The hosting panel is the new front door; chase an attacker from a forged session all the way to root, breaking out of a container and burrowing into the host along the way. By correlating SIEM telemetry, host disk forensics, and network captures across the full intrusion.

Gh0stNet Intrusion

PREMIUM

Threat Hunting, Endpoint Forensics

hard

Synthesize forensic evidence from disk images, PCAP, and Splunk logs to reconstruct a Gh0stNet intrusion, identifying C2, persistence, and data exfiltration via DNS tunneling.

RepoReaper - Water Curse

PREMIUM

Endpoint Forensics

hard

Investigate a disk image to uncover a UAC bypass and process hollowing and trace the attack back to a compromised software repository.