Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

Phantom Installer

PREMIUMNew

Malware Analysis, Endpoint Forensics

easy

One installer looked just like the rest. By the time the damage was done, there was almost nothing left to investigate. Almost.

Crossed Signals

PREMIUMNew

Endpoint Forensics

medium

A routine security audit. A trusted messaging app. By the time the victim realized something was wrong, the damage was already done. Can you trace what happened?

Maromalix Nightmare

PREMIUM

Threat Hunting, Endpoint Forensics

medium

A deal was stolen before it was ever signed. Someone got in, found exactly what they needed, and vanished. Your job is to prove it.

Penumbra

PREMIUM

Endpoint Forensics

mediumCommunity rating: hard

Synthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.

Nitrogen - Blackcat Ransomware

PREMIUM

Threat Hunting

medium

Reconstruct multi-stage ransomware attack by correlating Splunk telemetry, disk forensics, and registry artifacts to identify persistence mechanisms, credential dumping, and lateral movement.

Famous Chollima

PREMIUM

Endpoint Forensics

medium

Synthesize forensic artifacts and Python source code from a disk image to reconstruct a credential theft attack, identifying persistence methods and C2 communications.

CredSnare - Angry Likho APT

PREMIUM

Threat Hunting

medium

Correlate Splunk logs and filesystem artifacts from a workstation and domain controller to reconstruct an attack chain involving Kerberos delegation and credential theft.

ResourcePacks

PREMIUM

Endpoint Forensics

medium

Reconstruct an attack timeline by analyzing forensic artifacts to identify a UAC bypass, WMI persistence, and backdoor user creation techniques.

VaultBreak

PREMIUM

Endpoint Forensics

medium

Reconstruct a multi-stage attack by analyzing Sysmon, WMI, and Prefetch logs to identify initial infection, advanced persistence, and C2 communications.

Beta Gamer

PREMIUM

Endpoint Forensics

medium

Reconstruct an intrusion timeline by analyzing event logs, registry, file system, and network artifacts to identify attacker TTPs and data exfiltration.

MeteorHit - Indra

PREMIUM

Endpoint Forensics

medium

Reconstruct a wiper malware attack by analyzing registry, event logs, and USN journal artifacts using Registry Explorer, Event Log Explorer, and VirusTotal.

Ancientland Breach - LockBit

PREMIUMNew

Endpoint Forensics, Network Forensics

hard

Trace a real-world attack chain end to end — from a leaked VPN config to domain-wide ransomware. Along the way you will decode obfuscated malware, reverse-engineer a kernel exploit, crack beacon encryption, and reconstruct the attacker's every move from disk, memory, and network artifacts.

Maromafix Falldown - RansomHub

PREMIUM

Threat Hunting, Endpoint Forensics

hard

Reconstruct a multi-stage ransomware attack by correlating Windows event logs, disk artifacts, and malware analysis using Elastic, MFTECmd, RegRipper, and DNSpy.

Recruiter - Hanoi Op

PREMIUM

Endpoint Forensics

hard

When a "candidate" submits a resume that’s more than it seems, it’s up to you to hunt through the artifacts, reconstruct the infection chain, and stop a data breach in its tracks.

LFI Escalation

PREMIUM

Endpoint Forensics

hard

Latrodectus – LunarSpider

PREMIUM

Threat Hunting

hard

Correlate Splunk Sysmon logs and disk forensic artifacts across multiple hosts to reconstruct a multi-stage Latrodectus malware intrusion from initial access to data exfiltration.

Spooler - APT28

PREMIUM

Endpoint Forensics

hard

Hunt browser downloads, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

BlackSuit APT Breach

PREMIUM

Threat Hunting

hard

YARA Trap

PREMIUM

Endpoint Forensics

hard

Investigate attacker behavior by analyzing Windows artifacts to identify persistence, privilege escalation, and lateral movement using MFTECmd, PECmd, BitsParser, and registry analysis tools.

RepoReaper - Water Curse

PREMIUM

Endpoint Forensics

hard

Investigate a disk image to uncover a UAC bypass and process hollowing and trace the attack back to a compromised software repository.