Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

CursorJack
Endpoint Forensics, Cloud Forensics
easyA developer's workstation is the new perimeter — trace an MCP-based intrusion from the first malicious deeplink through to a multi-region cloud compromise and follow the money on-chain.

Fork Bomb - TeamPCP
Endpoint Forensics, Threat Intel
easyInvestigate a real-world supply chain attack from first alert to threat actor attribution — and find out how a single Python package nearly handed over the keys to an entire cloud environment.

ResourcePacks
Endpoint Forensics
mediumReconstruct an attack timeline by analyzing forensic artifacts to identify a UAC bypass, WMI persistence, and backdoor user creation techniques.

WorkFromHome
Endpoint Forensics
mediumAnalyze forensic artifacts to trace an attacker's progression from initial social engineering and remote access to a "Sticky Keys" privilege escalation.

VaultBreak
Endpoint Forensics
mediumReconstruct a multi-stage attack by analyzing Sysmon, WMI, and Prefetch logs to identify initial infection, advanced persistence, and C2 communications.

Yara Wizards
Detection Engineering
mediumAnalyze malware behavior and develop YARA rules for proactive detection by identifying packing methods, entropy levels, and execution patterns.

AzurePot
Endpoint Forensics
mediumUnderstand real-world Linux compromise via CVE-2021-41773 by analyzing disk, memory, and system artifacts to identify attacker techniques, persistence methods, and IOCs.

Formbook
Endpoint Forensics, Malware Analysis
hardTrace the attack chain from phishing delivery through obfuscated JavaScript, PowerShell loaders, and final payload execution.

RoastToRoot
Network Forensics
hardAnalyze network traffic to reconstruct a complete domain compromise attack chain, from AS-REP Roasting and Kerberoasting through privilege escalation, lateral movement, and data exfiltration using rclone.

YARA Trap
Endpoint Forensics
hardInvestigate attacker behavior by analyzing Windows artifacts to identify persistence, privilege escalation, and lateral movement using MFTECmd, PECmd, BitsParser, and registry analysis tools.

T1059-007
Malware Analysis
hardAnalyze malware file system activity with ProcMon, identify scheduled task persistence using AutoRuns, and configure PowerShell logging for script execution.

TeamCity Exploit - APT29
Threat Hunting
insaneCorrelate Splunk logs and host forensic artifacts from triage images to reconstruct a multi-stage TeamCity compromise and identify attacker TTPs.