Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

Maromalix Nightmare

PREMIUMNew

Threat Hunting, Endpoint Forensics

medium

A deal was stolen before it was ever signed. Someone got in, found exactly what they needed, and vanished. Your job is to prove it.

Penumbra

PREMIUMNew

Endpoint Forensics

medium

Synthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.

Tax Day - BYOVD

PREMIUM

Endpoint Forensics

medium

Correlate forensic artifacts from event logs, browser history, and prefetch with static analysis using IDA Pro to reconstruct a BYOVD attack chain and defense evasion tactics.

CodeFreeze

PREMIUM

Endpoint Forensics

medium

Reconstruct the complete attack timeline by analyzing browser history, event logs, registry, and Git artifacts to identify initial access, persistence, and data exfiltration mechanisms.

Rhadamanthys

PREMIUM

Endpoint Forensics

medium

Hunt mail caches, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

Famous Chollima

PREMIUM

Endpoint Forensics

medium

Synthesize forensic artifacts and Python source code from a disk image to reconstruct a credential theft attack, identifying persistence methods and C2 communications.

ResourcePacks

PREMIUM

Endpoint Forensics

medium

Reconstruct an attack timeline by analyzing forensic artifacts to identify a UAC bypass, WMI persistence, and backdoor user creation techniques.

NetX-Support - TA569

PREMIUM

Endpoint Forensics

medium

Analyze browser, filesystem, and event artifacts to reconstruct the attack chain, identify the malicious download source, extract second-stage and C2 indicators, and determine persistence, account creation, and lateral movement.

Fog Ransomware - Fluttering Scorpius

PREMIUM

Endpoint Forensics

medium

Reconstruct the Fog ransomware attack chain by analyzing browser, registry, event logs, and MFT artifacts to identify initial access, persistence, BYOVD privilege escalation, and IOCs.

VaultBreak

PREMIUM

Endpoint Forensics

medium

Reconstruct a multi-stage attack by analyzing Sysmon, WMI, and Prefetch logs to identify initial infection, advanced persistence, and C2 communications.

MinerHunt

PREMIUM

Endpoint Forensics

medium

Correlate Windows Event Logs and Sysmon artifacts to reconstruct a SQL Server attack, identifying initial access, multiple persistence techniques, and the attacker's cryptomining objective.

Beta Gamer

PREMIUM

Endpoint Forensics

medium

Reconstruct an intrusion timeline by analyzing event logs, registry, file system, and network artifacts to identify attacker TTPs and data exfiltration.

ELPACO-team

PREMIUM

Endpoint Forensics

medium

Correlate Sysmon, MFT, and application logs to reconstruct a ransomware attack timeline, identifying persistence, defense evasion, and data exfiltration TTPs.

DarkCrystal

PREMIUM

Endpoint Forensics

medium

Reconstruct a multi-stage malware attack chain by analyzing Windows event logs with EvtxECmd and memory dumps with Volatility to identify LOLBins and C2 communications.

Andromeda Bot - UNC4210

PREMIUM

Endpoint Forensics

medium

Analyze memory images and event logs using MemProcFS, EvtxECmd, and Timeline Explorer to identify Andromeda bot IOCs, reconstruct its infection timeline, and attribute it to an APT group.

Akira - Storm-1567

PREMIUM

Endpoint Forensics

medium

Learn to investigate Akira ransomware using memory forensics to identify IOCs, analyze attacker behavior, reconstruct timelines, and uncover system compromise, defense evasion, and persistence methods.

IcedID 2 - GOLD CABIN

PREMIUM

Endpoint Forensics

medium

Analyze memory artifacts and trace a ransomware attack's origin, execution, and persistence using forensic tools like Volatility 3 and MemProcFS.

KrakenKeylogger

Endpoint Forensics

medium

Analyze Windows 10 notification artifacts, installed applications, LNK files, and Applications logs to uncover malicious activity and enhance forensic investigation capabilities.

Poisoned Pipeline

PREMIUMNew

Threat Hunting, Endpoint Forensics

hard

Investigate a multi-stage supply-chain intrusion that landed via a poisoned npm dependency and pivoted through CI/CD into production and AWS by pivoting across Splunk, disk images, and git history.

Maromafix Falldown - RansomHub

PREMIUM

Threat Hunting, Endpoint Forensics

hard

Reconstruct a multi-stage ransomware attack by correlating Windows event logs, disk artifacts, and malware analysis using Elastic, MFTECmd, RegRipper, and DNSpy.