Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

Maromalix Nightmare
Threat Hunting, Endpoint Forensics
mediumA deal was stolen before it was ever signed. Someone got in, found exactly what they needed, and vanished. Your job is to prove it.

Penumbra
Endpoint Forensics
mediumSynthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.

Tax Day - BYOVD
Endpoint Forensics
mediumCorrelate forensic artifacts from event logs, browser history, and prefetch with static analysis using IDA Pro to reconstruct a BYOVD attack chain and defense evasion tactics.

CodeFreeze
Endpoint Forensics
mediumReconstruct the complete attack timeline by analyzing browser history, event logs, registry, and Git artifacts to identify initial access, persistence, and data exfiltration mechanisms.

Rhadamanthys
Endpoint Forensics
mediumHunt mail caches, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

Famous Chollima
Endpoint Forensics
mediumSynthesize forensic artifacts and Python source code from a disk image to reconstruct a credential theft attack, identifying persistence methods and C2 communications.

ResourcePacks
Endpoint Forensics
mediumReconstruct an attack timeline by analyzing forensic artifacts to identify a UAC bypass, WMI persistence, and backdoor user creation techniques.

NetX-Support - TA569
Endpoint Forensics
mediumAnalyze browser, filesystem, and event artifacts to reconstruct the attack chain, identify the malicious download source, extract second-stage and C2 indicators, and determine persistence, account creation, and lateral movement.

Fog Ransomware - Fluttering Scorpius
Endpoint Forensics
mediumReconstruct the Fog ransomware attack chain by analyzing browser, registry, event logs, and MFT artifacts to identify initial access, persistence, BYOVD privilege escalation, and IOCs.

VaultBreak
Endpoint Forensics
mediumReconstruct a multi-stage attack by analyzing Sysmon, WMI, and Prefetch logs to identify initial infection, advanced persistence, and C2 communications.

MinerHunt
Endpoint Forensics
mediumCorrelate Windows Event Logs and Sysmon artifacts to reconstruct a SQL Server attack, identifying initial access, multiple persistence techniques, and the attacker's cryptomining objective.

Beta Gamer
Endpoint Forensics
mediumReconstruct an intrusion timeline by analyzing event logs, registry, file system, and network artifacts to identify attacker TTPs and data exfiltration.

ELPACO-team
Endpoint Forensics
mediumCorrelate Sysmon, MFT, and application logs to reconstruct a ransomware attack timeline, identifying persistence, defense evasion, and data exfiltration TTPs.

DarkCrystal
Endpoint Forensics
mediumReconstruct a multi-stage malware attack chain by analyzing Windows event logs with EvtxECmd and memory dumps with Volatility to identify LOLBins and C2 communications.

Andromeda Bot - UNC4210
Endpoint Forensics
mediumAnalyze memory images and event logs using MemProcFS, EvtxECmd, and Timeline Explorer to identify Andromeda bot IOCs, reconstruct its infection timeline, and attribute it to an APT group.

Akira - Storm-1567
Endpoint Forensics
mediumLearn to investigate Akira ransomware using memory forensics to identify IOCs, analyze attacker behavior, reconstruct timelines, and uncover system compromise, defense evasion, and persistence methods.

IcedID 2 - GOLD CABIN
Endpoint Forensics
mediumAnalyze memory artifacts and trace a ransomware attack's origin, execution, and persistence using forensic tools like Volatility 3 and MemProcFS.

KrakenKeylogger
Endpoint Forensics
mediumAnalyze Windows 10 notification artifacts, installed applications, LNK files, and Applications logs to uncover malicious activity and enhance forensic investigation capabilities.

Poisoned Pipeline
Threat Hunting, Endpoint Forensics
hardInvestigate a multi-stage supply-chain intrusion that landed via a poisoned npm dependency and pivoted through CI/CD into production and AWS by pivoting across Splunk, disk images, and git history.

Maromafix Falldown - RansomHub
Threat Hunting, Endpoint Forensics
hardReconstruct a multi-stage ransomware attack by correlating Windows event logs, disk artifacts, and malware analysis using Elastic, MFTECmd, RegRipper, and DNSpy.