Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

GhostConnect - TA583
Threat Hunting
easyHunt Sysmon process trees, Chrome browsing artifacts, and Mark-of-the-Web streams to rebuild a the full kill chain from phishing delivery through AD enumeration to HTTPS exfiltration.

AbuSESer - Trufflenet
Cloud Forensics
easyInvestigate a complex Business Email Compromise attack by correlating AWS CloudTrail and Lambda logs in CloudWatch Logs Insights to reconstruct the attack timeline and attribute TTPs.

XLMRat
Network Forensics
easyAnalyze network traffic to identify malware delivery, deobfuscate scripts, and map attacker techniques using MITRE ATT&CK, focusing on stealthy execution and reflective code loading.

DanaBot
Network Forensics
easyAnalyze network traffic using Wireshark to identify DanaBot initial access, deobfuscate malicious JavaScript, and extract IOCs like IPs, file hashes, and execution processes.

Red Stealer
Threat Intel
easyAnalyze a suspicious executable using VirusTotal and MalwareBazaar to extract IOCs, identify C2 infrastructure, MITRE ATT&CK techniques, and privilege escalation mechanisms.

3CX Supply Chain
Threat Intel
easyReconstruct the 3CX supply chain attack by analyzing compromised MSI and DLL artifacts to identify TTPs and attribute the incident to a threat actor.

IcedID
Threat Intel
easyInvestigate IcedID malware using VirusTotal and threat intelligence platforms to identify IOCs, associated threat actors, and execution mechanisms.

Ramnit
Endpoint Forensics
easyAnalyze a memory dump using Volatility to identify a malicious process, extract network IOCs, file hash, and compilation timestamp, correlating with external threat intelligence.

Oski
Threat Intel
easyAnalyze a sandbox report using Any.Run to identify Stealc malware behavior, extract configuration details, and map observed tactics to MITRE ATT&CK.

Yellow RAT
Threat Intel
easyAnalyze malware artifacts using threat intelligence platforms like VirusTotal to identify IOCs, C2 servers, and understand adversary tactics.

T1595
Network Forensics
easyAnalyze the PCAP file to identify malicious activity, using tools like Wireshark to detect threats, IP origins, and attacker techniques.

Rhadamanthys
Endpoint Forensics
mediumHunt mail caches, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

Poisoned PyTorch
Threat Hunting
mediumInvestigate a software supply-chain compromise that escalates into a ransomware attack, with emphasis on identifying pre-encryption operations.

RaaS Unfold - RansomHub
Threat Intel
mediumA ransomware empire built on the ashes of its predecessors — trace its origins, expose its operators, and unfold its playbook.

Stolen Time - HiddenTear
Threat Hunting
mediumSynthesize and correlate diverse forensic artifacts from multiple systems to reconstruct the complete HiddenTear attack chain and attribute threat actor TTPs.

Nitrogen - Blackcat Ransomware
Threat Hunting
mediumReconstruct multi-stage ransomware attack by correlating Splunk telemetry, disk forensics, and registry artifacts to identify persistence mechanisms, credential dumping, and lateral movement.

MBuchus
Threat Intel
mediumUtilize OSINT, VirusTotal, and crt.sh to analyze a multi-stage malvertising campaign, identifying initial access, malware payloads, and attacker infrastructure.

BRabbit
Threat Intel
mediumReconstruct a Bad Rabbit ransomware attack chain by analyzing phishing, persistence, and MBR modification using dynamic analysis and MITRE ATT&CK.

Andromeda Bot - UNC4210
Endpoint Forensics
mediumAnalyze memory images and event logs using MemProcFS, EvtxECmd, and Timeline Explorer to identify Andromeda bot IOCs, reconstruct its infection timeline, and attribute it to an APT group.

LummaStealer - Angry Likho
Endpoint Forensics
mediumAnalyze multi-stage malware behavior, decode obfuscated scripts, trace execution flow, and identify evasion, persistence, and exfiltration tactics using forensic tools.