CyberDefenders · cyberdefenders.org

  1. Practice
  2. Labs

Blue Team Labs

Put your knowledge into practice with gamified cyber security challenges.

Operation Cronos - Lockbit lab thumbnail

Operation Cronos - Lockbit

PREMIUM

Threat Intel

easy

Follow the trail from a single file hash through one of the most destructive ransomware operations in history — and the international law enforcement effort that brought it down.

GhostConnect - TA583 lab thumbnail

GhostConnect - TA583

PREMIUM

Threat Hunting

easy

Hunt Sysmon process trees, Chrome browsing artifacts, and Mark-of-the-Web streams to rebuild a the full kill chain from phishing delivery through AD enumeration to HTTPS exfiltration.

CursorJack lab thumbnail

CursorJack

PREMIUM

Endpoint Forensics, Cloud Forensics

easy

A developer's workstation is the new perimeter — trace an MCP-based intrusion from the first malicious deeplink through to a multi-region cloud compromise and follow the money on-chain.

Fork Bomb - TeamPCP lab thumbnail

Fork Bomb - TeamPCP

PREMIUM

Endpoint Forensics, Threat Intel

easy

Investigate a real-world supply chain attack from first alert to threat actor attribution — and find out how a single Python package nearly handed over the keys to an entire cloud environment.

DynamicEscalate lab thumbnail

DynamicEscalate

PREMIUM

Cloud Forensics

easy

Reconstruct a Microsoft Entra ID privilege escalation chain by correlating Exchange message traces, Azure AD telemetry, and unified audit logs using KQL.

AbuSESer - Trufflenet lab thumbnail

AbuSESer - Trufflenet

PREMIUM

Cloud Forensics

easy

Investigate a complex Business Email Compromise attack by correlating AWS CloudTrail and Lambda logs in CloudWatch Logs Insights to reconstruct the attack timeline and attribute TTPs.

ContainerBreak - Rootkit Trail lab thumbnail

ContainerBreak - Rootkit Trail

PREMIUM

Endpoint Forensics

easy

RediShell - Kinsing lab thumbnail

RediShell - Kinsing

PREMIUM

Network Forensics

easy

The packet capture was killed mid-attack. Race against incomplete evidence to reconstruct how attackers breached Jenkins, pivoted through containers, and escaped to the host

Maranhao lab thumbnail

Maranhao

PREMIUM

Endpoint Forensics

easy

Investigate a trojanized game installer by analyzing browser history, logs, registry hives, and filesystem artifacts to map the full attack chain and extract IOCs.

Rogue Azure lab thumbnail

Rogue Azure

PREMIUM

Cloud Forensics

easy

Reconstruct a multi-stage Azure attack timeline by analyzing Entra ID, Audit, and Storage Blob logs using Kusto Query Language to identify initial access, persistence, privilege escalation, and data exfiltration.

RevengeHotels APT lab thumbnail

RevengeHotels APT

PREMIUM

Endpoint Forensics

easy

Reconstruct multi-stage APT attack chain by correlating email, browser, Sysmon logs, and registry artifacts to identify persistence mechanisms and data exfiltration techniques.

Lockdown lab thumbnail

Network Forensics

easy

Reconstruct a multi-stage intrusion by analyzing network traffic, memory, and malware artifacts using Wireshark, Volatility, and VirusTotal, mapping findings to MITRE ATT&CK.

XLMRat lab thumbnail

Network Forensics

easy

Analyze network traffic to identify malware delivery, deobfuscate scripts, and map attacker techniques using MITRE ATT&CK, focusing on stealthy execution and reflective code loading.

SigmaPredator lab thumbnail

SigmaPredator

PREMIUM

Detection Engineering

easy

Design and validate Sigma rules to detect event log clearing techniques across CLI, WMI, and PowerShell execution artifacts.

OpenCTI 101 - APT29 lab thumbnail

OpenCTI 101 - APT29

PREMIUM

Threat Intel

easy

Identify threat actor TTPs and IOCs for APT29 by navigating and querying the OpenCTI threat intelligence platform.

AWSWatcher lab thumbnail

AWSWatcher

PREMIUM

Cloud Forensics

easy

Analyze AWS GuardDuty, CloudTrail, S3, and CloudWatch logs to identify attacker actions, exploited misconfigurations, and reconstruct an AWS cloud security incident.

Tusk Infostealer lab thumbnail

Threat Intel

easy

Analyze threat intelligence and malware configuration to identify TTPs, extract IOCs, and track cryptocurrency flow of the Tusk Infostealer campaign.

FakeGPT lab thumbnail

Malware Analysis

easy

Analyze a malicious Chrome extension's code and behavior to identify data theft mechanisms, covert exfiltration via `<img>` tags, and anti-analysis techniques.

Openfire lab thumbnail

Openfire

PREMIUM

Network Forensics

easy

Reconstruct an Openfire server attack timeline by analyzing PCAP files with Wireshark to identify login attempts, plugin uploads, command execution, and the exploited CVE-2023-32315 vulnerability.

DanaBot lab thumbnail

Network Forensics

easy

Analyze network traffic using Wireshark to identify DanaBot initial access, deobfuscate malicious JavaScript, and extract IOCs like IPs, file hashes, and execution processes.

Read the original on cyberdefenders.org ↗