- Practice
- Labs
Blue Team Labs
Put your knowledge into practice with gamified cyber security challenges.

Operation Cronos - Lockbit
PREMIUM
Threat Intel
easy
Follow the trail from a single file hash through one of the most destructive ransomware operations in history — and the international law enforcement effort that brought it down.

GhostConnect - TA583
PREMIUM
Threat Hunting
easy
Hunt Sysmon process trees, Chrome browsing artifacts, and Mark-of-the-Web streams to rebuild a the full kill chain from phishing delivery through AD enumeration to HTTPS exfiltration.

CursorJack
PREMIUM
Endpoint Forensics, Cloud Forensics
easy
A developer's workstation is the new perimeter — trace an MCP-based intrusion from the first malicious deeplink through to a multi-region cloud compromise and follow the money on-chain.

Fork Bomb - TeamPCP
PREMIUM
Endpoint Forensics, Threat Intel
easy
Investigate a real-world supply chain attack from first alert to threat actor attribution — and find out how a single Python package nearly handed over the keys to an entire cloud environment.

DynamicEscalate
PREMIUM
Cloud Forensics
easy
Reconstruct a Microsoft Entra ID privilege escalation chain by correlating Exchange message traces, Azure AD telemetry, and unified audit logs using KQL.

AbuSESer - Trufflenet
PREMIUM
Cloud Forensics
easy
Investigate a complex Business Email Compromise attack by correlating AWS CloudTrail and Lambda logs in CloudWatch Logs Insights to reconstruct the attack timeline and attribute TTPs.

ContainerBreak - Rootkit Trail
PREMIUM
Endpoint Forensics
easy

RediShell - Kinsing
PREMIUM
Network Forensics
easy
The packet capture was killed mid-attack. Race against incomplete evidence to reconstruct how attackers breached Jenkins, pivoted through containers, and escaped to the host

Maranhao
PREMIUM
Endpoint Forensics
easy
Investigate a trojanized game installer by analyzing browser history, logs, registry hives, and filesystem artifacts to map the full attack chain and extract IOCs.

Rogue Azure
PREMIUM
Cloud Forensics
easy
Reconstruct a multi-stage Azure attack timeline by analyzing Entra ID, Audit, and Storage Blob logs using Kusto Query Language to identify initial access, persistence, privilege escalation, and data exfiltration.

RevengeHotels APT
PREMIUM
Endpoint Forensics
easy
Reconstruct multi-stage APT attack chain by correlating email, browser, Sysmon logs, and registry artifacts to identify persistence mechanisms and data exfiltration techniques.

Network Forensics
easy
Reconstruct a multi-stage intrusion by analyzing network traffic, memory, and malware artifacts using Wireshark, Volatility, and VirusTotal, mapping findings to MITRE ATT&CK.

Network Forensics
easy
Analyze network traffic to identify malware delivery, deobfuscate scripts, and map attacker techniques using MITRE ATT&CK, focusing on stealthy execution and reflective code loading.

SigmaPredator
PREMIUM
Detection Engineering
easy
Design and validate Sigma rules to detect event log clearing techniques across CLI, WMI, and PowerShell execution artifacts.

OpenCTI 101 - APT29
PREMIUM
Threat Intel
easy
Identify threat actor TTPs and IOCs for APT29 by navigating and querying the OpenCTI threat intelligence platform.

AWSWatcher
PREMIUM
Cloud Forensics
easy
Analyze AWS GuardDuty, CloudTrail, S3, and CloudWatch logs to identify attacker actions, exploited misconfigurations, and reconstruct an AWS cloud security incident.

Threat Intel
easy
Analyze threat intelligence and malware configuration to identify TTPs, extract IOCs, and track cryptocurrency flow of the Tusk Infostealer campaign.

Malware Analysis
easy
Analyze a malicious Chrome extension's code and behavior to identify data theft mechanisms, covert exfiltration via `<img>` tags, and anti-analysis techniques.

Openfire
PREMIUM
Network Forensics
easy
Reconstruct an Openfire server attack timeline by analyzing PCAP files with Wireshark to identify login attempts, plugin uploads, command execution, and the exploited CVE-2023-32315 vulnerability.

Network Forensics
easy
Analyze network traffic using Wireshark to identify DanaBot initial access, deobfuscate malicious JavaScript, and extract IOCs like IPs, file hashes, and execution processes.