// defensive security operations

blue team operations
& SOC analysis

Over 119 live security alerts investigated, triaged, and documented — each one mapped to known attacker behaviour and written up with full methodology. 204+ completed lab scenarios covering network forensics, malware analysis, cloud intrusions, and incident response. Everything on this site is real work, publicly linked, and verifiable.

204
Total Labs
119
Investigations
CDSA
Certified
BTL1
Certified
CCDL1
Certified
13Cubed
Certified ×3
SC-200
Certified
93BTLO
89CyberDefenders
1LetsDefend
2TryHackMe
2HackSmarter
1DFIRLABS
16ThreatHuntingLabs
// live platform stats
HackTheBox Profile Threat Hunting Labs Profile
// competitive rankings
snapshot history ›
blue team labs online
inksec
Junior Defender
1355
Points
#3
Global
#2
AU Rank
19 Sep 2026 · graphi
cyberdefenders
@inksec
Pro
2400
Points
#2
Global
#1
AU Rank
30 Sep 2026 · ActiveMQ - LockBit Ransomware
blueteamlabs.online · cyberdefenders.org snapshot-based ›
// portfolio at a glance
204
Labs
119
SOC Alerts
86.6%
TP Rate
9
CVEs
view full breakdown →
Auto-generated from 119 documented investigations — tools used, malware families, MITRE coverage, CVEs, attack patterns. The actual writeups, certs, and daily work are below.
// recent activity
last update yesterday
rss ↗
last 30 days21 labs0 alerts0 posts7 rank snapshots
// team ctf event
holmes ctf 2026 ›
Holmes CTF 2026 — The Reichenbach Directive, certificate of participation
#149
of 5,637 Teams
111/111
Challenges Solved
8,725
Points
Team EL Chaoui · 17–21 Sep 2026 certificate of participation ›
// threat hunting competition
threat hunting labs ›
Threat Hunting Labs — Iranian APT Campaign Against Aerodyne Engineering, certificate of participation, final rank #6
#6
Final Rank
18
ATT&CK Techniques
KQL
Azure Log Analytics
Iranian APT Campaign Against Aerodyne Engineering · 25 Sep 2026 verify certificate ›
// featured build
Building a Hands-On SOC: Sentinel, ServiceNow & a Noisy Attack Range
Two live Sentinel environments — a permanent SOAR pipeline into ServiceNow and a disposable Atomic Red Team range — with detection engineering, automation playbooks, and threat hunting worked end to end.
explore the build →
// featured achievements
LetsDefend · Completed Pathway
SOC Analyst Learning Path
Certificate of Completion · February 2026
  • Real-world SIEM alert triage
  • Log analysis & correlation
  • Malware investigation & IOC identification
  • Incident documentation & reporting
  • Threat intelligence integration
view dashboard → certificate →
Level Effect · Certification
Certified Detection Engineer & Threat Hunter (CDETH)
Certified July 2026 · 16 Instructor-Reviewed Challenges
  • Alert classification — true positive / false positive with written justification
  • Regex pattern construction with detection-logic explanations
  • YARA rule authoring against real indicators of compromise
  • Sigma rule writing & tuning with detection logic explanations
  • Adversary emulation testing across MITRE ATT&CK TTPs
verify credential →
LetsDefend · Skill Path Complete
Malware Analysis Skill Path
Certificate of Completion · July 2026
  • Static & dynamic malware analysis
  • Sample triage & IOC extraction
  • Behavioural analysis in a sandbox
  • Malware classification & reporting
certificate →
CyberDefenders · Completed Track
SOC Analyst Tier 1
Completed April 2026 · 30 Investigations · 227 Questions
  • SIEM alert triage & log correlation
  • Network forensics & PCAP analysis
  • Memory forensics & disk image analysis
  • Threat intelligence & IOC attribution
  • Incident response & malware investigation
verify achievement →
CyberDefenders · In Progress
SOC Analyst Tier 2
Active lab grind · Endpoint & Memory Forensics focus
  • Memory forensics & volatile data analysis
  • Disk image forensics & file recovery
  • Malware triage & static analysis
  • Threat actor attribution & TI correlation
  • Advanced incident response workflows
TryHackMe · Certification
Security Analyst Level 1 (SAL1)
Certified April 2026 · Credly Verified
  • Alert triage & log analysis across SOC scenarios
  • PCAP investigation & network forensics
  • Threat intelligence & IOC correlation
  • Incident response workflows
  • Defensive reasoning & escalation methodology
verify on credly →
13Cubed · Mini Course
Architecting the Hunt
Certificate of Completion · August 2026
  • Hypothesis-driven threat hunting framework
  • Data acquisition & scoping for a hunt
  • Core hunting techniques & methodology
  • Countering cognitive bias in investigations
  • Hands-on lab practicing the full hunt cycle
verify credential →
Level Effect · Certification
Cyber Defense Certified Analyst (CDCA)
Certified July 2026 · Fully Practical, No Multiple Choice
  • Live Virtual SOC alert queue — Tier 1 through Tier 2 investigations
  • Network traffic analysis, email/header analysis, live Windows host triage, SIEM log hunting
  • DFIR methodology, timeline construction, playbook-driven investigation
  • Capstone incident report — IOC documentation, executive summary, technical analysis, remediations
  • Graded, section-by-section manual review — no automated scoring
verify credential →
Cybrixen · Certification
Cybrixen Certified SOC Analyst (CCSA)
Certified September 2026 · 91% · Scenario-Based Practical Exam
  • Monitoring, triaging & prioritizing security alerts (severity vs. priority)
  • Investigating alerts in SIEM — log searching, correlation, detection rules
  • Endpoint analysis with EDR — process trees, host & user context, artifacts
  • Applying MITRE ATT&CK, Cyber Kill Chain & Pyramid of Pain frameworks
  • Brute force, malicious PowerShell, malware, credential dumping & phishing investigations
  • Escalation & clear investigation summaries for L2/L3 handover
verify credential → certificate →
// youtube · daily grind
Day X: becoming a SOC analyst

One real LetsDefend alert per day, triaged out loud on camera. Structured workflow, log correlation, containment decisions — real analyst thinking documented publicly.

Format
Real alert → triage → log analysis → IOC correlation → containment decision → escalation or close. Every step narrated, every tool explained.
Also on YouTube
TryHackMe SAL1 walkthroughs · BTL1 lab investigations · platform-agnostic SOC methodology.
LetsDefend SOC Investigations ▶
LetsDefend SOC Investigations
119 videos · latest: SOC328
// youtube · cyberdefenders walkthroughs
Week X of DFIR

Full CyberDefenders lab walkthroughs on YouTube — every question answered, every tool and technique explained from scratch. Endpoint forensics, malware analysis, and threat investigation.

Format
One CyberDefenders lab per week. Full uncut walkthrough — artifact collection, tool usage, IOC extraction, and question-by-question reasoning explained out loud.
Coverage
Endpoint forensics · Malware analysis · Threat intelligence · Sysmon & evtx triage · .NET decompilation · C2 attribution
AzureSpray ▶
AzureSpray
Week 10 · Medium · Cloud Forensics
ContainerBreak - Rootkit Trail ▶
ContainerBreak - Rootkit Trail
Week 7 · Easy · [Endpoint Forensics]
view all DFIR episodes →
// daily soc practice · live investigation log
daily investigations

Every alert triaged, documented, and mapped to MITRE ATT&CK. Updated daily as part of the Day N of Becoming a SOC Analyst series.

119
Investigations
103
True Positives
95
MITRE Techniques
16
Critical
Latest: SOC328 — Akira Ransomware IOC's Detected
view full investigation log →
// kc7 · reusable detection patterns
kql pattern bank

Reusable KQL detection patterns auto-extracted from KC7 lab investigations — write the writeup once, every tagged query promotes itself into a searchable reference. Capability over completion: the queries are the takeaway.

16
Patterns Banked
5
Categories
9
ATT&CK Techniques
2
Source Labs
Categories: c2 · email · exfil · process · timeline
view the kql bank →
// mitre att&ck enterprise · technique coverage
att&ck heatmap

Every technique observed across labs and investigations mapped to MITRE ATT&CK Enterprise. Generated live from documented writeups — no manual curation.

406
Observations
94
Unique Techniques
14
Tactics Covered
T1105
Most Observed
explore full att&ck matrix →
// selected investigations
featured writeups

The newest Medium and Hard labs in each discipline, picked automatically as writeups land. 🔒 marks a lab still active on its platform: the writeup is complete but encrypted, and the password is available to recruiters on request.

incident response
The Nokoyawa Ransomware Intrusion - Public Case #18543 DFIRLABS Easy
Threat Hunting
The Nokoyawa Ransomware Intrusion - Public Case #185432026-08
Kibana/Sysmon investigation tracing an HTML-smuggled IcedID loader through process injection and scheduled-task persistence to Cobalt Strike C2 and domain-wide Nokoyawa ransomware deployment.
From SEO Poisoning to Custom RMM and Cobalt Strike — Incident Response (Case 2/4) ThreatHuntingLabs Hard
Incident Response
From SEO Poisoning to Custom RMM and Cobalt Strike — Incident Response (Case 2/4)2026-09
Incident response track scoping containment, evidence preservation, credential exposure, eradication and recovery for a workstation holding multiple remote-access footholds, with the replacement Beacon still communicating when the evidence window closes.
Phantom Pixels BTLO Hard
Incident Response
Phantom Pixels2026-06
Memory and malware-analysis investigation tracing a PawsRunner loader from a phishing-delivered JavaScript dropper, through env-var-obfuscated PowerShell and a steganographic PNG payload, to the in-memory execution of the PureLogs infostealer.
endpoint & network forensics
CodeFreeze 2 CyberDefenders Medium
Endpoint Forensics
CodeFreeze 22026-09
Endpoint triage investigation tracing a trojanised VS Code extension from an emailed archive through a WSL-hosted reverse shell and cron persistence to RustDesk credential theft and hands-on-keyboard access.
OpenWire CyberDefenders Medium
Network Forensics
OpenWire2026-07
Packet capture investigation tracing an unauthenticated ActiveMQ OpenWire deserialization exploit from initial C2 delivery through remote Java class instantiation to a second-stage reverse shell drop.
Spooler - APT28 CyberDefenders Hard
Endpoint Forensics
Spooler - APT282026-06
Trace an APT28 intrusion from a trojanized HR archive through mshta.exe remote HTA execution, certutil LOLBin download, DLL sideloading, dual-layer Print Spooler and Run key persistence, and AlwaysInstallElevated SYSTEM escalation.
threat hunting & threat intelligence
From SEO Poisoning to Custom RMM and Cobalt Strike — Threat Hunt (Case 1/4) ThreatHuntingLabs Medium
Threat Hunting
From SEO Poisoning to Custom RMM and Cobalt Strike — Threat Hunt (Case 1/4)2026-09
Endpoint telemetry hunt tracing an SEO-poisoned RVTools download through two parallel access paths, browser injection to Cobalt Strike and Level RMM to custom agents, to credential staging and failed lateral movement.
From SEO Poisoning to Custom RMM and Cobalt Strike — Detection Engineering (Case 3/4) ThreatHuntingLabs Hard
Detection Engineering
From SEO Poisoning to Custom RMM and Cobalt Strike — Detection Engineering (Case 3/4)2026-09
Detection engineering track turning an intrusion across browser injection, rogue RMM, a UAC-bypassed Cobalt Strike Beacon and credential staging into behavioural KQL rules that correlate multi-stage activity inside a single table.
ActiveMQ - LockBit Ransomware CyberDefenders Medium
Threat Hunting
ActiveMQ - LockBit Ransomware2026-09
Splunk threat hunt tracing an ActiveMQ CVE-2023-46604 RCE through GodPotato SYSTEM escalation and ADCS PKINIT abuse to SSH lateral movement, Telegram exfiltration, and LockBit ransomware.
cloud forensics & investigation
AzureSpray CyberDefenders Medium
Cloud Forensics
AzureSpray2026-08
Azure AD sign-in log investigation tracing a distributed password spray from cloud-hosted infrastructure through Smart Lockout evasion to a single compromised cloud identity.
GoogleCloudHunt CyberDefenders Medium
Cloud Forensics
GoogleCloudHunt2026-07
GCP audit log investigation using jq tracing a compromised principal through storage bucket exfiltration and Compute Engine access to a blocked Cloud SQL export and a persistent, attacker-created service account.
Code Blue - APT29 CyberDefenders Hard
Cloud Forensics
Code Blue - APT292026-06
Reconstruct a multi-stage APT29 intrusion by analyzing Azure and M365 logs to trace device code phishing, OAuth token ab...
malware analysis & reverse engineering
CryptLoad CyberDefenders Hard
Malware Analysis
CryptLoad2026-08
Malware analysis of a trojanized CPU-Z distribution tracing a proxy DLL sideload through a colon-hex encoded overlay and reflective PE chain to a Tor-capable backdoor with hVNC and credential theft modules.
Satisfaction CyberDefenders Medium
Malware Analysis
Satisfaction2026-06
A disgruntled physical insider brute-forces LimeSurvey admin, uploads a webshell-bearing plugin, and deploys an XOR-obfuscated shellcode injector — traced end-to-end from DHCP to Ghidra to urlscan.io.
AsyncRAT CyberDefenders Medium
Malware Analysis
AsyncRAT2026-04
Dissect a multi-stage AsyncRAT infection chain — obfuscated JS dropper, steganographic PNG payloads, and .NET loader — tracing persistence and extraction through each stage.
// all completed labs
lab grid

All platforms, all labs. Filter by platform, difficulty, or category. Adding new labs weekly.

skill
diff
showing 142 labs
RVTools Intrusion — Malware Analysis (Case 4/4) ThreatHuntingLabs Guided
RVTools Intrusion — Malware Analysis (Case 4/4)
Malware Analysis7-ZipPowerShellWindowsInstaller COMPythonVolatility3FLARE-VMT1027T1140T1036T1059.001T1543.003T1071.001T1090
Static and memory analysis of the RVTools intrusion payloads, peeling a nested decoy installer, an encrypted Python loader chain, a custom RMM agent, a proxy DLL and a masked in-memory Beacon without executing any of them.
From SEO Poisoning to Custom RMM and Cobalt Strike — Detection Engineering (Case 3/4) ThreatHuntingLabs Hard
From SEO Poisoning to Custom RMM and Cobalt Strike — Detection Engineering (Case 3/4)
Detection EngineeringEDR TelemetryKQLT1204.002T1218.007T1055.004T1134.004T1105T1219T1059.001T1059.006T1543.003T1548.002T1562.001T1555.003T1003.002T1053.005T1087.002T1021.002
Detection engineering track turning an intrusion across browser injection, rogue RMM, a UAC-bypassed Cobalt Strike Beacon and credential staging into behavioural KQL rules that correlate multi-stage activity inside a single table.
From SEO Poisoning to Custom RMM and Cobalt Strike — Incident Response (Case 2/4) ThreatHuntingLabs Hard
From SEO Poisoning to Custom RMM and Cobalt Strike — Incident Response (Case 2/4)
Incident ResponseEDR TelemetryKQLT1204.002T1055.004T1053.005T1219T1562.001T1562.004T1555.003T1003.002T1005T1087.002T1021.002T1071.001
Incident response track scoping containment, evidence preservation, credential exposure, eradication and recovery for a workstation holding multiple remote-access footholds, with the replacement Beacon still communicating when the evidence window closes.
From SEO Poisoning to Custom RMM and Cobalt Strike — Threat Hunt (Case 1/4) ThreatHuntingLabs Medium
From SEO Poisoning to Custom RMM and Cobalt Strike — Threat Hunt (Case 1/4)
Threat HuntingEDR TelemetryKQLT1204.002T1218.007T1055.004T1547.001T1059.001T1059.006T1548.002T1562.001T1053.005T1543.003T1219T1071.001T1016T1555.003T1003.002T1021.002
Endpoint telemetry hunt tracing an SEO-poisoned RVTools download through two parallel access paths, browser injection to Cobalt Strike and Level RMM to custom agents, to credential staging and failed lateral movement.
Unpacking DonutLoader — Malware Analysis (Case 2/2) ThreatHuntingLabs Guided
Unpacking DonutLoader — Malware Analysis (Case 2/2)
Malware AnalysisWindowsLoaderREMnux[T1059.001, T1059.003, T1547.001, T1055.002, T1027.013, T1497.001, T1140, T1555.003, T1552.001]
Static triage of a batch loader, its embedded second-stage injector, and a pair of .NET credential stealers recovered from a compromised host, worked directly in a REMnux workspace.
M365 Mailbox Intrusion — Detection Engineering (Case 3/3) ThreatHuntingLabs Guided
M365 Mailbox Intrusion — Detection Engineering (Case 3/3)
Detection EngineeringCloudMicrosoft 365EDR TelemetryKQL[T1078.004, T1526, T1114.002, T1114.003]
Detection Engineering pass against the same Microsoft 365 BEC intrusion investigated in the Threat Hunt and Incident Response labs — writing the rules that would have caught the actor rather than querying to find them after the fact.
M365 Mailbox Intrusion — Incident Response (Case 2/3) ThreatHuntingLabs Guided
M365 Mailbox Intrusion — Incident Response (Case 2/3)
Incident ResponseCloudMicrosoft 365EDR TelemetryKQL[T1078.004, T1526, T1114.002, T1114.003]
M365 audit and Entra telemetry investigation tracing valid-account access from a single-factor browser login through Graph discovery and OWA mailbox collection to external forwarding-rule persistence and a failed alert notification.
M365 Mailbox Intrusion — Threat Hunt (Case 1/3) ThreatHuntingLabs Guided
M365 Mailbox Intrusion — Threat Hunt (Case 1/3)
Threat HuntingCloudMicrosoft 365EDR TelemetryKQL[T1078.004, T1550.001, T1526, T1087.004, T1069.003, T1114.002, T1114.003, T1564.008]
Cloud audit investigation tracing a stolen session token from an interrupted browser login through Graph enumeration and OWA mailbox reads to a forwarding rule whose detection alert never reached an inbox.
The Recurring Impostor — Flash Hunt ThreatHuntingLabs Guided
The Recurring Impostor — Flash Hunt
Threat HuntingWindowsScheduled Task PersistenceEDR TelemetrySysmonWindows DefenderHunt.ioKQLT1095T1053.005T1105T1055T1036T1059.005T1547.001T1059.003T1562.001T1204.002T1499
A Windows workstation alert traces a two-stage trojan drop into recurring scheduled-task persistence masquerading as a legitimate system process, a Severe antivirus detection silently logged as a failed remediation, and a destructive lockout stage — a Flash Hunt (Threat Hunting Labs' rapid single-session format) earning a Distinction badge.
NightShade C2 Multi-Stage Infection — Malware Analysis (Case 2/2) ThreatHuntingLabs Guided
NightShade C2 Multi-Stage Infection — Malware Analysis (Case 2/2)
Malware AnalysisScript DeobfuscationLiving-Off-The-Land Runtime AbuseEDR TelemetryKQLT1059.005T1059.001T1027T1140T1071.001
Static and behavioural triage of the same NightShade installer chain's scripts and runtime payload — a VBScript stager, a PowerShell dropper, and an obfuscated JavaScript runner — part 2 of a 2-lab Flash Hunt case (Threat Hunting Labs) earning a Distinction badge.
NightShade C2 Multi-Stage Infection — Threat Hunt (Case 1/2) ThreatHuntingLabs Guided
NightShade C2 Multi-Stage Infection — Threat Hunt (Case 1/2)
Threat HuntingMulti-Stage Installer ChainLiving-Off-The-Land Runtime AbuseEDR TelemetryKQLT1204.002T1059.001T1059.005T1547.001T1053.005T1548.002T1105T1071.001T1036.005
A user-run MSI installer chains through script interpreters into a legitimate portable runtime used as a fetch-and-eval C2 client, with layered user- and SYSTEM-scope persistence and a later UAC-bypass privilege escalation — a Flash Hunt case (Threat Hunting Labs) earning a Distinction badge.
MacSync: From ClickFix to Data Theft — Flash Hunt ThreatHuntingLabs Guided
MacSync: From ClickFix to Data Theft — Flash Hunt
Threat HuntingmacOSClickFix Social EngineeringEDR TelemetryESF (Endpoint Security Framework)KQLT1566.002T1059.002T1059.004T1105T1140T1071.001T1567T1555.001T1552T1078.003T1074.001T1083T1070.004
A ClickFix-style macOS lure runs into a Base64 pipe-to-shell chain, AppleScript-orchestrated credential and developer-artifact staging, and an HTTP archive upload — a Flash Hunt (Threat Hunting Labs' rapid single-session format) earning a Distinction badge.
Ursnif Malware Targeting Italy — Malware Analysis (Case 4/4) ThreatHuntingLabs Guided
Ursnif Malware Targeting Italy — Malware Analysis (Case 4/4)
Malware AnalysisPE Static TriagePacking & ObfuscationShared Module AbuseEDR TelemetryKQLT1059.001T1218.010T1027.002T1129
Static and behavioural triage of the Ursnif artifact itself — packing, exports, and shared-module abuse — part 4 of a 4-lab case (Threat Hunt, Incident Response, Detection Engineering, Malware Analysis).
Ursnif Malware Targeting Italy — Detection Engineering (Case 3/4) ThreatHuntingLabs Guided
Ursnif Malware Targeting Italy — Detection Engineering (Case 3/4)
Detection EngineeringProxy Execution DetectionWeb-Based C2 DetectionRemote Access DetectionEDR TelemetryKQLT1218.010T1071.001T1059.001T1218T1021.005T1218.005
Building generalised detection logic for the same Ursnif intrusion — covering proxy execution, scripting, and remote access — part 3 of a 4-lab case (Threat Hunt, Incident Response, Detection Engineering, Malware Analysis).
Ursnif Malware Targeting Italy — Incident Response (Case 2/4) ThreatHuntingLabs Guided
Ursnif Malware Targeting Italy — Incident Response (Case 2/4)
Incident ResponseLiving-Off-The-Land Proxy ExecutionWeb-Based C2Remote Access & DiscoveryEDR TelemetryKQLT1105T1071.001T1059.001T1012T1021.005T1018T1218.010
Incident response pass through the same Ursnif intrusion — triage, scope, containment, and recovery across host and network evidence — part 2 of a 4-lab case (Threat Hunt, Incident Response, Detection Engineering, Malware Analysis).
Ursnif Malware Targeting Italy — Threat Hunt (Case 1/4) ThreatHuntingLabs Guided
Ursnif Malware Targeting Italy — Threat Hunt (Case 1/4)
Threat HuntingSigned Binary Proxy ExecutionRegistry-Based StagingCommand & Control AnalysisEDR TelemetryNetwork Logs (Zeek)KQLT1218.010T1218.011T1059.001T1071.001T1560T1070.004
Threat hunt through a signed-binary proxy execution chain, registry-based payload staging, and a dual command-and-control setup — part 1 of a 4-lab case (Threat Hunt, Incident Response, Detection Engineering, Malware Analysis).
AzureSpray CyberDefenders Medium
AzureSpray
Cloud ForensicsMicrosoft SentinelAzure MonitorKQL Query EditorAzure AD Sign-in LogsIdentity ProtectionAzure AD WorkbooksInitial AccessPersistencePrivilege EscalationStealthCredential AccessDiscoveryT1110.003T1078.004T1087.004
Azure AD sign-in log investigation tracing a distributed password spray from cloud-hosted infrastructure through Smart Lockout evasion to a single compromised cloud identity.
GoogleCloudHunt CyberDefenders Medium
GoogleCloudHunt
Cloud ForensicsjqInitial AccessPersistencePrivilege EscalationDefense EvasionDiscoveryCollectionT1078.004T1580T1530T1567.002T1136.003T1098.001
GCP audit log investigation using jq tracing a compromised principal through storage bucket exfiltration and Compute Engine access to a blocked Cloud SQL export and a persistent, attacker-created service account.
OpenWire CyberDefenders Medium
OpenWire
Network ForensicsWiresharkZuiNetwork MinerInitial AccessExecutionCommand and ControlT1190T1059.004T1105
Packet capture investigation tracing an unauthenticated ActiveMQ OpenWire deserialization exploit from initial C2 delivery through remote Java class instantiation to a second-stage reverse shell drop.
ShadowRoast CyberDefenders Medium
ShadowRoast
Threat HuntingSplunkEZ ToolsEvent Log ExplorerKAPEEvent ViewerCyberChefDefense EvasionCredential AccessT1204.002T1036.005T1059.001T1059.003T1547.001T1558.004T1003.001T1207T1112T1021.001T1560.001
Splunk-driven Active Directory investigation tracing a masqueraded update utility through Kerberos credential harvesting and a DCShadow rogue domain controller to RDP-enabled lateral movement and file server data staging.
Phantom Pixels BTLO Hard
Phantom Pixels
Incident ResponseDNSSpyVolatilityMemProcFST1566.001T1059.007T1059.001T1140T1027T1027.003T1620T1134.004T1562.001T1105T1071.001T1555T1041
Memory and malware-analysis investigation tracing a PawsRunner loader from a phishing-delivered JavaScript dropper, through env-var-obfuscated PowerShell and a steganographic PNG payload, to the in-memory execution of the PureLogs infostealer.
Spooler - APT28 CyberDefenders Hard
Spooler - APT28
Endpoint ForensicsRegistry ExplorerDB Browser for SQLitePECmdMFTECmdAmcacheParserTimeline ExplorerWindows Event ViewerVirusTotalInitial AccessExecutionDefense EvasionPersistencePrivilege EscalationT1566T1204.002T1218.005T1574.001T1105T1547.001T1547.010T1218.007
Trace an APT28 intrusion from a trojanized HR archive through mshta.exe remote HTA execution, certutil LOLBin download, DLL sideloading, dual-layer Print Spooler and Run key persistence, and AlwaysInstallElevated SYSTEM escalation.
Maromafix Falldown - RansomHub CyberDefenders Hard
Maromafix Falldown - RansomHub
Threat HuntingRegRipperDB Browser for SQLiteCyberChefdnSpyELKTimeline ExplorerMFTECmdDetect It Easydefender-dump.pyCobaltStrikeParserInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementImpactT1566.002T1059.001T1071.004T1547.001T1046T1087.002T1649T1550.003T1021.002T1562.001T1070.001T1486T1041T1567
Full RansomHub kill chain: ClickFix initial access via compromised website, Cobalt Strike beacon delivered through DNS TXT payload, ESC1 ADCS abuse for privilege escalation, smbexec.py lateral movement, and RansomHub ransomware deployed during an 11-minute logging blind window.
Satisfaction CyberDefenders Medium
Satisfaction
Malware AnalysisCyberChefWiresharkDetect It EasyURLScan.ioGhidraPowerShellPersistencePrivilege EscalationDefense EvasionCredential AccessT1110.001T1505.003T1059.001T1027T1027.010T1055T1037.001T1036.005
A disgruntled physical insider brute-forces LimeSurvey admin, uploads a webshell-bearing plugin, and deploys an XOR-obfuscated shellcode injector — traced end-to-end from DHCP to Ghidra to urlscan.io.
MarkShell - TA577 CyberDefenders Hard
MarkShell - TA577
Threat HuntingCyberChefDetect It EasySplunkIDAPEStudioscdbgCobaltStrikeParserReconnaissanceExecutionPrivilege EscalationDefense EvasionCredential AccessLateral MovementT1566.002T1218.005T1059.001T1027.010T1027T1055T1071.001T1548.002T1552.002T1078T1021.001T1021.006T1046T1135T1219T1555.003T1036.005
Investigate a TA577-attributed multi-stage phishing intrusion across a healthcare network, from DMARC-lure archive delivery through Covenant C2, AlwaysInstallElevated privesc, credential harvesting, Cobalt Strike lateral movement, and Atera RMM persistence on the domain controller.
RoastToRoot CyberDefenders Hard
RoastToRoot
Network ForensicsWiresharkNotepad++JohnTheRipper7zipReconnaissanceInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryCollectionExfiltrationT1595.001T1110.001T1558.004T1558.003T1078.002T1482T1087.002T1069.002T1560.001T1039T1048.002T1070.001T1543.003
Analyze a network capture to reconstruct a full AD domain compromise chain — AS-REP Roasting, BloodHound enumeration, Kerberoasting, privilege escalation, and rclone-based data exfiltration via smbexec.
Formbook CyberDefenders Hard
Formbook
Endpoint ForensicsEvent Log ExplorerCyberChefDB Browser for SQLiteNotepad++PowerShellInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCommand and ControlT1566.001T1059.007T1059.001T1027.010T1027T1053.005T1547.001T1218.004T1055T1071.004T1041T1082T1486
Trace a FormBook infection chain from a phishing RAR lure through obfuscated JScript, AES-encrypted PNG payloads, reflective .NET loading, MSBuild LOLBin abuse, and final injection into Chrome for C2 beaconing.
Stolen Time - HiddenTear CyberDefenders Medium
Stolen Time - HiddenTear
Threat HuntingDB Browser for SQLiteRegistry ExplorerTimeline ExplorerSplunkEZ ToolsVirusTotalExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationImpactT1204.002T1059.003T1218.004T1055.001T1562.001T1070.006T1547.005T1053.005T1546.003T1543.003T1003.001T1134.003T1558.001T1021.002T1087.002T1046T1560.001T1048T1490T1486
Synthesize and correlate diverse forensic artifacts from multiple systems to reconstruct the complete HiddenTear attack ...
CallMeOnTheChain - EtherRAT CyberDefenders Medium
CallMeOnTheChain - EtherRAT
Network ForensicsWiresharkuniqsorttsharkEtherscan.ioInitial AccessExecutionPersistencePrivilege EscalationCommand and ControlT1190T1059.004T1027.010T1105T1547.013T1098.004T1071.001T1102.001T1041T1056.001
Decrypt traffic, decompile smart contracts, and uncover how attackers turned the blockchain into a C2 channel....
GhostConnect - TA583 CyberDefenders Easy
GhostConnect - TA583
Threat HuntingDB Browser for SQLiteSplunkVirusTotalInitial AccessExecutionDiscoveryCollectionT1566.002T1059.005T1059.001T1105T1082T1069.002T1087.002T1057T1560.001T1041T1562.001T1053.005
Investigate a TA583-attributed intrusion against FedBridge analyst chriskarma — phishing lure to VBS stager, multi-stage loader chain, AD enumeration, and Base64 exfiltration over HTTPS — surfacing operator OPSEC failures along the way.
Hammer In The Vault BTLO Medium
Hammer In The Vault
Incident ResponseRegistry ExplorerNotepadEvent Log ExplorerEric Zimmerman ToolsT1566.003T1204.002T1059.001T1546.002T1105T1068T1562.001T1027
A Sopranos network workstation was compromised via a malicious Obsidian vault delivered over Telegram, executing a reverse shell through the obsidian-shellcommands plugin, establishing screensaver persistence, and attempting privilege escalation via the BlueHammer Windows Defender zero-day.
CodeFreeze CyberDefenders Medium
CodeFreeze
Endpoint ForensicsEvent ViewerCyberChefRegistry ExplorerTimeline ExplorerPECmdDB Browser for SQLliteInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionT1204.002T1059.001T1105T1055T1574.002T1543.003T1036.004T1546T1552.001T1048.003T1070.004
Reconstruct a full attack chain against a developer workstation — from social engineering via Google Meet through C2 deployment, DLL hijacking for privilege escalation, and git hook-based credential exfiltration.
KioskExpo7 CyberDefenders Medium
KioskExpo7
Endpoint ForensicsCyberChefDB Browser for SQLiteEZ ToolsDCodeText EditorInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryCommand and ControlImpactT1659T1204.002T1059.001T1547.001T1548.002T1552.002T1036.005T1053.005T1071.001T1491.001
Analyse a KAPE triage image from a compromised conference kiosk to reconstruct a physical access attack chain from browser kiosk breakout through privilege escalation, credential theft, persistence via scheduled tasks, and attendee-targeting QR code swap.
Poisoned PyTorch CyberDefenders Medium
Poisoned PyTorch
Threat HuntingCyberChefSplunkIDAPEStudioInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementImpactT1195.001T1059.001T1547.001T1482T1552.001T1021.001T1136.002T1078.002T1490T1486
Trace a poisoned Python dependency supply chain compromise from initial execution through domain-wide Lynx ransomware deployment across PC01, DC01, and FILE-SERVER-01.
Fork Bomb - TeamPCP CyberDefenders Easy
Fork Bomb - TeamPCP
Endpoint ForensicsCyberChefNotepad++SysmonGoogle SearchInitial AccessPersistencePrivilege EscalationDiscoveryCollectionCommand and ControlImpactT1195.001T1546.004T1059.006T1005T1560.001T1041T1071.001T1053.006T1070.003T1027
Investigate a real-world PyPI supply chain attack — a trojanised litellm package deploys a .pth fork bomb, credential stealer, and persistence backdoor on a developer's EC2 workstation.
Supply Drop 1 BTLO Hard
Supply Drop 1
Incident ResponseMFTECmdPECmdWSLT1195.001T1059.004T1046T1105T1053.003T1136T1564.001T1071.003T1070.004T1027
A developer's workstation triggers SOC alerts during a project build — a poisoned Go dependency phones home to a C2, enabling attacker enumeration, persistence via gs-netcat and cron, and a follow-up Windows implant drop.
Fake BTLO Hard
Fake
Incident ResponseMFTECmdPECmdMFTExplorerEvtxECmdRegistry ExplorerCyberChefLECmdSQLite BrowserAppCompatCacheParserAmcacheParserT1566.002T1204.002T1218.005T1059.001T1027T1027.013T1140T1105T1068T1112T1070.001T1070.004T1083T1036.005T1547.013T1486T1490
LockBit 3.0 ransomware investigation — ClickFix phishing via nftlive.com leads to msfvenom shellcode C2, CVE-2024-35250 privilege escalation, Python .pth site-packages persistence, and full LockBit deployment with alphabet rename chain and event log truncation.
Dumpster BTLO Hard
Dumpster
Incident ResponseElasticZimmermanSQLite3stringsTimeliningT1659T1059.001T1027.010T1105T1547.009T1556.002T1110.003T1021.002T1003.001T1036.005T1055.012T1567.002T1555.003T1068T1562.001
Enterprise IR across three monitored endpoints and one unmonitored test machine — investigating a ClickFix initial access chain through to domain-wide credential theft via WerFault LSASS abuse, LSA password filter persistence surviving a full password reset, and browser data exfiltration
Frequency Noise BTLO Medium
Frequency Noise
Incident ResponseStringsIDAx64dbgT1027.013T1055T1106T1071.001
A suspicious binary was flagged during endpoint triage. Automated scanning returned clean — no known signatures, no read...
Supply Drop 2 BTLO Easy
Supply Drop 2
Incident ResponseStringsIDAx64dbg1036.005T1497.001T1055.012T1140T1071.001
Static and dynamic analysis of a disguised second-stage payload masquerading as the Windows Time service, uncovering anti-debug evasion, custom XOR decryption, UUID-based shellcode loading, and C2 beaconing.
Fail2Shell BTLO Medium
Fail2Shell
Incident ResponseVolatilityStringsNotepad++T1078T1083T1005T1560T1543T1546.016T1070.002T1059
Analyse a Linux memory image to reconstruct a post-compromise intrusion involving credential-based lateral movement, PAM persistence via pam_exec, Discord-based C2, and anti-forensic log deletion.
Bad Import BTLO Medium
Bad Import
Incident ResponseSplunkT1195.002T1059.001T1036.005T1547.001T1552.001T1021.006T1070.006T1105T1543.003T1055T1071.001
Investigate a supply chain compromise via a malicious npm package that established C2, exfiltrated credentials, laterally moved through a Jenkins build server, and deployed a malicious plugin to a production web application.
Curiosity BTLO Easy
Curiosity
Incident ResponseZimmerman toolsMFTECmdTimeline ExplorerT1005T1074.001T1036T1048T1564.001
Investigate a suspected insider threat by parsing the USN Journal from an employee workstation to trace unauthorized possession, staging, and exfiltration of stolen source code.
QBot CyberDefenders Medium
QBot
Endpoint ForensicsVolatility 3Initial AccessExecutionCommand and ControlT1566.001T1204.002T1059.005T1055T1071.001T1102
Reconstruct a QBot infection timeline from a Windows memory dump — identify C2 communications, trace the Excel macro delivery chain, extract and hash the malicious XLS, and attribute via VirusTotal.
GoldenSpray CyberDefenders Medium
GoldenSpray
Threat HuntingSplunkELKExecutionPersistencePrivilege EscalationCredential AccessLateral MovementT1110.003T1078T1105T1547.001T1003.001T1021.002T1053.005T1558.003T1560.001
Reconstruct a multi-stage intrusion — password spray from Finland, lateral movement via stolen credentials, mimikatz credential dump, scheduled task persistence on DC, and data staged for exfiltration.
AsyncRAT CyberDefenders Medium
AsyncRAT
Malware AnalysisVsCodeCyberChefdnSpyHexEditorWayback MachineJavaScript DeobuscatorExecutionPrivilege EscalationDefense EvasionT1059.001T1027.010T1027T1547.001T1105T1140
Dissect a multi-stage AsyncRAT infection chain — obfuscated JS dropper, steganographic PNG payloads, and .NET loader — tracing persistence and extraction through each stage.
MeteorHit - Indra CyberDefenders Medium
MeteorHit - Indra
Endpoint ForensicsRegistry ExplorerEvent Log ExplorerNTFS Log TrackerMFTECmdVirusTotalExecutionPersistencePrivilege EscalationDefense EvasionDiscoveryImpactT1059.003T1053.005T1562.001T1070.004T1490T1543.003T1113T1036.005
Reconstruct a wiper malware attack by analyzing registry, event logs, and USN journal artifacts from a KAPE triage collection.
Mitsu BTLO Easy
Mitsu
Incident ResponsePowerShellT1518T1136.001T1053.005T1547.001T1059.001T1112
You've been called to investigate suspicious activity on a computer. Due to an unfortunate accident involving honey, the...
AndroidBreach CyberDefenders Medium
AndroidBreach
Endpoint ForensicsALEAPPJADXDB Browser for SQLiteCyberChefInitial AccessPersistencePrivilege EscalationDefense EvasionDiscoveryCollectionExfiltrationImpactT1476T1417.001T1532T1041T1573.001
Analyse an Android dump to investigate a credential breach — ALEAPP triage surfaces a malicious APK download, JADX reverse engineering reveals a keylogger exfiltrating data via SMTP to mailtrap.io and encrypting device images with AES.
XMRig CyberDefenders Medium
XMRig
Endpoint ForensicsLinux Command Line ToolsTestDiskStringsPhotoRecInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionLateral MovementCollectionCommand and ControlExfiltrationT1110.001T1136.001T1548.003T1053.003T1105T1070.002T1070.003T1496
Linux disk image forensics — mount via losetup, recover deleted auth.log with PhotoRec, reconstruct SSH brute force and XMRig cryptominer deployment chain including cron persistence, sudoers manipulation, and attacker cleanup attempts.
Andromeda Bot - UNC4210 CyberDefenders Medium
Andromeda Bot - UNC4210
Endpoint ForensicsMemProcFSVirusTotalEvtxcmdTimeline ExplorerInitial AccessPersistencePrivilege EscalationDefense EvasionLateral MovementCommand and ControlT1091T1059.001T1562.001T1036.005T1071.001T1105T1055
Investigate a memory dump from a USB-propagated malware campaign — mount with MemProcFS, parse event logs in Timeline Explorer, and correlate Sysmon artefacts with Turla/UNC4210 threat intelligence to attribute the Andromeda bot reactivation.
Reveal CyberDefenders Easy
Reveal
Endpoint ForensicsVolatility 3Defense EvasionDiscoveryT1566.001T1059.001T1218.011T1071.001
Analyse a Windows memory dump to identify a STRELASTEALER infection chain — malicious document opens in wordpad, spawns a hidden PowerShell process that mounts a WebDAV share and executes a remote DLL via rundll32.
Web Investigation CyberDefenders Easy
Web Investigation
Network ForensicsWiresharkNetwork MinerInitial AccessPersistenceCommand and ControlT1190T1046T1110.001T1505.003T1059.004
Analyse a web server PCAP to trace a full attack chain — SQLi enumeration against a PHP search endpoint, gobuster directory brute force, admin panel credential stuffing, and web shell upload for RCE.
NPM Supply Chain Attacks HackSmarter Easy
NPM Supply Chain Attacks
Incident ResponsenetstatpscrontabCredential AccessCollectionT1195.002T1059.007T1053.003T1071.001T1105T1070.003T1036
NPM supply chain attack walkthrough — compromised Axios maintainer credentials used to publish a poisoned dependency that drops a Python RAT via postinstall, establishes cron persistence, and beacons to C2 over HTTPS.
Defender BTLO Medium
Defender
Incident ResponseEvent ViewerCommand PromptRegistry EditorT1562.001T1112T1059.001
Analyse Windows Defender Antivirus event logs and registry to identify tamper activity — exclusions added, protections disabled, and MAPS reporting silenced.
Insider Threat BTLO Hard
Insider Threat
Incident ResponseEvtxtractVolatility2MiTec Windows Registry RecoveryNotepad++T1098T1039T1052.001T1560.001T1078
Investigate a terminated employee's final session using memory forensics, file server security logs, and a registry hive to reconstruct data exfiltration to a USB device.
Photo BTLO Easy
Photo
Incident ResponseLinux CLIjpegdump.pycyberchefT1505T1505.003T1027T1001
Analyse two malicious JPEG samples — one hiding a PHP webshell in EXIF metadata, one concealing a .NET IRC RAT inside a fake PEM certificate between concatenated JPEG boundaries.
RDP BTLO Easy
RDP
Incident ResponseFTK ImagerRdpCacheStitcherbmc-toolsT1021.001T1005
Analyse a forensic disk image to recover RDP cache tiles, reconstruct remote desktop session fragments, and extract trade secrets.
Key Key BTLO Easy
Key Key
Endpoint ForensicsWiresharkIDAT1056.001T1041T1027
Analyse a Linux keylogger binary in IDA to identify the input device hook, log file path, and XOR encryption routine, then decrypt POST data from a Wireshark capture to recover an exfiltrated password and secret project name.
Brute BTLO Medium
Brute
Incident ResponseNotepad++MySQLT1595.003T1110.003T1136.001T1021.001T1505.003T1565.001
Investigate a compromised XAMPP web server by tracing an attack chain from feroxbuster directory scanning through FTP credential theft, brute force login, web shell deployment, website defacement, backdoor account creation, and database manipulation.
qbot BTLO Medium
qbot
Endpoint ForensicsCyberChefNotepad++Defense EvasionExecutionT1566.001T1027.006T1059.001T1059.003T1112T1105T1027T1059.007T1547.001T1140T1218.011
Dissect a Qbot HTML smuggling campaign that chains Office 365 impersonation, a password-protected IMG file, LNK execution, CMD variable obfuscation, registry-stored Base64 PowerShell, and a JScript WSF loader to deliver Fishlines.dll from a remote C2.
marionette BTLO Medium
marionette
Endpoint ForensicsText editorCLIT1070.006T1036.003T1003.001T1059.001T1083
Analyse an MFT CSV export from a suspected compromised macOS endpoint to identify timestomping anti-forensics, uncover masqueraded payloads, and attribute a post-exploitation toolkit including mimikatz, PowerView, and a PS1 lure disguised as a PDF invoice.
Suspended BTLO Easy
Suspended
Incident ResponseSublime Text 2Thunderbird BrowserOSINTT1566T1566.001T1566.002
Triage a phishing email impersonating Amazon by extracting headers, decoding a Base64 PDF attachment in CyberChef, and tracing a multi-hop redirect chain through Google Drawings to a malicious credential harvesting domain.
Vault BTLO Easy
Vault
Incident ResponseTimeline ExplorerT1528T1530T1552.001
Investigate a Defender for Cloud Key Vault alert by correlating Azure Sign-In logs with Key Vault diagnostic logs in Timeline Explorer to identify a compromised account, enumerate accessed vaults, and attribute tooling used to exfiltrate cryptographic keys and secrets.
Nano BTLO Easy
Nano
Incident ResponseRITAZeekZgrepT1071.004T1571T1102
Use RITA to identify C2 beaconing from a DigitalOcean-hosted server, then pivot to Zeek DNS logs to uncover a dnscat2 DNS tunnelling channel exfiltrating data via hex-encoded TXT record queries to cat.nanobotninjas.com.
Marksman BTLO Medium
Marksman
Incident ResponsePersistenceSniperPowerShellEvent ViewerT1110.001 T1546.012 T1053 T1136.001 T1098T1053.005T1562.001
Investigate a brute-forced Windows endpoint using PersistenceSniper and manual IR techniques to uncover IFEO abuse, a Meterpreter payload delivered over RDP drive redirection, Defender exclusion tampering, a broken scheduled task, and an attacker-created local administrator account.
Parse-Zilla BTLO Medium
Parse-Zilla
Incident ResponseLinux CLIjqT1016T1649T1039T1595.002T1190T1083T1005
Analyse JSON-format Traefik access logs using jq to identify an internal attacker who ran Nikto, attempted Shellshock exploitation via User-Agent injection, then manually exfiltrated a confidential acquisitions document from an exposed FTP directory.
Waf-o-calypse BTLO Medium
Waf-o-calypse
Incident ResponseLinux CLIjqgoaccessT1567T1596T1190T1059.003
Investigate a WAF bypass and UNION-based SQL injection attack against Cloth45.shop by correlating Traefik access logs with ModSecurity audit logs to identify the attacker, reconstruct the successful payload, and determine the exfiltrated table and column.
Crypto BTLO Medium
Crypto
Incident ResponseWiresharkPowerShell AnalysisVolatilityGrepT1059.004 T1059.001T1053.005T1547.001T1562.004T1496T1036.005T1105
Analyse a malicious PowerShell dropper, extract XMRig from a PCAP, and confirm active cryptomining execution via Volatility memory forensics across a multi-server compromise.
HUNT3R BTLO Medium
HUNT3R
Incident ResponseLinux CLISublime Text 2OSINTGnumericCyberChefT1584.006T1595.003T1190T1083
Analyse an IIS web server log dump to identify anomalous traffic, attribute the source IP via OSINT, and characterise a directory traversal/enumeration attack that successfully exfiltrated a configuration archive in under 20 seconds.
First Week BTLO Hard
First Week
Endpoint ForensicsJohnYARACyberChefDiEPEStudioText EditorOSINTdnSpyT1486T1547.001T1036.005T1562.001T1490T1027T1083T1057
Crack a password-protected ransomware builder, hunt a hidden malware sample using a custom YARA rule, decompile a .NET ransomware binary to extract encryption logic and persistence mechanisms, and investigate attacker-planted Defender-disabling persistence on a compromised endpoint.
Latent BTLO Medium
Latent
Endpoint ForensicsWiresharkVolatility3PeStudioStringsT1406.002T1059T1190T1505.003T1046T1021.002T1059.001T1547.001T1027.002T1071.001
A financial services company experiences strange delays in its system, seek it out.
DomainNance BTLO Medium
DomainNance
Incident ResponseWiresharkSplunkT1190T1059.007T1046T1078T1059.001T1105T1550.003T1558.001
A recently formed company working on mid scale workforce claimed to have a secure environment. Taking this as a challenge, a 13 year old kid tried to get into their environment and got succeded.
Azure Hunt CyberDefenders Easy
Azure Hunt
Cloud ForensicsELKKibanaPersistencePrivilege EscalationCollectionT1078.004T1530T1537T1136.003T1098.003
Investigate Azure audit and sign-in logs via Kibana to trace a multi-stage cloud compromise — from initial credential access through blob storage enumeration, lateral movement to a privileged account, VM start, database exfiltration, and persistence via a backdoor account with Owner-level RBAC.
You're Hired! BTLO Hard
You're Hired!
Incident ResponseILSPYCyberChefPEStudioEvent ViewerLog Parser 2.2T1041T1566.001T1204.002T1059.001T1055T1071.001T1082T1069.002T1482
While performing proactive hunting at one of our corporate customers, the threat hunting team escalated some cyclic, beaconing-like, network activity originating from one of their endpoints.
Fingerprint BTLO Easy
Fingerprint
Incident ResponseWiresharkT1046T1608.001T1059T1041T1190T1059.004T1071.001T1105T1505.003
Analyze the network traffic to identify the C2 communication and fingerprint it using ja3.
Crack BTLO Easy
Crack
Incident ResponseJSON CrackT1078.003T1133
Use JSON Crack to investigate failed login attempts to a website.
Insider Brett BTLO Easy
Insider Brett
Incident ResponseWiresharkT1110.001T1021.002T1059T1486
We have identified that one of our IT contractors was the likely culprit of a recent incident.
steam BTLO Medium
steam
Endpoint ForensicsFTK ImagerOSINTT1564.002
Gday Defenders, looks like one of our new content developers is having some trouble. He suspects one of his dogs is playing games on his computer.
toolate BTLO Medium
toolate
Incident ResponseWiresharkT1571T1055T1548.002T1027.010T1059.001T1113T1115T1036.005T1027
The company was compromised by an adversary. The server was taken offline as soon as the suspicious activities were identified. As a defender, you are required to perform analysis on the post-compromise actions taken on the server.
Backstage BTLO Medium
Backstage
Incident ResponseWiresharkExecutionCredential AccessT1102T1090.001T1078
We were notified of some unusual activity in our network from one of our newly set up servers. Not taking any chances, we immediately took the system down and decided to investigate. You are provided with access to the system and the network packet capture file. Find out what is going on!
Breach BTLO Easy
Breach
Incident ResponseWiresharkT1190T1136.001T1204.002
Your mission is to use Wireshark to analyze the provided network capture files, detect signs of the Openfire vulnerability being exploited, and gather enough evidence to understand the nature of the breach.
Fungames BTLO Easy
Fungames
Incident ResponseWiresharkCyberChefVirusTotalCredential AccessCollectionTA0031TA0010T1190T1078T1059.004T1068T1071.004
Full attack chain analysis of a PCAP from FunGames, an e-commerce platform. The attacker used SQLmap to extract credentials via SQLi, SSHed in with stolen creds, escalated to root via CVE-2024-1086 (Linux kernel netfilter exploit), then exfiltrated a customer's credit card data encoded as hex over a single malformed DNS query.
Trend BTLO Easy
Trend
Incident ResponseWiresharkPersistence1078.001T1059T1105T1059.003
A threat actor already inside the network exploited a TRENDnet TEW-652BRU router using CVE-2019-11399, a command injection vulnerability in the router's web interface.
Gothic Panda 1 BTLO Medium
Gothic Panda 1
Threat IntelligenceMITRE ATT&CK NavigatorOSINTGoogle Dorks
CHANGE ME
Deep Phish BTLO Medium
Deep Phish
Incident ResponseThunderbirdText EditorChrome Developer ToolsWiresharkT1566.002
Dig into a phishing email and website to uncover more secrets...
Multi Stages BTLO Medium
Multi Stages
Incident ResponseWireshark VolatilityT1587.001 T1059 T1086
A Cobalt Strike intrusion investigated across network and memory artifacts — identifying the beacon, staged PowerShell delivery, and a four-stage process injection chain using Wireshark and Volatility3.
Spilled Bucket BTLO Easy
Spilled Bucket
Cloud ForensicsSplunkT1651T1580T1098.003
The attackers were successful in attacking and gaining access to their cloud infrastructure. Can you help them out?
Indicators BTLO Easy
Indicators
Endpoint ForensicsPowerShellText EditorExiftoolMalwareBazaarVirusTotalCommand and ControlExecutionT1105
Static malware analysis of a Mirai botnet sample — extracting indicators via Exiftool, Zone Identifiers, hash enrichment, and manual binary inspection
Blocker BTLO Easy
Blocker
Detection EngineeringSysmonEvent ViewerURLHausDefense EvasionExecution
Sysmon 14 FileBlockExecutable analysis — identifying blocked executable events, threat hunting via hash enrichment, and writing preventative Sysmon configuration rules.
Print BTLO Easy
Print
Incident ResponseWiresharkEvent ViewerLateral MovementExecutionCommand and ControlT1210T1059
PrintNightmare exploit analysis — tracing DLL injection via SMB, Windows Print Spooler abuse, reverse shell callback identification, and WerFault parent process forensics.
Deep Blue BTLO Easy
Deep Blue
Incident ResponseDeepBlueCLI PowerShellEvent ViewerT1133T1078.003T1136.001T1543.003T1059.003T1021.001
A Windows workstation was recently compromised, and evidence suggests it was an attack against internet-facing RDP, then Meterpreter was deployed to conduct 'Actions on Objectives'. Can you verify these findings?
Winter Stew BTLO Easy
Winter Stew
Incident ResponseWiresharkReconnaissanceInitial AccessCredential AccessT1595T1595.001T1190T1552.001T1133
Analyze a network capture from a chemical plant DMZ monitoring workstation to identify reconnaissance activity, discover a dual-homed host, confirm nmap and ARP scanning, and extract SCADA system credentials transmitted in cleartext over HTTP.
Revenge Hotels APT CyberDefenders Easy
Revenge Hotels APT
Endpoint ForensicsCyberChefDB Browser for SQLitednSpyWindows Event ViewerInitial AccessPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationT1566.001T1204.002T1059.005T1059.001T1027T1562.001T1547.001T1543T1071.001T1005T1560.001T1041
Reconstruct a multi-stage RevengeHotels APT intrusion by correlating Chrome browser history, Sysmon event logs, registry artifacts, and .NET malware analysis to trace the full attack chain from phishing JS dropper through Quasar RAT persistence and data exfiltration.
IcedID CyberDefenders Easy
IcedID
Threat IntelVirusTotalAny.runtria.geWHOISInitial AccessExecutionPersistenceDefense EvasionCommand and ControlExfiltrationT1566.001T1204.002T1105T1027.002T1071.001T1573.002T1048.002T1547.001T1185T1189
Pure threat intelligence investigation into an IcedID malware sample — analyzing a malicious Excel macro dropper via hash lookup across VirusTotal, Any.run, and tria.ge to map C2 infrastructure, identify the threat actor GOLD CABIN, and document the staged payload delivery chain.
Redline CyberDefenders Easy
Redline
Endpoint ForensicsVolatilitystringsPrivilege EscalationDefense EvasionCommand and ControlExfiltrationT1055T1036.005T1071.001T1041T1555.003T1572T1105
Analyze a Windows memory dump using Volatility 3 to identify Redline stealer malware, trace attacker C2 infrastructure, and determine how the attacker bypassed the Network Intrusion Detection System via VPN tunneling.
Source Leak Investigation HackSmarter Easy
Source Leak Investigation
Incident ResponseDFIRDigital ForensicsT1005T1041T1078
First IR investigation: source code breach at indie game studio. Evidence collection, timeline analysis, root cause identification, and report writing.
Night Shift CTF TryHackMe Medium
Night Shift CTF
SOC SimulationAlert TriageLog CorrelationIRT1059.001T1566.001T1078T1021.002
Week-long SOC analyst simulation — 9 realistic enterprise scenarios covering alert triage, severity assessment, multi-source log correlation, and incident response.
Advent of Cyber 2025 (SOC-mas) TryHackMe Easy
Advent of Cyber 2025 (SOC-mas)
SOCSplunkDFIRPhishingNetwork ForensicsT1566.001T1059.001T1005T1071.001T1204.002
24 daily blue team challenges — phishing analysis, Splunk detections, alert triage, host forensics, network traffic analysis, and malware basics. Certified completion.
SOC Analyst Path LetsDefend Medium
SOC Analyst Path
Alert TriageSIEMMalwarePhishingNetworkT1566.001T1566.002T1071.001T1110.003T1021.002T1041
34 real-world SIEM alert investigations — phishing, malware beaconing, brute force, lateral movement, data exfiltration. Structured triage methodology documented across all cases.
REvil - GOLD SOUTHFIELD CyberDefenders Easy
REvil - GOLD SOUTHFIELD
Threat HuntingSplunkOSINTCredential AccessCollectionT1486T1490T1059.003T1572T1003.001T1005
Analyze Sysmon logs in Elastic SIEM to investigate REvil ransomware attack behaviors, decode recovery sabotage commands, and identify IOCs including the C2 onion domain.
MBuchus CyberDefenders Medium
MBuchus
Threat IntelOSINTVirusTotalcrt.shResource DevelopmentCommand and ControlT1189T1583.001T1608.001T1071.001
Utilize OSINT, VirusTotal, and crt.sh to analyze a multi-stage malvertising campaign, identifying initial access, malware payloads, and attacker infrastructure.
XXE Infiltration CyberDefenders Easy
XXE Infiltration
Network ForensicsWireshark BrimReconnaissanceInitial AccessPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryCollectionExfiltrationT1190T1505.003T1552.001T1595.002T1005T1041
Analyze PCAP data using Wireshark to identify XXE vulnerabilities, extract compromised credentials, and detect web shell uploads for persistence.
Tomcat Takeover CyberDefenders Easy
Tomcat Takeover
Network ForensicsWiresharkReconnaissanceExecutionPersistencePrivilege EscalationCredential AccessDiscoveryCommand and ControlT1190T1505.003T1059.004T1595.002T1083T1078.003
Analyze network traffic using Wireshark's custom columns, filters, and statistics to identify suspicious web server administration access and potential compromise.
RediShell Kinsing CyberDefenders Easy
RediShell Kinsing
Network ForensicsWiresharkInitial AccessExecutionPrivilege EscalationCredential AccessT1190T1611T1059.004T1068T1552.001
The packet capture was killed mid-attack. Race against incomplete evidence to reconstruct how attackers breached Jenkins, pivoted through containers, and escaped to the host
XWorm CyberDefenders Easy
XWorm
Malware AnalysisPEStudiodnSpyExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryCollectionT1059.003T1547.001T1027.002T1055.001T1082T1555.003T1005
Analyze malware behavior to identify persistence methods, evasion techniques, and C2 infrastructure by extracting artifacts and configuration data from static and dynamic analysis.
AWSRaid CyberDefenders Easy
AWSRaid
Cloud ForensicsSplunkPersistencePrivilege EscalationCredential AccessT1098.001T1136T1530T1552.001
Investigate AWS CloudTrail logs using Splunk to identify unauthorized access, analyze configuration changes, and detect persistence mechanisms.
SigmaPredator CyberDefenders Easy
SigmaPredator
Detection EngineeringVsCodeSigmaChainsawDefense EvasionT1070.001T1059.001T1059.003T1047
Design and validate Sigma rules to detect event log clearing techniques across CLI, WMI, and PowerShell execution artifacts.
ContainerBreak - Rootkit Trail CyberDefenders Easy
ContainerBreak - Rootkit Trail
Endpoint ForensicsLinux Command Line ToolsExecutionPersistencePrivilege EscalationDefense EvasionCommand and ControlT1611T1014T1059.004T1564.001T1068T1071.001
Investigated a post-container-escape Linux compromise involving rootkit installation, hidden processes, and persistence mechanisms identified through live forensic collection.
Maranhao CyberDefenders Easy
Maranhao
Endpoint ForensicsFTK ImagerInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessCollectionT1204.002T1547.001T1555.003T1036.005T1068T1005
Investigate a trojanized game installer by analyzing browser history, logs, registry hives, and filesystem artifacts to map the full attack chain and extract IOCs.
Lockdown CyberDefenders Easy
Lockdown
Network ForensicsCyberChefWiresharkVirusTotalVolatilityExecutionPersistencePrivilege EscalationDefense EvasionDiscoveryLateral MovementCommand and ControlT1190T1059.001T1547.001T1055.012T1068T1082T1021.002T1071.001
Reconstruct a multi-stage intrusion by analyzing network traffic, memory, and malware artifacts using Wireshark, Volatility, and VirusTotal, mapping findings to MITRE ATT&CK.
XLMRat CyberDefenders Easy
XLMRat
Network ForensicsCyberChefWiresharkVirusTotalPython3PowerShellExecutionDefense EvasionT1059.001T1140T1027.010T1055.002T1566.001
Analyze network traffic to identify malware delivery, deobfuscate scripts, and map attacker techniques using MITRE ATT&CK, focusing on stealthy execution and reflective code loading.
Openfire CyberDefenders Easy
Openfire
Network ForensicsWiresharkInitial AccessExecutionPersistenceDiscoveryCommand and ControlT1190T1505.003T1059.004T1046T1071.001
Reconstruct an Openfire server attack timeline by analyzing PCAP files with Wireshark to identify login attempts, plugin uploads, command execution, and the exploited CVE-2023-32315 vulnerability.
RetailBreach CyberDefenders Easy
RetailBreach
Network ForensicsWiresharkReconnaissanceInitial AccessExecutionDefense EvasionCredential AccessDiscoveryLateral MovementT1190T1059.007T1539T1595.002T1021.002T1083
Investigate network traffic with Wireshark to identify attacker TTPs, extract XSS payloads and session tokens, and determine exploited web application vulnerabilities.
jetbrains CyberDefenders Easy
jetbrains
Network ForensicsWiresharkNetworkMinerBrimInitial AccessExecutionCommand and ControlT1190T1505.003T1059.004T1071.001
Analyze network traffic using Wireshark to identify web server exploitation, extract attacker IOCs and persistence mechanisms, and map attack techniques to MITRE ATT&CK.
PacketDetective CyberDefenders Easy
PacketDetective
Network ForensicsWiresharkExecutionDefense EvasionCommand and ControlT1078T1059.003T1071.001T1021.002
Analyze network traffic in PCAP files using Wireshark to extract IOCs and reconstruct attacker tactics like authentication and remote execution.
GrabThePhisher CyberDefenders Easy
GrabThePhisher
Threat IntelText EditorInitial AccessExfiltrationT1566.003T1567T1056.002T1189
Analyze a cryptocurrency phishing kit to identify exfiltration methods, extract critical IOCs, and gather threat actor intelligence using local logs and Telegram APIs.
Ramnit CyberDefenders Easy
Ramnit
Endpoint ForensicsVolatility 3VirusTotalExecutionDefense EvasionCommand and ControlT1055.012T1036.005T1071.001T1140
Analyze a memory dump using Volatility to identify a malicious process, extract network IOCs, file hash, and compilation timestamp, correlating with external threat intelligence.
NerisBot CyberDefenders Easy
NerisBot
Threat HuntingSplunkCommand and ControlT1071.001T1071.004T1568.002
Reconstruct the attack timeline by correlating Suricata and Zeek logs in Splunk to identify malicious IPs, C2 domains, targeted hosts, and file hashes.
Insider CyberDefenders Easy
Insider
Endpoint ForensicsFTK ImagerExecutionCredential AccessT1059.004T1552.001T1083T1005
Analyze Linux disk image artifacts, including logs and Bash history, using FTK Imager to investigate insider threat activities and reconstruct user actions.
Volatility Traces CyberDefenders Easy
Volatility Traces
Endpoint ForensicsVolatility 3ExecutionPersistenceT1055.012T1547.001T1059.003T1027
Analyze a memory dump using Volatility to identify malicious processes, persistence mechanisms, defense evasion techniques, and map them to MITRE ATT&CK.
DanaBot CyberDefenders Easy
DanaBot
Network ForensicsWiresharkVirusTotalANY.RUNNetwork MinerExecutionCommand and ControlT1059.007T1140T1071.001T1105T1566.002
Analyze network traffic using Wireshark to identify DanaBot initial access, deobfuscate malicious JavaScript, and extract IOCs like IPs, file hashes, and execution processes.
3cx Supply Chain CyberDefenders Easy
3cx Supply Chain
Threat IntelVirusTotalPersistencePrivilege EscalationDefense EvasionDiscoveryT1195T1574.002T1518.001T1082T1036.005
Reconstruct the 3CX supply chain attack by analyzing compromised MSI and DLL artifacts to identify TTPs and attribute the incident to a threat actor.
Red Stealer CyberDefenders Easy
Red Stealer
Threat IntelWhoisVirusTotalMalwareBazaarThreatFoxANY.RUNExecutionPersistencePrivilege EscalationDefense EvasionDiscoveryCollectionImpactT1059.003T1547.001T1548.002T1027.002T1082T1005T1486
Analyze a suspicious executable using VirusTotal and MalwareBazaar to extract IOCs, identify C2 infrastructure, MITRE ATT&CK techniques, and privilege escalation mechanisms.
PSEXEC Hunt CyberDefenders Easy
PSEXEC Hunt
Network ForensicsWiresharkExecutionDefense EvasionDiscoveryLateral MovementT1021.002T1569.002T1018T1078.002T1036.005
Analyze SMB traffic in a PCAP file using Wireshark to identify PsExec lateral movement, compromised systems, user credentials, and administrative shares.
The Crime CyberDefenders Easy
The Crime
Endpoint ForensicsALEAPPDB Browser for SQLiteT1005T1217
Utilize ALEAPP to analyze Android device artifacts, reconstructing a victim's financial details, movements, and communication patterns.
Lespion CyberDefenders Easy
Lespion
Threat IntelWiresharkGoogle MapsGoogle Image searchSherlockT1593T1552.001T1496T1589
Investigated an insider breach using GitHub analysis and OSINT pivoting to uncover exposed credentials, crypto-mining activity, and geolocation evidence.
Amadey - APT-C-36 CyberDefenders Easy
Amadey - APT-C-36
Endpoint ForensicsMemory AnalysisVolatility 3ExecutionPersistencePrivilege EscalationDefense EvasionCommand and ControlExfiltrationT1055.001T1547.001T1071.001T1041T1068T1140
Reconstruct Amadey Trojan behavior by analyzing memory dumps with Volatility3 to identify malicious processes, C2 communications, payload delivery, and persistence mechanisms.
Yellow Rat CyberDefenders Easy
Yellow Rat
Threat IntelVirusTotalRed CanaryExecutionPersistenceDefense EvasionCommand and ControlExfiltrationT1547.009T1071.001T1574.002T1041T1027
Analyzed Yellow Cockatoo RAT DLL using VirusTotal and ANY.RUN, identifying C2 infrastructure, persistence via .lnk startup files, and solarmarker.dat drop.
PoisonedCredentials CyberDefenders Easy
PoisonedCredentials
Network ForensicsPCAP AnalysisWiresharkT1557T1187T1550.002T1021.002T1040
Analyzed PCAP data to detect LLMNR poisoning, identify the rogue responder, extract NTLM credentials, and confirm unauthorized SMB access to the targeted host.
Oski CyberDefenders Easy
Oski
Threat IntelligenceMalware AnalysisSandbox AnalysisCredential AccessPCAP AnalysisT1555.003T1573.001T1071.001T1027.002T1539
Analyzed a Stealc malware sample using VirusTotal and Any.Run to extract configuration details, identify command and control infrastructure, recover RC4 encryption keys, and map observed behaviour to MITRE ATT&CK techniques.
WebStrike CyberDefenders Easy
WebStrike
Network ForensicsPCAP AnalysisWiresharkWeb ShellT1190T1505.003T1059.004T1552.001T1041
Suspicious file identified on a company web server. PCAP analysis revealed a double-extension bypass (image.jpg.php) used to upload a PHP webshell, reverse shell attempt via netcat on port 8080, and /etc/passwd exfiltration attempt. Attacker attributed to Tianjin, China via IP2Location.
Exxtensity BTLO Easy
Exxtensity
Endpoint ForensicsWiresharkExtAnalysisPersistenceCollectionT1176T1056.001T1112T1040
Browser extension forensics identifying malicious extensions via manifest analysis, registry policy manipulation, keylogger traffic capture, and ExtAnalysis domain enumeration.
Vortex BTLO Easy
Vortex
Incident ResponseWiresharkT1566T1204T1566.001T1204.002T1555.003T1071.001T1048
PCAP analysis of a credential-stealing malware infection — tracing C2 traffic, decoding exfiltrated credentials, and identifying SMTP data theft from Brianas compromised workstation.
Splunk It BTLO Easy
Splunk It
Incident ResponseSplunk BTL1Credential AccessCollectionT1204.001T1003.003T1059.003T1005
One of the employees clicked on a malicious link and got the endpoint compromised. After executing malicious files and getting a foothold, the attacker compromised the AD by dumping sensitive information.
Spider BTLO Easy
Spider
Threat IntelligenceOSINTT1087T1087.002T1586T1078T1566.002
Threat intelligence investigation into Scattered Spider UNC3944 — a financially motivated group leveraging social engineering, SIM swapping, and RaaS affiliations to breach high-profile organisations across multiple sectors.
Attacks BTLO Easy
Attacks
Incident ResponseEvent ViewerCredential AccessCollectionT1003.001T1059.003T1005
Test your knowledge of MITRE ATT&CK while investigating the logs from a compromised Windows host
Anakus BTLO Easy
Anakus
Reverse EngineeringCyberChefDetect it EasySysinternalsSuiteTimeline ExplorerWiresharkBTL1ExecutionPersistenceDefense EvasionCommand and ControlT1059.003T1547.001T1027.002T1140T1071.001
It looks like the assessment will take place virtually, and I will be given a VM, with plenty of tools to analyze Threat logs and Malware
Foxy BTLO Easy
Foxy
Threat IntelligenceLinux CLIGnumericText EditorOSINTT1204.002T1566T1566.001T1586T1078
As an Intelligence Analyst you are tasked with assisting the SOC Analysts with their investigations, providing additional context
Middle Mayhem BTLO Easy
Middle Mayhem
Incident ResponseNextJSSplunkInitial AccessDefense EvasionExecutionCredential AccessLateral MovementCollectionT1190T1059.007T1550T1021.002T1005
Your SOC team has been provided with SIEM logs from the incident. Analyze the attack pattern to determine how attackers bypassed authentication, gained remote code execution, and moved laterally through the network.
Bec-Ky BTLO Easy
Bec-Ky
Incident ResponseBECEmail ForensicsT1078T1114.002T1566.002T1565.001
Business Email Compromise investigation — suspected cyber incident involving unauthorised bank transfers from company pension fund. Trace the attacker's methodology.
Piggy BTLO Easy
Piggy
PCAP AnalysisWiresharkOSINTMITRE ATT&CKT1048T1590T1071.001
Multi-PCAP investigation — SSH data exfiltration identification, malware infrastructure discovery, ASN attribution, MITRE ATT&CK mapping across four capture files.
no labs match that filter.
// active labs
active labs

Writeups are complete but locked until these labs officially retire. Reach out if you need the password.

Gifted Crooks BTLO Easy
Gifted Crooks
Threat IntelOSINTMISPICANNCredential AccessCollectionT1583.001T1552.001T1005
A lab introducing players to MISP as a Threat Intelligence Platform (TIP), its practical use cases, and the fields commonly used by CTI analysts for enrichment, correlation, and reporting.
RaaS Unfold RansomHub CyberDefenders Medium
RaaS Unfold RansomHub
Threat IntelVirusTotalGoogle SearchImpactT1486T1490T1489
A ransomware empire built on the ashes of its predecessors — trace its origins, expose its operators, and unfold its playbook.
Rogue Azure CyberDefenders Easy
Rogue Azure
Cloud ForensicsMicrosoft SentinelAzure MonitorKQL Query EditorAzure AD Sign-in LogsInitial AccessPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationT1110.003T1078T1550.001T1136T1098.001T1484.001T1530T1567
Investigate a multi-stage Azure tenant compromise by querying sign-in logs, audit logs, and storage blob logs using KQL in Microsoft Sentinel to identify a password spray attack, post-exploitation persistence via malicious app registrations, privilege escalation to Global Administrator, and sensitive file exfiltration from Azure Blob Storage.
DynamicEscalate CyberDefenders Easy
DynamicEscalate
Cloud ForensicsMicrosoft SentinelAzure MonitorAzure AD Sign-in LogsAzure AD WorkbooksInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionLateral MovementT1566.002T1078.004T1136.003T1098.003T1484.002
Investigate a suspected Azure AD privilege escalation via device-code phishing, guest account creation, and dynamic group manipulation using Microsoft Sentinel and KQL.
AbuSESer - Trufflenet CyberDefenders Easy
AbuSESer - Trufflenet
Cloud ForensicsCloudWatchVirusTotalExecutionPrivilege EscalationDefense EvasionCredential AccessDiscoveryCollectionImpactT1526T1530T1078.004T1550.001T1555.006T1059.009T1657
Investigate a Business Email Compromise attack against an AWS environment — TruffleHog credential discovery in a public S3 bucket leads to IAM role chaining, Secrets Manager exfiltration, EC2 IMDS abuse, and Lambda invocation to send fraudulent invoices.
Macro-ni BTLO Easy
Macro-ni
Incident ResponseCyberchefT1566.001T1059.001T1027.010T1027T1140T1071.001
Decode a multi-layer obfuscated VBA macro embedded in a phishing document to identify shellcode and extract the C2 IP.
Testa BTLO Easy
Testa
Incident ResponseOTModbusT1046T1565.001T1078T1499.004
Analyse a Modbus/TCP packet capture from an oil terminal OT network to identify an unauthorised host, trace attacker write operations against holding registers and coils, and determine the precise moment operations were disrupted.
Strange Martketplace BTLO Easy
Strange Martketplace
Incident ResponseChainsawGitYaraT1195.001T1555T1041T1560.001T1485T1059.001T1105T1136
Investigate a developer workstation compromised via a trojanized VS Code extension, tracing credential theft, staged exfiltration, and source code tampering through Chainsaw event log analysis and live endpoint triage.
Eros BTLO Easy
Eros
Incident ResponseAICLIWebAppT1190T1059.004T1136.001T1078
Investigate the compromise of a boutique dating platform via prompt injection against an unsanitised AI assistant endpoint, tracing credential leakage, RCE, and OS-level persistence through application logs, source code review, and SQLite database analysis.
MailFall BTLO Hard
MailFall
Incident ResponseZimmermanStringsSqlite3Reg ExplorerEvt ExplorerCyberChefDNSpyT1190T1505.003T1059.001T1059.005T1068T1543.003T1219T1078T1136.001T1566.002T1041
Triage forensic image of a compromised SmarterMail server — trace lateral movement from an internal workstation through CVE-2025-52691 web shell deployment, GodPotato privilege escalation, GoToHTTP RAT persistence, and mail panel takeover culminating in a phishing campaign against internal users.
Bada Breach BTLO Easy
Bada Breach
Incident ResponseZimmermanCyberChefBTL2ELK
During routine web research as part of his role in SEO and competitor analysis, Junior Soprano discovered a publicly acc...
TxDrop BTLO Hard
TxDrop
Incident ResponseNode.jsvolatilityWiresharkMemProcFSCyberChefT1195.001T1059.007T1059.006T1027.013T1140T1102.001T1071.001T1095T1041T1567.002T1115T1555.003T1555.005T1497.001T1518.001T1554T1057T1571
A backend developer at EZ-CERT clones a GitHub repo for an evaluation. Within seconds a six-stage DPRK chain executes in Node, exfiltrates the environment, drops a Python stealer, and pulls its final RAT body from a BSC transaction resolved via Tron with Aptos as a fallback. Full reverse of the BeaverTail/InvisibleFerret/JADESNOW chain end to end.
ClickFix - VodkaStealer CyberDefenders Medium
ClickFix - VodkaStealer
Threat HuntingRegistry ExplorerSplunkFTK ImagerExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationImpactT1204.002T1059.001T1574.009T1003.001T1550.002T1021.002T1053.005T1555.003T1041T1070.004T1036.005T1071.001
Investigate a ClickFix-initiated intrusion across four corporate endpoints, tracing the full attack chain from initial access through privilege escalation, lateral movement, and VodkaStealer exfiltration.
CursorJack CyberDefenders Easy
CursorJack
Endpoint ForensicsDB Browser for SQLiteNotepad++Google SearchTrailInspectorInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryCollectionImpactT1204.001T1059.003T1105T1552.001T1074.001T1078.004T1496T1036.005
Trace an MCP supply chain intrusion from a typosquatted developer tool site through credential theft, multi-region AWS cryptomining deployment, and on-chain follow-the-money analysis linking the attacker wallet to a $285M DeFi exploit.
Rhadamanthys CyberDefenders Medium
Rhadamanthys
Endpoint ForensicsEvent Log ExplorerCyberChefTimeline ExplorerEric Zimmerman ToolsInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryCommand and ControlT1566.001T1204.002T1218.011T1059.001T1036.005T1548.002T1053.005T1003.001T1046T1071.001T1105T1560.001
Disk image forensics — reconstruct a full Rhadamanthys Stealer intrusion from a malicious Word document through SharpHound enumeration, privilege escalation, LSASS dumping, and stealer DLL deployment using MFT records, Prefetch artefacts, LNK files, and Sysmon event logs.
ConsentStorm CyberDefenders Medium
ConsentStorm
Cloud ForensicsEntra ID Sign-in LogsEntra ID Audit LogsAzure Activity LogsOffice 365 Audit LogsAzure Diagnostics LogsMicrosoft SentinelKQL Query EditorInitial AccessPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationT1566.002T1528T1078.004T1059.001T1136.003T1098.001T1556T1484.002T1530T1555
Investigate a Storm-0558 cloud intrusion against NexGen Energy tracing an illicit OAuth consent grant through service account pivoting, ABAC bypass via tag manipulation, and Key Vault credential theft to final data exfiltration.
Shadow Token Symphony - APT29 CyberDefenders Medium
Shadow Token Symphony - APT29
Cloud ForensicsMicrosoft SentinelInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementT1078.004T1110.003T1543.003T1528T1550.001T1136.003T1098.003T1530T1087.004T1526
Analyze Microsoft Sentinel logs across Windows events and Azure AD to reconstruct a multi-stage APT29 intrusion spanning on-prem lateral movement, cloud credential spray, token abuse, Graph API recon, and Key Vault exfiltration.
Code Blue - APT29 CyberDefenders Hard
Code Blue - APT29
Cloud ForensicsEntra ID Sign-in LogsEntra ID Audit LogsAzure Activity LogsOffice 365 Audit LogsAzure Diagnostics LogsMicrosoft SentinelKQL Query EditorInitial AccessPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollection
Reconstruct a multi-stage APT29 intrusion by analyzing Azure and M365 logs to trace device code phishing, OAuth token ab...
Recruiter - Hanoi Op CyberDefenders Hard
Recruiter - Hanoi Op
Endpoint ForensicsDB Browser for SQLiteRegistry ExplorerMFTECmdTimeline ExplorerEvtxECmdEric Zimmerman ToolsPECmdExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessT1204.002T1059.001T1105T1036.005T1003.002T1547.003T1053.005T1020T1025
A malicious CV submitted via a job portal triggers a multi-stage infection chain: LNK execution, FTP-based stager, credential theft, hash dumping, lateral movement, time provider persistence, and USB-triggered exfiltration via rclone to Backblaze B2.
Poisoned Aid BTLO Medium
Poisoned Aid
Incident ResponseRegistry ExplorerEric Zimmerman toolsWiresharkEvent Log ExplorerDB BrowserSqlite3T1566.001T1204.002T1053.005T1059.005T1027.013T1036.005T1041T1113T1115T1056.001T1005T1071.001
Analyse a KAPE triage image and PCAP from a compromised EZ-CERT workstation — trace a spearphishing LNK through PyArmor-obfuscated infostealer execution, scheduled task persistence, and multi-vector data exfiltration including screenshots, keylogging, and credential harvesting.
Operation Cronos - Lockbit CyberDefenders Medium
Operation Cronos - Lockbit
Threat IntelGoogle SearchThreat Intelligence ReportsOSINTImpactT1190T1078T1133T1189T1003T1219T1562.001T1070.001T1486T1490T1489T1041T1537T1027
Threat intelligence profile covering LockBit's full lifecycle — from ABCD ransomware origins through RaaS dominance, Operation Cronos takedown, LockBitSupp unmasking, and LockBit 5.0 resurgence. Completed as part of the CyberDefenders Operation Cronos lab.
Tax Day - BYOVD CyberDefenders Easy
Tax Day - BYOVD
Endpoint ForensicsDB Browser for SQLiteTimeline ExplorerWindows Event ViewerPECmdIDA ProResource DevelopmentPersistencePrivilege EscalationDefense EvasionCommand and ControlT1189T1204.002T1219T1543.003T1012T1059.001T1003.001T1562.001T1068T1105T1036.005
Reconstruct a tax-themed malvertising intrusion from a Velociraptor triage collection — Atera RMM delivery through to a BYOVD Windows Defender kill and LSASS dump — pivoting across event logs, browser history, prefetch and IDA Pro.
RansomedTrust - Lynx CyberDefenders Medium
RansomedTrust - Lynx
Threat HuntingCyberChefSplunkIDACFF ExplorerPEStudioInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlImpact1557.001T1482T1087.002T1566.001T1204.002T1059.001T1574.010T1003.001T1558.004T1558.003T1055.012T1136.002T1219T1021.002T1110.003T1571T1048T1486T1490
Splunk and PE static-analysis investigation tracing a Lynx ransomware affiliate from an LLMNR-poisoned Linux foothold through cross-forest credential theft to trust-abusing mass deployment.
BYOVD - Hive0163 CyberDefenders Medium
BYOVD - Hive0163
Malware AnalysisOpenSSLEvent ViewerCyberChefVirusTotalRegistry ExplorerIDA ProPythonDetect It EasyPE-bearpe-sieveExecutionPersistencePrivilege EscalationDefense EvasionDiscoveryCollectionCommand and ControlExfiltrationImpactT1204.002T1105T1071.001T1547.001T1552.001T1068T1562.001T1548.002T1027.010T1567.002T1027.002T1053.005T1622T1070.004T1070.001T1489T1486T1657
Correlate diverse forensic artifacts to reconstruct a multi-stage ransomware attack, synthesizing insights from BYOVD, c...
Forum Breach BTLO Medium
Forum Breach
Incident ResponsemactimeNotepad++stringscyberchefT1190T1505.003T1068T1003.007T1560T1041T1059.004
UAC artifact analysis tracing an unauthenticated Discuz! database export through a race condition authentication bypass, malicious plugin RCE, and reverse shell to a full mysqldump exfiltration.
Gh0stNet Intrusion CyberDefenders Hard
Gh0stNet Intrusion
Threat Huntingpe-sieveWiresharkRegistry ExplorerFLOSS/StringsSplunkCyberChefGhidraCFF ExplorerFTK ImagerPECmdRegistry Explorer/RECmdIDAInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessLateral MovementCollectionCommand and ControlExfiltrationT1091T1204.002T1036.008T1027T1547.001T1056.001T1071.001T1552.006T1021.001T1546.003T1021.003T1560.001T1074.001T1048.003
Cross-artifact investigation tracing a USB-borne Gh0st/Farfli RAT infection through keylogged RDP credential theft to GPP credential abuse, WMI persistence, DCOM lateral movement, and DNS-tunneled exfiltration inside a corporate domain.
BreakOut-Daedalus CyberDefenders Medium
BreakOut-Daedalus
Threat HuntingWiresharkNetwork MinerSplunkKAPEArsenal Image MounterAutopsyFTK ImagerInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltration
SIEM, disk, and network investigation tracing a forged cPanel/WHM session through container escape and a kernel zero-day to full host root compromise.
Hidden Launch BTLO Medium
Hidden Launch
Incident ResponseMACFSEventsUnifiedLogIteratorT1204.004T1059.004T1059.002T1105T1056.002T1548.006T1543.001T1564.001T1036.005T1555.001T1539T1005T1560.001
A seemingly routine command executed from a malicious website has opened the door to a stealthy macOS intrusion. The att...
CryptLoad CyberDefenders Hard
CryptLoad
Malware AnalysisIDAPythonCFF ExplorerIDA ProPowerShellDetect It Easyx64dbgpe-sieveGhidraInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessCommand and Control"[T1195.002T1574.002T1620T1027.002T1140T1070.006T1546.015T1053.005T1555.003T1539T1071.001T1090.003T1573.001T1497.001T1106]"
Malware analysis of a trojanized CPU-Z distribution tracing a proxy DLL sideload through a colon-hex encoded overlay and reflective PE chain to a Tor-capable backdoor with hVNC and credential theft modules.
Penumbra CyberDefenders Medium
Penumbra
Endpoint ForensicsDB Browser for SQLiteRegistry Explorer/RECmdFTK ImagerAutopsyMFTECmdTimeline ExplorerEvtxECmdText EditorHexEditorInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionDiscoveryCollectionCommand and ControlExfiltrationT1204.004T1219T1059.003T1098T1078.001T1037.001T1562.001T1070.001T1530T1005T1105T1560.001T1041T1070.004
Endpoint triage investigation tracing a ClickFix social-engineering lure through silent AnyDesk deployment and Guest-account persistence to the archived exfiltration of 35 cloud-synced documents.
Renegade BTLO Hard
Renegade
Incident ResponserpatoolDnSpyVSCode
You're the lead malware analyst on a high-priority incident. A user at a major organization downloaded what appeared to ...
Maromalix Nightmare CyberDefenders Medium
Maromalix Nightmare
Threat HuntingELKMFTECmdTimeline ExplorerJLECmdRegRipperRegistry Explorer/RECmdStringsImpacketInitial AccessExecutionPrivilege EscalationStealthCredential AccessDiscoveryLateral MovementCommand and ControlT1189T1204.002T1059.003T1059.001T1083T1057T1518.001T1555.003T1055.001T1572T1102T1021.001T1068T1574.002T1012T1003.002T1543.003T1036.004T1112T1550.002T1005T1560.001
A deal was stolen before it was ever signed. Someone got in, found exactly what they needed, and vanished. Your job is t...
Hollow Chapter BTLO Hard
Hollow Chapter
Incident ResponseEZToolsde4dotDnSpyT1608.006T1204.002T1059.003T1059.001T1202T1027.013T1140T1036.005T1036.008T1564.001T1053.005T1562.001T1548.002T1620T1055.012T1070.004
KAPE triage investigation tracing a poisoned search result through a PDF-embedded LOLBin chain to layered scheduled-task persistence and a reflectively loaded .NET RAT.
Crossed Signals CyberDefenders Medium
Crossed Signals
Endpoint ForensicsRegRipperDB Browser for SQLCipherDB Browser for SQLiteVirusTotalmimikatzMFTECmdTimeline ExplorerJLECmdhayabusaInitial AccessPersistencePrivilege EscalationStealthDiscoveryCollectionCommand and ControlT1566.004T1656T1204.002T1056.002T1078.003T1021.001T1219T1059.001T1105T1543.003T1136.001T1098T1083T1005T1552.001T1555.003
Endpoint forensics investigation tracing a vishing-driven credential theft from an AiTM phishing page through RDP reuse and a failed RMM deployment to targeted legal document collection, with the attacker's own Signal conversation recovered via the DPAPI key chain.
The Nokoyawa Ransomware Intrusion - Public Case #18543 DFIRLABS Easy
The Nokoyawa Ransomware Intrusion - Public Case #18543
Threat HuntingKibanaElastic SecurityInitial AccessExecutionPersistenceDefense EvasionDiscoveryCredential AccessLateral MovementCommand and ControlImpactT1204.002T1059.003T1218.011T1036.005T1055.001T1053.005T1087.002T1003.001T1552.001T1021.001T1047T1071.001T1486
Kibana/Sysmon investigation tracing an HTML-smuggled IcedID loader through process injection and scheduled-task persistence to Cobalt Strike C2 and domain-wide Nokoyawa ransomware deployment.
MiniFast - UNC1549 CyberDefenders Medium
MiniFast - UNC1549
Network ForensicstsharkCyberChefFLOSS/StringsWiresharkResource DevelopmentInitial AccessStealthDiscoveryCollectionCommand and ControlExfiltrationImpactT1608.006T1204.002T1574.002T1036.005T1105T1071.001T1132.001T1033T1082T1016T1049T1057T1087.001T1083T1005T1552.001T1560.001T1041T1486
Network forensics investigation tracing an SEO-poisoned software download from a typosquatted vendor domain through a polling HTTP implant to credential theft and ransomware deployment.
Shattered Dream BTLO Medium
Shattered Dream
Incident ResponseEZToolssysmonCyberChefT1204.002T1036.005T1027.009T1140T1620T1071.001T1584.004
Endpoint triage investigation tracing a Lazarus Operation Dream Job intrusion from a recruiter-delivered archive through a trojanised open-source PDF reader to a reflectively loaded backdoor beaconing at a compromised relay host.
Phantom Installer CyberDefenders Easy
Phantom Installer
Endpoint ForensicsDB Browser for SQLiteFTK ImagerVirusTotalMFTECmdTimeline ExplorerPECmddnSpyResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationStealthDefense ImpairmentImpactT1608.006T1204.002T1036.005T1574.014T1053.005T1027T1071.001T1562.001T1562.002T1070.001T1070.004T1490T1485
Triage image investigation tracing a trojanized software installer from an SEO-poisoned download through AppDomainManager hijacking and scheduled task abuse to a destructive .NET wiper.
Ancientland Breach - LockBit CyberDefenders Hard
Ancientland Breach - LockBit
Endpoint ForensicshayabusaCyberChefVirusTotalWiresharkIDAMFTECmdTimeline ExplorerVolatility 3ImpacketInitial AccessExecutionPersistencePrivilege EscalationCredential AccessCommand and ControlExfiltrationT1133T1110.001T1190T1059.004T1105T1102.001T1037.004T1572T1021.001T1068T1003.001T1071.001T1573.001T1041T1047T1484.001T1053.005T1547.004T1562.002T1486
Multi-host DFIR investigation tracing a ransomware operator from a brute-forced VPN gateway through a firewall RCE and blockchain-resolved C2 to domain-wide encryption.
Graphi BTLO Hard
Graphi
Incident Responsex64IDApssuspendT1543.003T1027T1140T1016T1550.001T1102.002T1071.001T1074.001T1567.002T1562.001
Static and dynamic analysis of a svchost-hosted implant that self-configures via XOR-obfuscated blobs and uses Microsoft Graph as its entire C2 channel.
CodeFreeze 2 CyberDefenders Medium
CodeFreeze 2
Endpoint ForensicsPythonCyberChefDB Browser for SQLiteRegistry Explorer/RECmdMFTECmdTimeline ExplorerInitial AccessExecutionPersistencePrivilege EscalationStealthDiscoveryCollectionCommand and ControlExfiltrationT1566.001T1204.002T1176.002T1059.007T1059.004T1140T1571T1053.003T1564.001T1036.005T1552.001T1217T1074.001T1560.001T1567.002T1070.004T1219.002
Endpoint triage investigation tracing a trojanised VS Code extension from an emailed archive through a WSL-hosted reverse shell and cron persistence to RustDesk credential theft and hands-on-keyboard access.
ActiveMQ - LockBit Ransomware CyberDefenders Medium
ActiveMQ - LockBit Ransomware
Threat HuntingSplunkInitial AccessExecutionPersistencePrivilege EscalationStealthCredential AccessDiscoveryLateral MovementCommand and ControlExfiltrationImpactT1190T1059.001T1105T1543.003T1068T1649T1550.003T1021.004T1567T1486T1036.005
Splunk threat hunt tracing an ActiveMQ CVE-2023-46604 RCE through GodPotato SYSTEM escalation and ADCS PKINIT abuse to SSH lateral movement, Telegram exfiltration, and LockBit ransomware.
// hackthebox sherlocks · dfir investigations
sherlock writeups

HTB Sherlocks — DFIR investigations covering endpoint forensics, threat intelligence, network analysis, and memory forensics.

// active sherlocks
active sherlocks

Writeups complete but locked until these sherlocks officially retire. Reach out if you need the password.

// challenges
challenge log

Shorter CTF-style challenges. Same platforms, less depth.

Follina BTLO Easy
Follina
Threat IntelligenceVirusTotalAny.RunOSINTT1203T1566.001T1204.002T1059.003
On a Friday evening when you were in a mood to celebrate your weekend, your team was alerted with a new RCE vulnerability actively being exploited.
Squid Game BTLO Medium
Squid Game
Threat IntelligenceGoogleSteghideStegsolve.jarPythonCredential AccessCollectionT1027T1552.001T1005
Will you survive the Squid Games?
The Report BTLO Easy
The Report
Threat IntelOSINTCredential AccessCollectionT1003T1005T1566
As part of gathering intel you were assigned a task to study a threat report released in 2022 and suggest some useful outcomes for your SOC.
ATT&CK BTLO Easy
ATT&CK
Threat IntelligenceMitre attack frameworkExecutionCommand and ControlT1059.003T1071.001
See how you can operationalize the MITRE ATT&CK framework to solve these scenario-based problems.
D3FEND CyberDefenders Easy
D3FEND
Threat IntelligenceD3FEND Framework
Navigating the MITRE D3FEND framework to identify defensive techniques, tactics, artifacts and open-source tooling mapped to ATT&CK.
Shiba Insider BTLO Easy
Shiba Insider
Network ForensicsWiresharkT1040T1048
Can you uncover the insider?
Meta BTLO Easy
Meta
Threat Intelligenceexiftoolreverse image searchT1589T1592
OSINT and metadata forensics challenge — extracting EXIF data from suspect images to locate a criminal on the run.
bruteforce BTLO Medium
bruteforce
Network ForensicsgrepexcelT1110.001T1078
Analysis of Windows Security Event logs revealing an RDP brute force attack targeting the local Administrator account from a Vietnamese IP address, generating over 3000 Audit Failure events.
Paranoid BTLO Medium
Paranoid
Incident ResponseaureportT1110.001T1046T1059.004T1068T1005T1070.002
Analysis of Linux auditd logs revealing an SSH brute force attack against a local account, followed by post-exploitation enumeration via LinPEAS, privilege escalation using a compiled CVE-2021-3156 (Baron Samedit) exploit, and exfiltration of /etc/shadow before the attacker cleaned up their tracks.
Network Analysis - Ransomware BTLO Medium
Network Analysis - Ransomware
Incident ResponseWiresharkTCPDumpT1486T1071.001T1041
Analysis of ransomware network traffic to identify a TeslaCrypt infection, recover the malicious executable, and decrypt an encrypted tender document using the Cisco Talos TeslaCrypt decryptor — made possible by TeslaCrypt's authors publicly releasing their master key in 2016.
ILoveYou BTLO Easy
ILoveYou
Endpoint ForensicsText EditorRegshotT1566.001T1059.005T1547.001T1204.002
Static analysis of the infamous ILOVEYOU VBScript worm from 2000 using olevba, examining its email propagation mechanism, file infection routines, registry persistence, IRC spreading, and the embedded Barok password-stealing trojan.
Teh Report II BTLO Medium
Teh Report II
Incident ResponsePDF
Analysis of the MITRE '11 Strategies of a World-Class Cybersecurity Operations Center' to extract key SOC concepts including organisational models, workflow, tooling standards, data retention, and red teaming approaches.
Phising analysis 2 BTLO Easy
Phising analysis 2
Threat IntelligenceText EditorThunderbirdT1566.002
Analysis of a phishing email impersonating Amazon, delivered to saintington73@outlook.com. The email body is base64 encoded HTML, the CTA button points to a typosquatted domain, and the attacker left a personal Facebook profile URL embedded in the footer.
Log Analysis Sysmon BTLO Medium
Log Analysis Sysmon
Endpoint ForensicsText EditorPowerShellLinux CLICommand and ControlT1574.007T1134.001
You are provided with Sysmon logs from a compromised endpoint. Analyse the logs to find out the steps and techniques used by the attacker.
Secrets BTLO Easy
Secrets
Incident Responsehashcatjwt.ioDefense EvasionExecutionT1110.002T1078T1550.001T1606.001
You’re a senior cyber security engineer and during your shift, we have intercepted/noticed a high privilege actions from unknown source that could be identified as malicious.
Veriarty BTLO Medium
Veriarty
Threat IntelligencehashcatveracryptgppT1027T1027.003T1140T1553T1560T1564.001T1573
DI Lestrade has intercepted a transmission from a criminal known as Moriarty
injectionpart4 BTLO Easy
injectionpart4
Malware AnalysisIDAcodebrowserghiraDefense EvasionExecutionT1055.002T1059.001T1105T1027T1140
Reverse engineer the given file and understand the behavior. You can use any disassembler you like to complete this challenge.
secure shell BTLO Hard
secure shell
Incident Responselinux-cliT1110T1078T1021.004
We had a SSH service on a system and noticed unusual change in size of the log file.
Phishing Analysis BTLO Easy
Phishing Analysis
Security OperationsText EditorThunderbirdT1566.001T1598.003T1071.003
Can you investigate the email and attachment to collect useful artifacts?
Malware Analysis Ransomware Script BTLO Easy
Malware Analysis Ransomware Script
Endpoint Forensicslinux-cliT1486T1059.004T1070.002T1105T1491.001T1102
investigate suspicious script file
// home lab infrastructure
lab environments
📡
Splunk Enterprise SIEM
Production-style SIEM for alert detection, log analysis, and threat hunting.
Host:Ubuntu 24.04 · Splunk Enterprise
Agent:Windows 11 · Universal Forwarder
Telemetry:Sysmon event collection & parsing
Use Cases:Detection rules · SPL queries · dashboards
🦠
Malware Analysis Sandbox
Isolated environment for safe detonation, static analysis, and reverse engineering.
Platform:FlareVM · isolated virtual network
Tools:IDA · Ghidra · PE analysis · debuggers
Analysis:Static & dynamic examination
Use Cases:IOC extraction · behaviour analysis
🏠
Home Lab — Full Stack
pfSense + Security Onion + Splunk + Active Directory environment for realistic detection practice.
Network:SPAN mirroring · network segmentation
Detection:Zeek · Suricata · Splunk dashboards
AD Lab:Windows domain · attack simulation
Platform:CachyOS · virtualisation workstation
// investigation documentation
documentation & profiles
🗂️
Alert Triage Log
Every SOC investigation documented — dated, MITRE ATT&CK mapped, and publicly queryable. Updated daily.
  • 119 investigations logged & counting
  • 103 true positives · 16 false positives
  • 95 unique MITRE ATT&CK techniques observed
  • Latest: SOC328 — Akira Ransomware IOC's Detected
view full log →
⌨️
Command Reference
Every command used across real lab investigations — searchable, filterable, and copyable. Built so future me doesn't have to google the same thing twice.
  • 797 commands and growing
  • Volatility · Splunk · Wireshark · Zeek
  • Linked back to source lab for context
  • Auto-extracted from investigation notes
view command reference →
🔗
Public Platform Profiles
Verified investigation work across multiple SOC training platforms — all publicly verifiable.
  • LetsDefend — 119 alert investigations documented
  • TryHackMe — SAL1 certified · SOC Level 1 path
  • GitHub — full writeup repository
  • Real-time metrics & platform rankings
view leaderboard history →
✍️
Writing
Exam reviews, milestone reflections, and methodology notes — things that don't fit neatly elsewhere but are worth writing down.
  • BTL1 exam review — preparation & lessons
  • Day 100: reflections on daily alert triage
  • Not a blog. Just writing.
read →