{"labs":[{"name":"Lockdown","slug":"lockdown","description":"Reconstruct a multi-stage intrusion by analyzing network traffic, memory, and malware artifacts using Wireshark, Volatility, and VirusTotal, mapping findings to MITRE ATT&CK.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2026-02-13T07:47:32.314Z"},{"name":"XWorm","slug":"xworm","description":"Analyze malware behavior to identify persistence methods, evasion techniques, and C2 infrastructure by extracting artifacts and configuration data from static and dynamic analysis.","difficulty":"medium","categories":["Malware Analysis"],"completedAt":"2026-02-13T07:44:15.978Z"},{"name":"HawkEye","slug":"hawkeye","description":"Reconstruct a HawkEye Keylogger data exfiltration incident by analyzing network traffic with Wireshark and CyberChef, identifying IoCs and stolen credentials.","difficulty":"medium","categories":["Network Forensics"],"completedAt":"2025-07-07T01:59:38.099Z"},{"name":"OpenWire","slug":"openwire","description":"Investigate a Java deserialization vulnerability in Apache ActiveMQ that enables remote code execution through insecure class loading.","difficulty":"medium","categories":["Network Forensics"],"completedAt":"2025-07-07T01:25:04.231Z"},{"name":"MalDoc101","slug":"maldoc101","description":"Analyze obfuscated scripts to identify malicious infrastructure, specifically extracting the first FQDN used to download a trojan, enhancing skills in threat hunting and incident response.","difficulty":"medium","categories":["Malware Analysis"],"completedAt":"2025-07-06T04:35:08.916Z"},{"name":"FakeGPT","slug":"fakegpt","description":"Analyze a malicious Chrome extension's code and behavior to identify data theft mechanisms, covert exfiltration via `<img>` tags, and anti-analysis techniques.","difficulty":"easy","categories":["Malware Analysis"],"completedAt":"2025-07-04T05:17:20.503Z"},{"name":"Obfuscated","slug":"obfuscated","description":"Deobfuscate multi-stage VBA and JavaScript malware from a Word document, extracting IOCs and reconstructing execution flow with Oledump, CyberChef, and WSH.","difficulty":"medium","categories":["Malware Analysis"],"completedAt":"2025-06-28T18:28:51.326Z"},{"name":"BRabbit","slug":"brabbit","description":"Reconstruct a Bad Rabbit ransomware attack chain by analyzing phishing, persistence, and MBR modification using dynamic analysis and MITRE ATT&CK.","difficulty":"medium","categories":["Threat Intel"],"completedAt":"2025-06-26T17:07:38.940Z"},{"name":"RotaJakiro","slug":"rotajakiro","description":"Reverse engineer and analyze RotaJakiro Linux malware using Ghidra, strace, and Wireshark to identify persistence, anti-analysis, and C2 mechanisms.","difficulty":"hard","categories":["Malware Analysis"],"completedAt":"2025-06-25T16:18:50.430Z"},{"name":"Silent Breach","slug":"silent-breach","description":"Analyze a forensic image to extract communication artifacts, identify malware behavior, and decrypt encrypted files using FTK Imager, string analysis, and PowerShell scripting.","difficulty":"medium","categories":["Endpoint Forensics"],"completedAt":"2025-06-25T15:13:20.047Z"},{"name":"SolarDisruption","slug":"solardisruption","description":"Investigate PLC network traffic and system logs to identify insider manipulation attempts and determine the cause of the solar panel disruption at AetherCore Technologies.","difficulty":"hard","categories":["Network Forensics"],"completedAt":"2025-06-25T13:40:21.979Z"},{"name":"Tusk Infostealer","slug":"tusk-infostealer","description":"Analyze threat intelligence and malware configuration to identify TTPs, extract IOCs, and track cryptocurrency flow of the Tusk Infostealer campaign.","difficulty":"easy","categories":["Threat Intel"],"completedAt":"2025-06-25T12:48:01.858Z"},{"name":"PacketDetective","slug":"packetdetective","description":"Analyze network traffic in PCAP files using Wireshark to extract IOCs and reconstruct attacker tactics like authentication and remote execution.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2025-06-25T12:09:24.140Z"},{"name":"Tomcat Takeover","slug":"tomcat-takeover","description":"Analyze network traffic using Wireshark's custom columns, filters, and statistics to identify suspicious web server administration access and potential compromise.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2025-06-25T08:47:48.451Z"},{"name":"PaloAltoRCE - UTA0218","slug":"paloaltorce-uta0218","description":"Reconstruct a Palo Alto RCE attack timeline by analyzing firewall logs in ELK, identifying initial access, reverse shell, persistence, and data exfiltration artifacts.","difficulty":"hard","categories":["Threat Hunting"],"completedAt":"2025-06-25T03:51:22.066Z"},{"name":"XLMRat","slug":"xlmrat","description":"Analyze network traffic to identify malware delivery, deobfuscate scripts, and map attacker techniques using MITRE ATT&CK, focusing on stealthy execution and reflective code loading.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2025-06-24T15:01:54.788Z"},{"name":"Reveal","slug":"reveal","description":"Reconstruct a multi-stage attack by analyzing Windows memory dumps using Volatility 3, identifying malicious processes, command lines, and correlating findings with threat intelligence.","difficulty":"easy","categories":["Endpoint Forensics"],"completedAt":"2025-06-24T14:21:06.075Z"},{"name":"Web Investigation","slug":"web-investigation","description":"Examine network traffic with Wireshark to investigate web server compromise, identify SQL injection, extract attacker credentials, and detect uploaded malware.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2025-06-24T13:57:03.233Z"},{"name":"AsyncRAT","slug":"asyncrat","description":"This lab aims to equip learners with practical skills in malware analysis by dissecting a multi-stage AsyncRAT infection. Participants will explore obfuscation techniques, payload extraction, persistence mechanisms, and steganographic methods used in real-world malware, enhancing their ability to detect, analyze, and respond to complex cyber threats.","difficulty":"medium","categories":["Malware Analysis"],"completedAt":"2025-06-24T08:11:24.347Z"},{"name":"MeteorHit - Indra","slug":"meteorhit-indra","description":"Reconstruct a wiper malware attack by analyzing registry, event logs, and USN journal artifacts using Registry Explorer, Event Log Explorer, and VirusTotal.","difficulty":"medium","categories":["Endpoint Forensics"],"completedAt":"2025-06-24T07:40:13.915Z"},{"name":"AndroidBreach","slug":"androidbreach","description":"Analyze an Android device dump and reverse engineer a malicious APK using ALEAPP and JADX-GUI to identify malware functionality, data exfiltration, and extract compromised credentials.","difficulty":"medium","categories":["Endpoint Forensics"],"completedAt":"2025-06-23T16:16:36.788Z"},{"name":"IcedID","slug":"icedid","description":"Investigate IcedID malware using VirusTotal and threat intelligence platforms to identify IOCs, associated threat actors, and execution mechanisms.","difficulty":"easy","categories":["Threat Intel"],"completedAt":"2025-06-23T16:03:21.067Z"},{"name":"GrabThePhisher","slug":"grabthephisher","description":"Analyze a cryptocurrency phishing kit to identify exfiltration methods, extract critical IOCs, and gather threat actor intelligence using local logs and Telegram APIs.","difficulty":"easy","categories":["Threat Intel"],"completedAt":"2025-06-23T15:53:35.976Z"},{"name":"Ramnit","slug":"ramnit","description":"Analyze a memory dump using Volatility to identify a malicious process, extract network IOCs, file hash, and compilation timestamp, correlating with external threat intelligence.","difficulty":"easy","categories":["Endpoint Forensics"],"completedAt":"2025-06-23T15:39:32.225Z"},{"name":"Insider","slug":"insider","description":"Analyze Linux disk image artifacts, including logs and Bash history, using FTK Imager to investigate insider threat activities and reconstruct user actions.","difficulty":"easy","categories":["Endpoint Forensics"],"completedAt":"2025-06-23T15:07:33.254Z"},{"name":"DanaBot","slug":"danabot","description":"Analyze network traffic using Wireshark to identify DanaBot initial access, deobfuscate malicious JavaScript, and extract IOCs like IPs, file hashes, and execution processes.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2025-06-23T15:02:04.249Z"},{"name":"3CX Supply Chain","slug":"3cx-supply-chain","description":"Reconstruct the 3CX supply chain attack by analyzing compromised MSI and DLL artifacts to identify TTPs and attribute the incident to a threat actor.","difficulty":"easy","categories":["Threat Intel"],"completedAt":"2025-06-23T14:57:28.784Z"},{"name":"Red Stealer","slug":"red-stealer","description":"Analyze a suspicious executable using VirusTotal and MalwareBazaar to extract IOCs, identify C2 infrastructure, MITRE ATT&CK techniques, and privilege escalation mechanisms.","difficulty":"easy","categories":["Threat Intel"],"completedAt":"2025-06-23T14:27:37.497Z"},{"name":"PsExec Hunt","slug":"psexec-hunt","description":"Analyze SMB traffic in a PCAP file using Wireshark to identify PsExec lateral movement, compromised systems, user credentials, and administrative shares.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2025-06-23T14:22:27.162Z"},{"name":"The Crime","slug":"the-crime","description":"Utilize ALEAPP to analyze Android device artifacts, reconstructing a victim's financial details, movements, and communication patterns.","difficulty":"easy","categories":["Endpoint Forensics"],"completedAt":"2025-06-23T14:18:10.331Z"},{"name":"Amadey - APT-C-36","slug":"amadey-apt-c-36","description":"Reconstruct Amadey Trojan behavior by analyzing memory dumps with Volatility3 to identify malicious processes, C2 communications, payload delivery, and persistence mechanisms.","difficulty":"medium","categories":["Endpoint Forensics"],"completedAt":"2025-06-23T14:13:20.564Z"},{"name":"Yellow RAT","slug":"yellow-rat","description":"Analyze malware artifacts using threat intelligence platforms like VirusTotal to identify IOCs, C2 servers, and understand adversary tactics.","difficulty":"easy","categories":["Threat Intel"],"completedAt":"2025-06-23T14:06:40.324Z"},{"name":"PoisonedCredentials","slug":"poisonedcredentials","description":"Analyze network traffic for LLMNR/NBT-NS poisoning attacks using Wireshark to identify the rogue machine, compromised accounts, and affected systems.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2025-06-23T14:03:25.582Z"},{"name":"Oski","slug":"oski","description":"Analyze a sandbox report using Any.Run to identify Stealc malware behavior, extract configuration details, and map observed tactics to MITRE ATT&CK.","difficulty":"easy","categories":["Threat Intel"],"completedAt":"2025-06-23T13:44:20.492Z"},{"name":"WebStrike","slug":"webstrike","description":"Analyze network traffic using Wireshark to investigate a web server compromise, identify web shell deployment, reverse shell communication, and data exfiltration.","difficulty":"easy","categories":["Network Forensics"],"completedAt":"2025-06-23T13:38:01.486Z"},{"name":"Intel101","slug":"intel101","description":"Apply open-source intelligence (OSINT) techniques using Whois, Wayback Machine, and Google Lens to investigate digital footprints and extract specific information.","difficulty":"medium","categories":["Threat Intel"],"completedAt":"2023-06-29T05:42:52.513Z"},{"name":"Lespion","slug":"lespion","description":"Investigate an insider threat by analyzing GitHub repositories for exposed credentials, using OSINT tools to correlate online accounts, and performing image analysis to identify locations.","difficulty":"easy","categories":["Threat Intel"],"completedAt":"2023-06-29T05:00:26.100Z"},{"name":"RedLine","slug":"redline","description":"Employ Volatility to analyze a memory dump, identifying suspicious processes, network IOCs, memory protections, and attacker's command-and-control infrastructure.","difficulty":"easy","categories":["Endpoint Forensics"],"completedAt":"2023-06-25T13:34:28.763Z"}],"total":38}