BlueTeamLabs: CountdownFor this challenge, we've been tasked with investigating a disk image to find evidence of a gang's planned attack. We'll use Autopsy and ThumbCache Viewer to uncover the gang's plans and target.2024-08-22
NICE: Firewall Update: Tables for TwoFor this challenge, we've been tasked with migrating systems to use the nftables firewall. We will need to enable the service, configure the rules, and enable logging on the Domain Controller.2024-08-20
BlueTeamLabs: Winter Stew 2023For this challenge we'll be using Wireshark to investigate whether an endpoint has been compromised, types of scans conducted, which ports were open, and identify login attempts.2024-08-16
TryHackMe: TempestIn this challenge we will be analyzing Sysmon Logs and a PCAP to uncover the actions taken by a threat actor throughout several stages of the Cyber Kill Chain.2024-08-13
NICE: Least Privilege Put OffsIn this NICE challenge we're tasked with creating OUs and assinging various permissions, GPOs, and configuring basic ACLs on a Linux fileshare.2024-08-11
LetsDefend: PDFURIPDFURI tasks us with performing disk forensics and analyzing artifacts with various tools, such as FTK Imager, Event Viewer, PDFStreamDumper, and DB Browser.2024-08-08
LetsDefend: Malicious Web Traffic AnalysisIn this challenge, we'll be analyzing a pcap to identify various attacks against a webserver.2024-08-07
LetsDefend: Linux Memory ForensicsWe've been tasked with analyzing the memory capture of a compromised device to find various IOCs and pieces of evidence, including the attacker's reverse shell, IP address, and location.2024-07-26
LetsDefend: Windows Memory DumpFor this challenge we've been tasked with determining which user downloaded a malicious crack tool, where the file was downloaded, and what actions were taken by the second-stage payload.2024-07-24
LetsDefend: Memory AnalysisFor this challenge we've been tasked with finding the malicious process running on a compromised endpoint and to determine which user is responsible. This write-up includes instructions for Volatility 2 and corresponding commands for Volatility 3.2024-07-22