All Labs

Hands-on, downloadable cybersecurity labs for Blue Team defenders. Filter by difficulty or topic area.

Filter by difficulty:
Filter by topic:
Showing 3 labs
SOC Alert Triage
Beginner
SOC SIEM Detection

Learn to triage alerts in a simulated SOC environment. Analyze Splunk dashboards, correlate events, and identify true vs false positives using realistic PCAP and log data.

RDP Brute Force Detection
Intermediate
SOC IR Windows

Detect and respond to an RDP brute force attack using Windows Event Logs and Splunk. Identify attacker patterns, build detection rules, and simulate initial containment steps.

Suspicious PowerShell Analysis
Advanced
DFIR Malware PowerShell

Analyze obfuscated PowerShell scripts and memory artifacts. Understand living-off-the-land techniques, decode malicious payloads, and build detection logic.

// More labs in development — suggest a topic