Specifications
| Format | Labs |
|---|---|
| Level | Intermediate, Advanced |
| Price | Free |
| Access | No registration |
| Activity | Active |
| Language | EN |
| Category | Forensics, DFIR, SecOps |
A blue-team site in an otherwise offensive catalogue: evidence triage, memory and disk imaging, network capture analysis, threat hunting and perimeter defence. Entry is a Join For Free button rather than a request form, with self-contained labs sitting alongside seasonal competitions.
Pros & cons
Pros
- Incident-shaped tasks with real artefacts: memory dumps, disk images, logs
- Free entry through a button, with no request form and no sales call
- Labs and seasonal competitions sit side by side
Cons
- You need real comfort with analysis tooling, otherwise the first hour is setup
- English only, and there are no community walkthroughs to fall back on
- Some labs assume a Windows forensic background and skip the Linux half of the tooling
Who it fits
Fits SOC analysts, DFIR work, and anyone crossing from offensive testing to detection. The tasks are built like an incident review, from first triage to a written report, so start with the labs rather than a seasonal CTF.
Getting started
- Open the Blue Team Labs section and pick a lab that states its level and prerequisites
- Establish facts before a theory: timeline, processes, listening sockets, outbound traffic
- Write the report in the format the task asks for, the checker reads the structure
History
The site grew out of Blue Team Labs material and picked up a SANS Team of the Year award in 2023. Entry has stayed free and the seasonal Blue Team CTF runs on a regular calendar. Verified, with the Join For Free path still opening the material and new labs still arriving. No task count is published, so catalogue size is a matter of browsing.