Challenge Catalog180 modules
Your first mission

New here? Start with this one.

We picked Phishing & Email Threat Analysis as the perfect first step — no experience needed. You'll learn the basics and earn your first win in about 15 minutes.

180 results
🛡️Cyber Defense
📧
START HERE
Rookie
Phishing & Email Threat Analysis

Spot the scam: catch a phishing email red-handed.

▶ GUIDED

Analyze reported phishing emails, extract IOCs, and verify SPF/DKIM configurations.

phishingemailioc
~15 min phishing
Be a Cyber Defense Analyst
🛡️Cyber Defense
🔥
Rookie
Firewall Log Review

Read the firewall's diary to find the bad guys.

▶ GUIDED

Read and interpret basic firewall deny/allow logs, identify suspicious IPs, and generate a simple report.

firewalllogsreview
~15 min firewall
Be a Cyber Defense Analyst
🛡️Cyber Defense
📊
Rookie
Intro to SIEM Alerting

Build your first alarm system for hackers.

▶ GUIDED

Configure basic SIEM alert rules for failed logins, set severity thresholds, and triage your first alerts.

siemalertsentry-level
~15 min siem
Be a Cyber Defense Analyst
🛡️Cyber Defense
🦠
Rookie
Malware Sample Identification

Play detective: identify a mystery virus.

▶ GUIDED

Use static analysis tools to classify malware samples by type, extract hashes, and look up IOCs in public threat intel feeds.

malwarestatic-analysisioc
~15 min malware
Be a Cyber Defense Analyst
🛡️Cyber Defense
🖥️
Rookie
Endpoint Security Baseline

Lock down a computer like a pro.

▶ GUIDED

Audit an endpoint for missing patches, disabled antivirus, and weak configurations using a CIS benchmark checklist.

endpointcis-benchmarkhardening
~15 min endpoint
Be a Cyber Defense Analyst
🌐Networking
🛡️
Rookie
Network Security Fundamentals

Map the network and guard the gates.

▶ GUIDED

Entry-level network defense: discover hosts, analyze firewall logs, and configure SNMPv3 monitoring.

networkingmonitoringentry-level
~15 min networking
Be a Cyber Defense Infrastructure Support Specialist
🌐Networking
🔌
Rookie
Switch Port Security

Lock the doors on a network switch.

▶ GUIDED

Enable port security, configure MAC address sticky learning, and disable unused ports on a core switch.

switchport-securitylayer2
~15 min switch
Be a Cyber Defense Infrastructure Support Specialist
🌐Networking
🌐
Rookie
DNS Security Basics

Stop bad websites at the front door.

▶ GUIDED

Configure DNS filtering, enable DNSSEC, and identify malicious domain queries in logs.

dnsdnssecfiltering
~15 min dns
Be a Cyber Defense Infrastructure Support Specialist
🌐Networking
🔒
Rookie
VPN Configuration Basics

Build a secret tunnel between two offices.

▶ GUIDED

Set up a basic site-to-site IPsec VPN, verify connectivity, and review tunnel logs.

vpnipsecconnectivity
~15 min vpn
Be a Cyber Defense Infrastructure Support Specialist
🌐Networking
⚙️
Rookie
Network Device Hardening

Make a router hacker-proof.

▶ GUIDED

Apply CIS-recommended hardening to routers and switches: disable Telnet, enable SSH, restrict SNMP communities.

hardeningrouterssh
~15 min hardening
Be a Cyber Defense Infrastructure Support Specialist
🚨Incident Response
📋
Rookie
Incident Response Lifecycle Intro

Be the first responder when alarms go off.

▶ GUIDED

Walk through NIST IR lifecycle: prepare, detect, contain, eradicate, recover. Document a simulated low-severity alert.

ir-lifecyclenistdocumentation
~15 min ir-lifecycle
Be a Cyber Defense Incident Responder
🚨Incident Response
🚧
Rookie
Host Isolation Procedure

Quarantine a sick computer to stop the spread.

▶ GUIDED

Identify a compromised workstation, isolate it from the network, and collect basic triage artifacts.

isolationtriagecontainment
~15 min isolation
Be a Cyber Defense Incident Responder
🚨Incident Response
🔍
Rookie
Evidence Collection Basics

Bag and tag digital evidence like a CSI.

▶ GUIDED

Learn chain-of-custody procedures, image a USB drive, and hash-verify the image using MD5/SHA256.

evidencechain-of-custodyhashing
~15 min evidence
Be a Cyber Defense Incident Responder
🚨Incident Response
🎫
Rookie
Malware Alert Triage

Sort real threats from false alarms.

▶ GUIDED

Receive an AV alert, verify true/false positive status, escalate if needed, and fill out an incident ticket.

triageav-alertticketing
~15 min triage
Be a Cyber Defense Incident Responder
🚨Incident Response
🔑
Rookie
Password Spray Detection

Catch someone trying every door at once.

▶ GUIDED

Detect a low-and-slow password spray attack in authentication logs and block the offending IP range.

password-sprayauthenticationdetection
~15 min password-spray
Be a Cyber Defense Incident Responder
🐞Vuln Assessment
🔎
Rookie
Intro Vulnerability Scanning

Scan a network for open cracks.

▶ GUIDED

Run an unauthenticated Nessus scan against a single subnet and review the output for critical findings.

nessusscanningintro
~15 min nessus
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
📈
Rookie
CVSS Score Interpretation

Rank dangers: which bug fixes first?

▶ GUIDED

Evaluate five CVEs using the CVSS v3.1 calculator, rank them by environmental score, and recommend remediation priority.

cvsscveprioritization
~15 min cvss
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
🩹
Rookie
Patch Verification Exercise

Prove a computer's wounds are patched.

▶ GUIDED

Confirm that KB patches are applied on Windows hosts, compare system versions to CVE advisories, and document compliance.

patchingcompliancewindows
~15 min patching
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
🗺️
Rookie
Open Port Audit

Find every open door on the network.

▶ GUIDED

Use Nmap to audit all listening ports on the DMZ, compare results to the approved service list, and flag anomalies.

nmapport-auditdmz
~15 min nmap
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
📝
Rookie
Vulnerability Report Writing

Write the report that gets bugs fixed.

▶ GUIDED

Take raw scanner output and write an executive-friendly vulnerability report with risk ratings and remediation steps.

report-writingexecutive-summaryremediation
~15 min report-writing
Be a Vulnerability Assessment Analyst
🌐Networking
🌐
Rookie
VLAN Segmentation Intro

Slice the network into separate lanes.

▶ GUIDED

Create VLANs for server, user, and guest traffic. Apply inter-VLAN routing policies.

vlansegmentationrouting
~15 min vlan
Be a Network Operations Specialist
🌐Networking
📡
Rookie
Network Monitoring with SNMP

Set up a dashboard that watches the network.

▶ GUIDED

Configure SNMPv3 on network devices, set up a monitoring dashboard, and create threshold alerts.

snmpmonitoringdashboard
~15 min snmp
Be a Network Operations Specialist
🌐Networking
📐
Rookie
Subnetting Lab

Design the address map for three offices.

▶ GUIDED

Design an IP addressing scheme for a three-site network using VLSM, allocating appropriate ranges per department.

subnettingvlsmip-planning
~15 min subnetting
Be a Network Operations Specialist
🌐Networking
📶
Rookie
Wireless Network Security Basics

Make the Wi-Fi safe for everyone.

▶ GUIDED

Configure WPA3 on an access point, create a guest SSID with captive portal, and audit client associations.

wirelesswpa3guest-network
~15 min wireless
Be a Network Operations Specialist
🌐Networking
🛠️
Rookie
Network Troubleshooting Fundamentals

Play network doctor and fix three outages.

▶ GUIDED

Diagnose three simulated network outages using ping, traceroute, and show commands on a Cisco switch.

troubleshootingdiagnosticscisco
~15 min troubleshooting
Be a Network Operations Specialist
🛠️Administration
🖥️
Rookie
Active Directory Basics

Be the boss of user accounts and rules.

▶ GUIDED

Build an AD OU structure, apply security GPOs, and manage patch deployment via WSUS.

active-directorygpowindows
~15 min active-directory
Be a System Administrator
🛠️Administration
🐧
Rookie
Linux Server Hardening

Turn a fresh Linux box into a fortress.

▶ GUIDED

Secure a fresh Ubuntu server: disable root SSH, configure UFW, apply CIS Level 1 benchmarks, and set up fail2ban.

linuxhardeningufw+1
~15 min linux
Be a System Administrator
🛠️Administration
💾
Rookie
Backup and Recovery Basics

Save the day with a good backup.

▶ GUIDED

Configure a daily backup job for critical files, test restoration to a sandbox, and document the recovery procedure.

backuprecoverydocumentation
~15 min backup
Be a System Administrator
🛠️Administration
👤
Rookie
User Account Management

Create, change, and lock out users.

▶ GUIDED

Create, modify, and disable user accounts using AD and PowerShell scripts. Enforce password complexity policies.

user-accountspowershelliam
~15 min user-accounts
Be a System Administrator
🛠️Administration
🏛️
Rookie
Certificate Authority Setup

Hand out digital ID badges to computers.

▶ GUIDED

Stand up a basic internal PKI with a two-tier CA hierarchy, issue a TLS certificate to a web server, and verify the chain.

pkicatls
~15 min pki
Be a System Administrator
🔍Digital Forensics
🗂️
Rookie
File System Forensics Intro

Dig through a hard drive for hidden files.

▶ GUIDED

Browse an NTFS filesystem image using Autopsy; identify deleted files, timestamps, and metadata.

ntfsautopsyfile-forensics
~15 min ntfs
Be a Digital Forensics Analyst
🔍Digital Forensics
🌍
Rookie
Browser Artifact Analysis

Reconstruct what someone did online.

▶ GUIDED

Extract browser history, cookies, and downloads from a forensic image to reconstruct user activity.

browser-forensicshistoryartifacts
~15 min browser-forensics
Be a Digital Forensics Analyst
🔍Digital Forensics
📋
Rookie
Windows Event Log Analysis

Read a computer's diary for clues.

▶ GUIDED

Filter Security, System, and Application event logs to identify login anomalies and service crashes.

windows-event-loglog-analysisanomalies
~15 min windows-event-log
Be a Digital Forensics Analyst
🔍Digital Forensics
🔏
Rookie
Hash Verification & Chain of Custody

Prove evidence wasn't tampered with.

▶ GUIDED

Verify integrity of forensic evidence using MD5/SHA256 hashing, and complete a chain-of-custody form.

hashingintegritychain-of-custody
~15 min hashing
Be a Digital Forensics Analyst
🔍Digital Forensics
📦
Rookie
Basic Network Packet Capture

Watch data fly by and find leaked passwords.

▶ GUIDED

Capture live traffic with Wireshark, filter by protocol, and identify plaintext credentials in the capture.

wiresharkpcapcredentials
~15 min wireshark
Be a Digital Forensics Analyst
📡Threat Intel
🔭
Rookie
OSINT Fundamentals

Stalk a target using only public info.

▶ GUIDED

Use open-source tools (Shodan, Maltego, VirusTotal) to gather threat intelligence about a target domain.

osintthreat-intelshodan
~15 min osint
Be a Threat/Warning Analyst
📡Threat Intel
🏷️
Rookie
IOC Classification

Sort the clues: is it a real threat?

▶ GUIDED

Classify a list of indicators (IPs, domains, hashes) by type and confidence level using a structured threat intel format.

iocclassificationthreat-intel
~15 min ioc
Be a Threat/Warning Analyst
📡Threat Intel
🗺️
Rookie
MITRE ATT&CK Navigator Intro

Map hacker moves on the ATT&CK board.

▶ GUIDED

Map a set of observed TTPs to the ATT&CK framework using Navigator, identify coverage gaps.

mitre-attckttpnavigator
~15 min mitre-attck
Be a Threat/Warning Analyst
📡Threat Intel
📡
Rookie
Threat Feed Integration

Wire up a feed of fresh threat intel.

▶ GUIDED

Subscribe to a free threat feed, import IOCs into the SIEM, and create detection rules based on feed data.

threat-feedsiemdetection-rules
~15 min threat-feed
Be a Threat/Warning Analyst
📡Threat Intel
🎭
Rookie
Social Engineering Awareness Analysis

Decode the tricks scammers use.

▶ GUIDED

Review phishing campaigns, analyze social engineering TTPs, and produce an awareness report for end users.

phishingsocial-engineeringawareness
~15 min phishing
Be a Threat/Warning Analyst
📐Architecture
📐
Rookie
Security Architecture Fundamentals

Design a network that's hard to crack.

▶ GUIDED

Identify security design principles (defense in depth, least privilege) and apply them to a simple network diagram.

architecturedesignprinciples
~15 min architecture
Be a Security Architect
📐Architecture
🗺️
Rookie
Trust Boundary Mapping

Draw the lines attackers can't cross.

▶ GUIDED

Identify trust boundaries in a three-tier web application and document data flows and control points.

trust-boundarydata-flowweb-app
~15 min trust-boundary
Be a Security Architect
📐Architecture
📄
Rookie
Security Requirement Documentation

Turn rules into a security blueprint.

▶ GUIDED

Translate business requirements into security controls using NIST 800-53, document in a security plan template.

nistdocumentationsecurity-plan
~15 min nist
Be a Security Architect
📐Architecture
🔐
Rookie
Encryption Standards Review

Pick the locks that actually hold.

▶ GUIDED

Compare symmetric and asymmetric algorithms, evaluate TLS versions in use, and recommend secure configurations.

encryptiontlscryptography
~15 min encryption
Be a Security Architect
📐Architecture
☁️
Rookie
Cloud Security Fundamentals

Lock down a leaky cloud storage bucket.

▶ GUIDED

Review AWS shared responsibility model, identify misconfigured S3 buckets, and apply least-privilege IAM policies.

cloudawss3+1
~15 min cloud
Be a Security Architect
🚔Cybercrime
⚖️
Rookie
Cybercrime Evidence Basics

Learn how cyber cops bag evidence.

▶ GUIDED

Identify digital evidence types, proper seizure procedures, and legal considerations for computer crime investigations.

cybercrimeevidencelegal
~15 min cybercrime
Be a Cyber Crime Investigator
🚔Cybercrime
📨
Rookie
Email Header Investigation

Trace a fake email back to its source.

▶ GUIDED

Analyze email headers to trace origin, identify spoofed addresses, and correlate with known threat actors.

email-headerspoofinginvestigation
~15 min email-header
Be a Cyber Crime Investigator
🚔Cybercrime
🕵️
Rookie
Social Media Investigation OSINT

Build a suspect profile from public posts.

▶ GUIDED

Use OSINT tools to build a profile of a suspected cybercriminal from public social media and forum activity.

osintsocial-mediaprofiling
~15 min osint
Be a Cyber Crime Investigator
🚔Cybercrime
📝
Rookie
Report Writing for Investigations

Write the report that holds up in court.

▶ GUIDED

Write a factual, legally defensible investigation report from a set of digital evidence artifacts.

report-writinglegaldocumentation
~15 min report-writing
Be a Cyber Crime Investigator
🚔Cybercrime
🗃️
Rookie
Network Log Investigation

Follow the breadcrumbs in the logs.

▶ GUIDED

Analyze proxy and firewall logs to identify unauthorized data access and build a basic incident timeline.

log-investigationtimelineproxy
~15 min log-investigation
Be a Cyber Crime Investigator
🏴Cyber Offense
🧭
Rookie
Reconnaissance Basics

Scout a target without getting caught.

▶ GUIDED

Conduct passive and active reconnaissance on a target range using whois, DNS enumeration, and Nmap.

reconnmapdns-enumeration
~15 min recon
Be a Cyber Operator
🏴Cyber Offense
💻
Rookie
Linux Command Line Basics

Master the hacker's command line.

▶ GUIDED

Master essential Linux commands for offensive operations: file manipulation, process inspection, and basic networking.

linuxclifundamentals
~15 min linux
Be a Cyber Operator
🏴Cyber Offense
🐍
Rookie
Scripting for Security

Automate the boring stuff with Python.

▶ GUIDED

Write basic Python and Bash scripts to automate port scanning, file hashing, and log parsing tasks.

scriptingpythonbash+1
~15 min scripting
Be a Cyber Operator
🏴Cyber Offense
🌐
Rookie
Web Application Testing Basics

Spy on a website's traffic with Burp.

▶ GUIDED

Use Burp Suite Community edition to intercept HTTP traffic, modify requests, and identify input fields for testing.

burp-suiteweb-apphttp-interception
~15 min burp-suite
Be a Cyber Operator
🏴Cyber Offense
☠️
Rookie
Kali Linux Environment Setup

Build your hacker toolkit from scratch.

▶ GUIDED

Configure a Kali Linux attack workstation, update tools, configure anonymization, and verify lab connectivity.

kalisetuplab-prep
~15 min kali
Be a Cyber Operator
🛡️Cyber Defense
🔍
Agent
SOC Analyst — Threat Detection

Hunt port scans and chase SIEM alerts.

▶ GUIDED

Detect port scans with firewall logs, run vulnerability scans against the server farm, and investigate SIEM alerts.

socsiemdetection
~30 min soc
Be a Cyber Defense Analyst
🛡️Cyber Defense
Agent
SIEM Correlation Rules

Write rules that catch multi-step attacks.

▶ GUIDED

Build multi-event correlation rules in Splunk to detect brute force, lateral movement, and privilege escalation patterns.

splunkcorrelationdetection-rules
~30 min splunk
Be a Cyber Defense Analyst
🛡️Cyber Defense
📉
Agent
Behavioral Analytics Baselining

Learn what's normal, then catch the weird.

▶ GUIDED

Establish normal baselines for user and device behavior, then detect anomalies indicating insider threats.

uebabaselininganomaly-detection
~30 min ueba
Be a Cyber Defense Analyst
🛡️Cyber Defense
🚨
Agent
IDS Rule Creation

Write your own hacker-detection rules.

▶ GUIDED

Write custom Snort/Suricata rules to detect specific attack patterns observed in threat intelligence feeds.

snortsuricataids-rules
~30 min snort
Be a Cyber Defense Analyst
🛡️Cyber Defense
📡
Agent
Network Traffic Analysis

Find the spy beaconing home in a PCAP.

▶ GUIDED

Analyze a 48-hour PCAP for C2 beaconing, data staging, and exfiltration attempts. Produce IOC list.

pcapc2-beaconingnetwork-analysis
~30 min pcap
Be a Cyber Defense Analyst
🌐Networking
🔐
Agent
Network Segmentation & VLAN Hardening

Build walls between network zones.

▶ GUIDED

Configure VLAN segmentation, harden firewall rules, and deploy 802.1X port authentication.

vlansfirewallnac+1
~30 min vlans
Be a Cyber Defense Infrastructure Support Specialist
🌐Networking
🔧
Agent
Firewall Policy Optimization

Clean up a messy firewall rulebook.

▶ GUIDED

Audit an existing firewall ruleset, remove shadowed and redundant rules, and document the change.

firewallpolicyoptimization
~30 min firewall
Be a Cyber Defense Infrastructure Support Specialist
🌐Networking
🎛️
Agent
IPS Tuning Lab

Turn down the noise on a loud alarm.

▶ GUIDED

Reduce false positives on a production IPS sensor by adjusting sensitivity thresholds and suppressing known-good signatures.

ipstuningfalse-positive
~30 min ips
Be a Cyber Defense Infrastructure Support Specialist
🌐Networking
⚖️
Agent
Load Balancer Security

Guard the front door that shares the load.

▶ GUIDED

Configure a reverse proxy/load balancer with SSL termination, HTTP security headers, and DDoS rate limiting.

load-balancerreverse-proxyssl
~30 min load-balancer
Be a Cyber Defense Infrastructure Support Specialist
🌐Networking
🔄
Agent
Network Redundancy & Failover

Make the network that never sleeps.

▶ GUIDED

Configure HSRP/VRRP for router redundancy, test failover, and document RTO/RPO for the network segment.

hsrpfailoverredundancy
~30 min hsrp
Be a Cyber Defense Infrastructure Support Specialist
🚨Incident Response
🔒
Agent
Ransomware Initial Response

Stop a ransomware attack in its tracks.

▶ GUIDED

Receive a ransomware alert, perform immediate containment, identify affected hosts, and begin eradication.

ransomwarecontainmenteradication
~30 min ransomware
Be a Cyber Defense Incident Responder
🚨Incident Response
📧
Agent
Phishing Campaign Response

Fight back against a phishing blitz.

▶ GUIDED

Respond to a large-scale phishing campaign: identify victims, reset credentials, block IOCs, and send user notifications.

phishingresponseuser-notification
~30 min phishing
Be a Cyber Defense Incident Responder
🚨Incident Response
🕵️
Agent
Insider Threat Investigation

Catch a coworker gone rogue.

▶ GUIDED

Correlate AD, VPN, and file server logs to identify unauthorized after-hours access to sensitive data.

insider-threatlog-analysisforensics
~30 min insider-threat
Be a Digital Forensics Analyst
🚨Incident Response
🚶
Agent
Lateral Movement Detection

Spot a hacker hopping between computers.

▶ GUIDED

Identify Pass-the-Hash and Pass-the-Ticket attacks within Windows event logs; block attacker lateral movement.

lateral-movementpthwindows
~30 min lateral-movement
Be a Cyber Defense Incident Responder
🚨Incident Response
🌊
Agent
DDoS Response Playbook

Survive a flood of fake traffic.

▶ GUIDED

Execute a DDoS response playbook: identify attack type, implement rate limiting, engage upstream ISP blackholing.

ddosrate-limitingblackholing
~30 min ddos
Be a Cyber Defense Incident Responder
🐞Vuln Assessment
📊
Agent
Vulnerability Management Cycle

Run a full scan-and-fix loop.

▶ GUIDED

Enumerate all zones with Nmap, run NSE scripts, and produce a remediation report.

nmapvulnerabilityscanning
~30 min nmap
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
🔑
Agent
Authenticated Vulnerability Scan

Scan deeper with real login credentials.

▶ GUIDED

Run credentialed Nessus scans against Windows and Linux hosts; compare results to unauthenticated scans.

nessusauthenticated-scancomparison
~30 min nessus
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
🌐
Agent
Web Application Scanning

Hunt the OWASP Top 10 on a website.

▶ GUIDED

Run OWASP ZAP against a web application, identify OWASP Top 10 findings, and prioritize remediations.

owasp-zapweb-apptop-10
~30 min owasp-zap
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
🐳
Agent
Container Image Scanning

X-ray a Docker image for hidden bugs.

▶ GUIDED

Scan Docker images with Trivy, identify vulnerable base images, and apply image hardening techniques.

dockertrivycontainer-security
~30 min docker
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
🗺️
Agent
Risk-Based Remediation Planning

Decide which 200 bugs to fix first.

▶ GUIDED

Take scanner output from 200+ findings, apply business context to prioritize critical remediations, and build a remediation roadmap.

risk-basedremediationroadmap
~30 min risk-based
Be a Vulnerability Assessment Analyst
📡Threat Intel
🕸️
Agent
Threat Intelligence Platform Setup

Stand up your own threat intel hub.

▶ GUIDED

Deploy MISP, import threat feeds, tag IOCs, and share intelligence with a simulated ISA partner.

mispthreat-intelsharing
~30 min misp
Be a Threat/Warning Analyst
📡Threat Intel
🎯
Agent
Threat Actor Profiling

Profile a real nation-state hacker crew.

▶ GUIDED

Research a nation-state APT group using Cyber Kill Chain and ATT&CK, and produce a threat profile document.

aptthreat-profilingkill-chain
~30 min apt
Be a Threat/Warning Analyst
📡Threat Intel
🔬
Agent
Malware Behavioral Analysis

Watch a virus misbehave in a sandbox.

▶ GUIDED

Detonate malware in a sandbox, document behavioral IOCs (registry, network, file), and map to ATT&CK techniques.

sandboxbehavioral-analysismalware
~30 min sandbox
Be a Threat/Warning Analyst
📡Threat Intel
🏹
Agent
Threat Hunt — Living off the Land

Hunt hackers hiding in normal tools.

▶ GUIDED

Hunt for LOLBin abuse (PowerShell, WMI, MSHTA) using endpoint telemetry and Sigma rules.

lolbinsthreat-huntingsigma
~30 min lolbins
Be a Threat/Warning Analyst
📡Threat Intel
💎
Agent
Intelligence Report Production

Brief the team on what the bad guys want.

▶ GUIDED

Produce a finished tactical intelligence report using the Diamond Model, suitable for an operations team briefing.

intelligence-reportdiamond-modelbriefing
~30 min intelligence-report
Be a Threat/Warning Analyst
🌐Networking
🗺️
Agent
BGP Routing Security

Stop attackers from hijacking the internet's roads.

▶ GUIDED

Configure BGP prefix filtering, RPKI, and route dampening to prevent route hijacking.

bgprpkirouting
~30 min bgp
Be a Network Operations Specialist
🌐Networking
🔗
Agent
OSPF Secure Deployment

Lock down the routes between routers.

▶ GUIDED

Deploy OSPF across a multi-area network with MD5 authentication, summarization, and stub areas.

ospfauthenticationrouting
~30 min ospf
Be a Network Operations Specialist
🌐Networking
📊
Agent
QoS and Traffic Shaping

Make the fast lane for video calls.

▶ GUIDED

Implement QoS policies to prioritize VoIP and video traffic, verify with simulation tools.

qostraffic-shapingvoip
~30 min qos
Be a Network Operations Specialist
🌐Networking
🎛️
Agent
SDN Controller Deployment

Steer the whole network with software.

▶ GUIDED

Deploy an OpenDaylight SDN controller, configure southbound interfaces, and push flow rules to virtual switches.

sdnopenflowvirtual-switch
~30 min sdn
Be a Network Operations Specialist
🌐Networking
📈
Agent
Network Capacity Planning

Predict when the network will run out of room.

▶ GUIDED

Analyze 90-day utilization trends using SNMP data, identify bottlenecks, and produce an upgrade recommendation.

capacity-planningutilizationsnmp
~30 min capacity-planning
Be a Network Operations Specialist
🛠️Administration
📜
Agent
Advanced Group Policy

Push security rules to every PC at once.

▶ GUIDED

Implement AppLocker, LAPS, and fine-grained password policies via AD Group Policy.

gpoapplockerlaps
~30 min gpo
Be a System Administrator
🛠️Administration
📱
Agent
SCCM/Intune Endpoint Management

Manage phones and laptops from the cloud.

▶ GUIDED

Configure compliance policies in Intune, enforce BitLocker encryption, and manage application deployment.

intunemdmbitlocker
~30 min intune
Be a System Administrator
🛠️Administration
⚙️
Agent
Infrastructure as Code Security

Find the holes in auto-built servers.

▶ GUIDED

Review Terraform and Ansible scripts for security misconfigurations, apply hardening templates.

iacterraformansible
~30 min iac
Be a System Administrator
🛠️Administration
🔐
Agent
PAM Implementation

Control who gets the master keys.

▶ GUIDED

Deploy a Privileged Access Management solution, configure session recording, and enforce just-in-time access.

pamjit-accesssession-recording
~30 min pam
Be a System Administrator
🛠️Administration
🗄️
Agent
Log Management & Retention

Keep every log, safely, for years.

▶ GUIDED

Configure centralized log collection from all infrastructure devices, set retention policies, and verify log integrity.

log-managementsiemretention
~30 min log-management
Be a System Administrator
📐Architecture
🏗️
Agent
Zero Trust Design Phase 1

Design a network that trusts nobody.

▶ GUIDED

Design identity-centric access controls, define micro-perimeters, and map data flows for a hybrid environment.

zero-trustidentitydesign
~30 min zero-trust
Be a Security Architect
📐Architecture
🧮
Agent
Threat Modeling with STRIDE

Brainstorm every way an app could break.

▶ GUIDED

Apply STRIDE methodology to a microservices architecture, identify threats, and propose mitigations.

stridethreat-modelingmicroservices
~30 min stride
Be a Security Architect
📐Architecture
📋
Agent
Security Controls Mapping

Find the gaps in a company's defenses.

▶ GUIDED

Map CIS Controls v8 to an organization's current security posture and identify control gaps.

cis-controlsgap-analysisposture
~30 min cis-controls
Be a Security Architect
📐Architecture
☁️
Agent
Hybrid Cloud Security Architecture

Connect the office to the cloud safely.

▶ GUIDED

Design secure connectivity between on-premises and AWS/Azure environments with proper identity federation.

hybrid-cloudfederationidentity
~30 min hybrid-cloud
Be a Security Architect
📐Architecture
🔄
Agent
Security Review for DevOps Pipeline

Bake security into the code factory.

▶ GUIDED

Embed SAST, DAST, and dependency scanning into a CI/CD pipeline; define security gates and approval workflows.

devsecopscicdsast-dast
~30 min devsecops
Be a Security Architect
🔍Digital Forensics
🧠
Agent
Memory Forensics Intro

Read a computer's mind with Volatility.

▶ GUIDED

Acquire a memory dump and use Volatility to list processes, find injected code, and extract network connections.

memory-forensicsvolatilityinjection
~30 min memory-forensics
Be a Digital Forensics Analyst
🔍Digital Forensics
🗝️
Agent
Registry Forensics

Dig through the Windows registry for secrets.

▶ GUIDED

Analyze Windows registry hives for persistence mechanisms, recently accessed files, and USB history.

registrypersistenceusb
~30 min registry
Be a Digital Forensics Analyst
🔍Digital Forensics
📬
Agent
Email Forensics Investigation

Uncover spear-phishing in a mailbox.

▶ GUIDED

Analyze mailbox exports to identify spear-phishing attacks, trace email routes, and recover deleted messages.

email-forensicsspear-phishingmailbox
~30 min email-forensics
Be a Digital Forensics Analyst
🔍Digital Forensics
📱
Agent
Mobile Device Forensics Basics

Pull clues out of a seized phone.

▶ GUIDED

Extract and analyze data from an Android device image using Cellebrite/ALEAPP tools for a simulated investigation.

mobile-forensicsandroidextraction
~30 min mobile-forensics
Be a Digital Forensics Analyst
🔍Digital Forensics
🌊
Agent
Network Forensics — PCAP Analysis

Rebuild a hack from a pile of packets.

▶ GUIDED

Analyze a multi-protocol PCAP file to reconstruct a web intrusion, extract credentials, and identify exfiltrated files.

pcapnetwork-forensicscredentials
~30 min pcap
Be a Digital Forensics Analyst
🏴Cyber Offense
⚔️
Agent
Metasploit Framework Exploitation

Break in with Metasploit, then pivot.

▶ GUIDED

Exploit a vulnerable service with Metasploit, post-exploit for credentials, and pivot to a second target.

metasploitexploitationpivoting
~30 min metasploit
Be a Cyber Operator
🏴Cyber Offense
🔓
Agent
Password Cracking Lab

Crack stolen hashes with Hashcat.

▶ GUIDED

Use Hashcat and John the Ripper to crack NTLM, MD5, and bcrypt hashes using wordlist and rule attacks.

hashcatjohncracking
~30 min hashcat
Be a Cyber Operator
🏴Cyber Offense
📶
Agent
Wireless Network Attacks

Break a Wi-Fi password the hard way.

▶ GUIDED

Capture WPA2 handshakes, perform deauth attacks, crack PSK, and evaluate evil twin attack feasibility.

wpa2deauthevil-twin
~30 min wpa2
Be a Cyber Operator
🏴Cyber Offense
🩸
Agent
Active Directory Enumeration

Map every path to the crown jewels.

▶ GUIDED

Use BloodHound and PowerView to enumerate AD attack paths, find Kerberoastable accounts, and map domain trusts.

bloodhoundad-enumerationkerberoasting
~30 min bloodhound
Be a Cyber Operator
🏴Cyber Offense
📡
Agent
C2 Framework Setup

Stand up your own command-and-control server.

▶ GUIDED

Stand up a Havoc/Sliver C2 server, generate a staged payload, establish a callback, and blend traffic.

c2sliverpayload
~30 min c2
Be a Cyber Operator
🚨Incident Response
🚨
Specialist
Full Incident Response — Ransomware

Run the whole response on a live ransomware hit.

▶ GUIDED

Triage a PowerShell-delivered ransomware incident: isolate host, analyze memory, block lateral movement, document timeline.

ransomwareincident-responsememory-forensics
~45 min ransomware
Be a Cyber Defense Incident Responder
🚨Incident Response
⛓️
Specialist
Supply Chain Compromise Response

Hunt a backdoor snuck in via a software update.

▶ GUIDED

Investigate a compromised software update mechanism, identify affected endpoints, and implement emergency mitigations.

supply-chainsolarwinds-styleresponse
~45 min supply-chain
Be a Cyber Defense Incident Responder
🚨Incident Response
☁️
Specialist
Cloud Incident Response

Chase a hacker through a hijacked AWS account.

▶ GUIDED

Respond to a compromised AWS IAM role: revoke credentials, audit CloudTrail, identify exfiltrated S3 data.

awscloud-ircloudtrail
~45 min aws
Be a Cyber Defense Incident Responder
🚨Incident Response
🧹
Specialist
Active Threat Eradication

Rip out every foothold an APT left behind.

▶ GUIDED

Conduct environment-wide cleanup after a confirmed APT intrusion: remove persistence, flush caches, rebuild keys.

eradicationaptcleanup
~45 min eradication
Be a Cyber Defense Incident Responder
🚨Incident Response
💼
Specialist
Business Email Compromise Response

Trace a stolen inbox and stop the wire fraud.

▶ GUIDED

Investigate a BEC incident: trace OAuth token theft, identify forwarding rules, notify affected parties, and harden M365.

becm365oauth-abuse
~45 min bec
Be a Cyber Defense Incident Responder
🐞Vuln Assessment
⚔️
Specialist
Red Team — Web App & SMB Exploitation

Break into a web server, then own the network.

▶ GUIDED

Conduct OWASP Top 10 assessment on DMZ web server and exploit EternalBlue on unpatched Windows hosts.

red-teamexploitationweb-app+1
~45 min red-team
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
☁️
Specialist
Cloud Penetration Testing

Escalate from one AWS flaw to total control.

▶ GUIDED

Enumerate and exploit AWS misconfiguration: SSRF to metadata service, privilege escalation via role chaining.

aws-pentestssrfprivilege-escalation
~45 min aws-pentest
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
👑
Specialist
Active Directory Attack Chain

Chain attacks all the way to domain admin.

▶ GUIDED

Full AD attack: Kerberoasting → AS-REP Roasting → DCSync → Golden Ticket. Document each step with evidence.

ad-attackdcsyncgolden-ticket
~45 min ad-attack
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
📱
Specialist
Mobile Application Assessment

Pick apart an Android app for weaknesses.

▶ GUIDED

Perform dynamic and static analysis of an Android APK: intercept traffic, identify insecure data storage, bypass root detection.

mobile-pentestandroidapk
~45 min mobile-pentest
Be a Vulnerability Assessment Analyst
🐞Vuln Assessment
🔧
Specialist
Hardware & Firmware Assessment

Rip open an IoT gadget's secrets.

▶ GUIDED

Extract firmware from an IoT device, identify embedded credentials, reverse engineer a binary, and document findings.

firmwareiotreverse-engineering
~45 min firmware
Be a Vulnerability Assessment Analyst
📡Threat Intel
📡
Specialist
DNS Tunneling Detection & Response

Catch spies sneaking data out through DNS.

▶ GUIDED

Detect DNS tunneling with pcap analysis, hunt for C2 beaconing, and map findings to MITRE ATT&CK.

dns-tunnelingc2threat-hunting+1
~45 min dns-tunneling
Be a Threat/Warning Analyst
📡Threat Intel
🔬
Specialist
Malware Reverse Engineering

Take a virus apart, line by line.

▶ GUIDED

Perform static and dynamic reverse engineering of a .NET malware dropper using dnSpy, identify capabilities and C2 logic.

reverse-engineeringmalwarednspy
~45 min reverse-engineering
Be a Threat/Warning Analyst
📡Threat Intel
🦌
Specialist
Threat Hunting with ELK

Hunt Cobalt Strike beacons in Elastic.

▶ GUIDED

Use Elastic Security to build hunting queries for Cobalt Strike beacons, write detection rules, and tune false positives.

elkcobalt-strikethreat-hunting
~45 min elk
Be a Threat/Warning Analyst
📡Threat Intel
💣
Specialist
Ransomware Campaign Analysis

Dissect a real ransomware crew's playbook.

▶ GUIDED

Analyze a ransomware campaign from initial access to encryption: identify the group, TTPs, and defensive recommendations.

ransomware-analysiscampaignttp
~45 min ransomware-analysis
Be a Threat/Warning Analyst
📡Threat Intel
🤖
Specialist
Automated Detection Engineering

Build a pipeline that tests its own alarms.

▶ GUIDED

Build an automated detection pipeline using Sigma, ATT&CK, and SIEM to continuously test and improve detection coverage.

sigmadetection-engineeringautomation
~45 min sigma
Be a Threat/Warning Analyst
🛡️Cyber Defense
⚙️
Specialist
OT/ICS — SCADA Network Defense

Defend a power plant's control network.

▶ GUIDED

Detect unauthorized Modbus write commands, segment the SCADA network, and apply ICS-specific firewall rules.

oticsscada+1
~45 min ot
Be a Cyber Defense Analyst
🛡️Cyber Defense
Specialist
SIEM Engineering — Advanced Use Cases

Write the rules that catch the sneakiest attacks.

▶ GUIDED

Build multi-phase correlation rules in Splunk ES for living-off-the-land attacks, data exfiltration, and credential theft.

splunk-escorrelationadvanced-detection
~45 min splunk-es
Be a Cyber Defense Analyst
🛡️Cyber Defense
🍯
Specialist
Deception Technology Deployment

Set traps and watch attackers fall in.

▶ GUIDED

Deploy honeypots and canary tokens across the network, configure alerts, and analyze attacker behavior on deception assets.

honeypotcanary-tokendeception
~45 min honeypot
Be a Cyber Defense Analyst
🛡️Cyber Defense
🎫
Specialist
Kerberos Attack Detection

Spot the telltale signs of ticket theft.

▶ GUIDED

Detect Kerberoasting, AS-REP Roasting, and Silver Ticket attacks through Windows Security events and network traffic.

kerberoskerberoastingdetection
~45 min kerberos
Be a Cyber Defense Analyst
🛡️Cyber Defense
💜
Specialist
Purple Team Exercise

Attack and defend at the same time.

▶ GUIDED

Coordinate with a red team: pre-agree TTPs, execute attacks, verify detections, identify coverage gaps, and improve rules.

purple-teamdetection-gapcollaborative
~45 min purple-team
Be a Cyber Defense Analyst
🔍Digital Forensics
💾
Specialist
Disk & Network Forensics

Rebuild a breach from disk and wire.

▶ GUIDED

Forensically image an isolated workstation, analyze the filesystem for artifacts, and reconstruct breach timeline from PCAP.

disk-forensicspcaptimeline
~45 min disk-forensics
Be a Digital Forensics Analyst
🔍Digital Forensics
🕳️
Specialist
Anti-Forensics Detection

Catch the hacker who tried to cover their tracks.

▶ GUIDED

Identify timestomping, log clearing, and file shredding artifacts, and recover evidence despite anti-forensics techniques.

anti-forensicstimestompingrecovery
~45 min anti-forensics
Be a Digital Forensics Analyst
🔍Digital Forensics
🧠
Specialist
Advanced Memory Analysis

Pull a live implant out of RAM.

▶ GUIDED

Extract C2 implant from process memory, dump encryption keys, and reconstruct decrypted network communications.

memory-forensicsc2decryption
~45 min memory-forensics
Be a Digital Forensics Analyst
🔍Digital Forensics
🐧
Specialist
Linux Forensics Investigation

Investigate a pwned Linux server.

▶ GUIDED

Investigate a compromised Linux server: analyze bash history, cron jobs, SUID binaries, and kernel module persistence.

linux-forensicspersistencerootkit
~45 min linux-forensics
Be a Digital Forensics Analyst
🔍Digital Forensics
☁️
Specialist
Cloud Forensics — AWS

Snapshot and dissect a hacked cloud server.

▶ GUIDED

Collect forensic evidence from a compromised EC2 instance: snapshot EBS, analyze VPC flow logs, and query CloudTrail.

cloud-forensicsawsec2+1
~45 min cloud-forensics
Be a Digital Forensics Analyst
📐Architecture
🏛️
Specialist
Zero Trust Full Implementation

Roll out zero trust across a whole company.

▶ GUIDED

Implement full micro-segmentation, integrate SASE, and deploy continuous verification across the enterprise.

zero-trustsasemicrosegmentation
~45 min zero-trust
Be a Security Architect
📐Architecture
🌐
Specialist
Secure SD-WAN Design

Design encrypted links for a branch network.

▶ GUIDED

Design a secure SD-WAN deployment with encrypted overlays, centralized policy management, and anomaly detection integration.

sd-wanencrypted-overlaypolicy
~45 min sd-wan
Be a Security Architect
📐Architecture
🔑
Specialist
Identity Fabric Architecture

Unify every login under one smart gate.

▶ GUIDED

Design a unified identity fabric across on-premises AD, Azure AD, and external IdPs with conditional access policies.

identity-fabricfederationconditional-access
~45 min identity-fabric
Be a Security Architect
📐Architecture
🏗️
Specialist
SIEM Architecture Design

Architect the brain that eats all the logs.

▶ GUIDED

Design an enterprise SIEM ingestion pipeline: log sources, normalization, correlation, and long-term storage tiers.

siem-architecturepipelinenormalization
~45 min siem-architecture
Be a Security Architect
📐Architecture
🔐
Specialist
Cryptographic Architecture Review

Future-proof the company's encryption.

▶ GUIDED

Audit enterprise cryptographic standards, identify deprecated algorithms, design a migration to post-quantum-ready algorithms.

cryptographypost-quantummigration
~45 min cryptography
Be a Security Architect
🏴Cyber Offense
🎭
Specialist
Full Red Team Engagement

Run a complete attack from phish to theft.

Execute a full red team operation: initial access via spear-phishing, establish persistence, lateral movement, and data exfiltration.

red-teamfull-engagementexfiltration
~45 min red-team
Be a Cyber Operator
Coming Soon
🏴Cyber Offense
👻
Specialist
Evasion Techniques Lab

Sneak past the antivirus like a ghost.

Bypass AV/EDR using custom loaders, reflective injection, and process hollowing. Measure evasion effectiveness.

evasionedr-bypassprocess-hollowing
~45 min evasion
Be a Cyber Operator
Coming Soon
🏴Cyber Offense
🏴
Specialist
Adversarial Simulation — FIN7

Mimic a real financial hacking crew.

Simulate FIN7 TTPs: spear-phish, CARBANAK loader, persistence via COM hijacking, and financial data exfiltration.

fin7carbanaksimulation
~45 min fin7
Be a Cyber Operator
Coming Soon
🏴Cyber Offense
🚪
Specialist
Physical Security & Social Engineering

Clone a badge and talk your way in.

Simulate a physical intrusion: badge cloning, tailgating assessment, and USB drop attack simulation.

physical-securitysocial-engineeringusb-drop
~45 min physical-security
Be a Cyber Operator
Coming Soon
🏴Cyber Offense
⚙️
Specialist
OT/ICS Red Team

Attack a factory's control systems.

Assess an OT network: enumerate Modbus/DNP3 devices, replay control commands, identify safety system vulnerabilities.

ics-red-teammodbusscada
~45 min ics-red-team
Be a Cyber Operator
Coming Soon
🌐Networking
🚦
Specialist
BGP Hijack Detection & Response

Catch the internet's roads being stolen.

Detect a BGP route hijack in real time, validate RPKI, implement emergency prefix withdrawal, and notify upstream.

bgp-hijackrpkiemergency-response
~45 min bgp-hijack
Be a Network Operations Specialist
Coming Soon
🌐Networking
🌊
Specialist
DDoS Mitigation at Scale

Survive a massive flood of junk traffic.

Implement BGP Flowspec, RTBH, and scrubbing center policies to mitigate a multi-vector volumetric DDoS attack.

ddos-mitigationflowspecrtbh
~45 min ddos-mitigation
Be a Network Operations Specialist
Coming Soon
🌐Networking
🤖
Specialist
Network Automation Security

Lock down the bots that run the network.

Secure network automation pipelines using Ansible Vault, signed playbooks, and read-only API tokens for network devices.

automation-securityansibleapi-security
~45 min automation-security
Be a Network Operations Specialist
Coming Soon
🌐Networking
🔍
Specialist
Encrypted Traffic Analysis

Spot bad TLS traffic without decrypting it.

Use JA3/JA3S, HASSH, and SSL certificate anomalies to identify malicious TLS without decryption.

tls-analysisja3encrypted-traffic
~45 min tls-analysis
Be a Network Operations Specialist
Coming Soon
🌐Networking
🐳
Specialist
Kubernetes Network Policy Hardening

Wall off the pods in a Kubernetes cluster.

Define and test Kubernetes NetworkPolicy rules to restrict pod-to-pod communication and egress in a production cluster.

kubernetesnetwork-policypod-security
~45 min kubernetes
Be a Network Operations Specialist
Coming Soon
📐Architecture
🏛️
Legend
Zero Trust Architecture Implementation

Build zero trust from blueprint to live.

Design and implement full microsegmentation for the server farm, deploy cloud S3 security, and validate with penetration testing.

zero-trustcloudarchitecture+1
~60 min zero-trust
Be a Security Architect
Coming Soon
📐Architecture
🏢
Legend
Enterprise Security Transformation

Lead a multi-year security overhaul.

Lead a multi-year security transformation program: security architecture, roadmap, governance model, and board presentation.

transformationgovernanceciso
~60 min transformation
Be a Security Architect
Coming Soon
📐Architecture
🌀
Legend
Resilience Engineering

Stress-test defenses until they bend, not break.

Design chaos engineering tests for security controls, validate resilience under simulated attack conditions and partial failures.

chaos-engineeringresiliencesecurity-validation
~60 min chaos-engineering
Be a Security Architect
Coming Soon
📐Architecture
⚛️
Legend
Post-Quantum Cryptography Migration

Prep the company for the quantum age.

Plan and pilot a migration from RSA/ECC to CRYSTALS-Kyber and CRYSTALS-Dilithium across an enterprise PKI.

post-quantumpki-migrationnist-pqc
~60 min post-quantum
Be a Security Architect
Coming Soon
📐Architecture
🤖
Legend
AI/ML Security in Architecture

Defend the AI the SOC relies on.

Integrate AI/ML-based anomaly detection into the SOC architecture, addressing model poisoning and adversarial input risks.

ai-securitymlmodel-poisoning
~60 min ai-security
Be a Security Architect
Coming Soon
🏴Cyber Offense
🎯
Legend
APT Hunt — Full Kill Chain

Hunt a nation-state across the whole kill chain.

Hunt for APT indicators across all systems: LOLBin abuse, credential dumping, lateral movement, exfiltration. Full ATT&CK mapping.

aptthreat-huntingkill-chain+2
~60 min apt
Be a Threat/Warning Analyst
Coming Soon
🏴Cyber Offense
🌍
Legend
Nation-State Attribution Analysis

Name the hacking crew behind the breach.

Analyze malware, infrastructure, and TTPs to attribute an intrusion to a known nation-state group with confidence scoring.

attributionnation-stateconfidence-scoring
~60 min attribution
Be a Threat/Warning Analyst
Coming Soon
🏴Cyber Offense
🌐
Legend
Strategic Intelligence Forecasting

Predict next quarter's cyber threats.

Produce a 6-month threat forecast for a critical infrastructure sector using geopolitical intelligence and historical TTP data.

strategic-intelforecastinggeopolitical
~60 min strategic-intel
Be a Threat/Warning Analyst
Coming Soon
🏴Cyber Offense
💀
Legend
Zero-Day Vulnerability Research

Build a working exploit for a fresh bug.

Research and develop a proof-of-concept exploit for a memory corruption vulnerability in a network service (controlled lab).

zero-dayvulnerability-researchexploit-dev
~60 min zero-day
Be a Threat/Warning Analyst
Coming Soon
🏴Cyber Offense
🍯
Legend
Deception Operations Planning

Run a company-wide honeynet sting.

Design an enterprise-wide deception campaign with honeynets, breadcrumbs, and canary documents. Measure attacker interaction.

deceptionhoneynetbreadcrumbs
~60 min deception
Be a Threat/Warning Analyst
Coming Soon
🚨Incident Response
🔴🔵
Legend
Red vs Blue — Full Range Exercise

Attack, then flip sides and defend.

Combined offense and defense: exploit vulnerabilities, establish persistence, then switch to defender role to detect and eradicate.

red-teamblue-teamfull-exercise+1
~60 min red-team
Be a Cyber Defense Incident Responder
Coming Soon
🚨Incident Response
🆘
Legend
Nation-State Intrusion Response

Lead the response to a state-sponsored breach.

Lead a whole-of-enterprise response to an active nation-state intrusion: crisis management, legal coordination, and public disclosure.

nation-statecrisis-managementdisclosure
~60 min nation-state
Be a Cyber Defense Incident Responder
Coming Soon
🚨Incident Response
💥
Legend
Wiper Malware Response

Recover from an attack meant to destroy.

Respond to a destructive wiper attack targeting OT and IT networks simultaneously. Coordinate recovery across business units.

wiperdestructive-attackot-it-convergence
~60 min wiper
Be a Cyber Defense Incident Responder
Coming Soon
🚨Incident Response
🔧
Legend
Ransomware Full Recovery

Guide a company through ransomware to rebuild.

Lead full ransomware recovery: negotiation documentation, decryption key management, system rebuild, and lessons learned.

ransomware-recoverydecryptionrebuild
~60 min ransomware-recovery
Be a Cyber Defense Incident Responder
Coming Soon
🚨Incident Response
🏛️
Legend
CISA-Style Cybersecurity Tabletop

Run the war room for a critical-infrastructure drill.

Facilitate a multi-agency cybersecurity tabletop exercise simulating a critical infrastructure attack with cross-sector coordination.

tabletopcritical-infrastructurecross-sector
~60 min tabletop
Be a Cyber Defense Incident Responder
Coming Soon
🏴Cyber Offense
⚙️
Legend
Custom Implant Development

Code your own stealthy command-and-control tool.

Develop a fully custom C2 implant in C/C++ with encrypted comms, anti-analysis features, and automated tasking.

implant-developmentc2malware-dev
~60 min implant-development
Be a Cyber Operator
Coming Soon
🏴Cyber Offense
🏭
Legend
ICS/SCADA Exploitation

Hack a PLC and flip the switches.

Exploit vulnerabilities in HMI software and PLCs, modify ladder logic, and demonstrate impact in a controlled ICS environment.

ics-exploitationplchmi+1
~60 min ics-exploitation
Be a Cyber Operator
Coming Soon
🏴Cyber Offense
👑
Legend
Active Directory Persistence Research

Invent new ways to stay hidden in AD.

Research and demonstrate novel AD persistence techniques: AdminSDHolder abuse, DSRM backdoor, and SID history injection.

ad-persistencesid-historydsrm
~60 min ad-persistence
Be a Cyber Operator
Coming Soon
🏴Cyber Offense
🔌
Legend
Firmware Extraction & Analysis

Pull firmware off a chip and patch it.

Extract firmware via JTAG/UART, identify hardcoded credentials, and develop a firmware patch to remediate the vulnerability.

jtaguartfirmware-extraction
~60 min jtag
Be a Cyber Operator
Coming Soon
🏴Cyber Offense
Legend
Full Kill Chain Simulation — Critical Infrastructure

Simulate a full attack on a power grid.

Simulate an end-to-end APT attack on a power grid: initial access, persistence in IT, IT/OT pivot, and impact demonstration.

critical-infrastructurepower-gridapt-simulation
~60 min critical-infrastructure
Be a Cyber Operator
Coming Soon
🔍Digital Forensics
🌍
Legend
Multi-Jurisdictional Cyber Investigation

Run a forensic case across borders.

Lead a forensic investigation spanning cloud, on-premises, and international assets with legal hold coordination.

multi-jurisdictionlegal-holdinvestigation
~60 min multi-jurisdiction
Be a Digital Forensics Analyst
Coming Soon
🔍Digital Forensics
🦠
Legend
Rootkit Analysis & Detection

Hunt a kernel rootkit in memory.

Analyze a kernel-level rootkit using memory forensics, identify hooks, and develop detection signatures.

rootkitkernelmemory-forensics
~60 min rootkit
Be a Digital Forensics Analyst
Coming Soon
🔍Digital Forensics
📦
Legend
Supply Chain Forensics

Trace a backdoor through a build pipeline.

Investigate a compromised open-source dependency: trace build pipeline, identify tampered artifacts, scope affected systems.

supply-chainbuild-pipelineartifact-forensics
~60 min supply-chain
Be a Digital Forensics Analyst
Coming Soon
🔍Digital Forensics
⚖️
Legend
Expert Witness Report Preparation

Write the report you'd defend in court.

Prepare a forensic report suitable for court testimony, including methodology, chain of custody, and expert opinion sections.

expert-witnesscourt-reporttestimony
~60 min expert-witness
Be a Digital Forensics Analyst
Coming Soon
🔍Digital Forensics
💰
Legend
Blockchain & Cryptocurrency Forensics

Follow stolen crypto through mixers.

Trace cryptocurrency transactions through mixing services using on-chain analysis tools to recover stolen funds.

blockchain-forensicscrypto-tracingchainalysis
~60 min blockchain-forensics
Be a Digital Forensics Analyst
Coming Soon
🌐Networking
🏗️
Legend
Enterprise Firewall Architecture

Architect a multi-firewall fortress.

Design and implement a multi-vendor firewall architecture with ECMP, high availability, and unified policy management.

firewall-architecturehaecmp
~60 min firewall-architecture
Be a Cyber Defense Infrastructure Support Specialist
Coming Soon
🌐Networking
📡
Legend
5G Network Security Hardening

Harden a 5G core against attack.

Evaluate and harden a 5G SA core network: protect N interfaces, implement network slicing security, and audit SBI exposure.

5gnetwork-slicingcore-hardening
~60 min 5g
Be a Cyber Defense Infrastructure Support Specialist
Coming Soon
🌐Networking
🔗
Legend
MPLS Security Assessment

Test the seams of an MPLS VPN.

Assess MPLS VPN security: test label spoofing, BGP route injection, and unauthorized inter-VRF routing.

mplsvpn-securityvrf
~60 min mpls
Be a Cyber Defense Infrastructure Support Specialist
Coming Soon
🌐Networking
🏭
Legend
OT Network Security Architecture

Design defense-in-depth for a factory.

Design a defense-in-depth OT/ICS security architecture using Purdue model, unidirectional gateways, and OT-specific IDS.

ot-architecturepurdue-modelunidirectional-gateway
~60 min ot-architecture
Be a Cyber Defense Infrastructure Support Specialist
Coming Soon
🌐Networking
🎯
Legend
XDR Platform Integration

Wire every signal into one XDR brain.

Integrate an XDR platform across endpoint, network, cloud, and identity telemetry sources. Build and test expert-level playbooks.

xdrintegrationplaybooks
~60 min xdr
Be a Cyber Defense Infrastructure Support Specialist
Coming Soon
🐞Vuln Assessment
📋
Legend
Offensive Security Program Management

Run an entire red team program.

Build and manage an enterprise red team program: rules of engagement, risk frameworks, reporting standards, and metrics.

red-team-programroemetrics
~60 min red-team-program
Be a Vulnerability Assessment Analyst
Coming Soon
🐞Vuln Assessment
🔬
Legend
CVE Research & Responsible Disclosure

Find a bug, report it, earn a CVE.

Discover a vulnerability in open-source software, write a PoC, coordinate responsible disclosure, and publish a CVE.

cve-researchdisclosurepoc
~60 min cve-research
Be a Vulnerability Assessment Analyst
Coming Soon
🐞Vuln Assessment
🗺️
Legend
Continuous Threat Exposure Management

Run always-on attack surface management.

Implement CTEM: attack surface discovery, attack path simulation, exposure prioritization, and automated remediation workflows.

ctemattack-surfaceexposure-management
~60 min ctem
Be a Vulnerability Assessment Analyst
Coming Soon
🐞Vuln Assessment
💰
Legend
Bug Bounty Program Architecture

Launch a bug bounty from scratch.

Design and launch a bug bounty program: scope definition, triage processes, reward structure, and researcher communication.

bug-bountyvdpprogram-design
~60 min bug-bounty
Be a Vulnerability Assessment Analyst
Coming Soon
🐞Vuln Assessment
🥊
Legend
Red Team vs Active Defense

Pit red against active defense and measure who wins.

Pit red team against a blue team with active defense capabilities (deception, EDR, NDR) — measure dwell time and detection rates.

red-teamactive-defensedwell-time
~60 min red-team
Be a Vulnerability Assessment Analyst
Coming Soon