Blue Team Labs Online
Centri
Access and status
Cost
Partly free
Part of it is free and part is not. The entry says which part; read that before you plan around it.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
Who it is for, and when
The split matters in practice: the challenges are free and can be worked offline with your own tooling, which makes them a cheap way to keep hands in; the paid investigations give you a dedicated lab instance with the tools already installed when you want to practise in a SIEM or on a live box. The site lists 272 investigations for paid members, and PRO is published at £15 for one month, £40.50 for three, £76.50 for six and £144 annually.
What it does not cover
The platform states it is aimed at people who already have experience with security tooling rather than beginners, and the free tier gives you challenges only — no lab instances. It is defensive operations practice, not legal or expert-witness work.
Go to the source
Open at blueteamlabs.online (opens in a new tab)https://blueteamlabs.online/
Details
- Type
- Dataset
- Written for
- Working examinerWorking examiner
- Publisher
- Centri
- Topics
- ctf, training, incident-response, threat-hunting, memory-forensics, network
- Checked at source
Related entries
CyberDefenders
Partly freeA blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.
13Cubed
Partly freeA YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.
FIRST Conference
PaidThe annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.
SANS DFIR Summit & Training
Partly freeSANS's annual practitioner summit, with the 2026 edition running 15-16 October 2026 at the Hilton Arlington Rosslyn in Arlington, Virginia, followed by SANS courses 17-22 October. Both the summit and the courses can be attended in person or virtually.