Legal Cyber Academy
DatasetPartly freeCurrent

CyberDefenders

CyberDefenders

Access and status

Cost

Partly free

Part of it is free and part is not. The entry says which part; read that before you plan around it.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.

Who it is for, and when

It is the easiest way to get graded reps on realistic evidence without building an environment: you download the artefacts, work them with your own tools, and the questions tell you whether you actually found the right thing. The cloud and detection-engineering tracks cover ground that the older public corpora do not.

What it does not cover

Part of the catalogue is marked PREMIUM and needs a paid account; the site does not publish its prices on the challenge listing, so check before assuming a lab is open. The question-and-answer format rewards finding a specific string and teaches nothing about scoping, reporting or defending an opinion.

Go to the source

Open at cyberdefenders.org (opens in a new tab)

https://cyberdefenders.org/blueteam-ctf-challenges/

Details

Type
Dataset
Written for
New to the fieldWorking examinerNew to the field, Working examiner
Publisher
CyberDefenders
Topics
ctf, training, incident-response, threat-hunting, network, malware, cloud
Checked at source
  • A gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.

  • A daily handler diary — distinct from the SANS DFIR blog — in which a rotating roster of volunteer handlers writes up whatever they are currently seeing in honeypot data, malware samples, exploit traffic and log telemetry.

  • Two complementary open-source network monitoring engines, both actively released. Zeek (formerly Bro) turns traffic into structured, protocol-aware logs — connections, HTTP requests, DNS queries, TLS handshakes, files seen — using its own scripting language. Suricata, from OISF, is a signature and rule-driven IDS/IPS that also produces rich EVE JSON records and can extract files.

  • Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.

  • The annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.