CyberDefenders
CyberDefenders
Access and status
Cost
Partly free
Part of it is free and part is not. The entry says which part; read that before you plan around it.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
Who it is for, and when
It is the easiest way to get graded reps on realistic evidence without building an environment: you download the artefacts, work them with your own tools, and the questions tell you whether you actually found the right thing. The cloud and detection-engineering tracks cover ground that the older public corpora do not.
What it does not cover
Part of the catalogue is marked PREMIUM and needs a paid account; the site does not publish its prices on the challenge listing, so check before assuming a lab is open. The question-and-answer format rewards finding a specific string and teaches nothing about scoping, reporting or defending an opinion.
Go to the source
Open at cyberdefenders.org (opens in a new tab)https://cyberdefenders.org/blueteam-ctf-challenges/
Details
- Type
- Dataset
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Publisher
- CyberDefenders
- Topics
- ctf, training, incident-response, threat-hunting, network, malware, cloud
- Checked at source
Related entries
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
A daily handler diary — distinct from the SANS DFIR blog — in which a rotating roster of volunteer handlers writes up whatever they are currently seeing in honeypot data, malware samples, exploit traffic and log telemetry.
Two complementary open-source network monitoring engines, both actively released. Zeek (formerly Bro) turns traffic into structured, protocol-aware logs — connections, HTTP requests, DNS queries, TLS handshakes, files seen — using its own scripting language. Suricata, from OISF, is a signature and rule-driven IDS/IPS that also produces rich EVE JSON records and can extract files.
Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.
FIRST Conference
PaidThe annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.