BTLO training investigations
Technical Write-ups
14 investigations showing the evidence, queries, and reasoning behind each lab answer. These document training exercises, not production incidents.
No investigations match your filters.
Try another term or clear the filters to see all investigations.
Digital Forensics
3Indicators
The lab hands you one file, sh4, pulled off a compromised Windows server, and asks twelve questions about it.
Steam
Split VMware disks reveal a Linux Steam install hidden in a snap package path, with forensic clues spread across the image.
Sticky Situation
One disk image, ten questions, and a USB stick that left its traces all over the Windows registry.
Incident Response
3A PrintNightmare run against a Windows print spooler, told through one pcap and two event logs.
Spilled Bucket
Two AWS log sources, one Splunk instance, and an attack chain that keeps handing you the next question.
Splunk It
One malicious Invoice document, and the whole attack chain sits inside a single Splunk index.
Phishing Analysis
1Security Operations
4Blocker
Sysmon 14's FileBlockExecutable blocks suspicious executables before they reach disk; this lab traces Event ID 27 and builds detection rules.
Phishy
A single fake Office login page, and eight questions answered without leaving the browser.
Piggy
Four PCAPs reveal SSH data exfiltration, Trickbot command and control, cryptomining on unusual ports, and DNS tunneling.
Vortex
One PCAP traces a gift-card lure, a stealer's HTTP callback, and stolen credentials sent in cleartext over SMTP.
Threat Hunting
2BOTS v1
A Splunk CTF rather than a guided lab: fifteen questions against the BOTS v1 index, where the only way through is knowing which sourcetype holds the answer.
Drilldown
A Splunk hunt follows unusual EC2 traffic from a web server through Sysmon, Suricata, VirusTotal, and a Joomla payload upload.