Blue Team · Scenario Lab
Trace the system.
Explain the decision.
Move through 24 practical journeys: see how the technology connects, switch between normal, failure and attack overlays, and read the evidence each step leaves behind.
Start the power-on journey- TraceSee every dependency
- OverlaysNormal, failure and attack
- EvidenceWhat each step leaves behind
6 practice packs
Choose a system journey.
24 scenarios
Trace a managed PC from electrical reset through firmware, network and domain identity to DNS, BGP, TLS, WAF, application and database.
17 decision pointsWindows domain sign-in and Group PolicyFollow DC discovery, machine trust, user authentication, access-token creation and policy application on a Windows endpoint.
6 decision pointsLinux boot to an exposed serviceTrace a Linux server from firmware and kernel initialisation through systemd dependencies to a listening and logged network service.
5 decision pointsVM provisioning and monitoringProvision a virtual machine through the management plane, virtual network, approved image and security-control bootstrap.
5 decision pointsWired enterprise onboardingConnect a new managed device through link state, 802.1X, RADIUS policy, DHCP, DNS and domain discovery.
5 decision pointsCorporate Wi-Fi and 802.1XJoin an enterprise wireless network, validate RADIUS identity and recognise an evil-twin diversion.
4 decision pointsRemote worker through VPN to SaaSTrace device posture, MFA, VPN routes and DNS through federated SaaS authentication and session audit.
5 decision pointsMobile enrolment and corporate emailFollow a mobile device through MDM enrolment, compliance, certificate-backed access, SaaS identity and mailbox activity.
4 decision pointsInternal client through proxy, NAT, firewalls and BGPSeparate local forwarding, enterprise policy and external route selection on a normal outbound web session.
7 decision pointsPublic user through DNS, CDN, WAF and load balancerTrace a public request through authoritative DNS, Internet routing, TLS and edge security to a selected application backend.
5 decision pointsEmail authentication and deliveryFollow message submission, DNS-based sender authentication, filtering, delivery and mailbox audit evidence.
4 decision pointsBranch routing failureDiagnose link, OSPF, BGP, DNS and time dependencies without assuming every outage is an attack.
5 decision pointsWeb session to databaseFollow browser identity, session state, application authorisation, parameterised queries and database audit evidence.
4 decision pointsAbused API and cloud tokenInvestigate a stolen cloud token crossing gateway, service authorisation and data-access boundaries.
5 decision pointsCI/CD image to KubernetesTrace source and dependencies through a trusted build, registry admission, cluster identity and runtime telemetry.
4 decision pointsBackup failure and ransomware recoveryContain active ransomware safely, protect identity and backup control planes, determine clean scope and restore validated services in dependency order.
5 decision pointsAlert through SIEM, SOAR and case queueTrace raw telemetry through collection, parsing, enrichment and detection into accountable analyst triage.
4 decision pointsPhishing and BEC triagePreserve a suspicious message, trace delivery and authentication, prove user action, scope identity impact and choose proportionate containment.
4 decision pointsMalware execution, persistence and C2Build a process and network timeline from initial execution through persistence and command-and-control.
5 decision pointsKerberos, NTLM and LDAP identity compromiseSeparate ticketing, compatibility authentication and directory access while investigating credential and privilege abuse.
5 decision pointsVulnerability to risk treatment and remediationMove from a scanner finding to validated exposure, business impact, treatment, control testing and residual risk.
3 decision pointsEvil twin and DNS poisoningInvestigate a wireless lookalike, weak server validation, rogue DHCP and poisoned name resolution.
5 decision pointsData exfiltration and privacy responseCorrelate identity, data and network evidence, contain safely and translate technical scope into privacy and partner decisions.
5 decision pointsThird-party incident and collection gapsScope a supplier compromise when direct telemetry is incomplete and reporting duties cross organisational boundaries.
5 decision pointsCoverage map
Every baseline area has somewhere to learn and practise.
28 explicit knowledge requirements are validated against Learn and Scenario Lab during every build.