Skip to main content

Blue Team · Scenario Lab

Trace the system.
Explain the decision.

Move through 24 practical journeys: see how the technology connects, switch between normal, failure and attack overlays, and read the evidence each step leaves behind.

Start the power-on journey
  1. TraceSee every dependency
  2. OverlaysNormal, failure and attack
  3. EvidenceWhat each step leaves behind

6 practice packs

Choose a system journey.

24 scenarios

Systems and access · 35 minPower-on to an enterprise website

Trace a managed PC from electrical reset through firmware, network and domain identity to DNS, BGP, TLS, WAF, application and database.

17 decision points
Systems and access · 24 minWindows domain sign-in and Group Policy

Follow DC discovery, machine trust, user authentication, access-token creation and policy application on a Windows endpoint.

6 decision points
Systems and access · 22 minLinux boot to an exposed service

Trace a Linux server from firmware and kernel initialisation through systemd dependencies to a listening and logged network service.

5 decision points
Systems and access · 22 minVM provisioning and monitoring

Provision a virtual machine through the management plane, virtual network, approved image and security-control bootstrap.

5 decision points
Users and connectivity · 20 minWired enterprise onboarding

Connect a new managed device through link state, 802.1X, RADIUS policy, DHCP, DNS and domain discovery.

5 decision points
Users and connectivity · 22 minCorporate Wi-Fi and 802.1X

Join an enterprise wireless network, validate RADIUS identity and recognise an evil-twin diversion.

4 decision points
Users and connectivity · 24 minRemote worker through VPN to SaaS

Trace device posture, MFA, VPN routes and DNS through federated SaaS authentication and session audit.

5 decision points
Users and connectivity · 22 minMobile enrolment and corporate email

Follow a mobile device through MDM enrolment, compliance, certificate-backed access, SaaS identity and mailbox activity.

4 decision points
Network journeys · 25 minInternal client through proxy, NAT, firewalls and BGP

Separate local forwarding, enterprise policy and external route selection on a normal outbound web session.

7 decision points
Network journeys · 26 minPublic user through DNS, CDN, WAF and load balancer

Trace a public request through authoritative DNS, Internet routing, TLS and edge security to a selected application backend.

5 decision points
Network journeys · 22 minEmail authentication and delivery

Follow message submission, DNS-based sender authentication, filtering, delivery and mailbox audit evidence.

4 decision points
Network journeys · 25 minBranch routing failure

Diagnose link, OSPF, BGP, DNS and time dependencies without assuming every outage is an attack.

5 decision points
Applications and data · 25 minWeb session to database

Follow browser identity, session state, application authorisation, parameterised queries and database audit evidence.

4 decision points
Applications and data · 24 minAbused API and cloud token

Investigate a stolen cloud token crossing gateway, service authorisation and data-access boundaries.

5 decision points
Applications and data · 28 minCI/CD image to Kubernetes

Trace source and dependencies through a trusted build, registry admission, cluster identity and runtime telemetry.

4 decision points
Applications and data · 28 minBackup failure and ransomware recovery

Contain active ransomware safely, protect identity and backup control planes, determine clean scope and restore validated services in dependency order.

5 decision points
SecOps investigations · 25 minAlert through SIEM, SOAR and case queue

Trace raw telemetry through collection, parsing, enrichment and detection into accountable analyst triage.

4 decision points
SecOps investigations · 26 minPhishing and BEC triage

Preserve a suspicious message, trace delivery and authentication, prove user action, scope identity impact and choose proportionate containment.

4 decision points
SecOps investigations · 28 minMalware execution, persistence and C2

Build a process and network timeline from initial execution through persistence and command-and-control.

5 decision points
SecOps investigations · 30 minKerberos, NTLM and LDAP identity compromise

Separate ticketing, compatibility authentication and directory access while investigating credential and privilege abuse.

5 decision points
Risk and resilience · 24 minVulnerability to risk treatment and remediation

Move from a scanner finding to validated exposure, business impact, treatment, control testing and residual risk.

3 decision points
Risk and resilience · 26 minEvil twin and DNS poisoning

Investigate a wireless lookalike, weak server validation, rogue DHCP and poisoned name resolution.

5 decision points
Risk and resilience · 30 minData exfiltration and privacy response

Correlate identity, data and network evidence, contain safely and translate technical scope into privacy and partner decisions.

5 decision points
Risk and resilience · 30 minThird-party incident and collection gaps

Scope a supplier compromise when direct telemetry is incomplete and reporting duties cross organisational boundaries.

5 decision points

Coverage map

Every baseline area has somewhere to learn and practise.

28 explicit knowledge requirements are validated against Learn and Scenario Lab during every build.