Notes on CTF Platforms


These are some quick notes on how various CTF platforms work and their rules.

Blue Team Labs Online (BTLO)

Labs

  • Only blue team related labs
  • First-Blood (FB) refers to the first Defender to finish the lab, after launch
  • Lab types
    • Investigations
      • fully browser-based lab scenarios that require no setup or configuration
      • designed to replicate the kind of defensive work carried out in real-world security roles
    • Challenges
      • hands-on tasks that you download and complete on your local system or within a virtual machine
  • Categories
    • Incident Response — scenarios simulating real-world incidents
    • Digital Forensics — forensic investigation and evidence analysis tasks
    • Security Operations — challenges reflecting day-to-day security operations
    • Reverse Engineering — decoding and reverse engineering applications
    • CTF-Like Challenges — Capture the Flag style problem-solving scenarios
    • OSINT — intelligence gathering from publicly available sources
    • Threat Hunting — identifying and mitigating threats in simulated environments
    • Threat Intelligence — threat analysis and intelligence gathering scenarios

Lab Access

Free AccountPro Subscription
Active Investigations (15 labs)YesYes
Lab Hours10 hoursUnlimited
Retired InvestigationsNoYes
Retired ChallengesNoYes
  • There are 15 active labs at any one time
    • all free to play
    • split across difficulty levels
      • 3 Very Easy
      • 4 Easy
      • 4 Medium
      • 3 Hard
      • 1 Epic
  • Labs are rotated regularly, then retired into BTLO Pro
    • when a new lab is released within a difficulty level, the oldest lab in that category is retired
    • completed labs will be visible
  • Write-ups can only be published for retired content
  • Community authored content is no longer accepted, only idea submissions

Leaderboard / Scoring

  • Leaderboard points are only earned on the 15 free labs
  • Scoring is scaled depending on difficulty
    • Very Easy: up to 15 points
    • Easy: up to 25 points
    • Medium: up to 50 points
    • Hard: up to 100 points
    • Epic: up to 130 points

TryHackMe

Labs

  • Blue, red, and purple team related labs
  • Room Types
    • Challenges
      • no guidance
    • Walkthroughs
      • guided teaching
    • Network
      • more complex lab networked environments for Active Directory and corporate environment learning
  • Usage
    • Rooms can contain an:
      • Attack Box
        • not always need
        • Cloud hosted machine used to complete labs
        • Can use your own VM with VPN as alternative
      • Lab
        • This contains the lab setup that the attack box will access/connect to
  • Difficulty levels
    • Easy
    • Medium
    • Hard
    • Insane

Lab Access

  • Some labs are free tier, others require subscription

Scoring

  • earn points by completing rooms
  • points are earned by difficulty
    • challenge rooms generally more difficult than walkthrough rooms
    • also difficulty label
  • complete walkthrough room in the same month as release awards:
    • 25% of available points to account for Monthly and All-time leaderboards
  • complete walkthrough older than a month only awards:
    • 25% of the points towards All-time, not monthly leaderboards
  • challenge rooms
    • complete in same month as release for 100% of points towards both monthly and all-time leaderboards
    • otherwise will grant 100% of points to all-time, but only 25% to monthly

CyberDefenders

Labs

  • Only blue team focused
  • Types
    • Active
      • no walkthroughs or hints
      • earn leaderboard points
      • represent the latest real-world challenges
    • Retired
      • include walkthroughs and hints
      • no points, focus more on learning than competing
      • integrate educational-mode feature
        • ideal for beginners
        • offer structured, step-by-step learning
  • Trial labs
    • users get 5hrs of free access to select pro labs
  • Access types
    • Cloud labs
      • run entirely in cloud, no setup required
      • open in browser
    • Downloadable labs
      • download the full lab artifacts for local machine
  • Pro vs Free Labs
    • Free
      • available to all users no cost
    • Pro
      • only subscribers
      • can have enhanced browser-based lab experience
        • multi-regional servers for optimal performance
      • more complex and advanced scenarios
  • Categories
    • Threat hunting
      • refine threat detection skills using SIEM platforms
        • Splunk, Elastic, QRadar, Graylog, Arkime
    • Endpoint forensics
      • focus on analysis of host artifacts
      • broad spectrum
        • windows forensics
        • linux forensics
        • mobile forensics
        • memory dump analysis
    • Network forensics
      • focus on analyzing network data flows to trace adversarial activities
      • use tools such as Wireshark, Network Miner, Brim, etc.
    • Malware analysis
      • focus reverse engineering, static and dynamic analysis, and sandboxing
      • essential for understanding the behavior and impact of malware on systems
    • Threat intel
      • focuses on the process of collecting and analyzing information about potential adversaries
      • examine threat feeds, indicators of compromise (IOCs), studies on advanced persistent threats (APTs), and application of intel for defensive strategies
    • Detection Engineering
      • focus on creating and testing detection rules using tools like YARA and Sigma
    • Cloud forensics
      • focus on AWS, Azure, and GCP
      • analyze raw and processes logs with Splunk and Elastic SIEM

Write-Ups

  • can submit for retired labs only
  • aka walkthroughs
  • guidelines
    • focus on guiding rather than revealing direct answers
    • consider blurring answer or displaying only a portion
    • must reference a link to cyberdefenders.org

HackTheBox

  • more red team oriented, but has expanded blue team content
  • acquired LetsDefend
    • I personally don’t think LetsDefend is good, but I think HTB will improve it

Labs

  • Types
    • Machines
      • red team labs
      • are instances of vulnerable virtual machines
      • host different operating systems (such as Linux, Windows, and FreeBSD)
      • difficulty levels:
        1. Easy
        2. Medium
        3. Hard
        4. Insane
      • Tiers
        • Active
          • currently active and freely available
        • Retired
          • rotating shortlist of retired machines for free users
          • VIP+ exclusive access machines
    • Challenges
      • bite-sized applications designed for practicing specific penetration testing techniques
      • blue and red team
      • difficulty:
        1. Very Easy
        2. Easy
        3. Medium
        4. Hard
        5. Insane
      • Categories
        • Reversing
          • focus on reverse engineering
          • need to find out what a certain script or program does to find the flag
        • Misc
          • variety of content that don’t fit other categories
        • Stego
          • focus on finding or embedding hidden messages in plain-looking objects
        • Crypto
          • focuses on cryptographic functions
          • decrypting objects to find flag
        • Web
          • focus on web-based applications
          • need to detect, exploit, and search through vulnerable applications
        • Forensics
          • focus on data recovery and forensics
          • need to inspect small details in recovery data batches to discover what happened to target system
        • OSINT
          • focus on publicly available data farming
          • learn how to laterally move between search engine algorithms to find missing information
        • Pwn
          • focus on binary exploitation and memory corruption
          • create exploits that manipulate system memory to retrieve flag
        • Mobile
          • focus on handheld devices
          • analyze intrinsics of mobile apps to find hidden embedded functionalities and flags
        • Hardware
          • focus on penetrating different hardware systems
          • analyze attack methodologies for physical objects in everyday life
      • States
        • Active
          • no walkthroughs allowed to be published
          • completion rewards points based on difficulty
            • easy: 10-30 points
            • medium: 40-50 points
            • hard: 50-100 points
        • Retired
          • offer no points
          • good tool to learn about specific categories
      • How to play
        • need to download files provided as archive
        • some may require Docker container
    • Sherlocks
      • defensive investigatory scenarios designed to replicate real-life scenarios
      • Categories
        • DFIR
        • SOC
        • Malware Analysis
        • Threat Hunting
        • Threat Intelligence
        • Cloud
      • Difficulties
        • Easy
        • Medium
        • Hard
        • Insane
      • How to play
        • download investigation package
          • zip file with password
          • password is always hacktheblue
        • review contents in secure isolated environment
          • may contain real malware!
        • answer tasks
      • Playing Modes
        • Linear
          • answer investigatory question successfully unlocks the next
        • Free-flow
          • answer questions in any order
    • Fortresses
  • Access
    • use a dedicated machine/VM
      • Linux highly recommended
    • Use OpenVPN to create a link between local machine and lab machine
    • download a VPN config file that auto-configures your OpenVPN client
      • called VPN packs or VPN files
      • this places you in same IP subnet as vuln machines
      • download a VPN config pack based on lab type (machine, starting point, fortresses, etc.)
    • require:
      • latest version of openvpn
        • included in Kali and Parrot
    • sudo openvpn [your_filename].ovpn to connect to VPN

Content Sharing

  • You are permitted to upload, stream videos, and publish solutions only for HTB Free Academy Courses or specific retired Hack The Box content.
  • List of allowed Hack The Box content for publication:
    • Retired Machines
    • Retired Sherlocks
    • Retired Challenges
    • Starting Point Machines
    • Tier 0 Academy Modules
    • Mini Pro Labs that currently have available write-ups on the platform (specifically: POO, Xen, Ascension, RPG, and Hades).
  • Cannot share content on:
    • Pro labs, active machines, active challenges
  • Do not spoil active content