Notes on CTF Platforms
These are some quick notes on how various CTF platforms work and their rules.
Blue Team Labs Online (BTLO)
Labs
- Only blue team related labs
- First-Blood (FB) refers to the first Defender to finish the lab, after launch
- Lab types
- Investigations
- fully browser-based lab scenarios that require no setup or configuration
- designed to replicate the kind of defensive work carried out in real-world security roles
- Challenges
- hands-on tasks that you download and complete on your local system or within a virtual machine
- Investigations
- Categories
- Incident Response — scenarios simulating real-world incidents
- Digital Forensics — forensic investigation and evidence analysis tasks
- Security Operations — challenges reflecting day-to-day security operations
- Reverse Engineering — decoding and reverse engineering applications
- CTF-Like Challenges — Capture the Flag style problem-solving scenarios
- OSINT — intelligence gathering from publicly available sources
- Threat Hunting — identifying and mitigating threats in simulated environments
- Threat Intelligence — threat analysis and intelligence gathering scenarios
Lab Access
| Free Account | Pro Subscription | |
|---|---|---|
| Active Investigations (15 labs) | Yes | Yes |
| Lab Hours | 10 hours | Unlimited |
| Retired Investigations | No | Yes |
| Retired Challenges | No | Yes |
- There are 15 active labs at any one time
- all free to play
- split across difficulty levels
- 3 Very Easy
- 4 Easy
- 4 Medium
- 3 Hard
- 1 Epic
- Labs are rotated regularly, then retired into BTLO Pro
- when a new lab is released within a difficulty level, the oldest lab in that category is retired
- completed labs will be visible
- Write-ups can only be published for retired content
- Community authored content is no longer accepted, only idea submissions
Leaderboard / Scoring
- Leaderboard points are only earned on the 15 free labs
- Scoring is scaled depending on difficulty
- Very Easy: up to 15 points
- Easy: up to 25 points
- Medium: up to 50 points
- Hard: up to 100 points
- Epic: up to 130 points
TryHackMe
Labs
- Blue, red, and purple team related labs
- Room Types
- Challenges
- no guidance
- Walkthroughs
- guided teaching
- Network
- more complex lab networked environments for Active Directory and corporate environment learning
- Challenges
- Usage
- Rooms can contain an:
- Attack Box
- not always need
- Cloud hosted machine used to complete labs
- Can use your own VM with VPN as alternative
- Lab
- This contains the lab setup that the attack box will access/connect to
- Attack Box
- Rooms can contain an:
- Difficulty levels
- Easy
- Medium
- Hard
- Insane
Lab Access
- Some labs are free tier, others require subscription
Scoring
- earn points by completing rooms
- points are earned by difficulty
- challenge rooms generally more difficult than walkthrough rooms
- also difficulty label
- complete walkthrough room in the same month as release awards:
- 25% of available points to account for Monthly and All-time leaderboards
- complete walkthrough older than a month only awards:
- 25% of the points towards All-time, not monthly leaderboards
- challenge rooms
- complete in same month as release for 100% of points towards both monthly and all-time leaderboards
- otherwise will grant 100% of points to all-time, but only 25% to monthly
CyberDefenders
Labs
- Only blue team focused
- Types
- Active
- no walkthroughs or hints
- earn leaderboard points
- represent the latest real-world challenges
- Retired
- include walkthroughs and hints
- no points, focus more on learning than competing
- integrate educational-mode feature
- ideal for beginners
- offer structured, step-by-step learning
- Active
- Trial labs
- users get 5hrs of free access to select pro labs
- Access types
- Cloud labs
- run entirely in cloud, no setup required
- open in browser
- Downloadable labs
- download the full lab artifacts for local machine
- Cloud labs
- Pro vs Free Labs
- Free
- available to all users no cost
- Pro
- only subscribers
- can have enhanced browser-based lab experience
- multi-regional servers for optimal performance
- more complex and advanced scenarios
- Free
- Categories
- Threat hunting
- refine threat detection skills using SIEM platforms
- Splunk, Elastic, QRadar, Graylog, Arkime
- refine threat detection skills using SIEM platforms
- Endpoint forensics
- focus on analysis of host artifacts
- broad spectrum
- windows forensics
- linux forensics
- mobile forensics
- memory dump analysis
- Network forensics
- focus on analyzing network data flows to trace adversarial activities
- use tools such as Wireshark, Network Miner, Brim, etc.
- Malware analysis
- focus reverse engineering, static and dynamic analysis, and sandboxing
- essential for understanding the behavior and impact of malware on systems
- Threat intel
- focuses on the process of collecting and analyzing information about potential adversaries
- examine threat feeds, indicators of compromise (IOCs), studies on advanced persistent threats (APTs), and application of intel for defensive strategies
- Detection Engineering
- focus on creating and testing detection rules using tools like YARA and Sigma
- Cloud forensics
- focus on AWS, Azure, and GCP
- analyze raw and processes logs with Splunk and Elastic SIEM
- Threat hunting
Write-Ups
- can submit for retired labs only
- aka walkthroughs
- guidelines
- focus on guiding rather than revealing direct answers
- consider blurring answer or displaying only a portion
- must reference a link to cyberdefenders.org
HackTheBox
- more red team oriented, but has expanded blue team content
- acquired LetsDefend
- I personally don’t think LetsDefend is good, but I think HTB will improve it
Labs
- Types
- Machines
- red team labs
- are instances of vulnerable virtual machines
- host different operating systems (such as Linux, Windows, and FreeBSD)
- difficulty levels:
- Easy
- Medium
- Hard
- Insane
- Tiers
- Active
- currently active and freely available
- Retired
- rotating shortlist of retired machines for free users
- VIP+ exclusive access machines
- Active
- Challenges
- bite-sized applications designed for practicing specific penetration testing techniques
- blue and red team
- difficulty:
- Very Easy
- Easy
- Medium
- Hard
- Insane
- Categories
- Reversing
- focus on reverse engineering
- need to find out what a certain script or program does to find the flag
- Misc
- variety of content that don’t fit other categories
- Stego
- focus on finding or embedding hidden messages in plain-looking objects
- Crypto
- focuses on cryptographic functions
- decrypting objects to find flag
- Web
- focus on web-based applications
- need to detect, exploit, and search through vulnerable applications
- Forensics
- focus on data recovery and forensics
- need to inspect small details in recovery data batches to discover what happened to target system
- OSINT
- focus on publicly available data farming
- learn how to laterally move between search engine algorithms to find missing information
- Pwn
- focus on binary exploitation and memory corruption
- create exploits that manipulate system memory to retrieve flag
- Mobile
- focus on handheld devices
- analyze intrinsics of mobile apps to find hidden embedded functionalities and flags
- Hardware
- focus on penetrating different hardware systems
- analyze attack methodologies for physical objects in everyday life
- Reversing
- States
- Active
- no walkthroughs allowed to be published
- completion rewards points based on difficulty
- easy: 10-30 points
- medium: 40-50 points
- hard: 50-100 points
- Retired
- offer no points
- good tool to learn about specific categories
- Active
- How to play
- need to download files provided as archive
- some may require Docker container
- Sherlocks
- defensive investigatory scenarios designed to replicate real-life scenarios
- Categories
- DFIR
- SOC
- Malware Analysis
- Threat Hunting
- Threat Intelligence
- Cloud
- Difficulties
- Easy
- Medium
- Hard
- Insane
- How to play
- download investigation package
- zip file with password
- password is always
hacktheblue
- review contents in secure isolated environment
- may contain real malware!
- answer tasks
- download investigation package
- Playing Modes
- Linear
- answer investigatory question successfully unlocks the next
- Free-flow
- answer questions in any order
- Linear
- Fortresses
- Machines
- Access
- use a dedicated machine/VM
- Linux highly recommended
- Use OpenVPN to create a link between local machine and lab machine
- download a VPN config file that auto-configures your OpenVPN client
- called VPN packs or VPN files
- this places you in same IP subnet as vuln machines
- download a VPN config pack based on lab type (machine, starting point, fortresses, etc.)
- require:
- latest version of openvpn
- included in Kali and Parrot
- latest version of openvpn
sudo openvpn [your_filename].ovpnto connect to VPN
- use a dedicated machine/VM
Content Sharing
- You are permitted to upload, stream videos, and publish solutions only for HTB Free Academy Courses or specific retired Hack The Box content.
- List of allowed Hack The Box content for publication:
- Retired Machines
- Retired Sherlocks
- Retired Challenges
- Starting Point Machines
- Tier 0 Academy Modules
- Mini Pro Labs that currently have available write-ups on the platform (specifically: POO, Xen, Ascension, RPG, and Hades).
- Cannot share content on:
- Pro labs, active machines, active challenges
- Do not spoil active content