Solving the Openfire Lab Blue team challenge

Solving the Openfire Lab Blue team challenge

A blue-team walkthrough of the CyberDefenders Openfire challenge using Wireshark and Zui: recovering the CSRF token and credentials, tracing the malicious plugin upload and reverse shell, and identifying the exploited CVE.

August 24, 2025 · 4 min
Solving the ShadowCitadel Lab Blue team challenge

Solving the ShadowCitadel Lab Blue team challenge 🫆

A host-based forensics walkthrough of the ShadowCitadel challenge: following the attack from a malicious email attachment through a PowerShell downloader and second-stage executable to the C2 beacon IP and persistence mechanisms.

August 10, 2025 · 16 min
Solving the XLMRat Blue team challenge

Solving the XLMRat Blue team challenge

A blue-team walkthrough of the CyberDefenders XLMRat challenge: tracing the first-stage download URL and hosting provider from the PCAP, hashing the loader and executable payloads, and identifying the malware family and the LOLBin used for stealthy execution.

June 28, 2025 · 6 min
WebStrike Blue Team Challenge

Solving the WebStrike Blue Team Challenge

A blue-team walkthrough of the CyberDefenders WebStrike challenge: analyzing the PCAP to find the attack’s geographic origin and user agent, the uploaded web shell and its port, the upload directory, and the file targeted for exfiltration.

December 17, 2023 · 4 min