// provocativo · blue team
initializing secure sandbox_
> mounting sandbox fs
// route /labs/blue-team

BLUE TEAM OPERATIONS_

Defense & Analysis

A defensive sandbox. Sharpen the eyes that read logs, tune alerts, and pull signal from telemetry noise.

// privacy is normal
operator rank0 / 6
INITIATENEXT · APPRENTICE @ 2
defender console· 6 labs
showing 6 labs · category All
SORT · CANONICAL
BT-LOGLOG ANALYSIS

Log Triage

Read a block of Apache access logs and pick the row that betrays an attacker walking the directory tree.

BEGINNER
BT-ALERTDETECTION

Alert Tuning

Five Suricata alerts, five packet captures. Mark each one true-positive or false-positive without burning out the SOC.

INTERMEDIATE
BT-IOCIOC

IOC Hunt

A YARA rule meets a file dump. Pick the strings that fire the rule.

BEGINNER
BT-PHISHPHISHING

Phishing Forensics

An email's headers landed on your desk. Find the row that proves SPF failed and the domain was spoofed.

INTERMEDIATE
BT-TIMELINEIR

Incident Timeline

Six events from a real breach scattered out of order. Drop them back into the kill chain.

INTERMEDIATE
BT-SIGMADETECTION

Detection Engineering

A Sysmon Process Create event needs a Sigma rule. Pick the rule that actually fires on this telemetry.

ADVANCED
MITRE D3FEND v0.16 ships — 7 new artifact mappings//CISA AA24-241A · LockBit affiliate playbook released//Sigma rules repo · 80 new detections this week//Microsoft 365 audit log retention now 180 days by default//Velociraptor 0.74 · faster Windows EVTX parsing//OpenCTI 6 brings native STIX 2.1 bundles//Atomic Red Team adds 12 new T1059 atomics//MITRE D3FEND v0.16 ships — 7 new artifact mappings//CISA AA24-241A · LockBit affiliate playbook released//Sigma rules repo · 80 new detections this week//Microsoft 365 audit log retention now 180 days by default//Velociraptor 0.74 · faster Windows EVTX parsing//OpenCTI 6 brings native STIX 2.1 bundles//Atomic Red Team adds 12 new T1059 atomics//