This page will serve as a curated list of helpful DFIR related CTFs and Labs.
| Title | Developer | Type | Category | Release Year |
|---|---|---|---|---|
| IR003: Stealthy Network Breach and Escalation | Blue Cape Security | Lab | Network Intrustion | 2025 |
| IR002: Operation Red Echo | Blue Cape Security | Lab | Network Intrustion | 2025 |
| IR001: Operation Quiet Tunnel | Blue Cape Security | Lab | Ransomware | 2025 |
| FOR004: Suspicious Logons | Blue Cape Security | Lab | Endpoint Forensics | 2025 |
| FOR003: Unauthorized Access | Blue Cape Security | Lab | Endpoint Forensics | 2025 |
| FOR002: Suspicious Network Connections | Blue Cape Security | Lab | Endpoint Forensics | 2025 |
| FOR001: Disgruntled Manager’s Exodus | Blue Cape Security | Lab | Endpoint Forensics | 2025 |
| BlackSuit Ransomware - Private Case #29354 | The DFIR Report | Lab | Ransomware | 2024 |
| Backdoors and LockBit - Private Case #27138 | The DFIR Report | Lab | Ransomware | 2024 |
| LockBit Ransomware - Private Case #27244 | The DFIR Report | Lab | Ransomware | 2024 |
| DFIR Labs CTF | The DFIR Report | CTF | Various | 2024 - Present |
| Dagon Locker Ransomware - Private Case #23825 | The DFIR Report | Lab | Ransomware | 2024 |
| Qbot Leads to Domain Compromise - Private Case #27101 | The DFIR Report | Lab | Network Intrustion | 2024 |
| NetSupport Intrusion Results in Domain Compromise - Public Case #19438 | The DFIR Report | Lab | Network Intrustion | 2024 |
| A Truly Graceful Wipe Out - Public Case #21619 | The DFIR Report | Lab | Network Intrustion | 2024 |
| ALPHV Ransomware - Public Case #24952 | The DFIR Report | Lab | Ransomware | 2024 |
| BlueSky Ransomware - Public Case #19208 | The DFIR Report | Lab | Ransomware | 2024 |
| Elpaco-Team Ransomware - Public Case #30043 | The DFIR Report | Lab | Ransomware | 2025 |
| Mud In The Water - Private Case #29823 | The DFIR Report | Lab | Network Intrustion | 2025 |
| RansomHub Leads to Domain Compromise – Private Case #33490 | The DFIR Report | Lab | Ransomware | 2025 |
| Husky Corp | XINTRA | Lab | APT | 2024 |
| Waifu University | XINTRA | Lab | Ransomware | 2024 |
| Assassin Kitty | XINTRA | Lab | APT | 2024 |
| Virus Vipers | XINTRA | Lab | APT | 2024 |
| Linux Forensic Cases | Ali Hadi | Lab | Endpoint Forensics | 2024 |
| Unallocated Disk Space #01 - Investigation Case 1 | Ali Hadi | Lab | Endpoint Forensics | 2024 |
| Memory Forensics #01 - RansomCare Investigation Case 1 | Ali Hadi | Lab | Memory Forensics | 2024 |
| Challenge #11 - Where Did Administrator Go? | Ali Hadi | Lab | Endpoint Forensics | 2024 |
| Challenge #10 - Meeting Location Case | Ali Hadi | Lab | Endpoint Forensics | 2023 |
| Challenge #9 - Encrypt Them All Case | Ali Hadi | Lab | Endpoint Forensics | 2023 |
| Challenge #8 - NTFS File System Case | Ali Hadi | Lab | Endpoint Forensics | 2023 |
| Challenge #7 - SysInternals Case | Ali Hadi | Lab | Endpoint Forensics | 2022 |
| Challenge #6 - Browser Policy Violation Case | Ali Hadi | Lab | Endpoint Forensics | 2021 |
| Challenge #5 - BSides Amman 2021 2nd Edition / Windows Forensics Workshop Case | Ali Hadi | Lab | Endpoint Forensics | 2021 |
| Case 002 - Hudak's Honeypot | DFIR Madness | Lab | Various | 2021 |
| LetsDefend | LetsDefend | CTF | Various | 2021 |
| Mini Memory CTF - A Memory Forensics Challenge | 13Cubed | Lab | Memory Forensics | 2020 |
| MemLabs | Abhiram Kumar Patiballa | CTF | Memory Forensics | 2020 |
| Challenge #4 - Launching Attacks from Alternate Data Streams | Ali Hadi | Lab | Endpoint Forensics | 2020 |
| Challenge #3 - Mystery Hacked System | Ali Hadi | Lab | Endpoint Forensics | 2020 |
| Challenge #2 - User Policy Violation Case | Ali Hadi | Lab | Endpoint Forensics | 2020 |
| Challenge #1 - Web Server Case | Ali Hadi | Lab | Various | 2020 |
| Blue Team Labs Online | Blue Team Labs Online | CTF | Various | 2020 |
| CyberDefenders | CyberDefenders | CTF | Various | 2020 |
| Case 001 - The Case of the Stolen Szechuan Sauce | DFIR Madness | Lab | Various | 2020 |
| Pulling Threads | 13Cubed | Lab | Memory Forensics | 2019 |
| 2019 Tuck | Digital Corpora | Lab | Endpoint Forensics | 2019 |
| 2019 Owl | Digital Corpora | Lab | Various | 2019 |
| 2019 Narcos | Digital Corpora | Lab | Various | 2019 |
| TryHackMe | TryHackMe | CTF | Various | 2019 |
| 2018 Lone Wolf Scenario | Digital Corpora | Lab | Various | 2018 |
| HackTheBox | HackTheBox | CTF | Various | 2017 |
| 2012 National Gallery DC Attack | Digital Corpora | Lab | Various | 2012 |
| 2009 M57-Patents Scenario | Digital Corpora | Lab | Various | 2009 |
| 2008 Nitroba University Harassment Scenario | Digital Corpora | Lab | Network Forensics | 2008 |
| 2008 M57-Jean | Digital Corpora | Lab | Endpoint Forensics | 2008 |
