CyberDefenders for Beginners: Blue Team CTF Guide (2026)

CTF & Practice
14 min read
CyberDefenders for Beginners: Blue Team CTF Guide (2026)
On this page
  1. What Is CyberDefenders?
    1. How It Differs From Offensive CTFs
  2. How CyberDefenders Labs Work
    1. Cloud Labs vs Downloadable Labs
    2. Active vs Retired Labs
    3. Hints, Walkthroughs, and Help
  3. Is CyberDefenders Free? Free vs Pro
  4. Is CyberDefenders Good for Beginners?
  5. How to Solve Your First CyberDefenders Lab
    1. A Worked Example: Your First Pass on a PCAP
  6. CCDL1 Certification: Is It Worth It?
  7. CyberDefenders Alternatives
  8. Legal and Ethical Considerations
  9. Frequently Asked Questions
  10. Your Next Steps

Most CTF platforms teach you to break in. CyberDefenders teaches the other half of the job: someone already broke in, and you get the evidence. A packet capture, a memory dump, a pile of Windows event logs. Your task is to work out what happened, when, and how. If you have never opened a PCAP before, try the Packet Pursuit lab on HackerDNA first: it hides a flag across DNS, ICMP, and HTTP traffic, which is exactly the kind of digging CyberDefenders expects you to already be comfortable with.

This guide explains what CyberDefenders is, how its blue team labs work, what you get for free, whether it suits beginners, how to solve your first lab without a walkthrough, whether the CCDL1 certification is worth it, and which alternatives fit better at each stage.

TL;DR: CyberDefenders is a blue team training platform where you investigate realistic security incidents by answering questions from evidence such as PCAPs, disk images, memory dumps, and SIEM logs. Free accounts get free labs and limited cloud machine time, and CyberRange Pro opens the full library. It is excellent for future SOC analysts, but it expects you to know Wireshark and basic log analysis before your first lab.

What Is CyberDefenders?

CyberDefenders is a defensive security training platform that hosts "blue team CTF" labs: realistic incident scenarios where, instead of capturing a flag on a vulnerable machine, you answer a series of investigation questions using the evidence an attacker left behind.

The platform's practice area is called the CyberRange (you will also see the older names "BlueYard" and "Blue Team CTF Challenges" in search results and old write-ups). Its help center sorts labs into seven categories:

  • Network Forensics: tracing attacker activity through packet captures with Wireshark, NetworkMiner, and Brim.
  • Endpoint Forensics: Windows, Linux, and mobile artifacts, plus memory dump analysis.
  • Threat Hunting: proactive detection inside SIEMs such as Splunk, Elastic, QRadar, and Graylog.
  • Malware Analysis: static and dynamic analysis, sandboxing, and some reverse engineering.
  • Threat Intel: indicators of compromise, threat feeds, and known adversary groups.
  • Detection Engineering: writing and testing detection rules with YARA and Sigma.
  • Cloud Forensics: AWS, Azure, and GCP logs, raw and processed.

Each lab page also lists the MITRE ATT&CK tactics it covers. The beginner-friendly WebStrike lab, for example, walks through a web server compromise touching Initial Access, Execution, Persistence, Command and Control, and Exfiltration. That mapping matters more than it looks: ATT&CK is the shared vocabulary of real SOC teams, and learning it inside a lab is far easier than learning it from a table.

How It Differs From Offensive CTFs

On an offensive platform, you finish when you find the flag. On CyberDefenders, there is no single flag. A lab is a series of questions, usually answered in order, and each answer is a concrete fact: an attacker's IP address, a malicious file name, a timestamp, a hash, or an ATT&CK technique ID. The questions build a timeline, so by the last one you have written an incident report without noticing.

If you are still deciding which side of security you enjoy, our SOC analyst career guide explains what this kind of investigation looks like as a full-time job.

💻
Practice this now: Packet Pursuit - open a traffic capture, follow DNS, ICMP, and HTTP conversations, and reassemble a flag split across all three. It is a gentle warm-up for CyberDefenders' network forensics labs.

How CyberDefenders Labs Work

Before you join your first lab, three distinctions will save you confusion.

Cloud Labs vs Downloadable Labs

Cloud labs run a virtual machine in your browser, with the tools and evidence already installed. When the machine boots, open the "Start Here" folder on its desktop: it holds the artifacts, the tools, and the instructions. Pro users can pick a server region (the help center lists UAE, Frankfurt, USA East, and Singapore).

Downloadable labs give you the raw artifacts to analyze on your own machine. They are handy offline, but you supply the tools, and some archives contain real malware samples. The lab instructions give you the extraction password (on the Flare-On lab, for instance, it is simply the site's domain name). Open these only inside an isolated analysis VM, never on your everyday computer.

Active vs Retired Labs

This is the rule beginners miss most often:

  • Active labs are the latest releases. They award leaderboard points, but they come with no hints and no walkthroughs.
  • Retired labs are the archive. They award no leaderboard points, but most have per-question hints, an official walkthrough, and community write-ups in the left sidebar.

Our advice: ignore the leaderboard for your first month. Retired labs with hints are where you actually learn, and the points are not worth an evening spent stuck with no feedback.

Hints, Walkthroughs, and Help

Each question can have its own hint, which nudges you toward the right artifact without giving the answer away. If a hint is not enough, the "Need Help?" button at the top of the lab page links to that lab's Discord thread. Treat the full walkthrough as a last resort, and when you do open it, read only the part for the question you are stuck on.

Is CyberDefenders Free? Free vs Pro

Yes, you can use CyberDefenders for free, with limits. According to the CyberDefenders help center, "Free Labs are available to all users at no cost," while Pro Labs are reserved for CyberRange Pro subscribers.

FeatureFree accountCyberRange Pro
Free labsYesYes
Pro lab librarySelected "Trial Labs" onlyFull library, new labs every week
Cloud machine timeCappedUnlimited
Server region choiceNoUAE, Frankfurt, USA East, Singapore
Pro Discord channels and badgeNoYes

Two details are worth knowing before you pay:

  • Free cloud time is limited. The help center describes the free allowance in hours (one article mentions 10 hours of cloud machine time per month, another a one-time 5-hour pool for Trial Labs), so check your own account page. Either way, do your reading before you click "Start Machine."
  • Discounts are narrow. CyberDefenders says it does not offer general discounts to individuals. The yearly Pro plan includes two months free, and verified students get 50% off CyberRange Pro and 10% off CCDL1.

CyberDefenders does not publish Pro prices on a public pricing page, and third-party figures we found did not match each other, so we are not quoting one here. You will see the current price at checkout after signing up.

Is CyberDefenders Good for Beginners?

It is good for prepared beginners. CyberDefenders gives you evidence and questions, not lessons. If you already know how to apply a Wireshark display filter and what a Windows logon event looks like, its easy labs are a great next step. If both of those sound foreign, you will spend your free cloud hours searching for basics instead of investigating.

Here is our honest checklist. You are ready for your first CyberDefenders lab when you can:

  1. Filter a PCAP. Use display filters like http.request, dns, and ip.addr == 203.0.113.50, and use "Follow TCP Stream." Our Wireshark tutorial for beginners covers all of this.
  2. Read a web server log. Spot the one suspicious request among thousands of normal ones by status code, user agent, or an odd path.
  3. Recognize key Windows event IDs. 4624 (successful logon), 4625 (failed logon), 4688 (process creation), plus Sysmon Event ID 1 (process create) and 3 (network connection).
  4. Explain an IOC. Know why an IP, a domain, or a file hash can identify an attacker's infrastructure or tooling.

If two or more of these are shaky, build them first on a platform that teaches as you go, then come back. CyberDefenders will feel much more rewarding.

How to Solve Your First CyberDefenders Lab

The CyberDefenders help center recommends three starter labs: PacketDetective (network forensics), Amadey (endpoint forensics), and T1110.003 (threat hunting). Start with PacketDetective. It is rated easy, it only needs Wireshark, and its goal is to extract IOCs from PCAP files and reconstruct what the attacker did.

Whatever lab you pick, the same routine works:

  1. Read every question before touching the evidence. The questions are a map. If question 7 asks for an exfiltrated file name, you know exfiltration happened and you can watch for it from the start.
  2. Get the big picture first. In Wireshark, open Statistics > Protocol Hierarchy and Statistics > Conversations. In a SIEM, count events by host and by hour. You are looking for the loudest, strangest talker.
  3. Find patient zero. Identify the first malicious event (a phishing download, a brute-force burst, a web shell upload) and write down its exact timestamp.
  4. Build a timeline in a notes file. One line per finding: time, source, destination, what happened. Most later questions can be answered straight from this file.
  5. Check the answer format. Answers are exact strings. A wrong timezone, a missing port, or an uppercase hash where lowercase is expected will be marked wrong even if your reasoning is right.
  6. Write three sentences when you finish. How the attacker got in, what they did, and what evidence proved it. That summary is the skill employers test in interviews.

A Worked Example: Your First Pass on a PCAP

When you are working a downloadable network lab locally, tshark (Wireshark's command-line twin) answers the first questions faster than clicking around. These commands are standard in Wireshark 4.x and appear in the official tshark manual:

capinfos capture.pcap                       # duration, packet count, first and last packet time
tshark -r capture.pcap -q -z io,phs         # protocol hierarchy: what is in here?
tshark -r capture.pcap -q -z conv,tcp       # who talked to whom, and how much
tshark -r capture.pcap -Y "http.request" \
  -T fields -e frame.time -e ip.src -e http.request.method -e http.host -e http.request.uri
tshark -r capture.pcap --export-objects http,./http_files   # carve files sent over HTTP

The fourth command is the one that usually breaks a network lab open. Its output is one line per HTTP request, something like this (trimmed for width, addresses from the documentation range):

Mar  3, 2026 09:14:02  198.51.100.23  GET   shop.acme.example  /index.php
Mar  3, 2026 09:14:09  198.51.100.23  GET   shop.acme.example  /admin/
Mar  3, 2026 09:15:47  198.51.100.23  POST  shop.acme.example  /admin/upload.php
Mar  3, 2026 09:16:03  198.51.100.23  GET   shop.acme.example  /uploads/image.php?cmd=whoami

Four lines and you already have a story: reconnaissance, an admin panel, a file upload, and a web shell receiving commands. Each of those lines typically answers one lab question.

In practice, timestamps cost beginners the most points. Wireshark's default Time column shows seconds since the capture started, not a clock time. Before you copy any timestamp into an answer, switch to View > Time Display Format > UTC Date and Time of Day, and check whether the question wants UTC.

If the web log side of this example felt unfamiliar, the Log Hunter lab gives you a raw HTTP access log and asks you to find the single request that gave the attacker away. It is the same skill CyberDefenders tests, with a guided solution when you are done.

CCDL1 Certification: Is It Worth It?

CyberDefenders also runs two certifications: Certified CyberDefender Level 1 (CCDL1) for SOC analysts and Level 2 (CCDL2) for threat hunting and DFIR. CCDL1 is the one most beginners ask about. Here is what the official CCDL1 exam outline and help center say:

  • Format: 48 multiple-choice questions, each with 4 to 8 options, answered from a live virtual machine in your browser.
  • Duration and pass mark: 6 hours, with a minimum score of 70%.
  • Domains: SIEM Basics with Splunk (33.33%), Network and Endpoint Essentials (26.09%), DFIR (20.29%), Phishing and Email Security (10.14%), and Cloud Security (10.14%).
  • Purchase options: exam only, or a bundle with 4 months of course content, videos, and labs plus the exam.
  • Validity: 4 years, renewable by passing the latest exam version or submitting 36 CPE credits.

Our take: CCDL1 is a solid practical credential and a good structured study plan, especially the bundle. A third of the exam is Splunk, so it maps well to real SOC work. It is not yet a name HR filters recognize the way they recognize CompTIA Security+, so if you are job hunting, treat it as proof of hands-on skill that complements a better-known certification rather than replaces it. You can read the full CCDL1 exam outline before deciding.

CyberDefenders Alternatives

CyberDefenders is one of several blue team platforms, and they suit different stages. Here is how the main options compare:

PlatformFree optionPaid planStyleBest for
CyberDefendersFree labs, capped cloud timeCyberRange Pro, price at checkoutInvestigation questions on real evidenceSOC and DFIR practice once you know the basics
Blue Team Labs OnlineAll challenges, downloadable£15/month or £144/yearDownloadable challenges, browser investigations for ProOffline challenge practice
LetsDefendBasic plan, limited creditsVIP from $16.99/month billed yearlySimulated SOC with alerts to triageLearning the daily alert-triage workflow
HackerDNAFree tier, no credit cardPro planGuided browser labs and coursesLearning forensics and attack basics with guidance

Blue Team Labs Online (run by Centri) is the closest match in spirit. All of its challenges are free to download, and Pro (£15 a month, or £144 a year) adds browser-based investigation labs with no VM or VPN to set up.

LetsDefend is less of a CTF and more of a job simulator: alerts land in a queue and you triage them like a tier 1 analyst. Its VIP plan costs $24.99 a month, or $16.99 a month billed yearly, and students with a .edu email get 50% off.

HackerDNA fits before or alongside CyberDefenders. Forensics labs like Packet Pursuit and Log Hunter run in your browser and come with solutions, and the network detection chapter of HackerDNA's SOC analyst and blue team course has you run Suricata on a real capture, then catch a DNS tunneling channel and a C2 beacon. Because HackerDNA also teaches the offensive side, you learn what the attacks in those PCAPs look like from the attacker's seat, which makes them much easier to recognize as a defender.

For a wider view that includes offensive platforms, see our comparison of the best cybersecurity labs.

Critical reminder: Lab evidence is provided for training. Investigating real systems, real mailboxes, or real network traffic requires explicit written authorization from whoever owns them, even when your intentions are defensive.

  • Treat downloaded samples as live malware. Malware analysis labs can contain working malicious code. Use an isolated VM with snapshots, keep it off your home network, and never run a sample on your host.
  • Do not reuse lab techniques on other people's data. Reading someone's traffic or logs without permission is illegal in most countries, whatever the reason.
  • Respect platform rules on write-ups. Active labs have no public walkthroughs for a reason. Publish write-ups only for retired labs, through the platform's own submission process when it offers one.
  • Handle indicators carefully. Lab IOCs may point to real infrastructure that once belonged to an attacker. Look them up in threat intelligence tools, but do not connect to them or scan them.

Frequently Asked Questions

What is CyberDefenders?

CyberDefenders is a blue team training platform with realistic incident investigation labs. You analyze evidence such as packet captures, disk and memory images, and SIEM logs, then answer questions that reconstruct the attack. It covers network and endpoint forensics, threat hunting, malware analysis, threat intel, detection engineering, and cloud forensics.

Is CyberDefenders free?

Partly. Free labs are open to every account, and free users get a capped amount of cloud machine time plus access to selected Trial Labs. CyberRange Pro adds the full lab library, unlimited cloud machine time, and server region selection.

Is CyberDefenders good for beginners?

It suits beginners who already know Wireshark filters and basic log reading. Its labs give you evidence and questions rather than lessons. Complete beginners usually progress faster by learning the basics on a guided platform first, then using CyberDefenders' retired labs with hints.

What is the difference between active and retired CyberDefenders labs?

Active labs are new releases that award leaderboard points but offer no hints or walkthroughs. Retired labs are older releases with hints, an official walkthrough, and community write-ups, but they award no leaderboard points.

How long is the CCDL1 exam?

The CCDL1 exam lasts 6 hours and contains 48 multiple-choice questions answered from a live browser-based virtual machine. The passing score is 70%, and the certification stays valid for 4 years.

Is CyberDefenders better than TryHackMe for blue team?

They do different jobs. TryHackMe teaches concepts step by step inside guided rooms. CyberDefenders tests whether you can apply those concepts to an unguided investigation. Many learners use a guided platform to learn and CyberDefenders to practice.

Last verified: October 2026. Lab categories, free and Pro features, discounts, and CCDL1 exam details checked on the CyberDefenders help center. Blue Team Labs Online and LetsDefend prices checked on their own websites.

Your Next Steps

CyberDefenders is one of the best places to practice real blue team investigations, as long as you arrive with the basics. Make a free account, open the PacketDetective lab, read every question first, and build your timeline in a notes file. When you finish, write three sentences explaining the attack. That habit is what turns lab practice into interview answers.

If Wireshark filters and log analysis still feel new, build them first where you get guidance. Start with Packet Pursuit for traffic analysis and Log Hunter for web logs, then work through the network detection chapter of the SOC analyst course before you take on CyberDefenders' harder labs. You can start with HackerDNA's free tier - no credit card required.

HackerDNA Team

HackerDNA Team

Written by the HackerDNA team - cybersecurity professionals building hands-on hacking labs and educational content to help you develop real-world security skills.

Meet the Team

Ready to put this into practice?

Stop reading, start hacking. Real machines, in your browser, free.

Start Hacking Free
31,000+ Hackers Real labs Free
Start Hacking Free or solve today's hack, no account needed