Browse CTFs New CTF Sign in
Back to Learning Paths
Cyber Incident Responder
Practitioner Wave 1 Draft

Cyber Incident Responder

80.0h estimated 4 Courses

Practitioner-level certification for incident response professionals. Covers triage, network/host/file correlation, attack-chain reconstruction, and remediation.

Sign in to enroll

Incident Triage, Timeline and Prioritisation

16 cards

Correlating Multi-Host Authentication Anomalies to Detect Lateral Movement

log_analysis_siem Difficulty 1–5 30 min

Correlating Audit Events Across Linux and Windows Privilege Escalation Transitions

log_analysis_siem Difficulty 1–5 30 min

QR code decode

log_analysis_siem Difficulty 1–5 30 min

Sigreturn-Oriented Programming: Signal Frame Hijacking for Full CPU Register Control with Minimal Gadgets

log_analysis_siem Difficulty 1–5 30 min

Morse Code Decoding: Timing Analysis, Delimiter Identification and Transcription Methodology

log_analysis_siem Difficulty 1–5 30 min

Bacon cipher

log_analysis_siem Difficulty 1–5 30 min

Zero-width steganography

log_analysis_siem Difficulty 1–5 30 min

Brainfuck encoding

log_analysis_siem Difficulty 1–5 30 min

NATO phonetic alphabet

log_analysis_siem Difficulty 1–5 30 min

Multi-layer encoding chain

log_analysis_siem Difficulty 1–5 30 min

QR Code Forensics: Error Correction Analysis and Partially Damaged Payload Reconstruction

log_analysis_siem Difficulty 1–5 30 min

Baudot encoding

log_analysis_siem Difficulty 1–5 30 min

Leetspeak obfuscation

log_analysis_siem Difficulty 1–5 30 min

Azure RBAC Misconfiguration: Subscription-Scope Role Assignments and Service Principal Abuse

log_analysis_siem Difficulty 1–5 30 min

AWS Service Control Policy Misconfiguration: Cross-Account Permission Escalation

log_analysis_siem Difficulty 1–5 30 min

S3 Bucket Policy Misconfiguration: Public Access, Cross-Account Grants and Transport Gaps

log_analysis_siem Difficulty 1–5 30 min

Network, Host and File Correlation

64 cards

EXIF metadata

forensic_file_artifacts Difficulty 1–5 31 min

Hidden ZIP in image

forensic_file_artifacts Difficulty 1–5 30 min

Steganography

forensic_file_artifacts Difficulty 1–5 30 min

Corrupted archive

forensic_file_artifacts Difficulty 1–5 30 min

Detecting Advanced DNS Tunneling Evasion via Slow-Rate Exfiltration and Multi-Domain Correlation

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing HTTP Sessions via Multi-Request Correlation, Credential and Object Recovery

network_forensics_pcap Difficulty 1–5 30 min

Detecting TLS Fingerprint Anomalies via JA3/JA3S Computation and Malware Client Identification

network_forensics_pcap Difficulty 1–5 30 min

Detecting ICMP Covert Channels via Payload Anomaly Identification and Hidden Data Extraction

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing FTP Data Exfiltration via Passive Mode Analysis and TCP Stream Extraction

network_forensics_pcap Difficulty 1–5 30 min

Analyzing Advanced SMTP Exfiltration via MIME Multipart Parsing and Encoded Attachment Recovery

network_forensics_pcap Difficulty 1–5 30 min

Identifying IRC Botnet C2 via PRIVMSG Command Pattern Analysis and Bot Fingerprinting

network_forensics_pcap Difficulty 1–5 30 min

Detecting Kerberoasting and AS-REP Roasting via TGS-REQ Analysis and Ticket Extraction

network_forensics_pcap Difficulty 1–5 30 min

Analyzing WebSocket Data Exfiltration via Frame Demasking, Payload Extraction and Protocol Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Extracting Modbus Register Data via ICS/OT Protocol Forensics and Unauthorized Read Detection

network_forensics_pcap Difficulty 1–5 30 min

Recovering Corrupted PCAP Files via Magic Byte Forensics and Partial Capture Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Volatility 3 Advanced Analysis: Symbol Tables, Namespaced Plugins and Cross-Layer Memory Correlation

network_forensics_pcap Difficulty 1–5 30 min

In-Memory Password Recovery: LSASS Analysis, WDigest Extraction and Credential Cache Forensics

memory_forensics Difficulty 1–5 30 min

Detecting Process Injection: Identifying DLL Injection, Hollowing and Reflective Loading Artifacts

memory_forensics Difficulty 1–5 30 min

Identifying Log Tampering Through Clearance Events and Sequence Gap Analysis

memory_forensics Difficulty 1–5 30 min

Cloud Instance Metadata Credential Theft: IMDS Exploitation for IAM Role Token Extraction

forensic_file_artifacts Difficulty 1–5 30 min

Employee OSINT Profiling: Corporate Web Presence Analysis and Identity Correlation

forensic_file_artifacts Difficulty 1–5 30 min

Email-to-Pastebin OSINT Pivot: Address-Based Identity Tracing to Exposed Secret Discovery

forensic_file_artifacts Difficulty 1–5 30 min

Type Confusion Exploitation: C++ Vtable Misdirection and Union-Based Memory Reinterpretation for Code Execution

forensic_file_artifacts Difficulty 1–5 30 min

DOCX core metadata forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX hidden text forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX revision comment forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX acrostic steganography

network_forensics_pcap Difficulty 1–5 30 min

DOCX revision history (track changes)

network_forensics_pcap Difficulty 1–5 30 min

DOCX extended app properties forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX core metadata forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX hidden cell forensics (white-on-white)

network_forensics_pcap Difficulty 1–5 30 min

XLSX named range forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX cell comment forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX hidden worksheet forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX very-hidden worksheet forensics

network_forensics_pcap Difficulty 1–5 30 min

Shellcode Injection and Execution: NX-Free Environment Exploitation and NOP Sled Delivery

network_forensics_pcap Difficulty 1–5 30 min

IMDS SSRF to IAM Credential Theft: Metadata Endpoint Exploitation for Role Hijacking

network_forensics_pcap Difficulty 1–5 30 min

Lambda-to-Secrets-Manager Privilege Chain: Function Role Exploitation for Secret Retrieval

network_forensics_pcap Difficulty 1–5 30 min

Terraform State-to-AWS Pivot: Credential Extraction Chain from Leaked State to Live Resources

network_forensics_pcap Difficulty 1–5 30 min

Kubernetes RBAC to S3 Pivot: Pod Service Account Lateral Movement to Cloud Storage

network_forensics_pcap Difficulty 1–5 30 min

IAM Privilege Escalation Chain: AssumeRole, PassRole and CreatePolicyVersion Abuse Paths

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing Ransomware Infection Vectors from Multi-Source Log Evidence

network_forensics_pcap Difficulty 1–5 30 min

C2 Beaconing Detection via Log Interval Analysis and Temporal Correlation

network_forensics_pcap Difficulty 1–5 30 min

Correlating SQLi, XSS, LFI and RCE Attack Patterns Across Web Server Access Logs

network_forensics_pcap Difficulty 1–5 30 min

Detecting Malicious Service Persistence via Windows Event 7045 and Systemd Unit Forensics

network_forensics_pcap Difficulty 1–5 30 min

Detecting DNS Exfiltration Through Entropy-Based Subdomain Anomaly Analysis

network_forensics_pcap Difficulty 1–5 30 min

Instagram-to-Twitter Persona Pivot: Cross-Platform Handle Correlation and Profile Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Git Commit-to-Pastebin OSINT Pivot: Repository Secret Discovery Chained to Paste Platform Intelligence

forensic_file_artifacts Difficulty 1–5 30 min

E-Commerce Order-to-Email OSINT: Purchase Record Pivoting for Customer Identity Attribution

forensic_file_artifacts Difficulty 1–5 30 min

Corporate OSINT Chain: WHOIS, Website and SMTP Enumeration for Targeted Intelligence Gathering

forensic_file_artifacts Difficulty 1–5 30 min

Point-of-Interest to Social Media Pivot: Geographic OSINT Chained to Instagram Profile Identification

forensic_file_artifacts Difficulty 1–5 30 min

Git-to-S3 Infrastructure OSINT: Repository Credential Pivoting to Cloud Storage Data Extraction

forensic_file_artifacts Difficulty 1–5 30 min

Corporate OSINT Chain: Website, LDAP and SMTP Enumeration for Employee and Infrastructure Discovery

forensic_file_artifacts Difficulty 1–5 30 min

Four-Service Social OSINT Trail: Sequential Platform Pivoting for Target Activity Reconstruction

forensic_file_artifacts Difficulty 1–5 30 min

AWS S3 Bucket OSINT Enumeration: Public Bucket Discovery and Sensitive Data Identification

forensic_file_artifacts Difficulty 1–5 30 min

OAuth-to-Kubernetes-to-Git OSINT Pivot: Authorization Flow Exploitation Across Infrastructure Services

memory_forensics Difficulty 1–5 30 min

Corporate OSINT Chain: WHOIS, LDAP and SMTP Correlation for Organizational Intelligence

memory_forensics Difficulty 1–5 30 min

Social Media-to-Map-to-Stego-to-Chat Pivot: Multi-Modal OSINT Chain Across Four Data Domains

memory_forensics Difficulty 1–5 30 min

Full Corporate Breach Simulation: Five-Service OSINT Chain from Reconnaissance to Data Exfiltration

memory_forensics Difficulty 1–5 30 min

Social Media Identity Operations OSINT: Detecting Coordinated Inauthentic Behavior and Sockpuppet Networks

forensic_file_artifacts Difficulty 1–5 30 min

Cloud Asset Leak Investigation: Exposed Object Storage and Misconfigured Public Resource OSINT

forensic_file_artifacts Difficulty 1–5 30 min

Corporate Digital Footprint OSINT: Passive Reconnaissance and External Attack Surface Mapping

forensic_file_artifacts Difficulty 1–5 30 min

Multi-Service Infrastructure OSINT Chain: LDAP, OAuth, Kubernetes and Git Pivot Sequence

forensic_file_artifacts Difficulty 1–5 30 min

Multi-Platform OSINT Chain: Shop, Git, IMDS and Chat Pivot Across Five Distinct Data Sources

forensic_file_artifacts Difficulty 1–5 30 min

Attack-Chain Reconstruction, Remediation and Lessons Learned

110 cards

IDOR (numeric)

web_auth_sessions Difficulty 1–5 30 min

IDOR (UUID guessable)

web_auth_sessions Difficulty 1–5 30 min

Parameter pollution IDOR

web_auth_sessions Difficulty 1–5 30 min

Horizontal Privilege Escalation: Cross-User Resource Access via Insufficient IDOR Controls

web_auth_sessions Difficulty 1–5 30 min

Vertical Privilege Escalation: Role Bypass and Unauthorized Administrative Function Access

web_auth_sessions Difficulty 1–5 30 min

Role misassignment

web_auth_sessions Difficulty 1–5 30 min

Mass Assignment Vulnerability: Unfiltered Object Binding for Unauthorized Property Modification

web_auth_sessions Difficulty 1–5 30 min

Hidden admin endpoint

web_auth_sessions Difficulty 1–5 30 min

GraphQL overexposure

web_auth_sessions Difficulty 1–5 30 min

REST verb confusion

web_auth_sessions Difficulty 1–5 30 min

CORS misconfiguration

web_auth_sessions Difficulty 1–5 30 min

Multi-tenant data leak

web_auth_sessions Difficulty 1–5 30 min

SQL injection (classic)

web_auth_sessions Difficulty 1–5 30 min

SQLi blind time-based

web_auth_sessions Difficulty 1–5 30 min

SQLi second order

web_auth_sessions Difficulty 1–5 30 min

NoSQL Injection: MongoDB Operator Injection for Authentication Bypass and Data Enumeration

web_auth_sessions Difficulty 1–5 30 min

LDAP Injection: Filter String Manipulation for Authentication Bypass and Directory Enumeration

web_auth_sessions Difficulty 1–5 30 min

Template injection (Jinja2/Twig)

web_auth_sessions Difficulty 1–5 30 min

SSTI chain

web_auth_sessions Difficulty 1–5 30 min

OS Command Injection: Shell Metacharacter Exploitation for Server-Side Command Execution

web_auth_sessions Difficulty 1–5 30 min

Argument injection

web_auth_sessions Difficulty 1–5 30 min

Path traversal

web_auth_sessions Difficulty 1–5 30 min

LFI

web_auth_sessions Difficulty 1–5 30 min

RFI

web_auth_sessions Difficulty 1–5 30 min

SSTI to RCE chain

web_auth_sessions Difficulty 1–5 30 min

Reflected XSS: URL-Based Script Injection and Single-Interaction Client-Side Code Execution

web_auth_sessions Difficulty 1–5 30 min

Stored XSS: Persistent Script Injection for Session Hijacking and Admin Panel Exploitation

web_auth_sessions Difficulty 1–5 30 min

DOM-based XSS

web_auth_sessions Difficulty 1–5 30 min

CSP Bypass: Content Security Policy Circumvention via JSONP Endpoints, Trusted Domain Abuse and Nonce Prediction

web_auth_sessions Difficulty 1–5 30 min

AngularJS expression injection

web_auth_sessions Difficulty 1–5 30 min

Markdown rendering XSS

web_auth_sessions Difficulty 1–5 30 min

File upload XSS

web_auth_sessions Difficulty 1–5 30 min

Service worker abuse

web_injection_logic Difficulty 1–5 30 min

Basic SSRF Exploitation: Internal Service Enumeration via Server-Side URL Fetch Manipulation

web_injection_logic Difficulty 1–5 30 min

SSRF to Cloud Metadata: AWS IMDS Credential Theft via Server-Side Request Forgery

web_injection_logic Difficulty 1–5 30 min

SSRF via PDF Renderer: Headless Browser Exploitation for Internal Service Access via HTML Injection

web_injection_logic Difficulty 1–5 30 min

SSRF via webhook

web_injection_logic Difficulty 1–5 30 min

SSRF Filter Bypass: IP Encoding, URL Redirection and Parser Confusion for Blocklist Evasion

web_injection_logic Difficulty 1–5 30 min

DNS rebinding (simulated)

web_injection_logic Difficulty 1–5 30 min

Gopher Protocol SSRF: Arbitrary TCP Payload Injection for Redis, Memcached and FastCGI Exploitation

web_injection_logic Difficulty 1–5 30 min

SSRF → Redis (mocked)

web_injection_logic Difficulty 1–5 30 min

SSRF → internal admin

web_injection_logic Difficulty 1–5 30 min

Unrestricted file upload

web_injection_logic Difficulty 1–5 30 min

Extension bypass

web_injection_logic Difficulty 1–5 30 min

Content-Type Bypass: MIME Sniffing and Type Header Manipulation for Upload Restriction Evasion

web_injection_logic Difficulty 1–5 30 min

Zip Slip Path Traversal: Archive Extraction Directory Escape for Server-Side File System Write

web_injection_logic Difficulty 1–5 30 min

Archive bomb (simulated)

web_injection_logic Difficulty 1–5 30 min

Insecure deserialization (generic)

web_injection_logic Difficulty 1–5 30 min

PHAR deserialization (simulated)

web_injection_logic Difficulty 1–5 30 min

Pickle deserialization

web_injection_logic Difficulty 1–5 30 min

YAML unsafe load

web_injection_logic Difficulty 1–5 30 min

Prototype Pollution in Node.js: __proto__ Injection for Object.prototype Manipulation and RCE Gadget Chaining

web_injection_logic Difficulty 1–5 30 min

Race condition

web_injection_logic Difficulty 1–5 30 min

TOCTOU

web_injection_logic Difficulty 1–5 30 min

Double-spend

web_injection_logic Difficulty 1–5 30 min

Coupon stacking

web_injection_logic Difficulty 1–5 30 min

Quantity manipulation

web_injection_logic Difficulty 1–5 30 min

Order status tampering

web_injection_logic Difficulty 1–5 30 min

Payment bypass

web_injection_logic Difficulty 1–5 30 min

Feature flag abuse

web_injection_logic Difficulty 1–5 30 min

Logic-Based Privilege Escalation: Exploiting Flawed Business Rules for Unauthorized Role Promotion

web_injection_logic Difficulty 1–5 30 min

API Rate Limit Bypass: Request Throttling Circumvention via Header Manipulation and IP Rotation

web_injection_logic Difficulty 1–5 30 min

Pagination bypass

web_injection_logic Difficulty 1–5 30 min

Batch endpoint abuse

web_injection_logic Difficulty 1–5 30 min

Swagger exposed secrets

web_injection_logic Difficulty 1–5 30 min

API key leakage

web_injection_logic Difficulty 1–5 30 min

PNG metadata stego

web_injection_logic Difficulty 1–5 30 min

WAV LSB stego

web_injection_logic Difficulty 1–5 30 min

Nested archive

web_injection_logic Difficulty 1–5 30 min

Weak zip password

web_injection_logic Difficulty 1–5 30 min

Verifying Cryptographic Log Integrity by Detecting SHA-256 Hash Chain Breaks

web_injection_logic Difficulty 1–5 30 min

Detecting Log Injection Attacks Through CRLF Forensics and Entry Authenticity Analysis

web_injection_logic Difficulty 1–5 30 min

Detecting Timestamp Manipulation via MFT and NTP Cross-Correlation Sequence Analysis

web_injection_logic Difficulty 1–5 30 min

Reconstructing Event Timelines from Log Rotation Artifacts and Surviving Log Fragments

web_injection_logic Difficulty 1–5 30 min

Detecting Pass-the-Hash Attacks via NTLM Logon and Multi-Source Log Correlation

web_injection_logic Difficulty 1–5 30 min

Identifying Service-Based Persistence Through New Service Anomaly and Baseline Comparison

web_injection_logic Difficulty 1–5 30 min

Correlating Brute-Force Authentication Failures with Successful Lateral Pivot Events

web_injection_logic Difficulty 1–5 30 min

Identifying Base-Encoded Chunk Queries in DNS Exfiltration Log Records

web_injection_logic Difficulty 1–5 30 min

Tracing SUID Binary Exploitation via Setuid Syscall and Privilege Transition Correlation

web_injection_logic Difficulty 1–5 30 min

Detecting Cron-Based Persistence via Scheduled Task Forensics and Download-Execute Patterns

web_injection_logic Difficulty 1–5 30 min

Detecting Unauthorized Group Membership Changes via Privilege Escalation Audit Logs

web_injection_logic Difficulty 1–5 30 min

Detecting Sudo Abuse Through GTFOBins Traces and Sudoers Modification Forensics

web_auth_sessions Difficulty 1–5 30 min

Tracing Unauthorized Shadow File Access Using Auditd Event Log Forensics

web_auth_sessions Difficulty 1–5 30 min

SMTP Inbox OSINT: Mail Content Analysis, Sender Tracing and Inbox-Based Identity Discovery

web_auth_sessions Difficulty 1–5 30 min

LDAP Anonymous Reconnaissance: Unauthenticated Directory Traversal and User Attribute Harvesting

web_auth_sessions Difficulty 1–5 30 min

Git Repository History Secret Recovery: Identifying Deleted Credentials via Commit Log Forensics

web_auth_sessions Difficulty 1–5 30 min

PDF first-letter acrostic forensics

web_auth_sessions Difficulty 1–5 30 min

PDF JavaScript action forensics

web_auth_sessions Difficulty 1–5 30 min

PDF hidden AcroForm field forensics

web_auth_sessions Difficulty 1–5 30 min

PDF incremental update revision forensics

web_auth_sessions Difficulty 1–5 30 min

Terraform State File Exposure: Extracting Infrastructure Secrets from Public S3 Backends

web_auth_sessions Difficulty 1–5 30 min

Underground Forum-to-Pastebin OSINT Pivot: Alias Correlation and Leaked Document Discovery

osint_soc_enrichment Difficulty 1–5 30 min

Email-to-S3 OSINT Pivot: SMTP Reconnaissance Chaining to Cloud Storage Data Exposure

osint_soc_enrichment Difficulty 1–5 30 min

WHOIS-to-Employee OSINT Chain: Domain Registration Pivoting to Internal Staff Identification

osint_soc_enrichment Difficulty 1–5 30 min

Social-to-Chat OSINT Pivot: Instagram-to-Messaging Platform Identity Correlation

osint_soc_enrichment Difficulty 1–5 30 min

AWS Cognito Unauthenticated Identity Pool Exploitation: Anonymous Credential Escalation

osint_collection Difficulty 1–5 30 min

Terraform State Manipulation: Injecting Malicious Resource Definitions via Backend Write Access

osint_collection Difficulty 1–5 30 min

AWS CloudFormation Credential Exposure: Extracting Secrets from Stack Templates

osint_collection Difficulty 1–5 30 min

AWS Lambda Execution Role Privilege Escalation: Function Invocation for IAM Abuse

osint_collection Difficulty 1–5 30 min

AWS Secrets Manager Access Control Weaknesses: Scoping IAM Policies for GetSecretValue

osint_collection Difficulty 1–5 30 min

AWS Confused Deputy Attack: Cross-Account Role Assumption Without External ID Enforcement

osint_collection Difficulty 1–5 30 min

Reconstructing SMTP Email Sessions and Extracting Attachments from Network Traffic Captures

osint_collection Difficulty 1–5 30 min

Parsing FTP Command and Response Traffic with Passive Mode Data Channel Reconstruction

osint_collection Difficulty 1–5 30 min

Parsing Telnet IAC Command Sequences and Reconstructing Plaintext Sessions from PCAP

osint_collection Difficulty 1–5 30 min

Reconstructing IRC Sessions via Protocol PCAP Analysis and Channel Message Content Recovery

osint_collection Difficulty 1–5 30 min

Reconstructing LDAP Directory Queries via PCAP Analysis and Enumeration Pattern Detection

osint_collection Difficulty 1–5 30 min

Analyzing WebSocket PCAP Captures via HTTP Upgrade Detection and Frame Payload Extraction

osint_collection Difficulty 1–5 30 min

Reconstructing SIP Call Dialogs and Extracting RTP Stream Parameters for VoIP Forensics

osint_collection Difficulty 1–5 30 min

Enumerating Local Services via mDNS PCAP Multicast Record Analysis and Host Fingerprinting

osint_collection Difficulty 1–5 30 min

Interpreting Modbus/TCP Function Codes and Extracting PLC Register Values from PCAP

osint_collection Difficulty 1–5 30 min

Incident Report and Communication [Non-CTF]

0 cards

No cards in this course yet.

🏅

CTFFactory Cyber Incident Responder — Practitioner

Practitioner credential — awarded upon completion