Synapse Consulting
Home SynapseRM / TPRM Services Pricing About BlogCareersLabsContact
EN ยท FR
Test access Book a demo
Labs

Hands-on challenges

Practical exercises built from the techniques we meet on real engagements. Download the material, work in an isolated VM, and check your answer against the full solution.

Intermediate · ~60 min · DFIR / Maldoc
Challenge #01 · Analysing a multi-layer VBA maldoc

A suspicious Word attachment. Deobfuscate four VBA layers (Chr, StrReverse, XOR, Base64), extract the C2, and write a YARA rule.

START →
Intermediate · ~90 min · DFIR / Disk forensics
Challenge #02 · Disk image forensics: timeline & carving

A Linux ext4 image from an alleged data theft. Build a mactime timeline, recover deleted files by metadata and by carving, and separate facts from hypotheses.

START →
Advanced · ~90 min · OSINT / Attribution
Challenge #03 · Multi-source OSINT attribution

A Tor Onion service and a clearnet profile publish the same project. Attribute them to one operator via PGP fingerprint, PDF metadata, SHA-256 asset matching and idiolect.

START →
Intermediate · ~60 min · PDF forensics
Challenge #04 · Anatomy of a booby-trapped PDF

The ORION capstone. Spot a metadata discordance, uncover JavaScript that pdfinfo misses, decode FlateDecode and ASCIIHex+Flate streams, and tie all four labs together.

START →
Intermediate · ~45 min · Phishing / SVG
Challenge #05 · Hidden in an image: SVG smuggling

A weaponised SVG attachment. Find the embedded script, peel back two obfuscation layers, and recover the phishing redirect and the base64-embedded victim tracker.

START →
Intermediate · ~60 min · IR / Infostealer
Challenge #06 · After the steal: infostealer log triage

Triage a StealC-style stealer log: inventory stolen credentials, spot password reuse, find the session cookies that bypass MFA, and drive a prioritised incident response.

START →
Intermediate · ~50 min · Fileless / ClickFix
Challenge #07 · No file, no problem: a ClickFix incident

Reconstruct a ClickFix (fake-CAPTCHA) incident from Windows logs: read RunMRU, decode the PowerShell -EncodedCommand, follow the fileless cradle in Script Block Logging.

START →
Intermediate · ~45 min · Network / PCAP
Challenge #08 · The heartbeat: C2 beaconing in a PCAP

Work a packet capture: find the C2, prove the 30-second beacon, export the downloaded payload, and catch the data-exfiltration POST leaving the host.

START →
Intermediate · ~45 min · SQLite forensics
Challenge #09 · What they deleted: SQLite recovery

Recover a deleted record from a Chrome-style History database: read the live history, carve the free space, and reveal the entry the user tried to erase.

START →
Intermediate · ~60 min · SOC / Event logs
Challenge #10 · Reading the logs: a Windows intrusion

SOC triage over a Windows event export: trace the brute force and account takeover, the persistence and privilege escalation, and the lateral movement, then contain.

START →
More challenges in preparation.
Synapse Consulting

A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.

PLATFORM
SynapseRM / TPRM Pricing Test accessPresentation (PDF)
SERVICES
Governance Operational Training
COMPANY
About Contact Blog Labs Careers Privacy & cookies
Brussels, Belgium