u1tras wrote: » tedjames, thanks for your links. Seems like both of them are about "offense informs defense" approach.
u1tras wrote: » So, what about Immersivelabs? Has anyone tried this? Seems like their Labs contain different blue team exercises (as it's stated on the website).
u1tras wrote: » JDMurray, you can use a special prepared "BOSS of the SOC" Datasets for Splunk, as cyberguy suggested earlier.
u1tras wrote: » There is a summary of all options we've collected for Blue Team Labs during this thread: 1. Chris Long Detection Lab (free). 2. Hand made Security Onion/Vulnhub lab (free). 3. Boss of the SOC Datasets with Splunk (free). 4. SANS NetWars (Core Continuous/DFIR) (very expensive). 5. ISACA CSX Labs (expensive). 6. Immersive Labs (free if you have a .edu email). 7. eLearnSecurity Hera Labs (expensive).
SnotFunk wrote: » Why not setup you're own security onion lab, install a SIEM or use Kibana and then use tcpreplay and the pcaps from here:Malware-Traffic-Analysis.net Or if you just want to analyse pcaps, use wireshark.
nicolettean wrote: » Did anyone ever try any of these labs? If so, which ones? Curious to try one but want to know if one is better than another.