Hello Hack The Box Team,
I would like to suggest expanding the HTB Labs ecosystem by introducing dedicated Blue Team Pro Labs and Mini Pro Labs.
Currently, the Pro Labs experience is heavily oriented toward offensive security, which is valuable for penetration testers and red team professionals. However, I believe there is an opportunity to provide a similarly immersive experience for defensive security professionals.
My suggestion is to introduce realistic enterprise environments in which users act as SOC analysts, incident responders, and threat hunters. Instead of focusing primarily on compromising systems, participants would investigate security incidents, analyze telemetry, identify attacker activity, determine the scope of a compromise, and develop effective containment and remediation strategies.
Potential scenarios could include:
SOC Operations: Investigating alerts, correlating events, and distinguishing false positives from genuine threats.
Incident Response: Responding to ransomware incidents, compromised accounts, lateral movement, and data exfiltration.
Threat Hunting: Identifying stealthy attacker activity through Windows Event Logs, Sysmon, network traffic, and other telemetry.
Enterprise Detection Engineering: Developing and validating SIEM detection rules and investigating endpoint alerts.
Active Directory Defense: Detecting suspicious authentication, privilege escalation, persistence, and other signs of compromise.
Cloud Security: Investigating suspicious activity in cloud audit logs and responding to identity-related incidents.
The Pro Labs format could provide a complete enterprise environment with multiple interconnected systems, while Mini Pro Labs could focus on individual incidents and specific defensive skills.
Progression could be based on investigation quality, evidence collection, attack reconstruction, detection coverage, and the effectiveness of remediation recommendations.
I believe this addition would benefit aspiring SOC analysts, blue team engineers, incident responders, and experienced security professionals who want to practice defending realistic environments.
It could also complement HTB's existing offensive labs by allowing users to understand both how attacks happen and how to detect and stop them.
Thank you for considering this suggestion. I would love to see dedicated defensive Pro Labs become part of the HTB ecosystem.
Best regards,
A member of the Hack The Box community