CyberNexura
2 members · live gamified training

Level up your whole tech career

Master Cybersecurity

One gamified arena for the entire tech stack. Start with hands-on blue-team labs and SOC investigations, then grow into coding, AI, exam prep and AI study tools - all with the same XP, ranks and seasons.

Free to start · no credit card required

CybersecurityCodingAI & MLExamsTools
conn.log - threat hunt

$

0
Hands-on labs
0
Graded tasks
0
Blue-team domains
0
Findings submitted
One platform

Every skill, one arena

Start with blue-team cybersecurity - then grow into coding, AI, exam prep and study tools, all with the same XP, ranks and gamified progression.

Cybersecurity Learning

Live

Hands-on blue-team labs, SOC investigations and CTF challenges with an animated attack replay.

  • SOC investigations
  • Detection engineering
  • CTF challenges
Explore

Coding Learning

Soon

Guided, project-based tracks that teach real programming - from fundamentals to shipping.

  • Interactive lessons
  • Auto-graded projects
  • Language paths
In development

AI & Machine Learning

Soon

Learn ML by building - notebooks, model challenges and applied AI mini-projects.

  • ML foundations
  • Model challenges
  • Applied AI
In development

Vendor Exams

Soon

Realistic mock exams for the certs that matter - timed, scored and explained.

  • Timed mock exams
  • Question bank
  • Score analytics
In development

Student Tools

Soon

An AI toolbelt for studying: detect AI text, get tutored, and get help writing research.

  • AI Detector
  • AI Tutor
  • Research Writer
In development
Try it - no account needed

Solve a real question right now

Here's a slice of a threat hunt. Read the connection log, spot the command-and-control beacon, and submit the IP - exactly like a real lab task.

demo · beacon hunt

$ zeek-cut id.orig_h id.resp_h id.resp_p < conn.log

10.10.14.23 → 93.184.216.34 :443 ssl

10.10.14.10 → 142.250.72.14 :80 http

10.10.14.23 → 45.77.122.9 :443 ssl (x15, 60s interval)

10.10.20.5 → 151.101.1.140 :443 ssl

Which IP is the C2 beacon?

Hint: one host beacons on a fixed interval.

Blue-team domains

See labs by domain →
capture.pcap

$ zeek-cut id.orig_h id.resp_h service < conn.log

10.10.14.23 → 45.77.122.9 ssl (beacon x15, 60s)

10.10.14.10 → 142.250.72.14 http

Network ForensicsSee Network labs

Built for real defenders

Most platforms teach you to attack. CyberNexura trains you to detect, investigate, and respond - the way a real SOC works.

Real evidence, your tools

Download actual PCAPs, EVTX, memory dumps and phishing emails and analyze them in Wireshark, Zeek, or your own SIEM - not a locked-in browser VM.

Blue-team first

Purpose-built for defenders across SOC, DFIR, threat hunting and IR - not an afterthought bolted onto an offense platform.

Zero setup, works offline

Nothing to boot, no cloud machine to wait on. Pull the evidence and start investigating anywhere - even air-gapped.

Fair, instant grading

Findings are checked server-side, points scale with difficulty, and the full analyst writeup unlocks the moment you finish.

How it works

01

Download the evidence

Grab the real artifacts - PCAPs, event logs, memory images, phishing emails - and open them in your own tools.

02

Investigate and submit

Work the scenario, answer the graded questions, and get instant feedback. Answers are checked server-side.

03

Earn rank and climb

Score points scaled by difficulty, unlock the analyst writeup, and rise up the leaderboard.

Featured labs

Real scenarios you can start right now.

Browse all labs →
Insane
Hunt

Cloud Compromise - The Exposed AWS Access Key

A long-lived AWS access key was committed to a public GitHub repo and abused within minutes to mine crypto and plant a backdoor IAM user.

T1596.005 Search Open Technical Databases: Scan Public RepositoriesT1552.001 Unsecured Credentials: Credentials In Filesawscloudtrail
250 pts 0 60m
Hard
DFIR

Ransomware Precursor - The Living off the Land Execution

An internet-facing Confluence server was exploited and used to stage a Cobalt Strike beacon, run AD recon, and begin lateral movement - the classic 60 minutes before ransomware.

T1595.002 Active Scanning: Vulnerability ScanningT1190 Exploit Public-Facing Applicationliving-off-the-landcertutil
220 pts 0 55m
Medium
SIEM

Credential Theft - The Session Cookie Reuse

An employee's live HR portal session was hijacked and used to reroute their payroll direct deposit.

T1589.002 Gather Victim Identity Information: Email AddressesT1566.002 Phishing: Spearphishing Linkphishinginfostealer
150 pts 0 35m

Climb the ranks

Every solved task earns points. Progress from your first login to the top of the SOC.

Recruit
Analyst
SOC Analyst II
Threat Hunter
SOC Lead
IR Commander
Blue Team Legend

The board is live

Season 1: First Light · leading right now

The community lab bank

A library that grows with the community

Every analyst has a war story. Soon you'll be able to publish your own labs and writeups, so CyberNexura becomes an ever-growing bank of real-world defensive scenarios - authored by defenders, for defenders.

Author labs
Turn a real incident into a graded scenario.
Share writeups
Teach the method, not just the answer.
Earn reputation
Get credit as authors climb the board.
Vetted content
Reviewed before it reaches learners.

One platform, three fronts

The platform grows one facet at a time - defense first, then AI-assisted analysis, then offense.

Blue team - live nowAI-assisted analysisRed team & CTFs - soon

Questions, answered

Do I need to install anything?

No. Download the evidence files and analyze them in your own tools - Wireshark, Zeek, a SIEM, whatever you use. Nothing to boot, works even offline.

Is CyberNexura for beginners or pros?

Both. Start with the First Shift onboarding path, then climb from Easy labs all the way to the advanced Pro Range.

How is my work graded?

Findings are checked server-side and points scale with difficulty. The full analyst writeup unlocks the moment you complete a lab.

Is it free?

Yes - core labs, leaderboards, seasons and learning paths are free forever. Pro unlocks the advanced Pro Range and upcoming certifications.

Which domains are covered?

Network forensics, endpoint / DFIR, log analysis / SIEM, malware analysis, threat hunting, incident response, and email / phishing.

Ready to run your first investigation?

Create a free account and solve your first lab in minutes. Join 2 analysts already training.

Start free
Start free