Build Crew
Somebody has to build the company that gets breached, and then breach it. That is what the crew does, and it runs from now until October.
The scenario is not written yet, and that is on purpose. The crew picks it. Are we a power utility? A hospital? A tech firm? A manufacturer? That one decision drives the network, the staff, the data worth stealing, and how the attack plays out.
Same goes for the attack itself. The crew agrees the chain together before anyone runs it. Nobody is handed a script.
Four phases, in order. There is work at every skill level in each of them, so you do not need to already know this stuff to be useful.
Phase 3 matters more than it sounds. An attack in an empty network is easy to spot, because it is the only thing happening. The difficulty comes from burying it in ordinary Tuesday morning traffic, so there is real work in making the company feel lived in.
Whoever builds this will be more capable than most people competing, so the flags need a real difficulty gradient. Core flags almost everyone lands, and a long tail that most people will not, which is fine and intended.
Answerable by looking in the right place. These carry the points that let a beginner team finish the event having actually done something.
Q. What IP address is the host beaconing to? Q. What domain is the implant contacting? A. definitelynotmalware[.]ru
Need two or more sources correlated, or knowing what normal looks like before you can see abnormal. Reachable by anyone willing to work the timeline.
Q. Which account moved laterally, and from where? Q. What was staged for exfiltration, and when?
For people who enjoy the hunt. Renamed living-off-the-land binaries are the archetype: a legitimate signed Windows binary doing something it has no business doing, under a filename that is not its own.
Q. A signed Microsoft binary ran under an assumed name. Identify it, and prove how you know.
If you build it you know every flag and you wrote the attack, so competing is off the table. Here is what you do instead.
You work the other side of the table, helping teams and scoring their work alongside Recorded Future analysts and other industry people.
Reading a stack of incident reports teaches you more about writing one than writing one does.
They are working closely with us and there are certifications and training available through their team. We will set up a direct session for the crew.
Standing up an AD environment, generating realistic telemetry, and running an intrusion chain is a portfolio piece.
Same as everyone else on the day. Challenge coins and sponsor merch included.
Builders get first pick of running the attack side at the next event, which is the more interesting job anyway.
Flags earn points during the four hours. After the event, each team submits a written incident report structured on the SANS PICERL model, due a few days later: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned.
The write-up is optional but strongly encouraged, and it is a large share of the grade. It is also the same thing you would write in a real SOC, and it is a work sample you can show an employer, which a scoreboard position is not.
Register for the event first, then join the Discord and say you want to build. You will get a dedicated role that unlocks the infrastructure and build channels, which is where the crew is already working.
No experience required. Genuinely. Phase 1 is a conversation, phase 3 is inventing people, and there is plenty in between that you learn by doing.