Holmes CTF 2025 — going blue team
Most of what LoboSec does is offensive: find the bug, write the exploit, take the flag. Holmes CTF 2025 flipped that. It's a blue-team, DFIR-style event — you're handed the aftermath of an intrusion and asked to reconstruct what happened.
We entered specifically because it was uncomfortable.
A different kind of challenge
Instead of a service to attack, each stage of a defensive CTF gives you evidence:
- Disk and file artifacts — what was dropped, what was modified, and what someone tried to delete.
- Memory captures — the processes, connections and injected code that never touch disk.
- Logs and telemetry — authentication records, process creation events and network flows that turn scattered findings into a timeline.
The flag isn't "I got a shell." It's "I can tell you which account was compromised, when, and what the attacker did next."
What the team took away
Reading an intrusion backwards makes you a better attacker. Every noisy technique that showed up clearly in the logs is one we now think about differently when we're the ones making noise.
It also broadened who can contribute. Forensics and log analysis reward patience and methodical note-taking, which meant members who don't write exploits had a category where they were genuinely strong.
Where this goes
Defensive events are now a permanent part of our schedule rather than a one-off experiment. We're building out practice material for evidence triage and timeline reconstruction so the next blue-team competition starts from a much stronger base.
If the defensive side is what interests you, that's a great reason to join — come say hi in the Discord.