~/notes/navigating-the-labs
How to navigate the LabsWhere guided workshops, per-event CTF writeups, and investigation cases live, and where to start in each track.
The Labs has three tracks, one per practice type: guided workshops, per-event CTF writeups, and cases for investigations. They appear in that order on the Labs page because they follow a natural progression: learn the technique, apply it under pressure, then analyze a real artifact.
Workshops: guided material
Workshops are step-by-step series for reverse engineering, tooling, and lab practice. Each chapter builds on the previous one, so follow the numeric order.
The concrete example today is the GBA game reverse engineering series built around Pokemon FireRed. Its opening chapter, 00-comece-aqui (“Start here”), lays out the whole path: GBA architecture, ARM and Thumb, tooling, static analysis in Ghidra, dynamic analysis with mGBA and GDB, up to writing and installing your own patch.
Before starting, the chapter lists three prerequisites: your own legitimate dump of the game, a ready battle save, and the tools installed. The rule is explicit: every participant uses their own dump, with no commercial ROM distribution.
CTF: events and writeups
CTF groups writeups by competition, with per-challenge notes, exploit chains, and evidence. Each event shows placement, solve score, and the challenge list.
The reference event right now is the Fluid Attacks LATAM Challenge 2026-2: first place overall, 22 out of 22 solved. The writeups were prepared in English for the organizer review process, and the GitHub archive keeps the same texts alongside the scripts and artifacts used in the solves.
To study a specific challenge, enter through the event and then the challenge slug. To see the overall method, read the challenge list in scoreboard order.
Cases: full investigations
Cases are long-form investigations of artifacts, malware behavior, and technical incidents. This is where analysis that does not fit a competition writeup lives.
The first one is LAB-0001, about an HTA received from a known contact that turned into a WhatsApp Web spreading dropper. It covers triage, layered obfuscation, safe extraction, and the final chain down to browser automation. If you arrived here from the HTA triage note, that case is the natural follow-up.
Start with workshops to build foundations, use CTF to see technique applied, and go to cases when you want to follow an investigation end to end.