Verified credential
PHANTOM - CTI CTF Complete
Awarded to Anthony B on May 20, 2026
PHANTOM is awarded for completing Blue Team CTF I on Guardian Foundry, a hands-on cyber threat intelligence scenario built around a current real-world supply chain compromise pattern. Earners triaged a simulated CI/CD pipeline incident from raw artifacts, identified indicators of compromise, built detection rules across host and network telemetry, executed an enterprise-scale threat hunt, and produced a complete incident response report.
Criteria
To earn PHANTOM, learners completed the inaugural Blue Team CTF on Guardian Foundry and submitted passing work across all required deliverables:
- Extracted and answered 10 indicator-of-compromise questions from a multi-artifact incident package
- Completed 2 write-ups for threat actor attribution, and operational impact
- Authored 3 detection rules: YARA (malicious payload), Snort (exfiltration traffic), and Sigma (build-time process telemetry)
- Built an enterprise threat hunt query in either KQL or PowerShell
- Produced a complete incident report including IOC entries table, executive summary, technical analysis mapped to MITRE ATT&CK, and remediation steps
The incident was also manually reviewed and verified by an Instructor for accuracy and authenticity.