First look at Flare Academy Darkroom (CTIA)
BLUF: Flare Academy’s Darkroom is a free, self-paced underground-intelligence lab. I am in the CTIA track now. I will update this post as I go through it.
I have used Flare for years. I really like the product, and I like how they keep building and tightening the tooling. They have been good friends to me. I know a lot of the founders and some of the developers personally. They are an incredible company. Read the rest of this with that disclosure in mind: this is still a first look at the lab, not a paid review.
Why this matters
A lot of CTI training is still a redacted screenshot and a kill-chain slide. That is not how the work feels. Flare’s 3 August 2026 launch note puts you in a purpose-built lab: forum threads, initial access broker listings, ransomware-as-a-service ops, stealer-log archives, credential distribution, and cryptocurrency tracing, with AI threat-actor personas that change with your choices. Eric Clay (Head of Research) said in that note that the point is understanding how disconnected exposures come together before a breach. That matches the job I care about: identity exposure before the PDF.
Darkroom is the training surface that matches how I already use Flare for exposure and underground collection. I am not done with the CTIA lab. Early impression: it is built for practitioners, not a vendor tour.
What I am treating as in-scope for a public note
- The lab is free via Flare’s Discord onboarding at flare.io/darkroom. The CTIA track I am in is darkroom.labs.flare.io/ctia.
- Flare lists the runtime as about four hours, self-paced. Pass the assessment and Flare Academy will issue a cert, CPE, and a badge.
- Flare’s launch note also announced a live Darkroom CTF at DEF CON 34 on 6 August 2026. I am on the always-on lab, not the conference session.
- This writeup does not reproduce challenge answers, simulated IOCs, or actor dialogue from inside the environment. Those stay in the lab.
Defender takeaway
If you staff or hire for CTI / identity exposure / purple-team work, this is useful time: you practice pre-breach collection (what is listed, what is for sale, what identity residue is already in logs) instead of only reading incident reports. Pair it with your own org’s exposure monitoring. Do not treat the sim as a license to browse live criminal markets.
Open questions
- How closely the CTIA scoring maps to what a hiring manager would actually ask in an interview.
- Whether Flare will publish a public changelog for new Darkroom modules so this does not live only in Discord.
- After I finish the assessment: what I would change in a detection-validation lab that starts from the same identity-exposure picture.
How to start
Join via flare.io/darkroom, then the CTIA lab at darkroom.labs.flare.io/ctia. I will update this when I complete the track.