Skip to content
Vio£ethat
>about.violethat

We are building the playground we always wanted.

VioletHat started as a private research repository for detection engineers. Today, it is evolving into a hands-on platform for researching threats, understanding attacker behavior, and building effective detections.

  • DPIIT Recognized
  • Built by practitioners
>mission

Know Your Defense.

We exist to close the gap between understanding Windows internals and building real endpoint detections. VioletHat is not a log-analysis platform — it is a hands-on API hooking platform where players research Win32 APIs, develop hooks, and uncover hidden behavior through runtime visibility.

  • Built for real detection engineering

    Every challenge is designed around practical endpoint workflows — research APIs, develop hooks, compile detections, and uncover hidden behavior through runtime analysis.

  • Engineered by practitioners

    Built by professionals with hands-on experience in detection engineering, malware research, Windows internals, and offensive security — creating the platform we always wanted for learning low-level detection engineering.

  • Learn through runtime visibility

    VioletHat focuses on behavioral detection through API hooking and system-level observation, helping practitioners understand how real endpoint detections are built beyond traditional log analysis.

>the.founder

Built by a practitioner.

Not a marketing team. Not a course aggregator. One engineer who kept getting asked the same question — and decided to answer it with a platform.

Portrait of Kartik Durg, Founder of Violethat

Kartik Durg

Founder · Violethat

  • 9+ yrs in Cybersecurity

Kartik has spent the last decade deep in the trenches of cybersecurity — reverse-engineering malware, simulating real-world adversaries, and more recently pushing the boundaries of security research.

Violethat was born from a simple, recurring frustration. As detection engineers reached out asking where can I actually practice this for real? the honest answer was: nowhere good enough. So he built it.

The original Detect-DB research repository is now integrated into the VioletHat challenge catalog — so practitioners can move from researching attacker techniques to understanding their behavior and engineering detections for them.

Areas of expertise

  • Malware Analysis
  • Adversary Simulation
  • Detection Engineering
  • Reverse Engineering

The best way to engineer a detection is to understand the threat. The best way to understand the threat is to study how it behaves.

Kartik Durg
>ready.to.run

Capture your first flag today.

No setup. No VM. No install. Sign up free and start building your first detection.

No card required · 20+ free challenges · Cancel anytime