Live Labs
Real-world hacking labs, CTF challenges, and sandboxed environments. Earn points, climb the leaderboard, and sharpen your skills.
10
Total Labs
4,200
Total Points
4
Free Labs
9
Categories
XSS Playground
Practice Cross-Site Scripting attacks in a safe environment. Discover reflected, stored, and DOM-based XSS vulnerabilities across multiple difficulty levels.
SQL Injection Master
Exploit SQL injection vulnerabilities to extract sensitive data, bypass authentication, and escalate privileges. Covers UNION, blind, and time-based techniques.
Linux Privilege Escalation
Start as a low-privilege user and find your way to root. Covers SUID binaries, cron jobs, kernel exploits, misconfigured services, and more escalation vectors.
Network Recon Challenge
Perform network reconnaissance on a segmented corporate environment. Use Nmap, Masscan, and custom scripts to map the network, identify services, and find hidden hosts.
Active Directory Attack Lab
Compromise an Active Directory domain from initial foothold to Domain Admin. Covers Kerberoasting, AS-REP roasting, BloodHound, Pass-the-Hash, and DCSync.
Ransomware Response Simulation
Respond to a live ransomware incident. Analyze the malware, contain the spread, identify the attack vector, and write a professional incident report — all under time pressure.
Secure Code Review — Node.js
Review a Node.js Express application for security vulnerabilities. Find injection flaws, insecure deserialization, broken authentication, and IDOR bugs in production-like code.
Zero Day Rush
The ultimate pentesting challenge. A fully simulated enterprise network with multiple hosts, services, and attack paths. Chain multiple exploits to reach the final flag. Only the best complete it.
Web App Pentest — Guided Walkthrough
Step-by-step guided lab for your first web application penetration test. Follow the methodology: recon, enumeration, exploitation, post-exploitation, and reporting.
Container Escape
Break out of a Docker container and compromise the host system. Covers misconfigured mounts, privileged containers, kernel exploits, and Kubernetes pod escapes.