Lab library

Guided learning paths built from hands-on labs you run in your browser. Pick a path below, or browse every lab.

intermediate Subscription

Windows Privilege Escalation

Escalate from a low-privileged Windows shell to SYSTEM: enumeration, service misconfigurations, token-privilege abuse, and a foothold-to-SYSTEM capstone.

4 labs

intermediate Subscription

Web Application Attacker

Attack modern web applications end to end: recon, SQL injection, XSS, file-upload RCE and SSRF, ending in a chained server compromise.

6 labs

advanced Subscription

Threat Detection and Hunting

Proactively hunt adversaries your automated detections miss: hunting fundamentals, ATT&CK-technique hunts, and an undetected-intrusion capstone that ends in a new detection rule.

3 labs

intermediate Subscription

SOC Analyst and SIEM

Become an effective SOC analyst: SIEM fundamentals, log onboarding, detection engineering, alert triage, and a live intrusion capstone.

5 labs

beginner Subscription

Reconnaissance and OSINT

Map a target from nothing: passive OSINT, DNS and subdomain enumeration, active service discovery, and a prioritised attack-surface capstone.

4 labs

advanced Subscription

Post-Exploitation and C2

Operate after initial access: situational awareness and opsec, persistence, lateral movement, and a foothold-to-objective capstone, each paired with how defenders detect it.

4 labs

intermediate Subscription

Phishing and Initial Access

Understand and defend against phishing in an isolated sandbox: social-engineering fundamentals, email authentication and its gaps, and an authorised-simulation capstone that ends in layered defences.

3 labs

intermediate Subscription

Password and Credential Attacks

Attack the credentials layer: how hashes work, offline cracking, online spraying and stuffing, and a hashes-to-access capstone.

4 labs

intermediate Subscription

Network and Service Exploitation

Break into a network by attacking its exposed services: deep enumeration, exploiting vulnerable versions, attacking unauthenticated databases, and an initial-access capstone.

4 labs

advanced Subscription

Mobile Application Security

Assess mobile apps end to end: fundamentals and the untrusted client, static analysis for embedded secrets, dynamic analysis and traffic interception, and an access-another-user capstone.

4 labs

advanced Subscription

Malware Development and Offensive Tooling

Understand custom offensive tooling from the analyst's side, anatomy and telemetry, process injection, obfuscation and loaders, and a custom-implant analysis capstone that ends in a detection rule.

4 labs

intermediate Subscription

Linux Privilege Escalation

Escalate from a low-privileged shell to root on Linux: enumeration, SUID and sudo abuse, cron and PATH, kernel and capabilities, ending in a foothold-to-root capstone.

5 labs

advanced Subscription

IoT and OT Security

Assess connected and industrial devices: fundamentals and attack surface, firmware extraction and analysis, unauthenticated protocol abuse, and a device-compromise capstone.

4 labs

advanced Subscription

Exploit Development and Reversing

Go from reading a binary to writing an exploit: reverse-engineering fundamentals, memory-corruption basics, modern mitigations, and a working-exploit capstone.

4 labs

advanced Subscription

Evasion and EDR Bypass

Understand endpoint evasion in order to defeat it: how EDR sees, the families of evasion and their detection, and a catch-what-evaded capstone that ends in a resilient detection.

3 labs

intermediate Subscription

DFIR: Forensics and Incident Response

Investigate a compromise end to end: IR fundamentals, live-response triage, memory and disk forensics, timeline analysis, and a full intrusion-reconstruction capstone.

5 labs

advanced Subscription

Cloud and Identity Attacker

Attack cloud environments through identity: IAM fundamentals, credential theft, IAM privilege escalation, and an account-takeover capstone.

4 labs

intermediate Subscription

Active Directory Attacker

Go from an unprivileged domain foothold to full domain dominance: fundamentals, enumeration, attack-path analysis, credential attacks, ACL abuse, DCSync, golden tickets and ADCS, ending in a capstone compromise.

10 labs

intermediate Subscription

Password & Credential Attacks

The full credential-attack lifecycle: identifying hash types, offline cracking with Hashcat and John, wordlist/rule/mask crafting, online brute-force and spraying, and NTLM pass-the-hash/relay.

5 labs

intermediate Subscription

Hardening & Vulnerability Management

Defensive hardening and vuln management: baseline and harden Linux (CIS/Lynis) and Windows (audit policy + Sysmon), then run authenticated OpenVAS scans and prioritize remediation.

3 labs

intermediate Subscription

SOC Analyst & SIEM

Foundational blue-team skills: log-source literacy, standing up a Wazuh SIEM, building dashboards and alerts, triaging alerts, and analyzing Windows event logs.

5 labs

intermediate Subscription

Threat Detection & Hunting

Detection-engineering and threat-hunting: the MITRE ATT&CK framework, authoring Sigma rules, hypothesis-driven hunting in endpoint telemetry, and detecting common red-team TTPs.

4 labs

advanced Subscription

Active Directory Attacker

An end-to-end attack chain against a vulnerable Active Directory: enumeration, BloodHound, Kerberos attacks (Kerberoast/AS-REP), spraying, ACL/delegation abuse, lateral movement, credential dumping, DCSync, and golden/silver-ticket persistence.

10 labs

beginner

Red Team Foundations

Absolute-beginner offensive-security foundations: Linux CLI, networking, the lab environment, and Bash — everything you need before attacking.

4 labs