Lab library
Guided learning paths built from hands-on labs you run in your browser. Pick a path below, or browse every lab.
Windows Privilege Escalation
Escalate from a low-privileged Windows shell to SYSTEM: enumeration, service misconfigurations, token-privilege abuse, and a foothold-to-SYSTEM capstone.
4 labs
Web Application Attacker
Attack modern web applications end to end: recon, SQL injection, XSS, file-upload RCE and SSRF, ending in a chained server compromise.
6 labs
Threat Detection and Hunting
Proactively hunt adversaries your automated detections miss: hunting fundamentals, ATT&CK-technique hunts, and an undetected-intrusion capstone that ends in a new detection rule.
3 labs
SOC Analyst and SIEM
Become an effective SOC analyst: SIEM fundamentals, log onboarding, detection engineering, alert triage, and a live intrusion capstone.
5 labs
Reconnaissance and OSINT
Map a target from nothing: passive OSINT, DNS and subdomain enumeration, active service discovery, and a prioritised attack-surface capstone.
4 labs
Post-Exploitation and C2
Operate after initial access: situational awareness and opsec, persistence, lateral movement, and a foothold-to-objective capstone, each paired with how defenders detect it.
4 labs
Phishing and Initial Access
Understand and defend against phishing in an isolated sandbox: social-engineering fundamentals, email authentication and its gaps, and an authorised-simulation capstone that ends in layered defences.
3 labs
Password and Credential Attacks
Attack the credentials layer: how hashes work, offline cracking, online spraying and stuffing, and a hashes-to-access capstone.
4 labs
Network and Service Exploitation
Break into a network by attacking its exposed services: deep enumeration, exploiting vulnerable versions, attacking unauthenticated databases, and an initial-access capstone.
4 labs
Mobile Application Security
Assess mobile apps end to end: fundamentals and the untrusted client, static analysis for embedded secrets, dynamic analysis and traffic interception, and an access-another-user capstone.
4 labs
Malware Development and Offensive Tooling
Understand custom offensive tooling from the analyst's side, anatomy and telemetry, process injection, obfuscation and loaders, and a custom-implant analysis capstone that ends in a detection rule.
4 labs
Linux Privilege Escalation
Escalate from a low-privileged shell to root on Linux: enumeration, SUID and sudo abuse, cron and PATH, kernel and capabilities, ending in a foothold-to-root capstone.
5 labs
IoT and OT Security
Assess connected and industrial devices: fundamentals and attack surface, firmware extraction and analysis, unauthenticated protocol abuse, and a device-compromise capstone.
4 labs
Exploit Development and Reversing
Go from reading a binary to writing an exploit: reverse-engineering fundamentals, memory-corruption basics, modern mitigations, and a working-exploit capstone.
4 labs
Evasion and EDR Bypass
Understand endpoint evasion in order to defeat it: how EDR sees, the families of evasion and their detection, and a catch-what-evaded capstone that ends in a resilient detection.
3 labs
DFIR: Forensics and Incident Response
Investigate a compromise end to end: IR fundamentals, live-response triage, memory and disk forensics, timeline analysis, and a full intrusion-reconstruction capstone.
5 labs
Cloud and Identity Attacker
Attack cloud environments through identity: IAM fundamentals, credential theft, IAM privilege escalation, and an account-takeover capstone.
4 labs
Active Directory Attacker
Go from an unprivileged domain foothold to full domain dominance: fundamentals, enumeration, attack-path analysis, credential attacks, ACL abuse, DCSync, golden tickets and ADCS, ending in a capstone compromise.
10 labs
Password & Credential Attacks
The full credential-attack lifecycle: identifying hash types, offline cracking with Hashcat and John, wordlist/rule/mask crafting, online brute-force and spraying, and NTLM pass-the-hash/relay.
5 labs
Hardening & Vulnerability Management
Defensive hardening and vuln management: baseline and harden Linux (CIS/Lynis) and Windows (audit policy + Sysmon), then run authenticated OpenVAS scans and prioritize remediation.
3 labs
SOC Analyst & SIEM
Foundational blue-team skills: log-source literacy, standing up a Wazuh SIEM, building dashboards and alerts, triaging alerts, and analyzing Windows event logs.
5 labs
Threat Detection & Hunting
Detection-engineering and threat-hunting: the MITRE ATT&CK framework, authoring Sigma rules, hypothesis-driven hunting in endpoint telemetry, and detecting common red-team TTPs.
4 labs
Active Directory Attacker
An end-to-end attack chain against a vulnerable Active Directory: enumeration, BloodHound, Kerberos attacks (Kerberoast/AS-REP), spraying, ACL/delegation abuse, lateral movement, credential dumping, DCSync, and golden/silver-ticket persistence.
10 labs
Red Team Foundations
Absolute-beginner offensive-security foundations: Linux CLI, networking, the lab environment, and Bash — everything you need before attacking.
4 labs