Lab library
Guided learning paths built from hands-on labs you run in your browser. Pick a path below, or browse every lab.
Password & Credential Attacks
The full credential-attack lifecycle: identifying hash types, offline cracking with Hashcat and John, wordlist/rule/mask crafting, online brute-force and spraying, and NTLM pass-the-hash/relay.
5 labs
Network Security Monitoring
Detect attacks on the wire: dissect packets in Wireshark, deploy Suricata for signature-based IDS, and extract investigative metadata from Zeek logs.
3 labs
Purple Team Exercises
Advanced attack-and-detect capstones: run a red action, then detect and respond to it in the SIEM/EDR — covering web exploitation, AD attacks, lateral movement, ransomware, and C2 beaconing.
5 labs
Hardening & Vulnerability Management
Defensive hardening and vuln management: baseline and harden Linux (CIS/Lynis) and Windows (audit policy + Sysmon), then run authenticated OpenVAS scans and prioritize remediation.
3 labs
SOC Analyst & SIEM
Foundational blue-team skills: log-source literacy, standing up a Wazuh SIEM, building dashboards and alerts, triaging alerts, and analyzing Windows event logs.
5 labs
DFIR — Forensics & Incident Response
The incident-response lifecycle and digital forensics: triage, live endpoint forensics with Velociraptor, introductory memory analysis, and building a forensic timeline on a compromised host.
4 labs
Threat Detection & Hunting
Detection-engineering and threat-hunting: the MITRE ATT&CK framework, authoring Sigma rules, hypothesis-driven hunting in endpoint telemetry, and detecting common red-team TTPs.
4 labs
Active Directory Attacker
An end-to-end attack chain against a vulnerable Active Directory: enumeration, BloodHound, Kerberos attacks (Kerberoast/AS-REP), spraying, ACL/delegation abuse, lateral movement, credential dumping, DCSync, and golden/silver-ticket persistence.
10 labs
Privilege Escalation
Local privilege escalation on Linux and Windows: SUID/sudo/cron/capabilities, kernel and service flaws, Windows service/registry/token/UAC/DLL abuses, and automated enumeration.
7 labs
Network & Service Exploitation
Enumerate and exploit network services (SMB, FTP/SSH/Telnet, vulnerable web services, databases) with Metasploit and manual public exploits, then pivot through segmented networks.
7 labs
Web Application Attacker
End-to-end exploitation of OWASP-class web vulnerabilities against live deliberately-vulnerable apps: recon, injection, auth, access control, upload, traversal, command injection, and API/JWT attacks.
9 labs
Reconnaissance & OSINT
Build the full recon kill-chain: passive OSINT, active host discovery, Nmap service scanning, web/DNS enumeration, and turning findings into a vulnerability picture.
5 labs
Red Team Foundations
Absolute-beginner offensive-security foundations: Linux CLI, networking, the lab environment, and Bash — everything you need before attacking.
4 labs