1–24 of 135 labs
📚 Every track runs top to bottom: start with 🟢 Start Here, build up through🟡 Build Your Skills, and finish with 🔴 Go Advanced. Use the tabs to jump to a track.
Generated from 135 content files · 126 free · 9 members · 0 unstated ·5 of them appear on no hand-written card today (html-css-lab, js-lab, sql-lab, kali-env-setup-ar, nmap-scanning-ar)

🚀 Zero to Hacker

17 labs
Start Here — Foundations
Intermediate
Outline✓ Free
🚀 Zero to Hacker

DNS Enumeration with Python

Build a DNS reconnaissance tool from scratch in Python.

Start Lab →⏱ 1.5 hours
Beginner
Outline✓ Free
🚀 Zero to Hacker

File Transfers

Move files between machines using HTTP, FTP, SCP, SMB, and base64 encoding.

Start Lab →⏱ 45 minutes
Easy
✓ Free
🚀 Zero to Hacker

Hydra Brute Force

Online password attacks against SSH, FTP, HTTP forms, and RDP with Hydra.

Start Lab →⏱ 40 minutes
Easy
✓ Free
🚀 Zero to Hacker

Kali Linux Environment Setup

Set up your Kali VM, configure tools, and prepare your hacking lab environment.

Start Lab →⏱ 30 minutes
Medium
✓ Free
🚀 Zero to Hacker

Metasploit Framework Basics

msfconsole, searching modules, setting options, running exploits, and Meterpreter.

Start Lab →⏱ 75 minutes
Easy
✓ Free
🚀 Zero to Hacker

Netcat Fundamentals

Netcat as a network Swiss army knife — listeners, file transfer, reverse shells.

Start Lab →⏱ 35 minutes
Easy
✓ Free
🚀 Zero to Hacker

Network Scanning with Nmap

Host discovery, port scanning, service detection, OS fingerprinting, and NSE scripts.

Start Lab →⏱ 45 minutes
Easy
✓ Free
🚀 Zero to Hacker

OSINT & Passive Reconnaissance

End-to-end passive recon on a target: DNS, WHOIS, Shodan, theHarvester.

Start Lab →⏱ 50 minutes
Medium
✓ Free
🚀 Zero to Hacker

Password Cracking Lab

Crack NTLM, SHA1, and bcrypt hashes offline using hashcat and John the Ripper.

Start Lab →⏱ 60 minutes
Beginner
✓ Free
🚀 Zero to Hacker

Python Coding Lab

Socket programming, subprocess, file I/O, and building basic automation tools.

Start Lab →⏱ 3 hours
Intermediate
Outline✓ Free
🚀 Zero to Hacker

Service Footprinting

Banner grabbing and service enumeration across FTP, SSH, SMTP, SMB, and HTTP.

Start Lab →⏱ 1.5 hours
Easy
✓ Free
🚀 Zero to Hacker

Wireshark Packet Analysis

Capture, filter, and dissect network traffic to understand protocols.

Start Lab →⏱ 50 minutes
سهلالعربية
✓ Free
🚀 Zero to Hacker

إعداد بيئة كالي لينكس

Set up your Kali VM, configure tools, and prepare your hacking lab environment.

Start Lab →⏱ ٣٠ دقيقة
سهلالعربية
✓ Free
🚀 Zero to Hacker

فحص الشبكات باستخدام Nmap

Host discovery, port scanning, service detection, OS fingerprinting, and NSE scripts.

Start Lab →⏱ ٤٥ دقيقة

🕸️ Web Security

31 labs
Build Your Skills — Intermediate
Advanced
Outline✓ Free
🕸️ Web Security

Advanced SQL Injection

Second-order SQLi, stored procedures, and WAF bypass techniques.

Start Lab →⏱ 3 hours
Intermediate
Outline✓ Free
🕸️ Web Security

Advanced XSS & CSRF

XSS chaining, CSP bypass, CSRF token theft, and SameSite attribute bypass.

Start Lab →⏱ 1.5 hours
Intermediate
Outline✓ Free
🕸️ Web Security

Attacking Authentication Mechanisms

2FA bypass, brute force protection bypass, and credential stuffing.

Start Lab →⏱ 1.5 hours
Advanced
Outline✓ Free
🕸️ Web Security

Blind SQL Injection

Boolean-based and time-based blind SQLi with sqlmap and manual methods.

Start Lab →⏱ 3 hours
Intermediate
Outline✓ Free
🕸️ Web Security

Broken Authentication & Sessions

Session fixation, prediction, and authentication logic flaws.

Start Lab →⏱ 1.5 hours
Medium
✓ Free
🕸️ Web Security

File Upload Vulnerabilities

Bypass extension filters, MIME type checks, and upload webshells.

Start Lab →⏱ 55 minutes
Intermediate
Outline✓ Free
🕸️ Web Security

Injection Attacks: XPath, LDAP & HTML-to-PDF

Exploit XML XPath and LDAP directory injection vulnerabilities.

Start Lab →⏱ 1.5 hours
Medium
✓ Free
🕸️ Web Security

Local & Remote File Inclusion

Path traversal, null byte injection, PHP wrappers, and remote file inclusion.

Start Lab →⏱ 60 minutes
Intermediate
Outline✓ Free
🕸️ Web Security

NoSQL Injection

MongoDB operator injection, authentication bypass, and data extraction.

Start Lab →⏱ 1.5 hours
Intermediate
✓ Free
🕸️ Web Security

OAuth & JWT Attacks

alg:none bypass, RS256→HS256 confusion, JWT cracking, and OAuth code theft.

Start Lab →⏱ 2 hours
Intermediate
✓ Free
🕸️ Web Security

Server-Side Template Injection (SSTI)

Detect and exploit Jinja2, Twig, and Freemarker SSTI for RCE.

Start Lab →⏱ 2 hours
Intermediate
✓ Free
🕸️ Web Security

SSRF Attacks

Internal service access, cloud metadata exploitation, and SSRF filter bypasses.

Start Lab →⏱ 1.5 hours
Intermediate
✓ Free
🕸️ Web Security

Subdomain Takeover

Enumerate dangling DNS, claim GitHub Pages and S3 buckets, exploit cookie scope.

Start Lab →⏱ 1.5 hours
Intermediate
Outline✓ Free
🕸️ Web Security

Web Attacks: IDOR, XXE & Verb Tampering

XXE external entity injection, blind XXE via OOB, and mass IDOR testing.

Start Lab →⏱ 1.5 hours
Beginner
Outline✓ Free
🕸️ Web Security

WordPress Exploitation

WPScan, plugin CVEs, theme RCE, XML-RPC abuse, and brute force.

Start Lab →⏱ 45 minutes
Go Advanced — Advanced

🏰 Infrastructure & AD

21 labs
Go Advanced — Advanced
Advanced
Outline✓ Free
🏰 Infrastructure & AD

Active Directory Trust Attacks

SID history injection, foreign principal abuse, and cross-forest attacks.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
🏰 Infrastructure & AD

AD Certificate Services (ADCS) Attacks

ESC1–ESC8 ADCS misconfigurations for certificate-based domain compromise.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
🏰 Infrastructure & AD

Application Whitelisting Bypass

AppLocker rule bypass via trusted paths, DLL side-loading, and COM objects.

Start Lab →⏱ 3 hours
Intermediate
Outline✓ Free
🏰 Infrastructure & AD

Attacking Enterprise Networks

Full attack chain from external foothold to domain admin in a lab network.

Start Lab →⏱ 1.5 hours
Advanced
Outline✓ Free
🏰 Infrastructure & AD

Command & Control with Sliver

Deploy and operate the Sliver C2 framework for red team engagements.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
🏰 Infrastructure & AD

DACL Attacks in Active Directory

GenericAll, WriteDACL, GenericWrite, and AddMember for privesc.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
🏰 Infrastructure & AD

MSSQL, Exchange & SCCM Attacks

Linked server abuse, MSSQL xp_cmdshell, Exchange privilege escalation.

Start Lab →⏱ 3 hours
Intermediate
Outline✓ Free
🏰 Infrastructure & AD

Pivoting, Tunneling & Port Forwarding

Proxychains, SSH tunneling, Chisel, and Ligolo for network pivoting.

Start Lab →⏱ 1.5 hours
Advanced
Outline✓ Free
🏰 Infrastructure & AD

Supply Chain Attacks

Build process compromise, dependency confusion, and package hijacking.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
🏰 Infrastructure & AD

Windows Evasion Techniques

AMSI bypass, PowerShell logging bypass, and process injection methods.

Start Lab →⏱ 3 hours
Intermediate
Outline✓ Free
🏰 Infrastructure & AD

Windows Lateral Movement

PSExec, WMI, WinRM, DCOM, and token impersonation for lateral movement.

Start Lab →⏱ 1.5 hours
Intermediate
Outline✓ Free
🏰 Infrastructure & AD

WMI Tradecraft & Analysis

WMI for persistence, lateral movement, and stealthy code execution.

Start Lab →⏱ 1.5 hours

🛡️ Defensive

12 labs
Build Your Skills — Intermediate
Intermediate
Outline✓ Free
🛡️ Defensive

IDS/IPS Detection Engineering

Snort/Suricata rule writing, tuning, and evasion-aware detection.

Start Lab →⏱ 1.5 hours
Intermediate
Outline✓ Free
🛡️ Defensive

Linux Forensics

Disk acquisition, filesystem timeline, log analysis, and bash history forensics.

Start Lab →⏱ 1.5 hours
Intermediate
Outline✓ Free
🛡️ Defensive

Malicious Document Analysis

Analyse malicious Office documents, PDFs, and macros with olevba and remnux.

Start Lab →⏱ 1.5 hours
Intermediate
✓ Free
🛡️ Defensive

Memory Forensics with Volatility

Analyse infected memory dumps: find malware, C2 IPs, injected code, and creds.

Start Lab →⏱ 2 hours
Advanced
Outline✓ Free
🛡️ Defensive

Process Injection & Detection

Detect DLL injection, process hollowing, and reflective injection in EDR logs.

Start Lab →⏱ 3 hours
Intermediate
Outline✓ Free
🛡️ Defensive

Threat Hunting with Elastic

Hypothesis-driven hunting in Elastic/Kibana using KQL and EQL.

Start Lab →⏱ 1.5 hours
Intermediate
Outline✓ Free
🛡️ Defensive

User Behavior Forensics

UEBA concepts, detecting insider threats, and anomalous account activity.

Start Lab →⏱ 1.5 hours
Intermediate
Outline✓ Free
🛡️ Defensive

Windows Attacks & Defense

Attack and detect common Windows attack patterns in a paired lab environment.

Start Lab →⏱ 1.5 hours
Beginner
Outline✓ Free
🛡️ Defensive

YARA & Sigma for Defenders

Write YARA malware signatures and Sigma detection rules for SIEM platforms.

Start Lab →⏱ 45 minutes

💣 Exploit Dev

10 labs
Go Advanced — Advanced
Advanced
Outline✓ Free
💣 Exploit Dev

Dynamic Malware Analysis with WinDbg

Dynamic binary analysis with WinDBG, setting breakpoints, and inspecting memory.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
💣 Exploit Dev

Egghunters & Custom Shellcoding

Egghunter technique for small buffer spaces and custom shellcode writing.

Start Lab →⏱ 3 hours
Advanced
✓ Free
💣 Exploit Dev

Format String Vulnerabilities

Read stack memory, leak canaries, and perform arbitrary writes with %n.

Start Lab →⏱ 2.5 hours
Advanced
Outline✓ Free
💣 Exploit Dev

Introduction to Binary Fuzzing

AFL++, libFuzzer, and coverage-guided fuzzing to discover binary vulnerabilities.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
💣 Exploit Dev

Linux Process Injection & Detection

ptrace-based injection, LD_PRELOAD abuse, and /proc/mem manipulation.

Start Lab →⏱ 3 hours
Advanced
✓ Free
💣 Exploit Dev

Return Oriented Programming (ROP)

Bypass NX/DEP with ROP gadget chains, ret2libc, and ASLR defeat via info leaks.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
💣 Exploit Dev

SEH-Based Buffer Overflows

Structured Exception Handler overflow exploitation with POP/POP/RET chains.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
💣 Exploit Dev

Windows Heap Exploitation

Heap spray, use-after-free, and Windows heap internals for exploitation.

Start Lab →⏱ 3 hours
Advanced
Outline✓ Free
💣 Exploit Dev

Windows Stack Buffer Overflows (x86)

Full 32-bit Windows stack overflow with mona.py and custom shellcode.

Start Lab →⏱ 3 hours

📡 Wireless

9 labs

📱 Mobile

3 labs

☁️ Cloud

2 labs

🌐 Networking

11 labs

🤖 AI Security

14 labs
Build Your Skills — Intermediate
Intermediate
✓ Free
🤖 AI Security

Adversarial AI Evasion Under a Query Budget

Evade a phishing classifier you can train in seconds, but only through the API and only within a query budget — the way a real attacker has to.

Start Lab →⏱ 2.5 hours
Intermediate
✓ Free
🤖 AI Security

AI Data & Model Attacks: The Backdoor That Passes Every Test

Plant a backdoor in training data, keep clean accuracy at 95%, flip every triggered input, and prove the model passes its tests anyway.

Start Lab →⏱ 2.5 hours
Intermediate
🔒 Free account
🤖 AI Security

AI Lab: LLM-Assisted Log and Alert Triage

Run an LLM over a labelled alert corpus and find out where it helps, where it lies, and what it costs.

Start Lab →⏱ 3 hours
Intermediate
🔒 Free account
🤖 AI Security

AI Lab: Model Supply Chain — When torch.load Is Remote Code Execution

A downloaded model file can own your machine on load. Prove it safely, then build the scan-and-refuse controls that stop it — and load only what you trust.

Start Lab →⏱ 3 hours
Intermediate
🔒 Free account
🤖 AI Security

AI Lab: Securing a RAG Pipeline

Build a RAG stack on CPU, break it four ways, then drive the hidden attack tests from fail to pass.

Start Lab →⏱ 4 hours
Intermediate
🔒 Free account
🤖 AI Security

AI Lab: Unbounded Consumption

Turn a summarisation pipeline into a cost bomb, then defuse it with four controls and re-plot the curve.

Start Lab →⏱ 3 hours
Intermediate
🔒 Free account
🤖 AI Security

Excessive Agency

Exploit an agent with an unrestricted shell tool, then add an allowlist and approval gate and prove the same attack now fails. Before/after transcript grading.

Start Lab →⏱ 2 hours
Intermediate
🔒 Free account
🤖 AI Security

Hidden Context Exposure

Extract a decoy API key from a system prompt, then re-architect so the secret is never in context. Flag capture plus a hidden pytest on every context payload.

Start Lab →⏱ 2 hours
Intermediate
✓ Free
🤖 AI Security

LLM Output & Application Attacks

Insecure output handling: turn model output into XSS and command injection, then prove the fix blocks it. A two-stage grader script you run locally.

Start Lab →⏱ 1.5 hours
Intermediate
✓ Free
🤖 AI Security

Prompt Injection Attacks

Direct and indirect prompt injection against a RAG chatbot you build yourself, graded on a canary flag string.

Start Lab →⏱ 1.5 hours

🎮 Game Hacking

2 labs

🕳️ Uncatalogued

3 labs