121 labs
📚 Every track runs top to bottom: start with 🟢 Start Here, build up through 🟡 Build Your Skills, and finish with 🔴 Go Advanced. Use the tabs to jump to a track.

🚀 Zero to Hacker

15 labs
Start Here — Foundations
Easy ✓ Free
🚀 Zero to Hacker

Kali Environment Setup

Set up your Kali VM, configure tools, and prepare your hacking lab environment.

Start Lab →
Easy ✓ Free
🚀 Zero to Hacker

Network Scanning with Nmap

Host discovery, port scanning, service detection, OS fingerprinting, and NSE scripts.

Start Lab →
Easy ✓ Free
🚀 Zero to Hacker

Traffic Analysis with Wireshark

Capture, filter, and dissect network traffic to understand protocols.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

Netcat Fundamentals

Netcat as a network Swiss army knife — listeners, file transfer, reverse shells.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

Python Scripting Lab

Socket programming, subprocess, file I/O, and building basic automation tools.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

DNS Enumeration with Python

Build a DNS reconnaissance tool from scratch in Python.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

File Transfers

Move files between machines using HTTP, FTP, SCP, SMB, and base64 encoding.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

OSINT Reconnaissance

End-to-end passive recon on a target: DNS, WHOIS, Shodan, theHarvester.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

Service Footprinting

Banner grabbing and service enumeration across FTP, SSH, SMTP, SMB, and HTTP.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

Hydra Brute Force

Online password attacks against SSH, FTP, HTTP forms, and RDP with Hydra.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

Password Cracking

Crack NTLM, SHA1, and bcrypt hashes offline using hashcat and John the Ripper.

Start Lab →
Easy 🔒 Members
🚀 Zero to Hacker

Metasploit Basics

msfconsole, searching modules, setting options, running exploits, and Meterpreter.

Start Lab →

🕸️ Web Security

31 labs
Build Your Skills — Intermediate
Intermediate 🔒 Members
🕸️ Web Security

Advanced SQL Injection

Second-order SQLi, stored procedures, and WAF bypass techniques.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

Blind SQL Injection

Boolean-based and time-based blind SQLi with sqlmap and manual methods.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

NoSQL Injection

MongoDB operator injection, authentication bypass, and data extraction.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

XPath & LDAP Injection

Exploit XML XPath and LDAP directory injection vulnerabilities.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

Advanced XSS & CSRF

XSS chaining, CSP bypass, CSRF token theft, and SameSite attribute bypass.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

Broken Authentication & Sessions

Session fixation, prediction, and authentication logic flaws.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

Attacking Authentication

2FA bypass, brute force protection bypass, and credential stuffing.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

File Upload Vulnerabilities

Bypass extension filters, MIME type checks, and upload webshells.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

LFI & RFI

Path traversal, null byte injection, PHP wrappers, and remote file inclusion.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

OAuth & JWT Attacks

alg:none bypass, RS256→HS256 confusion, JWT cracking, and OAuth code theft.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

SSRF Attacks

Internal service access, cloud metadata exploitation, and SSRF filter bypasses.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

Server-Side Template Injection (SSTI)

Detect and exploit Jinja2, Twig, and Freemarker SSTI for RCE.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

IDOR & XXE Attacks

XXE external entity injection, blind XXE via OOB, and mass IDOR testing.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

Subdomain Takeover

Enumerate dangling DNS, claim GitHub Pages and S3 buckets, exploit cookie scope.

Start Lab →
Intermediate 🔒 Members
🕸️ Web Security

WordPress Exploitation

WPScan, plugin CVEs, theme RCE, XML-RPC abuse, and brute force.

Start Lab →

🏰 Infrastructure & AD

21 labs
Go Advanced — Advanced
Advanced 🔒 Members
🏰 Infrastructure & AD

AD Trust Attacks

SID history injection, foreign principal abuse, and cross-forest attacks.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

DACL Abuse Attacks

GenericAll, WriteDACL, GenericWrite, and AddMember for privesc.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

ADCS Certificate Attacks

ESC1–ESC8 ADCS misconfigurations for certificate-based domain compromise.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

Windows Lateral Movement

PSExec, WMI, WinRM, DCOM, and token impersonation for lateral movement.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

MSSQL/Exchange/SCCM Attacks

Linked server abuse, MSSQL xp_cmdshell, Exchange privilege escalation.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

WMI Tradecraft

WMI for persistence, lateral movement, and stealthy code execution.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

Attacking Enterprise Networks

Full attack chain from external foothold to domain admin in a lab network.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

C2 Framework: Sliver

Deploy and operate the Sliver C2 framework for red team engagements.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

Windows Evasion Techniques

AMSI bypass, PowerShell logging bypass, and process injection methods.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

AppLocker Bypass

AppLocker rule bypass via trusted paths, DLL side-loading, and COM objects.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

Pivoting & Tunneling

Proxychains, SSH tunneling, Chisel, and Ligolo for network pivoting.

Start Lab →
Advanced 🔒 Members
🏰 Infrastructure & AD

Supply Chain Attacks

Build process compromise, dependency confusion, and package hijacking.

Start Lab →

📡 Wireless

9 labs

🌐 Networking

11 labs

📱 Mobile

3 labs

☁️ Cloud

2 labs

💣 Exploit Dev

10 labs

🎮 Game Hacking

2 labs

🛡️ Defensive

12 labs

🤖 AI Security

5 labs